A knowledge base article about Socreg User Guide: Basic Functions and Use Cases provided by the UC Berkeley IT Service Hub - Knowledge Portal
What is Socreg?
Socreg is a self-service asset registration portal developed by the Information Security Office (ISO) to help campus departments and their Security Contacts maintain the registration of network assets and Protected Data, and to meet Policy requirements.
Socreg is designed to allow Security Contacts to update assets (IP Addresses and Subnets, Offsite Hostnames, Protected Data Applications, etc.).
Please note: Users accessing socreg.berkeley.edu from off-campus or while connected to CalVisitor must use the campus VPN.
What is a Security Contact?
A Security Contact is a group in your department that receives and responds to security notices from UC Berkeley’s Information Security Office (ISO). As a member, you have two main responsibilities:
- Manage your department's registered assets for routine security monitoring.
- Respond to or forward any security notices related to those assets.
Registered assets include computers and devices connected to the campus network. Click “Help” in the upper right corner of any Socreg page for additional information.
How to establish a Security Contact
Users accessing socreg.berkeley.edu from an off-campus IP address or while connected to Berkeley-Visitor WiFi will need to use the campus VPN.
Click on the left sidebar item ‘Asset/Access Requests’.
- If you’re not a member and a Security Contact exists, you can request membership by selecting “Request membership” from the New Requests drop-down. Your request will need approval from a Security Contact member.
- If there’s no Security Contact for your department, request one by choosing "New Departmental Request" from the New Requests drop-down.
As a member of a Security Contact, you can view and edit its details and membership. Each asset type has its own tab for viewing, adding, or removing assets. Registered assets will send security notices to the Security Contact's email, while other Socreg business emails go to individual members.
Helpful use cases to showcase how Socreg Security Contacts work
Use Case #1: Your department has several subunits that each manage their own network resources.
Solution: Socreg supports a parent-child relationship through “Group Security Contacts."
Group Security Contacts:
- Establish a Security Contact
- Claim subnets and IP addresses for your Security Contact
- Create Group Security Contacts for each sub-unit
- You will automatically be the first member, but you can add others by their CalNet ID.
- Check "Security Notices to parent also?” if notices should also go to the parent Security Contact
- Now members of the Group Security Contacts can:
- Claim subnets and IP addresses for their Security Contacts
- Add and remove members to the Security Contact
- You can be a member of both the parent and child Security Contact.
Use Case #2: You manage all devices for your department, but some labs, research groups, or other sub-units would also like to receive notices for their systems directly.
Solution: Socreg supports additional notices through “CC IP addresses"
- Under the “CC IPs” tab, add other Security Contacts to your IP addresses if they should be copied on any security notices sent to that IP address.
- Or, request CC IP addresses from other Security Contacts if you should be copied on their security notices.
Use Case #3: All of your department's IT resources are managed by IT Client Services.
Solution: Add IT Client Services to your Security Contact as a “Service Provider"
- Add IT Client Services as the service provider for your Security Contact. Note: contact IT Client Services before making this change. It is necessary to go through their onboarding process.
- ITCS staff can now add and remove network assets for your Security Contact.
- And ITCS will be automatically copied on any security notice sent to your registered assets, so they can help you resolve it.
Use Case #4: Your department maintains some systems internally, while other systems are supported by IT Client Services.
Solution: Create a “Group Security Contact” and add IT Client Services as a Service Provider
- Create a Group Security Contact under your Department Security Contact and add yourself as a member.
- Select IT Client Services as the Service Provider for this Security Contact. Note: contact IT Client Services before making this change. It is necessary to go through their onboarding process.
- Move assets as appropriate from the Department Security Contact to the Group Security Contact supported by IT Client Services.
Use Case #5: You are a database administrator, application developer, or otherwise support applications/middleware. The system administrators for the servers hosting your services now receive security notices, but you would like to receive them as well.
Solution: Socreg supports additional notices through “CC Security Contact IP addresses."
- Establish a Security Contact
- Request CC IP Addresses for the systems hosting your services
- The Security Contact claiming these IP addresses will need to approve your request
- Once approved, you will begin to be copied on security notices for these IP addresses
Use Case #6: You are a researcher within a large department. As part of your research, you have Protected Data on a server managed by Berkeley IT in the data center.
Solution: Create a Group Security Contact under your Department Security Contact
- Request the group from your Department Security Contact, providing its name, security notice email address, and other information.
- Register your Protected Data (PD) Application to your new Security Contact, including Protection Level, number of records, etc.
- Add components (IP Addresses, Devices, etc.) to the PD Application even if those assets belong to other Security Contacts.