Socreg User Guide: Basic Functions and Use Cases

A knowledge base article about Socreg User Guide: Basic Functions and Use Cases provided by the UC Berkeley IT Service Hub - Knowledge Portal

What is Socreg?

Socreg is a self-service asset registration portal developed by the Information Security Office (ISO) to help campus departments and their Security Contacts maintain the registration of network assets and Protected Data, and to meet Policy requirements. 

Socreg is designed to allow Security Contacts to update assets (IP Addresses and Subnets, Offsite Hostnames, Protected Data Applications, etc.). 

Please note: Users accessing socreg.berkeley.edu from off-campus or while connected to CalVisitor must use the campus VPN.

What is a Security Contact?

A Security Contact is a group in your department that receives and responds to security notices from UC Berkeley’s Information Security Office (ISO). As a member, you have two main responsibilities:

  1. Manage your department's registered assets for routine security monitoring.
  2. Respond to or forward any security notices related to those assets.
Registered assets include computers and devices connected to the campus network. Click “Help” in the upper right corner of any Socreg page for additional information.
 

How to establish a Security Contact

Users accessing socreg.berkeley.edu from an off-campus IP address or while connected to Berkeley-Visitor WiFi will need to use the campus VPN.

Click on the left sidebar item ‘Asset/Access Requests’.

As a member of a Security Contact, you can view and edit its details and membership. Each asset type has its own tab for viewing, adding, or removing assets. Registered assets will send security notices to the Security Contact's email, while other Socreg business emails go to individual members.

Helpful use cases to showcase how Socreg Security Contacts work

Use Case #1: Your department has several subunits that each manage their own network resources.

Solution: Socreg supports a parent-child relationship through “Group Security Contacts."

Group Security Contacts:

Use Case #2: You manage all devices for your department, but some labs, research groups, or other sub-units would also like to receive notices for their systems directly.

Solution: Socreg supports additional notices through “CC IP addresses"

Use Case #3: All of your department's IT resources are managed by IT Client Services.

Solution: Add IT Client Services to your Security Contact as a “Service Provider"

Use Case #4: Your department maintains some systems internally, while other systems are supported by IT Client Services.

Solution: Create a “Group Security Contact” and add IT Client Services as a Service Provider

Use Case #5: You are a database administrator, application developer, or otherwise support applications/middleware. The system administrators for the servers hosting your services now receive security notices, but you would like to receive them as well.

Solution: Socreg supports additional notices through “CC Security Contact IP addresses."

Use Case #6: You are a researcher within a large department. As part of your research, you have Protected Data on a server managed by Berkeley IT in the data center. 

Solution: Create a Group Security Contact under your Department Security Contact