Vendor Security Assessment FAQs

A knowledge base article about Vendor Security Assessment FAQs provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Can I request a new assessment for a Vendor that previously received a “Not Recommended” rating?

Units are allowed one (1) resubmission for Vendors with an overall Not Recommended rating. Before resubmitting, the Unit must ensure the Vendor has addressed the specific deficiencies identified in the initial assessment. If a Vendor receives a second Not Recommended rating, please consider alternative vendors or apply for an exception.

Why is there a limit on resubmissions?

Who needs to be involved in a Vendor Security Assessment?

The roles that are typically involved in participating in a Vendor Security Assessment include the following:

Role Responsibilities
Resource Owner/Proprietor Campus unit representative who has overall responsibility for the application (e.g., budgeting and resource allocation).
Implementation Project Manager Unit member responsible for the roll-out of the application or service, including vendor selection, configuration, and training.
UC Buyer Representative in the UC Procurement department responsible for the Vendor contract negotiation.
Vendor Representative Staff member of the service provider responsible for completing the Questionnaire. Ideally knowledgeable regarding the Vendor's security framework.
ISO Assessor A member of the ISO analysts team assigned as the primary assessor for the engagement.

How do I get started?

To request a Vendor Security Assessment Program evaluation for a PL2 system that is vendor-managed, review the Technical Details of the VSAP and then send an email to security-assessments@berkeley.edu.

Please include the following information:

What do I need to do if a Vendor's products or services use Artificial Intelligence (AI)?

AI functionality must be evaluated for security, privacy, and general AI risks. ISO will ask you to provide answers to these types of questions when triaging your VSA request:

Additional AI Resources

What should I do with the Venminder report and ISO guidance letter after an assessment is completed?

Once a VSA is complete, ISO recommends reviewing the guidance letter and the Venminder report with your Unit Information Security Lead (UISL) to decide on the appropriate course of action. The ISO guidance letter will specify what type of response the Unit requires per campus policy.

The Vendor requires a Non-Disclosure Agreement (NDA) to release security documentation. Who should sign the NDA?

The Requester is responsible for signing any NDAs with the Vendor. Inform the ISO Assessments Team on your corresponding ServiceNow ticket if the Vendor is asking that ISO or Venminder sign the NDA.

Will I need to provide any additional information or documents when requesting a VSA?

Yes. The Requester is responsible for providing vendor contact details, product name, and a completed UC Appendix DS Exhibit 1 form. Additionally, the following will speed up the process:

How long will a VSA take using Venminder?

A typical VSA takes 4 to 6 weeks starting from the date the Vendor has provided all requested information. Please plan accordingly.

What are the responsibilities and expectations for Units and Vendors during the VSA process?

Units should review the Responsibilities & Expectations (PDF) and share it with the Vendor so they are prepared for the process.

What is a "3rd-party service provider"?

An entity separate from the University that offers technologies used to store, process, or transport protected data on behalf of the University. This includes SaaS (e.g., Google) and IaaS (e.g., AWS) providers.

The contract has already been signed. What do I do?

It is still a good idea to perform a VSA for service providers handling UC PL3 or PL4 data. If the risk is High or Critical, it may be necessary to postpone or suspend service until issues are addressed.

Are Vendor services available that have already been approved?

Yes. Using these pre-approved services ensures they meet campus standards:

Visit the bConnected website for specific protection level details.

What is the purpose of the Vendor Security Assessment Program?

The program ensures service providers handling UC PL4 data meet policy requirements by evaluating security controls and ensuring the UCOP Data Security & Privacy Appendix is included in the contract.

The Data Security & Privacy Appendix was not included in the vendor contract. What do I do?

UCOP requires the Data Security and Privacy Appendix for all contracts involving covered data. If omitted, the VSA will likely return Critical risk findings, and use of the service may need to be suspended until resolved.