A knowledge base article about Vendor Security Assessment FAQs provided by the UC Berkeley IT Service Hub - Knowledge Portal
Table of Contents
Units are allowed one (1) resubmission for Vendors with an overall Not Recommended rating. Before resubmitting, the Unit must ensure the Vendor has addressed the specific deficiencies identified in the initial assessment. If a Vendor receives a second Not Recommended rating, please consider alternative vendors or apply for an exception.
Why is there a limit on resubmissions?
The roles that are typically involved in participating in a Vendor Security Assessment include the following:
| Role | Responsibilities |
|---|---|
| Resource Owner/Proprietor | Campus unit representative who has overall responsibility for the application (e.g., budgeting and resource allocation). |
| Implementation Project Manager | Unit member responsible for the roll-out of the application or service, including vendor selection, configuration, and training. |
| UC Buyer | Representative in the UC Procurement department responsible for the Vendor contract negotiation. |
| Vendor Representative | Staff member of the service provider responsible for completing the Questionnaire. Ideally knowledgeable regarding the Vendor's security framework. |
| ISO Assessor | A member of the ISO analysts team assigned as the primary assessor for the engagement. |
To request a Vendor Security Assessment Program evaluation for a PL2 system that is vendor-managed, review the Technical Details of the VSAP and then send an email to security-assessments@berkeley.edu.
Please include the following information:
AI functionality must be evaluated for security, privacy, and general AI risks. ISO will ask you to provide answers to these types of questions when triaging your VSA request:
Once a VSA is complete, ISO recommends reviewing the guidance letter and the Venminder report with your Unit Information Security Lead (UISL) to decide on the appropriate course of action. The ISO guidance letter will specify what type of response the Unit requires per campus policy.
The Requester is responsible for signing any NDAs with the Vendor. Inform the ISO Assessments Team on your corresponding ServiceNow ticket if the Vendor is asking that ISO or Venminder sign the NDA.
Yes. The Requester is responsible for providing vendor contact details, product name, and a completed UC Appendix DS Exhibit 1 form. Additionally, the following will speed up the process:
A typical VSA takes 4 to 6 weeks starting from the date the Vendor has provided all requested information. Please plan accordingly.
Units should review the Responsibilities & Expectations (PDF) and share it with the Vendor so they are prepared for the process.
An entity separate from the University that offers technologies used to store, process, or transport protected data on behalf of the University. This includes SaaS (e.g., Google) and IaaS (e.g., AWS) providers.
It is still a good idea to perform a VSA for service providers handling UC PL3 or PL4 data. If the risk is High or Critical, it may be necessary to postpone or suspend service until issues are addressed.
Yes. Using these pre-approved services ensures they meet campus standards:
Visit the bConnected website for specific protection level details.
The program ensures service providers handling UC PL4 data meet policy requirements by evaluating security controls and ensuring the UCOP Data Security & Privacy Appendix is included in the contract.
UCOP requires the Data Security and Privacy Appendix for all contracts involving covered data. If omitted, the VSA will likely return Critical risk findings, and use of the service may need to be suspended until resolved.