Details about the Vendor Security Assessment Service

A knowledge base article about Details about the Vendor Security Assessment Service provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

The Information Security Office (ISO) offers a Vendor Security Assessment (VSA) Service for agreements involving vendor access to UC systems or to data classified at Protection Level P3 or P4. The VSA requirement applies to new vendor agreements, renegotiated agreements, and renewals.

The purpose of the VSA Service is to determine whether the vendor’s security plan is adequate to safeguard UC systems and data. At the conclusion of the service, a report is provided to the requesting party including an overall risk rating, identified risks, and recommendations.

Note: A typical VSA takes 4 - 6 weeks to complete, starting from the date the vendor has provided all requested information. Please plan accordingly.

Roles and Responsibilities

The following campus roles typically participate in a VSA:

Role Responsibilities
Requester
  • Filling out the VSA intake form.
  • Coordinating with the vendor to ensure ISO and Venminder have all required information.
  • Responding to technical or use-case questions during the assessment.
  • Coordinating with the Unit Information Security Lead (UISL) and Unit Head to manage risks identified in the final report.
Buyer Representative in the UC Procurement department responsible for the vendor contract negotiation.
ISO Analyst Member of the ISO Security Assessments Team who reviews the vendor’s security plan and provides the final risk report and recommendations.
Venminder ISO’s contracted partner used to perform technical information security assessments on ISO’s behalf.

How to Get Started

  1. Gather the following from the Vendor:
    • Contact info (Name, title, email, phone).
    • Vendor Product Name.
    • SOC 2 Type II report (if available).
    • PCI DSS documentation (SAQ, AOC) if the vendor handles credit card data.
  2. Identify internal details: Unit name, Requester contact info, and the Procurement Buyer contact info.
  3. Complete Appendix DS Exhibit 1. (Contact the Privacy Office if assistance is needed).
  4. Work with your Buyer to ensure the vendor accepts Appendix DS terms and carries adequate cybersecurity insurance.
  5. Submit the Request a Vendor Security Assessment form (CalNet login required).
  6. Inform the vendor that Venminder will reach out to them on behalf of UC Berkeley.

If you have questions, please email security-assessments@berkeley.edu.

Frequently Asked Questions

For detailed answers to the following questions, please see: KB0015387 - Vendor Security Assessment FAQs.

Additional Resources