A knowledge base article about Details about the Vendor Security Assessment Service provided by the UC Berkeley IT Service Hub - Knowledge Portal
Table of Contents
The Information Security Office (ISO) offers a Vendor Security Assessment (VSA) Service for agreements involving vendor access to UC systems or to data classified at Protection Level P3 or P4. The VSA requirement applies to new vendor agreements, renegotiated agreements, and renewals.
The purpose of the VSA Service is to determine whether the vendor’s security plan is adequate to safeguard UC systems and data. At the conclusion of the service, a report is provided to the requesting party including an overall risk rating, identified risks, and recommendations.
Note: A typical VSA takes 4 - 6 weeks to complete, starting from the date the vendor has provided all requested information. Please plan accordingly.
The following campus roles typically participate in a VSA:
| Role | Responsibilities |
|---|---|
| Requester |
|
| Buyer | Representative in the UC Procurement department responsible for the vendor contract negotiation. |
| ISO Analyst | Member of the ISO Security Assessments Team who reviews the vendor’s security plan and provides the final risk report and recommendations. |
| Venminder | ISO’s contracted partner used to perform technical information security assessments on ISO’s behalf. |
If you have questions, please email security-assessments@berkeley.edu.
For detailed answers to the following questions, please see: KB0015387 - Vendor Security Assessment FAQs.