CPHS Questionnaire Guide for Electronic Safeguards

A knowledge base article about CPHS Questionnaire Guide for Electronic Safeguards provided by the UC Berkeley IT Service Hub - Knowledge Portal

The objective of the CPHS assessment is to ensure that covered devices (e.g., workstations, laptops, servers) comply with the data security requirements issued by the California Health and Human Services Agency (CHHSA) Committee for the Protection of Human Subjects (CPHS).

This guide walks through the questions in the Electronic Safeguards section and provides instructions to help you fulfill compliance requirements.

Table of Contents

Technical Details

ISO recommends the Secure Research Data & Compute (SRDC) platform or another approved server environment for handling PID. If you would like to use the SRDC platform, please contact Research IT for a consulting appointment.

Approved server environments:

Many requirements refer to the FIPS-140-2 standard, which specifies security requirements for cryptographic modules.

Before beginning the questionnaire

Fill out the CPHS Researchers and Covered Devices Google document.

  1. When finished, give ciso-mssei-ssp@calgroups.berkeley.edu commenter access.
  2. Keep the URL of the document handy to provide in the questionnaire.
  3. Keep this document updated for your own records/inventory.

Additional Resources


ELEC-01: Full Disk Encryption

Do workstations or laptops that handle PID have full disk encryption that uses FIPS 140-2 compliant encryption?

ELEC-02: Removable Media Encryption

Do removable media devices (USB drives, CD/DVDs, smartphones, backup tapes) have FIPS 140-2 compliant full disk encryption?

FIPS 140-2 compliant USB flash drives can be purchased to fulfill this requirement. Encryption and decryption are performed on the drive, leaving no trace on the host system.

ELEC-03: Security Patching

Do you apply security patches to all systems handling PID?

ELEC-04: Strong Passphrase Controls

Do all systems and media enforce strong passphrase controls consistent with campus passphrase requirements?

Ensure that all passphrases in the PID computing environment adhere to campus Passphrase Guidelines. These requirements apply to local user, SSO, default, and service accounts.

ELEC-05: Password Managers

Do all users utilizing PID utilize a password manager?

ISO recommends using LastPass. UC Berkeley offers Free LastPass Premium (KB0013773) to all students, staff, and faculty.

ELEC-06: Automatic Screen Lock

Is the automatic screen lock set to 15 minutes or less?

ELEC-07: Anti-Virus Software

Is anti-virus software used and configured to auto-update?

ELEC-08: Socreg Registration

Are your servers registered in Socreg to take advantage of campus intrusion detection and prevention services?

All server environments not in SRDC must be registered. Review the Socreg Asset Registration service page for more details.

ELEC-09: Log Correlation Service

Are your servers participating in the campus log correlation service?

Non-SRDC servers can enroll in the Security Event Logging service.

ELEC-10: Automated Audit Trails

Are automated audit trails enabled?

Describe the logging capabilities for logon events, policy changes, and privilege escalation on all PID-handling devices.

ELEC-11: Data Encryption in Transit

Is electronic PID encrypted when transmitted outside the secure network?

Refer to the Data Encryption in Transit Guideline.

ELEC-12: Internet Accessibility

Are systems storing PID inaccessible from the internet?

Systems should generally not be accessible from the internet. If remote access is required, you must comply with MSSND #8: Remote Access Services.

ELEC-13: Secure Disposal

Will PID be securely disposed of at the end of the project?

Use the campus Secure Deletion Guideline to determine the best method.

ELEC-14: MSSND Compliance

Do all devices meet campus Minimum Security Standards for Networked Devices?