A knowledge base article about CPHS Questionnaire Guide for Electronic Safeguards provided by the UC Berkeley IT Service Hub - Knowledge Portal
The objective of the CPHS assessment is to ensure that covered devices (e.g., workstations, laptops, servers) comply with the data security requirements issued by the California Health and Human Services Agency (CHHSA) Committee for the Protection of Human Subjects (CPHS).
This guide walks through the questions in the Electronic Safeguards section and provides instructions to help you fulfill compliance requirements.
Table of Contents
ISO recommends the Secure Research Data & Compute (SRDC) platform or another approved server environment for handling PID. If you would like to use the SRDC platform, please contact Research IT for a consulting appointment.
Approved server environments:
Many requirements refer to the FIPS-140-2 standard, which specifies security requirements for cryptographic modules.
Fill out the CPHS Researchers and Covered Devices Google document.
Do workstations or laptops that handle PID have full disk encryption that uses FIPS 140-2 compliant encryption?
Do removable media devices (USB drives, CD/DVDs, smartphones, backup tapes) have FIPS 140-2 compliant full disk encryption?
FIPS 140-2 compliant USB flash drives can be purchased to fulfill this requirement. Encryption and decryption are performed on the drive, leaving no trace on the host system.
Do you apply security patches to all systems handling PID?
Do all systems and media enforce strong passphrase controls consistent with campus passphrase requirements?
Ensure that all passphrases in the PID computing environment adhere to campus Passphrase Guidelines. These requirements apply to local user, SSO, default, and service accounts.
Do all users utilizing PID utilize a password manager?
ISO recommends using LastPass. UC Berkeley offers Free LastPass Premium (KB0013773) to all students, staff, and faculty.
Is the automatic screen lock set to 15 minutes or less?
Is anti-virus software used and configured to auto-update?
Are your servers registered in Socreg to take advantage of campus intrusion detection and prevention services?
All server environments not in SRDC must be registered. Review the Socreg Asset Registration service page for more details.
Are your servers participating in the campus log correlation service?
Non-SRDC servers can enroll in the Security Event Logging service.
Are automated audit trails enabled?
Describe the logging capabilities for logon events, policy changes, and privilege escalation on all PID-handling devices.
Is electronic PID encrypted when transmitted outside the secure network?
Refer to the Data Encryption in Transit Guideline.
Are systems storing PID inaccessible from the internet?
Systems should generally not be accessible from the internet. If remote access is required, you must comply with MSSND #8: Remote Access Services.
Will PID be securely disposed of at the end of the project?
Use the campus Secure Deletion Guideline to determine the best method.
Do all devices meet campus Minimum Security Standards for Networked Devices?