Overview
Assess the cybersecurity of technology solutions, vendors, and system changes that access, process, store, or transmit UCSF data.
How to access
Please contact IT Security for details.
Planning a new technology project?
Whether you are purchasing software, implementing a new application, integrating systems, renewing a technology service, or making significant changes to an existing solution, a Cyber Risk Assessment may be required.
Our team evaluates technology solutions that access, process, store, or transmit UCSF data to identify applicable cybersecurity requirements, security findings, and compliance gaps. We will determine the appropriate cybersecurity reviews for your project and guide you through the assessment process.
What to Expect
Step1
Submit Your Request
Submit a Cyber Risk Assessment request through ServiceNow. If additional information is needed, we will contact you.
Request a Cyber Risk AssessmentStep2
We Review Your Request
We review your request to determine the cybersecurity reviews required and identify any additional documentation needed.
Step3
We Assess the Solution
Our analysts evaluate your technology against applicable UCSF cybersecurity requirements. Depending on your project, multiple cybersecurity reviews may be performed.
Step4
Receive Your Results
You will receive an assessment summary describing the assessment outcome, findings, recommendations, and any required next steps.
Cyber Risk Assessments help ensure that technology solutions accessing, processing, storing, or transmitting UCSF data meet applicable cybersecurity requirements.
You should submit a request if your project involves:
- Purchasing or renewing a software product or cloud service
- Implementing a new application or technology solution
- Making significant changes to an existing system
- Creating a new integration or interface between systems
- Allowing a third party to access, process, store, or transmit UCSF data
- Introducing new technologies that will manage UCSF data
You do not need to determine which type of cybersecurity review is required before submitting your request. Our team reviews each request and determines the appropriate assessment activities based on your project.
To help us begin your assessment, please be prepared to provide:
Project Information
- Technology solution or system name
- Business purpose
- Business owner or sponsor
- Technical contact
- Vendor name (if applicable)
- Target implementation or go-live date
Supporting Documentation
Depending on your project, we may request supporting documentation such as:
- Architecture diagrams
- Data flow diagrams
- Integration documentation
- Vendor security documentation
- Security questionnaires
- Independent assurance reports (for example, SOC 2 Type II, HITRUST, or ISO 27001)
You do not need to have all documentation available before submitting your request. Your assigned analyst will let you know if additional information is needed during the assessment.
Depending on the nature of your project, Cyber Risk Assessment Services may notify other UCSF teams that your request could require their review or involvement.
The notified team independently determines whether additional review or follow-up is needed based on their own processes and responsibilities.
You do not need to contact these teams separately before submitting your request.
Cyber Risk Assessment Services evaluates a variety of technology solutions that access, process, store, or transmit UCSF data.
Depending on your project, one or more assessment services may be performed.
Technology Security Review
Evaluates whether a technology solution meets applicable UCSF cybersecurity requirements.
Examples include:
- New software implementations
- Cloud services
- Infrastructure changes
- Major system upgrades
- Significant configuration changes
Third-Party Due Diligence
Evaluates the cybersecurity posture of software vendors and service providers.
Examples include:
- Software as a Service (SaaS)
- Cloud hosting providers
- Managed service providers
- Vendor renewals
Integration Review
Evaluates new or modified connections between systems that exchange UCSF data.
Examples include:
- APIs
- Single Sign-On (SSO)
- Interfaces
- Data exchanges
- System integrations
You do not need to determine which assessment services apply to your project. After reviewing your request, Cyber Risk Assessment Services will determine the appropriate assessments based on the technology, data, and business use case.
What You'll Receive
At the conclusion of the assessment, you will receive an assessment summary that documents the results of our review.
Depending on the assessment, your summary may include:
- Assessment outcome
- Security findings
- Compliance gaps (when applicable)
- Recommendations
- Required remediation activities (when applicable)
- Additional considerations or next steps
If additional action is required, your analyst will explain the next steps and answer any questions about the assessment results.
About Cyber Risk Assessment Services
Cyber Risk Assessment Services evaluates technology solutions that access, process, store, or transmit UCSF data against applicable cybersecurity requirements.
We support the secure acquisition, implementation, integration, modification, and use of technology by evaluating technology solutions against applicable cybersecurity requirements and documenting assessment results.
Cyber Risk Assessments are advisory services. They do not approve projects, vendors, architectures, implementations, procurements, or risk acceptance decisions. Depending on the nature of your project, we may notify other UCSF teams whose services or review may also be applicable.
Use the information below to determine whether your project requires a Cyber Risk Assessment, understand what to expect during the assessment process, and prepare for a successful review.
How can we help you?
Need assistance?
Do you have issue with this service? Submit an IT Service Desk ticket for more assistance with this service.
We want to hear from you
Have you noticed a technical or content issue with this page? Provide feedback to assist the content owner with enhancing the content?
Send Feedback