Cyber Risk Assessment Services

Questions? Get IT help

Overview

Assess the cybersecurity of technology solutions, vendors, and system changes that access, process, store, or transmit UCSF data.

How to access

Please contact IT Security for details.

Planning a new technology project?

Whether you are purchasing software, implementing a new application, integrating systems, renewing a technology service, or making significant changes to an existing solution, a Cyber Risk Assessment may be required.

Our team evaluates technology solutions that access, process, store, or transmit UCSF data to identify applicable cybersecurity requirements, security findings, and compliance gaps. We will determine the appropriate cybersecurity reviews for your project and guide you through the assessment process.

What to Expect

Step1

Submit Your Request

Submit a Cyber Risk Assessment request through ServiceNow. If additional information is needed, we will contact you.

Request a Cyber Risk Assessment

Step2

We Review Your Request

We review your request to determine the cybersecurity reviews required and identify any additional documentation needed.

Step3

We Assess the Solution

Our analysts evaluate your technology against applicable UCSF cybersecurity requirements. Depending on your project, multiple cybersecurity reviews may be performed.

Step4

Receive Your Results

You will receive an assessment summary describing the assessment outcome, findings, recommendations, and any required next steps.

Cyber Risk Assessments help ensure that technology solutions accessing, processing, storing, or transmitting UCSF data meet applicable cybersecurity requirements.

You should submit a request if your project involves:

  • Purchasing or renewing a software product or cloud service
  • Implementing a new application or technology solution
  • Making significant changes to an existing system
  • Creating a new integration or interface between systems
  • Allowing a third party to access, process, store, or transmit UCSF data
  • Introducing new technologies that will manage UCSF data

You do not need to determine which type of cybersecurity review is required before submitting your request. Our team reviews each request and determines the appropriate assessment activities based on your project.

To help us begin your assessment, please be prepared to provide:

Project Information

  • Technology solution or system name
  • Business purpose
  • Business owner or sponsor
  • Technical contact
  • Vendor name (if applicable)
  • Target implementation or go-live date

Supporting Documentation

Depending on your project, we may request supporting documentation such as:

  • Architecture diagrams
  • Data flow diagrams
  • Integration documentation
  • Vendor security documentation
  • Security questionnaires
  • Independent assurance reports (for example, SOC 2 Type II, HITRUST, or ISO 27001)

You do not need to have all documentation available before submitting your request. Your assigned analyst will let you know if additional information is needed during the assessment.

Depending on the nature of your project, Cyber Risk Assessment Services may notify other UCSF teams that your request could require their review or involvement.

The notified team independently determines whether additional review or follow-up is needed based on their own processes and responsibilities.

You do not need to contact these teams separately before submitting your request.

Cyber Risk Assessment Services evaluates a variety of technology solutions that access, process, store, or transmit UCSF data.

Depending on your project, one or more assessment services may be performed.

Technology Security Review

Evaluates whether a technology solution meets applicable UCSF cybersecurity requirements.

Examples include:

  • New software implementations
  • Cloud services
  • Infrastructure changes
  • Major system upgrades
  • Significant configuration changes

Third-Party Due Diligence

Evaluates the cybersecurity posture of software vendors and service providers.

Examples include:

  • Software as a Service (SaaS)
  • Cloud hosting providers
  • Managed service providers
  • Vendor renewals

Integration Review

Evaluates new or modified connections between systems that exchange UCSF data.

Examples include:

  • APIs
  • Single Sign-On (SSO)
  • Interfaces
  • Data exchanges
  • System integrations

You do not need to determine which assessment services apply to your project. After reviewing your request, Cyber Risk Assessment Services will determine the appropriate assessments based on the technology, data, and business use case.

What You'll Receive

At the conclusion of the assessment, you will receive an assessment summary that documents the results of our review.

Depending on the assessment, your summary may include:

  • Assessment outcome
  • Security findings
  • Compliance gaps (when applicable)
  • Recommendations
  • Required remediation activities (when applicable)
  • Additional considerations or next steps

If additional action is required, your analyst will explain the next steps and answer any questions about the assessment results.

About Cyber Risk Assessment Services

Cyber Risk Assessment Services evaluates technology solutions that access, process, store, or transmit UCSF data against applicable cybersecurity requirements.

We support the secure acquisition, implementation, integration, modification, and use of technology by evaluating technology solutions against applicable cybersecurity requirements and documenting assessment results.

Cyber Risk Assessments are advisory services. They do not approve projects, vendors, architectures, implementations, procurements, or risk acceptance decisions. Depending on the nature of your project, we may notify other UCSF teams whose services or review may also be applicable.

Use the information below to determine whether your project requires a Cyber Risk Assessment, understand what to expect during the assessment process, and prepare for a successful review.

Service Owner Team: IT Security
Service Support Team: IT Security
Service Category: Security

How can we help you?

Need assistance?

Do you have issue with this service? Submit an IT Service Desk ticket for more assistance with this service.

Get IT Help

We want to hear from you

Have you noticed a technical or content issue with this page? Provide feedback to assist the content owner with enhancing the content?

Send Feedback