UC Policy IS-3 (v2019)
Overview of UC Policy BFB-IS-3
University of California Policy BFB-IS-3, published in 2019 by the UC Office of the President, establishes comprehensive information security requirements for all University of California locations, including campuses, medical centers, and national laboratories. The policy defines information security requirements for protecting institutional data and information systems across the UC system, covering governance, risk management, data classification, access controls, and specific security controls for safeguarding university assets. BFB-IS-3 emerged as part of UC's comprehensive information security program, recognizing that universities face unique security challenges including protection of research data, student information, and intellectual property.
The policy applies to all UC locations and third parties handling institutional data, establishing mandatory security requirements that ensure consistent protection of university information assets. BFB-IS-3 addresses the unique security challenges facing higher education institutions, including diverse IT environments, research data protection, student privacy requirements, and integration with external partners. The policy provides a framework for implementing information security controls that protect institutional data while enabling academic and research activities.
BFB-IS-3 establishes requirements for information security governance, risk management, data classification, access controls, encryption, incident response, and third-party security management. The policy requires UC locations to implement comprehensive information security programs, conduct risk assessments, classify data based on sensitivity, and implement security controls appropriate to data classification levels. Understanding BFB-IS-3 requirements enables UC locations and third parties to implement security programs that protect institutional data and comply with UC policy requirements.
Framework Applicability and Adoption
UC Policy BFB-IS-3 applies to all University of California locations including campuses, medical centers, national laboratories, and other UC facilities. The policy also applies to third parties that handle UC institutional data, requiring them to implement security controls that protect UC information. All UC locations must comply with BFB-IS-3 requirements as part of their information security obligations.
Adoption of BFB-IS-3 has been mandatory for all UC locations, driving widespread implementation of information security programs across the UC system. The policy's mandatory nature and enforcement by UC Office of the President ensure consistent security practices across UC locations. UC locations have implemented information security programs, risk management processes, data classification systems, and security controls to comply with BFB-IS-3 requirements.
Key Framework Components and Security Requirements
UC Policy BFB-IS-3 organizes information security requirements into key areas that address governance, risk management, data classification, access controls, encryption, incident response, and third-party security management. Each area provides specific requirements that UC locations and third parties must implement to achieve compliance.
Information Security Governance
BFB-IS-3 requires UC locations to establish information security governance structures that ensure effective information security management. Governance requirements include designation of information security officers, establishment of information security committees, and implementation of governance processes that provide oversight of information security programs. UC locations must establish clear accountability for information security outcomes, typically through designated leadership roles such as Chief Information Security Officers (CISOs) or equivalent positions.
Governance frameworks must include executive oversight, documented policies and procedures, and regular reporting mechanisms that provide visibility into security posture and emerging threats. UC locations must maintain awareness of evolving threat landscape and adjust security strategies accordingly. Information security governance enables UC locations to establish effective security programs and ensure that security remains a priority.
Risk Management and Assessment
BFB-IS-3 requires UC locations to implement risk management processes that identify, assess, and manage information security risks. Risk assessments must identify threats, vulnerabilities, and potential impacts to information security, enabling prioritization of security investments and control implementations based on actual risk exposure. UC locations must conduct regular risk assessments that address organizational risks, system risks, and operational risks that may affect information security.
Risk management processes must be integrated into organizational operations, updated regularly, and documented comprehensively. UC locations should establish risk management frameworks that address information security risks, implement risk mitigation strategies, and monitor risk management effectiveness. Risk management enables UC locations to identify and address security risks that may compromise information security.
Data Classification and Protection
BFB-IS-3 requires UC locations to classify institutional data based on sensitivity and implement protection measures appropriate to data classification levels. Data classification must address various data types including student records, research data, financial information, and personally identifiable information (PII). UC locations must implement data classification systems that identify data sensitivity and apply protection measures commensurate with risk.
Data protection requirements include encryption for sensitive data, access controls that restrict data access, and secure data handling procedures. UC locations must implement encryption for data at rest and in transit, establish access controls that prevent unauthorized data access, and implement secure data handling procedures that protect data throughout its lifecycle. Data classification and protection enable UC locations to protect institutional data appropriately.
Access Control and Identity Management
BFB-IS-3 requires UC locations to implement access controls that prevent unauthorized access to information systems and data. Access controls must include user authentication, authorization, and access management processes that prevent unauthorized access. UC locations must implement strong authentication mechanisms, including multi-factor authentication for high-risk access scenarios, and enforce the principle of least privilege.
Access control implementations must address both human users and system accounts, with particular attention to privileged accounts that possess elevated permissions. UC locations should implement role-based access controls that grant users access based on their job functions, conduct regular access reviews, and remove access when no longer needed. Access control and identity management enable UC locations to protect information from unauthorized access.
Encryption and Data Protection
BFB-IS-3 requires UC locations to implement encryption for sensitive institutional data both at rest and in transit. Encryption requirements typically cover data stored on devices and systems, as well as data moving across networks. UC locations must implement encryption standards that protect sensitive data, establish encryption key management processes, and ensure that encryption is implemented consistently.
Data protection programs must address the full information lifecycle, from creation through disposal. UC locations should implement secure deletion procedures, backup protection, and data loss prevention technologies that ensure sensitive information remains confidential and available when needed. Encryption and data protection enable UC locations to protect institutional data from unauthorized access or disclosure.
Incident Response and Business Continuity
BFB-IS-3 requires UC locations to develop and implement incident response plans that address information security incidents. Incident response plans must address incident detection, containment, eradication, and recovery procedures. UC locations must establish incident response teams, define roles and responsibilities, and establish communication procedures that enable effective incident management.
Incident response plans must be tested regularly, updated based on lessons learned, and integrated with business continuity plans. UC locations should maintain relationships with law enforcement, external cybersecurity experts, and communication teams to support effective incident management. Incident response and business continuity enable UC locations to respond effectively to security incidents and maintain operations.
Third-Party Security Management
BFB-IS-3 requires UC locations to implement third-party security management processes that assess and manage security risks from third-party service providers handling UC institutional data. Third-party security management must include due diligence assessments, contract requirements, ongoing monitoring, and incident notification obligations. UC locations must ensure that third parties implement security controls that protect UC data.
Third-party security management processes must assess third-party security capabilities, establish contract requirements that address security expectations, and monitor third-party compliance. UC locations should conduct regular third-party risk assessments, update third-party security management programs based on changes in third-party relationships, and ensure that third parties notify UC of security incidents. Third-party security management enables UC locations to manage security risks from third-party relationships.
Implementation Strategies and Best Practices
Successfully implementing UC Policy BFB-IS-3 requires UC locations to assess current information security posture, develop information security programs, and implement security controls progressively. UC locations should begin with gap assessments that evaluate current security practices against BFB-IS-3 requirements, identify compliance gaps, and develop implementation roadmaps.
Conduct BFB-IS-3 Gap Assessment: UC locations should assess current information security practices against BFB-IS-3 requirements to identify compliance gaps and prioritize implementation efforts. Gap assessments should evaluate governance structures, risk management processes, data classification systems, access controls, encryption implementation, and incident response capabilities. Assessment results should inform implementation roadmaps and resource allocation decisions, enabling UC locations to focus on areas that require immediate attention.
Develop Comprehensive Information Security Program: UC locations must develop information security programs that address BFB-IS-3 requirements and are based on risk assessments. Security programs must be documented, approved by senior management, and integrated into organizational operations. UC locations should ensure that security programs address identified risks, implement appropriate controls, and establish processes for continuous improvement. Comprehensive security programs enable UC locations to achieve and maintain BFB-IS-3 compliance.
Establish Information Security Governance: UC locations must establish information security governance structures that ensure effective security management. Governance structures must include executive oversight, security management structures, and reporting mechanisms. UC locations should establish information security committees, designate information security officers, and implement governance processes that enable effective security management. Strong governance enables UC locations to implement effective security programs.
Implement Data Classification System: UC locations must implement data classification systems that identify data sensitivity and apply protection measures appropriate to classification levels. Data classification systems must address various data types including student records, research data, financial information, and PII. UC locations should establish data classification criteria, train personnel on data classification, and implement processes that ensure data is classified consistently. Data classification enables UC locations to protect institutional data appropriately.
Implement Access Controls: UC locations must implement access controls that prevent unauthorized access to information systems and data. Access controls must include user authentication, authorization, and access management processes. UC locations should implement role-based access controls, multi-factor authentication for high-risk access, and regular access reviews that ensure access remains appropriate. Effective access controls enable UC locations to protect information from unauthorized access.
Implement Encryption: UC locations must implement encryption for sensitive institutional data both at rest and in transit. Encryption must use appropriate encryption standards, be implemented consistently, and be managed effectively. UC locations should establish encryption policies, implement encryption key management processes, and ensure that encryption protects sensitive data. Encryption enables UC locations to protect institutional data from unauthorized access.
Develop Incident Response Capabilities: UC locations must develop incident response capabilities that address information security incidents, including incident detection, containment, and recovery procedures. Incident response plans must be tested regularly, updated based on lessons learned, and integrated with business continuity plans. UC locations should ensure that incident response capabilities enable prompt detection, response, and recovery from security incidents. Effective incident response enables UC locations to respond effectively to security incidents.
Implement Third-Party Security Management: UC locations must implement third-party security management processes that assess and manage security risks from third-party service providers. Third-party security management must include due diligence assessments, contract requirements, ongoing monitoring, and incident notification. UC locations should ensure that third-party security management addresses security risks from third-party relationships effectively.
Relationship to Other Frameworks and Standards
UC Policy BFB-IS-3 complements and aligns with other cybersecurity frameworks and standards, providing UC-specific guidance that supports comprehensive cybersecurity programs.
ISO/IEC 27001: BFB-IS-3 aligns with ISO/IEC 27001 information security management system requirements, providing UC-specific guidance that supports ISO/IEC 27001 implementation. UC locations implementing ISO/IEC 27001 can leverage BFB-IS-3 requirements to implement security practices. The frameworks complement each other, with ISO/IEC 27001 providing management system requirements and BFB-IS-3 providing UC-specific security requirements.
NIST Cybersecurity Framework: BFB-IS-3 aligns with NIST Cybersecurity Framework functions including Identify, Protect, Detect, Respond, and Recover, providing UC-specific guidance for implementing framework practices. UC locations implementing the Cybersecurity Framework can use BFB-IS-3 requirements to implement framework practices. The frameworks complement each other, with the Cybersecurity Framework providing strategic guidance and BFB-IS-3 providing UC-specific requirements.
FERPA and HIPAA: BFB-IS-3 aligns with federal privacy regulations including FERPA (Family Educational Rights and Privacy Act) and HIPAA (Health Insurance Portability and Accountability Act), providing complementary security requirements for protecting student and health information. UC locations subject to FERPA and HIPAA can leverage BFB-IS-3 requirements to implement security practices that protect student and health information. The frameworks work together, with FERPA and HIPAA providing privacy requirements and BFB-IS-3 providing security requirements.
Common Challenges and Solutions
UC locations implementing UC Policy BFB-IS-3 frequently encounter similar challenges related to data classification, access control implementation, encryption deployment, third-party management, and resource constraints. Understanding these common challenges helps UC locations plan proactively and implement BFB-IS-3 requirements effectively.
Data Classification Implementation: UC locations may struggle to implement data classification systems, particularly when data is diverse or when classification criteria are unclear. Data classification requires UC locations to identify data sensitivity, apply classification labels, and implement protection measures appropriate to classification levels. UC locations may face challenges classifying research data, determining appropriate protection measures, or ensuring consistent classification across departments.
Solutions include establishing clear data classification criteria, training personnel on data classification, and implementing processes that ensure consistent classification. UC locations should develop data classification guidelines that address various data types, provide training that helps personnel classify data correctly, and implement tools that support data classification. Data classification enables UC locations to protect institutional data appropriately.
Access Control Implementation: UC locations may struggle to implement access controls, particularly when access requirements are complex or when legacy systems limit access control options. Access control implementation requires UC locations to implement authentication mechanisms, authorization processes, and access management procedures. UC locations may face challenges implementing multi-factor authentication, managing access across diverse systems, or conducting regular access reviews.
Solutions include implementing identity and access management (IAM) systems, establishing access control processes, and conducting regular access reviews. UC locations should implement IAM systems that centralize access management, establish processes that govern access provisioning and revocation, and conduct regular access reviews that ensure access remains appropriate. Access control enables UC locations to protect information from unauthorized access.
Encryption Deployment: UC locations may struggle to deploy encryption comprehensively, particularly when systems are diverse or when encryption impacts performance. Encryption deployment requires UC locations to implement encryption for data at rest and in transit, manage encryption keys, and ensure that encryption is implemented consistently. UC locations may face challenges implementing encryption for legacy systems, managing encryption keys, or ensuring that encryption doesn't interfere with operations.
Solutions include developing encryption strategies, implementing encryption key management systems, and deploying encryption progressively. UC locations should develop encryption strategies that address data at rest and in transit, implement encryption key management systems that protect keys, and deploy encryption progressively starting with high-risk data. Encryption enables UC locations to protect institutional data from unauthorized access.
Third-Party Security Management: UC locations may struggle to manage security risks from third-party service providers, particularly when third parties are numerous or when third-party systems are complex. Third-party security management requires UC locations to assess third-party security capabilities, establish contract requirements, and monitor third-party compliance. UC locations may face challenges assessing third-party security, establishing contract requirements, or monitoring third-party compliance.
Solutions include developing third-party security management processes, establishing contract requirements, and implementing third-party monitoring. UC locations should develop processes that assess third-party security, establish contract requirements that address security expectations, and implement monitoring that verifies third-party compliance. Third-party security management enables UC locations to manage security risks from third-party relationships.
Resource Constraints: UC locations may struggle to allocate resources for BFB-IS-3 implementation, particularly when resources are limited or when competing priorities exist. Implementation requires resources including personnel, technology, and time that may be constrained. UC locations may face challenges securing executive support, allocating budget, or finding qualified personnel.
Solutions include prioritizing requirements based on risk, leveraging automation and tools, and engaging external service providers. UC locations should prioritize requirements that address the greatest risks, leverage automation and tools that improve efficiency, and engage external service providers that provide capabilities without requiring internal resource development. Risk-based prioritization enables UC locations to allocate limited resources effectively.
Audit and Compliance Validation
UC locations subject to UC Policy BFB-IS-3 must demonstrate compliance through various assessment and audit mechanisms. UC Office of the President may conduct audits to verify compliance with policy requirements. UC locations must maintain evidence of compliance, ensure security controls are implemented effectively, and respond to audit findings.
Internal assessments provide opportunities for UC locations to evaluate information security implementation, identify gaps, and improve security practices proactively. UC locations should conduct regular internal assessments that evaluate governance, risk management, data classification, access controls, encryption, and incident response. Internal assessments should identify strengths and weaknesses, prioritize improvement opportunities, and verify that security practices comply with BFB-IS-3 requirements.
Frequently Asked Questions
What is UC Policy BFB-IS-3?
UC Policy BFB-IS-3 is a comprehensive information security policy published by the University of California Office of the President that establishes information security requirements for all UC locations and third parties handling institutional data. The policy covers governance, risk management, data classification, access controls, encryption, incident response, and third-party security management. BFB-IS-3 ensures consistent protection of university information assets across the UC system.
Who must comply with UC Policy BFB-IS-3?
BFB-IS-3 applies to all University of California locations including campuses, medical centers, national laboratories, and other UC facilities. The policy also applies to third parties that handle UC institutional data, requiring them to implement security controls that protect UC information. All UC locations must comply with BFB-IS-3 requirements as part of their information security obligations.
What are the key requirements of BFB-IS-3?
Key requirements include establishing information security governance, implementing risk management processes, classifying institutional data, implementing access controls, encrypting sensitive data, developing incident response plans, and managing third-party security risks. UC locations must implement comprehensive information security programs that address all policy requirements.
How does BFB-IS-3 relate to other cybersecurity frameworks?
BFB-IS-3 aligns with other cybersecurity frameworks including ISO/IEC 27001, NIST Cybersecurity Framework, and federal privacy regulations including FERPA and HIPAA, providing UC-specific guidance that supports comprehensive cybersecurity programs. UC locations implementing other frameworks can leverage BFB-IS-3 requirements to implement security practices that comply with UC policy.
What are the main challenges in implementing BFB-IS-3?
Main challenges include data classification implementation requiring clear criteria and consistent application, access control implementation requiring IAM systems and processes, encryption deployment requiring comprehensive coverage and key management, third-party security management requiring assessment and monitoring processes, and resource constraints limiting security investments. UC locations should address these challenges through careful planning and progressive implementation.
How long does it take to implement BFB-IS-3 requirements?
Implementation timelines vary based on UC location size, current security maturity, and resource availability. Small UC locations may implement basic requirements in 6-12 months, while larger locations may require 12-24 months for comprehensive implementation. UC locations should prioritize requirements based on risk, implementing progressively and building capabilities over time.
Conclusion
UC Policy BFB-IS-3 provides essential information security requirements for all University of California locations and third parties handling institutional data, establishing comprehensive security requirements that protect university information assets. The policy's mandatory nature and enforcement by UC Office of the President ensure consistent security practices across the UC system. Understanding BFB-IS-3 requirements enables UC locations and third parties to implement security programs that protect institutional data and comply with UC policy requirements.
Successful BFB-IS-3 implementation requires executive support, adequate resources, qualified personnel, and sustained commitment to maintaining information security practices. UC locations must comply with mandatory requirements, while third parties can use BFB-IS-3 guidance to implement security practices. The policy complements other cybersecurity frameworks, enabling UC locations to implement security practices that support comprehensive cybersecurity programs.
By following structured implementation approaches, prioritizing requirements based on risk, and maintaining security effectiveness over time, UC locations can achieve meaningful security improvements that protect institutional data and enable academic and research activities. The investment in information security maturity pays dividends through reduced security risk, enhanced protection of institutional data, and improved ability to protect university operations from cyber threats.