These services help campus departments understand and meet information security requirements, manage institutional risk, and align systems, applications, and data practices with UC and UCSB policies.
Use this section to find security requirements, policy guidance, risk management processes, and tools that support secure operations across campus.
Understand Security Policy
Know the rules, responsibilities, and expectations that guide campus information security
Classify Your Data
Understand how UC Protection Levels apply to institutional data and systems
Securing Devices
UCSB deploys several mechanisms to secure computers, servers, and other devices that access campus
systems or data
What do you want to do?
Secure an application
or system
Guidance for managing application credentials and improving visibility into security posture
Prepare for disruptions
Resources for maintaining critical operations and recovering from incidents, outages, or other disruptions
Work with regulated
or restricted data
Guidance for processes involving higher-risk data, including government licensed datasets
Policy Exceptions and Risk Acceptance
UCSB recognizes that some systems, services, vendors, vulnerabilities, or business processes may not be able to fully meet a specific security policy or standard as written. In these cases, an exception or risk acceptance request may be submitted to document the need, affected system or service, alternative security controls, data sensitivity, duration, and long-term mitigation plan.
Exception and risk acceptance requests are reviewed by the appropriate security and unit leadership, and approval is not guaranteed. To begin the process, complete and submit the Policy Exception or Risk Acceptance request form in ServiceNow.
Get Help
Not sure which security requirements or processes apply to your system, application, or data?
Contact the security@ucsb.edu for guidance before moving forward.