These services help campus departments understand and meet information security requirements, manage institutional risk, and align systems, applications, and data practices with UC and UCSB policies.

Use this section to find security requirements, policy guidance, risk management processes, and tools that support secure operations across campus.

Understand Security Policy

Know the rules, responsibilities, and expectations that guide campus information security

Security Policy

Classify Your Data

Understand how UC Protection Levels apply to institutional data and systems

UC Protection Levels

Securing Devices

UCSB deploys several mechanisms to secure computers, servers, and other devices that access campus 
systems or data

Device Security Information

What do you want to do?

Secure an application 
or system

Guidance for managing application credentials and improving visibility into security posture

Prepare for disruptions

Resources for maintaining critical operations and recovering from incidents, outages, or other disruptions

Work with regulated 
or restricted data

Guidance for processes involving higher-risk data, including government licensed datasets

Policy Exceptions and Risk Acceptance


UCSB recognizes that some systems, services, vendors, vulnerabilities, or business processes may not be able to fully meet a specific security policy or standard as written. In these cases, an exception or risk acceptance request may be submitted to document the need, affected system or service, alternative security controls, data sensitivity, duration, and long-term mitigation plan.


Exception and risk acceptance requests are reviewed by the appropriate security and unit leadership, and approval is not guaranteed. To begin the process, complete and submit the Policy Exception or Risk Acceptance request form in ServiceNow.

Get Help 

Not sure which security requirements or processes apply to your system, application, or data? 
Contact the security@ucsb.edu for guidance before moving forward.