Meeting system-wide cybersecurity compliance at The University of California, Berkeley

Overview

The University of Chicago, colloquially known as UChicago, is an R1 university in Chicago, Illinois. It consistently ranks among the top universities in the world, is a leading research institution, and educates over 18,000 students.

Challenge

“Every department at the University of Chicago functions like a state with its own goals, authority, and power. That all creates [often unseen] risk,” says Jessica Sandy, an IT Risk Analyst on the UChicago Information Assurance team, a subset of the larger Information Security team. She’s responsible for several different tasks in the area of IT Risk Management, including reviewing contracts, creating policies, training staff, and of course, assessing information security risks.

Although most of UChicago’s IT Risk Management is centered around NIST CSF, many of the 45-and-counting units require compliance with differing regulations like CMMC, DFARS, GLBA, GDPR, FERPA, and several others. Plus, highly sensitive environments, like the Biological Sciences Department and the Medical Center, require compliance with HIPAA. Many of these entities also have their own information security teams that operate separately from Jessica’s team but still collaborate with them.

To make matters more complex, everything UChicago did to calculate IT risk was manual, conducted via Qualtrics, outdated Excel spreadsheets, and a homegrown tool that did not cover the entire organization.

She goes on to say that UChicago needed a way to ensure that academic freedom and technological development weren’t at odds with one another. On the one hand, “you have to keep up, but you also have to do what you need to stay secure.”

These challenges catalyzed UChicago to search for a platform that easily allowed them to quantify IT risk across dozens of departments, involve busy department heads, and eradicate inconsistent manual processes that took time and resources away from other dimensions of IT Risk Management.

Solution

They found their time-saving solution in Isora GRC from SaltyCloud.

  • Preloaded NIST CSF templates save time and allow UChicago to automate the distribution of their questionnaires and customize them wherever needed across units.
  • Auditable system of record features makes it easy to measure progress and change over time to track even the most granular risk mitigation efforts more effectively.
  • It allows the university to broaden its scope beyond its manual limitations without the extra bells and whistles, the “overkill,” of the behemoth competitors they considered.
  • Ongoing support from the SaltyCloud team provides a partner in growth as they scale their process and expand their use cases outside of IT.

“It’s easy to scale, and the time to value is great. It only took us a month to get what manually took us eight months.”

Isora GRC also makes it easy for Jessica’s team to remain flexible and iterate to stay ahead of constantly evolving regulations.

Outcomes

Since UChicago adopted Isora GRC, Jessica and her team have observed numerous positive outcomes in their workflow.

  • Remain flexible and able to iterate on assessments efficiently as new data points illuminate the unknown.
  • Able to extract assessment data easily for deeper analysis, from dense, convoluted spreadsheets to insightful reports.
  • Regain valuable time spent on manual processes to focus on new risk dimensions.
  • Better data means strategic conversations with department heads and UChicago leadership.
Other Relevant Content

Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua.