Public-domain · open source
OpenJurist

Cal. Gov. Code § 11549.3

Office of Information Security

Showing this section's text as in effect on January 1, 2011 (in force January 1, 2011 – January 1, 2013). View current text →

(a) The director shall establish an information security program. The program responsibilities include, but are not limited to, all of the following:

(1) The creation, updating, and publishing of information security and privacy policies, standards, and procedures for state agencies in the State Administrative Manual.

(2) The creation, issuance, and maintenance of policies, standards, and procedures directing state agencies to effectively manage security and risk for all of the following:

(A) Information technology, which includes, but is not limited to, all electronic technology systems and services, automated information handling, system design and analysis, conversion of data, computer programming, information storage and retrieval, telecommunications, requisite system controls, simulation, electronic commerce, and all related interactions between people and machines.

(B) Information that is identified as mission critical, confidential, sensitive, or personal, as defined and published by the office.

(3) The creation, issuance, and maintenance of policies, standards, and procedures directing state agencies for the collection, tracking, and reporting of information regarding security and privacy incidents.

(4) The creation, issuance, and maintenance of policies, standards, and procedures directing state agencies in the development, maintenance, testing, and filing of each agency’s disaster recovery plan.

(5) Coordination of the activities of agency information security officers, for purposes of integrating statewide security initiatives and ensuring compliance with information security and privacy policies and standards.

(6) Promotion and enhancement of the state agencies’ risk management and privacy programs through education, awareness, collaboration, and consultation.

(7) Representing the state before the federal government, other state agencies, local government entities, and private industry on issues that have statewide impact on information security and privacy.

(b) An information security officer appointed pursuant to Section 11546.1 shall implement the policies and procedures issued by the Office of Information Security, including, but not limited to, performing all of the following duties:

(1) Comply with the information security and privacy policies, standards, and procedures issued pursuant to this chapter by the Office of Information Security.

(2) Comply with filing requirements and incident notification by providing timely information and reports as required by policy or directives of the office.

(c) The office may conduct, or require to be conducted, independent security assessments of any state agency, department, or office, the cost of which shall be funded by the state agency, department, or office being assessed.

(d) The office may require an audit of information security to ensure program compliance, the cost of which shall be funded by the state agency, department, or office being audited.

(e) The office shall report to the California Technology Agency any state agency found to be noncompliant with information security program requirements.

Official source: California Legislative Information. Reproduced from public-domain California statutes; confirm against the official source for the current text. Not legal advice.