Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 3 – Electronic Signatures

View All Articles >

41021.1 Policy

  • This policy shall establish the criteria under which an electronic signature (e-signature), including a digital signature as specified herein, is deemed official and acceptable by the California Department of Corrections and Rehabilitation (CDCRCalifornia Department of Corrections and Rehabilitation or the department).

  • This policy guides the department to adopt a reliable and consistent approach to the use of e-signature, modernize records, reduce the need for physical record keeping, and improve customer service.

41021.2 Purpose

  • The purpose of this policy is to:

    • Establish requirements for the permissible use of an e-signature in lieu of a handwritten signature in connection with official department activities.

    • Ensure that the use of an e-signature is consistent with the department’s policies, standard practices, and all applicable laws.

    • Establish standards governing the use of e-signatures pursuant to applicable state laws and regulations requiring the digitization of official forms and the use of e-signatures in lieu of wet signatures where not otherwise prohibited.

41021.3 Scope and Applicability

  • The scope and applicability of this policy extend to all information assets owned or operated by the department.

  • This policy applies to all business processes conducted by the department that require e-signatures.

  • This policy applies to all department personnel and governs all uses of e-signatures in connection with official department activities.

41021.4 Policy Directives

  • The adoption of an e-signature option is determined by the department’s operational needs. If the department elects to implement an e-signature option, it shall adhere to the following:

    • Format business documents to require the signature line to accept e-signature.

    • Use an e-signature service solution that is approved by the State of California.

    • Ensure processes and technologies are in place to accept and enable the use of an e-signature.

    • Implement confidentiality procedures to address accurate identification, authentication, authorization, and accountability.

    • Ensure all electronic forms clearly and unambiguously show the chain of approval of all parties required to sign that document.

    • Ensure the e-signature document includes the date the document was signed.

    • Implement integrity procedures to address non-repudiation.

    • Ensure all e-signature electronic records are maintained in a record keeping system.

    • Ensure e-signatures comply with all applicable state and federal standards, laws, and regulations.

41021.5 Documents Involving Other Parties

  • In the case of contracts or transactions requiring signatures from outside parties, e-signatures may be used only with the prior consent of all parties to the agreement. No party shall be required to accept an e-signature, and each party retains the right to determine their preferred method of signing. Consent to use e-signatures may be withdrawn at any time by any party, such that future documents must be signed in hard copy format. If consent is withdrawn, it shall not invalidate any documents already in effect that were signed electronically before consent was withdrawn.

41021.6 Criteria to Determine Acceptable E‑Signature Technology

  • The department’s designated Information Technology (ITInformation Technology) application owner or service provider ensures the acceptable e-signature requirements are met. An acceptable e-signature technology must be capable of generating signatures that meet the following criteria:

    • It is unique to the person using it.

    • It is capable of verification.

    • It is under the sole control of the person using it.

    • It is linked to data in such a manner that if the data changes, the digital signature is invalidated.

    • It conforms to Government Code (GCGovernment Code), section 16.5 (a-d).

  • An example of two acceptable e-signature technologies used by the department are: Public Key Cryptography and Signature Dynamics, provided the signatures created by those technologies are generated, captured, and stored in accordance with applicable statutory provisions and the established guidelines from California Code of Regulations (CCRCalifornia Code of Regulations), Title 2, Division 7, Chapter 10.

    • The e-signature technology used by the department is dependent on the program area’s requirements and suitable technology to meet the business needs.

41021.7 Types of E‑Signatures Approved for Use

Revised May 28, 2026
  • Only the following types of an e-signature are approved for use by the department:

    • Name typed or stamped

      • A person signing or stamping a form electronically does so by typing or stamping their name in the designated signature field with a statement confirming agreement.

    • Recorded voice

      • The following criteria is required to use a recorded voice as an e-signature, the recorded voice must:

        • Be associated with the speaker;

        • Be associated with a specific document or record;

        • Show evidence of the speaker’s intent to be bound to the terms and conditions in that specific document or record;

        • Be captured in electronic format.

      • A simple voice recording may not establish intent of agreement, therefore the department may require additional authentication, such as a voice system with keypad verification to confirm agreement, or other verbal confirmation to verify identity.

    • Personal Identification Number (PIN) or password

      • When using a PIN or password for an e-signature, a person accessing an application is requested to enter identifying information. Identifying information may include an identification number, the person’s name, and a “shared secret” (called “shared” because it is known to both the user and the system), such as a PIN or password. The system checks that the PIN or password is indeed associated with the person accessing the system to authenticate the person. Sometimes the entry of some personal information (for example: name or date of birth) along with the PIN and password is also required.

    • Digitized image of handwritten signature

      • A digitized signature is a graphical image of a handwritten signature. Some applications require a person to create a handwritten signature using a special computer input device, such as a digital pen and pad.

    • Digital signature

      • The department shall follow the regulations for acceptable technologies for digital signatures established by the California Secretary of State in CCRCalifornia Code of Regulations, Title 2, Division 7, Chapter 10.

41021.8 Roles and Responsibilities

  • The department Chief Information Officer (CIO) or designee shall:

    • Ensure that all users of the department information assets are aware of this policy and acknowledge their individual responsibilities.

    • Ensure that this policy is reviewed annually and updated accordingly.

    • Audit and assess departmental compliance with this policy at least once every two years.

  • The department Information Security Officer (ISOInformation Security Officer) shall:

    • Participate in the data retention processes, provide advice, and assist information asset owners and information asset custodians in assessing security requirements for e-signature solutions as appropriate.

    • Ensure confidentiality standards to address accurate identification, authentication, authorization, and accountability for e-signature resources are established.

    • Ensure that data security controls, methods and processes meet the department and applicable regulatory requirements for security and privacy.

  • The department information assets owners shall:

    • Ensure that this policy is implemented, and implementation is reviewed at least once annually.

    • Ensure access to technology and process controls with e-signature solutions are commensurate with the data classification level or criticality of information assets under their purview.

    • Take reasonable steps to keep personal information only as long as it is necessary to carry out the purposes for which the information was collected.

    • Ensure that systems and communications information assets under their purview are categorized and classified. For more details on information asset classification refer to the Department Operations Manual (DOMDepartment Operations Manual), Chapter 4, Article 61, Data Security Policy.

    • Ensure that e-signature solutions under their purview comply with this policy.

  • The department information asset custodians shall:

    • Implement e-signature solutions as approved by information assets owners.

    • Create, grant, and revoke e-signature credentials upon notification from the information assets owners.

  • All department users shall be aware of and adhere to all department information security and privacy policies.

41021.9 Compliance

  • The department shall comply with the information security and privacy policies, standards and procedures issued by the California Department of Technology (CDT), Office of Information Security (OIS). In addition to compliance with the information security and privacy policies, standards, procedures, and filing requirements issued by the OIS, the department shall ensure compliance with all security and privacy laws, regulations, rules, and standards specific to and governing the administration of their programs. Program administrators shall work with their general counsel, ISOInformation Security Officer, and privacy program officer or coordinator to identify all security and privacy requirements applicable to their programs and ensure implementation of the requisite controls.

  • Non-compliance with this policy may result in disciplinary or adverse action as set forth in DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.

  • The consequences of negligence and non-compliance with state laws and policies may include departmental and personal:

    • Loss of delegated authorities.

    • Negative audit findings.

    • Monetary penalties.

    • Legal actions.

41021.10 Audits

  • The department has the right to audit any activities related to the use of state information assets.

  • CDT, OIS, and the department have the statutory right to audit departmental readiness to respond and recover from an incident.

41021.11 Duty to Report

  • Violations of this policy shall be reported to the department’s Office of the Information Security Officer (OISO).

41021.12 Security Variance Process

  • If compliance is not feasible or is technically impossible, or if deviation from this policy is necessary to support a business function, the respective manager must formally request a security variation as defined in the DOMDepartment Operations Manual, Chapter 4, Article 70, Security Variance Policy.

41021.13 Authority

  • This policy complies with GCGovernment Code, section 11549.3.

41021.14 Revisions

  • The CIO or designee shall ensure the contents of this article are current and accurate.

References

  • (1) CCRCalifornia Code of Regulations, Title 2, Division 7, Chapter 10, section 22000 et seq.

  • (2) Civil Codes 1633.1-1633.17.

  • (3) DOMDepartment Operations Manual, Chapter 3, Article 22.

  • (4) DOMDepartment Operations Manual, Chapter 4, Articles 60, 61, and 70.

  • (5) FIPS, 180-4 and 186-5.

  • (6) GCGovernment Code, §§ 16.5 and 11549.3.

    (7) Health Care Department Operations Manual (HCDOM) 5.3.4 Digital Signature Security.

    (8) NIST 800-63B and SP 800-186.

    (9) SAMState Administrative Manual, §§ 1710, 1734, 5300, and Management Memo 20-07.

    (10) SIMM 5300-B, 5310-B, and 5310.6.

Revision History

  • (1) Effective: May 28, 2026.