Article 3 – Electronic Signatures
41021.8 Roles and Responsibilities
-
The department Chief Information Officer (CIO) or designee shall:
-
Ensure that all users of the department information assets are aware of this policy and acknowledge their individual responsibilities.
-
Ensure that this policy is reviewed annually and updated accordingly.
-
Audit and assess departmental compliance with this policy at least once every two years.
-
-
The department Information Security Officer (ISOInformation Security Officer) shall:
-
Participate in the data retention processes, provide advice, and assist information asset owners and information asset custodians in assessing security requirements for e-signature solutions as appropriate.
-
Ensure confidentiality standards to address accurate identification, authentication, authorization, and accountability for e-signature resources are established.
-
Ensure that data security controls, methods and processes meet the department and applicable regulatory requirements for security and privacy.
-
-
The department information assets owners shall:
-
Ensure that this policy is implemented, and implementation is reviewed at least once annually.
-
Ensure access to technology and process controls with e-signature solutions are commensurate with the data classification level or criticality of information assets under their purview.
-
Take reasonable steps to keep personal information only as long as it is necessary to carry out the purposes for which the information was collected.
-
Ensure that systems and communications information assets under their purview are categorized and classified. For more details on information asset classification refer to the Department Operations Manual (DOMDepartment Operations Manual), Chapter 4, Article 61, Data Security Policy.
-
Ensure that e-signature solutions under their purview comply with this policy.
-
-
The department information asset custodians shall:
-
Implement e-signature solutions as approved by information assets owners.
-
Create, grant, and revoke e-signature credentials upon notification from the information assets owners.
-
-
All department users shall be aware of and adhere to all department information security and privacy policies.