Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 45 – Information Security

View All Articles >

49020.1 Policy

  • It is the policy of the California Department of Corrections and Rehabilitation (CDCRCalifornia Department of Corrections and Rehabilitation or the department) to protect against the unauthorized modification, deletion, or disclosure of information included in department files and databases. The department regards its information assets, including data processing capabilities and automated files, to be essential resources. The department shall assume full responsibility for ensuring the security and integrity of its information resources.

49020.2 Purpose

  • The purpose of this policy is to maintain a standard of practice to prevent misuse or loss of department information assets. This policy shall:

    • Maintain management and staff accountability for the protection of departmental information assets.

    • Maintain processes for the analysis of risks associated with departmental information assets.

    • Maintain cost-effective risk management processes intended to preserve the department’s ability to meet program objectives in the event of the unavailability, loss, or misuse of information assets.

    • Protect authorized departmental employees from mishandling the department’s information assets due to internal misuse, external factors, or improper influence including temptation, coercion, and threat.

    • Maintain agreements with state and non-state entities to cover, at a minimum, the following:

      • Appropriate levels of confidentiality for the data based on data classification.

      • Standards for transmission and storage of the data, if applicable.

      • Agreement to comply with all state policy and law regarding use of information resources and data.

      • Signed confidentiality statements.

      • Agreements to apply security patches and upgrades, and keep virus software up-to-date on all systems on which data may be used.

      • Agreements to notify the information owners promptly if a security incident involving the data occurs.

    • Maintain appropriate policies and procedures to protect and secure Information Technology (ITInformation Technology) infrastructure.

    • Require that if a data file is downloaded to a mobile device or desktop computer from another computer system, the specifications for information integrity and security which have been established for the original data file must be applied in the new environment.

    • Require encryption, or equally effective measures, for all personal, sensitive, or confidential information that is stored on portable electronic storage media, including, but not limited to, CDs and thumb drives and on portable computing devices, including, but not limited to, laptop and notebook computers. This policy does not apply to mainframe and server tapes.

49020.3 Scope and Applicability

  • The scope of this policy extends to all state and department information security policies and to all state information assets owned or operated by the department.

  • This policy applies to all department personnel.

49020.4 Roles and Responsibilities

  • Secretary

    • The Secretary shall ensure the department’s information security has a risk management program to:

      • Assigns management responsibilities for an information security program.

      • Support the integrity and security of automated and paper information, produced or used in the course of agency operations.

      • Comply with state and audit requirements relating to the integrity of information assets.

  • Chief Information Officer (CIO) or Designee

    • The CIO or designee shall maintain an information security program within the department. It is the responsibility of the CIO or designee to assure that information assets are protected from the effects of damage and destruction, as well as from unauthorized or accidental modification, access, or disclosure. Specifically, the CIO or designee shall:he CIO or designee shall:

      • Enforce state-level security policies.

      • Establish and internal policies that provide for the security of ITInformation Technology facilities, software and equipment, and the integrity and security of the agency’s automated information.

      • Department compliance with reporting requirements related to security issues.

      • Appointment of a qualified Agency Information Security Officer (AISO).

      • The participation of management during the planning, development, modification, and implementation of security policies and procedures.

      • All department information asset-users are aware of this policy and acknowledge their individual responsibilities.

      • The policy is reviewed annually and updated accordingly.

      • The required audit and compliance assessments for this policy are completed at least once every two years.

  • AISO

    • Government Code (GCGovernment Code), section 11546.1 requires that each agency designate an AISO. Additionally, to avoid conflicts of interest, the AISO shall not:

      • Have direct responsibility for information processing.

      • Have direct responsibility for access management functions.

      • Have direct responsibility for any departmental computer-based systems.

      • Have any special allegiance or bias toward a particular program or organization.

    • The AISO is responsible for overseeing the department policies designed to protect its information assets. In accordance with state policy, the AISO shall be accountable to the Secretary and CIO with respect to the following responsibilities:

      • The department’s Information Security Office.

      • Establish and maintain security policies and programs designed to protect information assets.

      • Identify confidential, sensitive information, and critical applications.

      • Identify vulnerabilities that may cause inappropriate or accidental access, destruction or disclosure of information, and the establishment of security controls necessary to eliminate or minimize their potential effects.

      • Establish and maintain programs necessary to monitor and ensure the compliance of established security and risk management policies and procedures.

      • Coordinate with internal auditors to define their roles in automated information system planning, development, implementation, operations, and modifications relative to security.

      • Coordinate with the applicable data center’s Office of the Information Security Officer (OISO) or staff on matters related to the planning, development, implementation, or modification of information security policies and programs that affect the department.

      • Acquire appropriate security equipment and software.

      • Establish and maintain programs to comply with control agency reporting requirements.

      • Develop and maintain controls and safeguards to control user access to information.

      • Establish and maintain training programs to ensure CDCRCalifornia Department of Corrections and Rehabilitation staff (with particular emphasis on the owners, users, and custodians of information) are educated and aware of their roles and responsibilities relative to information security.

      • Report allegations of misconduct or criminal activity to the department’s Office of Internal Affairs (OIAOffice of Internal Affairs) and assist with investigations as necessary.

  • Department Owners of Information Assets and Program Management

    • In relation to the department’s security program, department owners of information assets and program managers shall ensure:

      • Procedures are established and maintained to comply with State information security policy in relation to ownership, user, and if appropriate, information asset custodian responsibilities.

      • State program policies and requirements are identified relative to security requirements.

      • Proper data classification of automated information for which the program is assigned ownership responsibility.

      • Participation of the OISO and technical staff in identifying and selecting appropriate and cost-effective security controls and procedures, and to protect information assets.

      • Appropriate security requirements for user access to automated information are defined for files or databases for which the program is assigned ownership responsibility.

      • Proper planning, development, and establishment of security policies and procedures for files or databases for which the program has ownership responsibility, and for physical devices assigned to and located in the program area(s).

      • Information asset custodians are provided the appropriate direction to implement the security controls and procedures that have been defined.

      • Procedures are established to comply with control agency reporting requirements.

  • EISEnterprise Information Services (formerly Information Services Division) Departmental Technical Management

    • Department technical management shall ensure:

      • Management, the OISO, assigned owners, custodians, and users are provided the necessary technical support services with which to define and select cost effective security controls, policies, and procedures.

      • Implementation of security controls and procedures as defined by the owners of information.

      • Implementation of system controls necessary to identify actual or attempted violations of security policies or procedures.

      • The owners of information and the OISO are notified of any actual or attempted violations of security policies and procedures.

  • Department Users

    • Department users have the following security responsibilities:

      • Implement and monitor data quality assurance functions to ensure the integrity of data for which the program is assigned ownership responsibility.

      • Comply with applicable federal, state, and department security policies and procedures.

      • Comply with applicable federal and state statutes.

      • Ensure management, OISO, and assigned owners, custodians, and other users are provided the necessary technical support services with which to define and select cost-effective security controls, policies, and procedures.

      • Ensure implementation of security controls and procedures as defined by the owners of information.

      • Ensure implementation of system controls necessary to identify actual or attempted violations of security policies or procedures.

      • Ensure the owners of information and the Information Security Office are notified of any actual or attempted violations of security policies and procedures.

      • Be aware of and adhere to all department information security and privacy policies.

  • Information Security Coordinators

    • Every organizational entity that uses computer systems, or uses computer applications shall designate an Information Security Coordinator (ISCInformation Security Coordinators) for each site maintained by that entity. The designated ISCInformation Security Coordinators shall be responsible for ensuring that applicable CDCRCalifornia Department of Corrections and Rehabilitation policies and procedures are followed, and shall act as the security liaison to the Information Security Office. The OISO will serve as the ISCInformation Security Coordinators for EISEnterprise Information Services (formerly Information Services Division) staff that do not have a designated ISCInformation Security Coordinators.

    • A procedure shall be developed by each of these organizational entities, subject to approval by the department OISO. The procedure shall adhere to the following guidelines:

      • The designation of an ISCInformation Security Coordinators for the decentralized or control entity shall be in writing and shall identify the name, work address, and telephone number of the ISCInformation Security Coordinators.

      • The department OISO shall maintain a file of all current and past designated ISCs.

      • The designated ISCInformation Security Coordinators shall be made aware that they are the designated ISCInformation Security Coordinators and the responsibility that the designation entails.

      • The designated ISCInformation Security Coordinators shall ensure compliance with information security policies and procedures, and with any security guidelines issued by the owners of decentralized automated systems.

49020.5 Department Information Asset Protection

Revised May 20, 2026
  • The department shall provide for the integrity and security of its information assets by identifying all automated files and databases for which CDCRCalifornia Department of Corrections and Rehabilitation has ownership responsibility, and ensuring that responsibility for each automated file or database is defined with respect to the following:

    • Owners of the information within the department.

    • Custodians of the information.

    • Users of the information.

    • Classification of the information to ensure that each automated file or database is identified as to its information class in accordance with law and administrative policy.

49020.5.1 Information Security Ownership/Authority

  • An owner of any departmental information shall be the approval authority for all requests for access to such information under their control. Approval authority may be delegated to a designated representative. The owner has an obligation to restrict access to the specific information to instances that are necessary and sufficient to meet the demonstrated need or right of the requestor. The owner shall consult with EISEnterprise Information Services (formerly Information Services Division) to determine the most appropriate on-line access mechanisms for a specific request, keeping in mind that EISEnterprise Information Services (formerly Information Services Division) is obligated to restrict the mechanisms to those that are necessary and sufficient to meet the requestor’s need for, or right to, such information.

  • The owner is ultimately responsible for the integrity of the entrusted information. This responsibility requires that the owner have control over who can access, modify, disclose, or destroy information. The owner shall exercise the responsibility to communicate information security requirements to all appropriate personnel, and to make use of all available security features. Additionally, the owner shall determine that implemented security measures are adequate to meet the requirements of the application, and ensure that an employee’s access authority is removed immediately upon separation or change of duties such that access is no longer necessary.

49020.5.2 Classification of Information

  • The department’s records, automated files, and databases are essential public resources that must be given appropriate protections from unauthorized use, access, disclosure, modification, loss, or deletion. The discovery and classification of CDCRCalifornia Department of Corrections and Rehabilitation information assets is a continuing endeavor and requires the ongoing support of information owners and other stakeholders.

    • The EISEnterprise Information Services (formerly Information Services Division) Enterprise Architecture organization is responsible for maintaining and facilitating the processes and procedures for enterprise governance of CDCRCalifornia Department of Corrections and Rehabilitation information assets and engaging information owners and stakeholders for information security classification decision-making and governance.

    • Information owners are responsible for reviewing and classifying information, solely or with others, for information they own or share ownership of, and for participating in the department information governance process; the final ruling for security classification decisions rests with the information owners.

    • Stakeholders are responsible for raising Information security concerns with respect to information security classification and ensuring information is treated appropriately based on duly made classification decisions.

    • All users of departmental information are responsible for protecting CDCRCalifornia Department of Corrections and Rehabilitation Information under their control or influence from unauthorized use, access, disclosure, modification, loss, or deletion, including notifying appropriate CDCRCalifornia Department of Corrections and Rehabilitation authorities when vulnerabilities to department information is noticed or when security classifications or protections for department information appear inadequate.

  • The department will classify each record, file, and database using the following classification structure:

    • Public Information – information maintained by CDCRCalifornia Department of Corrections and Rehabilitation that is not exempt from disclosure under the provisions of the California Public Records Act (Gov Code, sections 7920.000 et seq.) or other applicable state or federal laws.

    • Confidential Information – information maintained by CDCRCalifornia Department of Corrections and Rehabilitation that is exempt from disclosure under the provisions of the California Public Records Act (Gov Code, sections 7920.000 et seq.) or other applicable state or federal laws.

    • High Risk Confidential Information (HRCI) – Non-public information that could result in a significant harm (including financial, legal, risk to life and safety or reputational damage) to the department or individual(s) if compromised through alteration, corruption, loss, misuse, or unauthorized disclosure. Examples of HRCI include, but are not limited to, information such as the following:

      • Personally identifiable information such as a person’s name in conjunction with the person’s social security number, credit or debit card information, individual financial account, driver’s license number, state identity document (IDInstitutions Division (see DAI)) number, or passport number, or a name in conjunction with biometric information;

      • Personal health information such as any information about health status, provisions of health care, or payment for health care information as protected under the Health Insurance Portability and Accountability Act of 1996;

      • Correctional Offender Record Information as defined in California Penal Code (PCPenal Code), sections 13100-13104;

      • All ITInformation Technology infrastructure information that would reveal vulnerabilities to, or otherwise increase the potential for an attack on, an information technology system of a public agency, including but not limited to firewall and router configurations, server names, internet protocol (IP) addresses, and other system configurations;

      • Any document which contains information identifying any confidential informant, or confidential information provided, as defined in California Code of Regulations (CCRCalifornia Code of Regulations), Title 15, section 3321;

      • Any documentation of information which contains information or data within any Gang Data Base as defined in the Department Operations Manual (DOMDepartment Operations Manual), sections 52070.22-52070.24;

      • Records of investigations, intelligence information, or security procedures as specified in the California Public Records Act (PRAPublic Records Act), section 7923.600(a).

      • Personnel, medical, or similar files, the disclosure of which would constitute an unwarranted invasion of personal privacy protected under the California GCGovernment Code, section 7927.700 or the Peace Officers Bill of Rights under GCGovernment Code, sections 3300, et seq.

      • Sensitive Information – information maintained by the department that requires a higher than normal assurance of accuracy and completeness. Thus the key factor for sensitive information is that of integrity. Typically, sensitive information includes records of financial transactions and regulatory actions.

  • Personal Information requested by researchers not under the authority of CDCRCalifornia Department of Corrections and Rehabilitation may only be received by University of California or other non-profit educational institutions and in accordance with the provisions set forth in law, including the prior review and approval by the Committee for the Protection of Human Subjects (CPHS) of the California Health and Human Services Agency before such information is released. See Civil Code (CIV), section 1798.24(t).

49020.6 Human Resources Security

  • The department requires that personnel practices related to security management must include:

    • Employment history and background checks on all employees.

    • The signing of the Computing Technology User Agreement Form 1857 for all staff that uses the department’s ITInformation Technology, thereby agreeing to abide by the department’s workgroup computing policies.

49020.6.1 Segregation of Duties in the Information Security Program

  • There shall be a strict separation of duties among, and within, all organizations responsible for using, operating, and developing computer-based information systems. Separation of duties shall be maintained to ensure a separation of responsibilities for initiating and authorizing transactions, recording of transactions, and custody of assets. Segregation of duties, similar to that required in manual systems, shall be implemented in computerized systems.

    • The following guidelines shall be used regarding such separation of duties:

      • Convert and Conceal – No one person should be able to convert a resource to their personal use and be able to conceal the action.

      • Custody and Control – No one person should have custody of an asset and, at the same time, be solely responsible for the accounting for that asset.

      • Custody and Access – No one person shall have custody of an asset and, at the same time, have unrestricted access to the records pertaining to that asset.

      • Origination and Authorization – No one person shall both originate and authorize a transaction.

      • Originate and Maintain – No one person shall both enter a transaction and maintain the related master file.

      • Access and Restriction – Access to transactions shall be on a need-to-know basis.

  • EISEnterprise Information Services (formerly Information Services Division) or designee is charged with the responsibility for the development and maintenance of computer based systems for the department. In this capacity, EISEnterprise Information Services (formerly Information Services Division) provides a service to actual or potential users of computer-based information systems. In addition, there are several computer “user” groups throughout the department. Each of these organizations is providing a service to all actual or potential users of computer based information systems.

  • To ensure that assigned responsibilities are met and that separation of duties is maintained, individuals or programs shall not originate or authorize transactions, have custody or control over online data processing assets, or have the authority to originate master file changes. Source documents shall originate and be controlled by functions independent of such persons or programs.

  • Appropriate procedures shall be developed, subject to approval by the AISO, to ensure that adequate controls exist to ensure the separation of duties and responsibilities.

  • The procedures may include variances to the ITInformation Technology Change Management Process in order to resolve failures of critical applications. For information regarding this process refer to DOMDepartment Operations Manual, Chapter 4, Article 50, Change and Configuration Management Policy. Such variances shall provide for audit trails and retroactive release or approval documentation, and require the prior approval of the AISO.

49020.6.2 Information Security Awareness

  • It is the responsibility of the department management at all levels to ensure that personnel are aware of their responsibilities:

    • All employees are accountable for the implementation of information security policies and procedures within their areas of responsibility.

    • Accountability requires that employees be aware of the department’s information security policies and procedures.

    • All employees changing jobs or exiting owner, user, or custodian status, shall have their security privileges reviewed immediately, and such persons shall be prevented from having any further opportunity to access information which they no longer have a business need based on their new job duties.

    • Employees with the status of owner, user, or custodian shall have a job description that details that status and the security requirements therein.

49020.6.3 Consequences of Information Security Violations

  • During the time that a suspected violation is under investigation, the suspected violator’s access privileges may be revoked or other appropriate action taken to prevent harm to the department.

49020.6.4 Return of Information Assets

  • All employees, contractors, and third party users shall immediately return all of the department’s information and assets in their possession upon termination of their employment, contract, or agreement.

  • All employees on extended leave or absence shall return department-issued information assets or ensure appropriate custody and access controls are in place, as determined by their Hiring Authority.

49020.6.5 Removal of Access Rights

  • Upon termination, position change or change of duties, the access rights of an individual to assets associated with information systems and services shall be evaluated. This will determine whether it is necessary to remove access rights. Changes of employment should be reflected in removal of all access rights that were not approved for the new position. The access rights that should be removed or adapted include physical and logical access, keys, identification cards, information processing facilities, subscriptions, and removal from any documentation that identifies them as a current member of the group. If a departing employee, contractor or third-party user has known passwords for accounts remaining active, these should be changed upon termination or change of employment, contract or agreement.

49020.7 Physical Access Control to Information Assets and Environmental Safety

  • The sensitivity of the department’s information assets and personnel safety requires that all the department computer facilities have physical controls to prevent unauthorized access.

    • All information resource facilities must be physically protected in proportion to the criticality or importance of their function. Physical access procedures must be documented, and access to such facilities must be controlled. Access lists must be reviewed at least quarterly or more frequently depending on the nature of the systems that are being protected.

    • Each owner and custodian of departmental information systems shall establish physical controls over their information assets. This requirement applies to workstations with confidential or sensitive information and includes network and data communications components, as well as, application and database servers.

49020.7.1 Use of Secure Areas to Protect Data and Information

  • The use of secure areas to protect data and information shall adhere to the following:

    • Use physical methods to control access to areas. These methods include, but are not limited to, locked doors, secured cage areas, vaults, IDInstitutions Division (see DAI) cards, and biometrics.

    • Restrict building access to authorized personnel.

    • Identify areas within a building that should receive special protection and be designated as a secure area. An example is a server room.

    • Security methods should be commensurate with security risk.

    • Ensure that physical barriers are used to prevent contamination from external environmental sources.

    • Compliance with fire codes.

    • Installation, use and maintenance of air handling, cooling, uninterruptible power supply and generator backup to protect the ITInformation Technology investment in server rooms.

49020.7.2 Managing Physical Access to Protect Data and Information

  • To manage the department’s protection of data and information, all physical access to facilities that host critical CDCRCalifornia Department of Corrections and Rehabilitation ITInformation Technology infrastructure, systems, and programs, must follow the principle of least privileged access.

  • The process of granting physical access to information resource facilities must include the approval of the CIO, or designee.

    • Personnel, including full and part-time staff, contractors and vendors’ staff should be granted access to only those facilities and systems that are necessary for the fulfillment of their job responsibilities.

    • Access reviews must be conducted at least quarterly, or more frequently, depending on the nature of the systems that are being protected.

    • Removal of individuals who no longer require access must then be completed in a timely manner.

  • Access cards and keys must be appropriately protected, not shared or transferred, and returned when no longer needed. Lost or stolen cards and keys must be reported immediately.

  • Security clearance for visitors should include, but is not limited to, a sign-in book which includes the date and time of entry and departure, employee escort within a secured area IDInstitutions Division (see DAI) check, and IDInstitutions Division (see DAI) badges where critical information resources are contained.

49020.7.3 Protecting Against External and Environmental Threats

  • Department personnel shall give consideration to any external and environmental security threats presented by neighboring premises, e.g. a fire in a neighboring building, water leaking from the roof or in floors below ground level or an explosion in the street.

    • The following guidelines should be considered to avoid damage from the fire, flood, earthquake, explosion, civil unrest, and other forms of natural or man-made disaster:

      • Hazardous or combustible materials should be stored at a safe distance from a secure area. Bulk supplies such as stationary should not be stored within a secure area;

      • Fallback equipment and back-up media should be sited at a safe distance to avoid damage from a disaster affecting the main site;

      • Appropriate firefighting equipment should be provided and suitably placed.

49020.7.4 Working in Secure Areas

  • Physical protection and guidelines for working in secure areas shall be applied. The following guidelines should be considered:

    • Personnel should only be aware of the existence of, or activities within, a secure area on a need to know basis;

    • Unsupervised personnel working in secure areas should be avoided both for safety reasons and to prevent opportunities for malicious activities;

    • Vacant secure areas should be physically locked and periodically checked;

    • Photographic, video, audio or other recording equipment, such as cameras in mobile devices, should not be allowed, unless authorized.

49020.7.5 Data Processing Equipment Siting and Protection

  • Data processing equipment shall be sited and protected to reduce the risks from environment threats and hazards, and opportunities for unauthorized access.

    • The following guidelines shall be applied to protect equipment:

      • Equipment should be sited to minimize unnecessary access into work areas;

      • Facilities handling sensitive data should be positioned and the viewing angle restricted to reduce the risk of information be viewed by unauthorized persons during their use, and storage facilities secured to avoid unauthorized access;

      • Items requiring special protection should be isolated to reduce the general level of protection required;

      • Controls shall be adopted to minimize the risk of potential physical threats, e.g., theft, fire, explosive, smoke, water (or water supply failure), dust, vibration, chemical effects, electrical supply interference, communications interference, electromagnetic radiation, and vandalism;

      • Guidelines for eating, drinking, and smoking in proximity to facilities should be established;

      • Equipment processing confidential and/or sensitive information shall be protected to minimize the risk of information leakage due to emanation.

49020.7.6 Cabling Security

  • Power and telecommunications cabling carrying data or supporting information services shall adhere to established department standards and procedures. Cabling should be secured and protected from interception or damage. The following cabling security guidelines shall be considered:

    • Power and telecommunication lines into facilities shall be underground, where possible, or subject to adequate alternative protection.

    • Network cabling shall be protected from unauthorized interception or damage, for example by using conduit or by avoiding routes through public areas.

    • Power cables should be segregated from communications cables to prevent interference.

    • Clearly identifiable cable and equipment markings shall be used to minimize handling errors, such as accidental patching of wrong network cables.

    • For sensitive or critical systems, further controls to consider include:

      • Installation of armored conduit and locked rooms or boxes at inspection and termination points;

      • Use of alternative routings and/or transmission media providing appropriate security;

      • Use of fiber optic cabling;

      • Use of electromagnetic shielding to protect the cables;

      • Initiation of technical sweeps and physical inspections for unauthorized devices being attached to cables;

      • Controlled access to patch panels and cable rooms.

  • All network connectivity in proximity to incarcerated population shall abide by current approved network authentication technology, as defined by the ISOInformation Security Officer.

49020.7.7 Secure Disposal or Re‑Use of Equipment

  • All items of equipment containing storage media shall be checked by the appropriate ITInformation Technology support staff to ensure that any confidential or sensitive data and licensed software has been removed or securely overwritten prior to disposal.

49020.7.8 Removal of Property

  • Equipment, information, or software shall not be taken off-site without prior authorization.

  • For administrative purposes, all information residing on the department’s computers that is considered to be sensitive or confidential shall be treated as such by all persons who have access to it and shall be protected from unauthorized access.

49020.8 Information Integrity and Data Security

  • Security controls shall be established to ensure that data entered into and stored in its automated files or databases are complete and accurate, as well as ensuring the accuracy of disseminated information. Security measures will be established to ensure that access is limited to authorized users.

49020.8.1 High Risk Confidential Information

  • No HRCI shall be present on any computer resource, including workstations that are not under the department’s direct control. Any exceptions must be authorized on a case-by-case basis by the AISO and the owner of the information, unless encrypted using a department approved encryption standard. HRCI is defined as non-public information that if disclosed could result in a significant harm (including financial, legal, risk to life and safety or reputational damage) to the department or individual(s) if compromised through alternation, corruption, loss, misuse, or unauthorized disclosure. Examples of HRCI include, but are not limited to:

    • Personally identifiable information such as a person’s name in conjunction with the person’s social security number, credit or debit card information, individual financial account, driver’s license number, State IDInstitutions Division (see DAI) number, or passport number, or a name in conjunction with biometric information;

    • Protected health information such as any information about health status, provisions of health care, or payment for health care information as protected under the Health Insurance Portability and Accountability Act of 1996;

    • An incarcerated person’s or supervised person’s correctional criminal record information, as defined in California PCPenal Code, sections 13100-13104 regarding “criminal offender record information;”

    • All ITInformation Technology infrastructure information that would reveal vulnerabilities to, or otherwise increase the potential for an attack on, an information technology system of a public agency, including but not limited to firewall and router configurations, server names, IP addresses, and other system configurations;

    • Any document which contains information identifying any confidential informant, or confidential information, as defined in CCRCalifornia Code of Regulations, Title 15, section 3321;

    • Any documentation of information which contains information or data within any Gang Data Base as defined in the DOMDepartment Operations Manual, Chapter 5, Article 22, sections 52070.22-52070.24;

    • Records of investigations, intelligence information, or security procedures as specified in the PRAPublic Records Act, section 7923.600(a).

49020.8.2 Confidentiality of Security Mechanisms

  • The specific security mechanisms used by the department to control access to its information resources are confidential.

  • Information concerning specific details of access controls shall not be divulged except on a need-to-know basis, and then only to persons for whom there are signed security agreements on file.

49020.8.3 Confidentiality of Production Application Software

  • All documentation concerning production applications residing on the department mainframes, servers, network infrastructure, and workstations is confidential.

  • Appropriate procedures to protect and preserve the confidentiality of an application’s documentation are to be developed by the data custodian that has responsibility for, or custody of, such application. The procedures shall ensure that documentation is not divulged except on a “need-to-know” basis, and then only to persons for whom there are signed security agreements on file.

49020.8.4 Confidentiality Agreements

  • Requirements for confidentiality or non-disclosure agreements reflecting the department needs for the protection of information should be identified and regularly reviewed. Confidentiality and non-disclosure agreements protect organizational information and inform signatories of their responsibility to protect, use, and disclose information in a responsible and authorized manner.

  • Confidentiality or non-disclosure agreements should address the requirement to protect confidential information using legally enforceable terms. To identify requirements for confidentiality or non-disclosure agreements, the following elements should be considered:

    • A definition of the information to be protected (e.g., confidential information);

    • Expected duration of an agreement, including cases where confidentiality might need to be maintained indefinitely;

    • Required actions when an agreement is terminated;

    • Responsibilities and actions of signatories to avoid unauthorized information disclosure (such as “need-to-know”);

    • Ownership of information, trade secrets and intellectual property, and how this relates to the protection of confidential information;

    • The permitted use of confidential information, and rights of the signatory to use information;

    • The right to audit and monitor activities that involve confidential information;

    • Process for notification and reporting of unauthorized disclosure or confidential information breaches;

    • Terms for information to be returned or destroyed at agreement cessation; and

    • Expected actions to be taken in case this agreement is breached.

  • Based on the department’s security requirements, other elements may be needed in a confidentiality or non-disclosure agreement. Confidentiality and non-disclosure agreements should comply with all applicable laws and regulations for the jurisdiction to which it applies. Requirements for confidentiality and non-disclosure agreements should be reviewed periodically and when changes occur that influence these requirements.

49020.8.5 Information Sharing with External Parties

  • The risk to the department information and facilities from business processes involving external parties should be identified and appropriate controls implemented before granting access.

  • When there is a need to allow an external party access to the facilities or information of the department, a risk assessment should be carried out to identify any requirements for specific controls. The identification of risks related to external party access should take into account the following issues:

    • The facilities the external party is required to access;

    • The type of access the external party will have to the information and facilities, e.g., physical access to offices, computer rooms, filing cabinets or logical access to an organization’s databases and information systems;

    • Network connectivity between the organization’s and the external party’s network(s), e.g., permanent connection, remote access;

    • Whether the access is taking place on-site or off-site;

    • The value and sensitivity of the information involved, and its criticality for business operations;

    • The controls necessary to protect information that is not intended to be accessible by external parties;

    • The external party personnel involved in handling the organization’s information;

    • How the organization or personnel authorized to have access can be identified, the authorization verified, and how often this needs to be reconfirmed;

    • The controls employed by the external party when storing, processing, communicating, sharing, and exchanging information;

    • The impact of access not being available to the external party when required, and the external party’s entering or receiving inaccurate or misleading information;

    • Practices and procedures to deal with information security incidents and potential damages, and the terms and conditions for the continuation of external party access in the case of an information security incident;

    • Legal and regulatory requirements and other contractual obligations relevant to the external party that should be taken into account; and

    • How the interests of any other stakeholders may be affected by the arrangements. Access by external parties to the department’s information should not be provided until the appropriate controls have been implemented and, where feasible, a Data Sharing Agreement (DSA) or Memorandum of Understanding (MOUMemorandum Of Understanding) has been signed, defining the terms and conditions for the connection or access and the working arrangement. Generally, all security requirements resulting from work with external parties or internal controls should be reflected by the agreement with the external party.

  • It should be ensured that the external party is aware of their obligations, and accepts the responsibilities and liabilities involved in accessing, processing, communicating, or managing the organization’s information and facilities.

49020.8.6 Personal Computer Security

  • Information maintained in a personal computer system, including laptop computers and mobile devices, must be subjected to the same degree of management control and verification of accuracy that is provided for information that is maintained in other automated files. Files containing HRCI or sensitive data shall not be stored in personal computer systems unless it can be demonstrated that doing so is in the best interest of the department and that security measures have been implemented to provide adequate protection. Proposals to use desktop or laptop computers to maintain or access files containing HRCI or sensitive data must be approved by the AISO before implementation.

49020.8.7 Personal Computing Devices

  • Using personally-owned devices to access departmental information resources may jeopardize the integrity and security of CDCRCalifornia Department of Corrections and Rehabilitation’s information resources. The following provisions shall be followed:

    • Personally-owned electronic devices shall not connect to, transfer data to or from, or be used to copy data to or from the CDCRCalifornia Department of Corrections and Rehabilitation network;

    • Personally-owned smartphones or tablets, such as Android or iPhone devices, shall not connect to, transfer data to or from, or be used to copy data to or from the CDCRCalifornia Department of Corrections and Rehabilitation network;

    • CDCRCalifornia Department of Corrections and Rehabilitation electronic-mail (e-mail) shall not be setup for delivery or used on any personally-owned smartphone or electronic device;

    • Personally-owned USB memory “sticks,” “cards,” or “external drives,” shall not be used to copy, forward, or transfer CDCRCalifornia Department of Corrections and Rehabilitation data from CDCRCalifornia Department of Corrections and Rehabilitation local drives, networks, or e-mail systems.

  • Exemptions to these provisions shall require approval from the department personnel’s hiring authority.

49020.9 Mobile Computing and Storage Devices

  • All mobile computing and storage devices that access the department network or store department data must be compliant with CDCRCalifornia Department of Corrections and Rehabilitation information security policies and standards. All storage devices that may contain CDCRCalifornia Department of Corrections and Rehabilitation data must also be compliant (e.g., repurposed equipment). The following provisions shall be followed:

    • HRCI stored on any computing and storage devices must be encrypted.

    • Any and all mobile computing devices used within the CDCRCalifornia Department of Corrections and Rehabilitation information and computing environments must meet all applicable department encryption standards. Mobile computing devices shall be tracked in an information assets inventory.

    • CDCRCalifornia Department of Corrections and Rehabilitation information security policies applicable to desktop or workstation computers apply to mobile computing devices.

    • Employees will delete information from their portable device or portable storage media once it is no longer needed.

    • All department laptops shall connect to the CDCRCalifornia Department of Corrections and Rehabilitation network at a minimum of 42 days or another designated time frame to receive updates.

    • Personal long distance calls shall not be made from state-issued handheld devices except as authorized in DOMDepartment Operations Manual, Chapter 1, Article 12, Telephones, Facsimiles, and Cellular Type Telephones.

    • Personal local calls shall not be made from state-issued handheld devices except as authorized in DOMDepartment Operations Manual, Chapter 1, Article 12, Telephones, Facsimiles, and Cellular Type Telephones.

49020.10 Access Control

  • Access to any of the department’s computerized information on any of the department’s computers or the OTech Data Center is restricted to authorized persons. All access to CDCRCalifornia Department of Corrections and Rehabilitation’s information systems shall be protected by at least user IDInstitutions Division (see DAI)/password access control. Any software installed on information systems which use password protection features shall provide for non-display of, and restricted control over, passwords. No software that allows the authentication process to be bypassed or comprised may be installed on those computers.

    • Any person requiring such access shall:

      • Be a state employee or a bona fide representative of the department.

      • Demonstrate either a need for, or a legal right to, the information.

      • Receive formal authorization from the owner of the information.

      • Accept legal responsibility for preserving the security of the information.

  • The sensitivity of the information residing in the department’s computerized environments requires strict controls over who is allowed access to that environment, which information may be accessed, and how that information may be accessed.

  • The following uniform access authorization procedure assumes that all pertinent procedures have been followed, and all department-required system approvals have been obtained. This policy procedure is for access to existing information resources. The uniform access authorization procedure is as follows.

    • All access requests shall be sent to the system owner with a copy to the AISO. The request shall contain the following:

      • The name of the requester.

      • The specific information for which access is desired.

      • The reason(s) why the requestor has a need for, or right to, the information.

      • The frequency and duration of the requested access.

      • The type of access (e.g., read, update, copy, etc.).

  • After the data owner approves the request for access and returns it to the requestor, the approval is then routed to either EISEnterprise Information Services (formerly Information Services Division) or the requesting organization’s ISCInformation Security Coordinators for action.

49020.10.1 Information Security‑Responsibilities of Password Owners

  • Access to CDCRCalifornia Department of Corrections and Rehabilitation’s information systems is restricted by password to only authorized persons. Authorized persons shall never reveal their passwords to anyone for any reason. Authorized persons using a computer shall log off or activate a password-protected screensaver before leaving the immediate vicinity of the computer or terminal. Additionally, no ability shall exist for a user to store, load, or invoke the log on process on any department computer, by any method that includes the user Resource Access Control Facility (RACF), IDInstitutions Division (see DAI), or the password. Violation of this policy may result in the revocation of all access privileges and appropriate disciplinary action. Such disciplinary action may be based not only on the violation itself, but also on all activity performed by those obtaining access to a system or information asset due to a violation of this policy.

  • The password is a major “key” to the integrity of CDCRCalifornia Department of Corrections and Rehabilitation’s automated environment. The password policy exists to protect the integrity of that “key.” User IDs shall never be duplicated. User IDInstitutions Division (see DAI) security is backed up by the existence of passwords. Owners are responsible for anything for which their password is used. In addition to any password requirements associated with specific systems or services, as a matter of self-protection, the password owner shall:

    • Not share their password.

    • Not write down their the password.

    • Not use an obvious password. Obvious passwords include one’s name or nickname, the names of one’s children, one’s user IDInstitutions Division (see DAI), names, or words associated with hobbies (“DANCER,” “SKIER,” “GOLFER,” etc.), names associated with favorite books, TV shows, or movies (“JEDI,” “FRODO,” “PICARD,” “RHETT,” etc.), “SECRET,” “SECURE,” “PASSWORD,” all spaces or the “enter” key, “9999999”, “XXXXXXX,” driver’s license, social security numbers, the name of the current month, etc.

    • Not use single words that can be looked up in any dictionary, including foreign languages (e.g., Latin).

    • Use non-obvious passwords, such as word combinations rather than single words (“COMPUTERUSER,” “SKIBUM,” “IAMADANCER,” etc.) intentionally misspelled words (“KRAKER,” “KORECTUNS,” etc.), or random combinations of letters and numbers, etc.

  • If a password is forgotten, the password owner shall contact the local ITInformation Technology support staff or the CDCRCalifornia Department of Corrections and Rehabilitation Help Desk for a password reset. They shall validate the owner’s identity and give a new temporary, one-time password. The owner shall change this password immediately.

  • If anyone asks for a password, the owner shall refuse to provide it and shall refer the person to a supervisor. The owner shall then notify the supervisor.

  • Anyone who knows or suspects that password has been compromised, including instances where a known correct password is no longer accepted, shall take the following actions:

    • Notify the ISCInformation Security Coordinators;

    • Notify the immediate manager/supervisor;

    • Notify the Information Security Office;

    • Complete a “security incident report” and submit it to the Information Security Office.

49020.10.2 Information Security‑Responsibilities of Supervisors

  • People are provided passwords because their jobs require them to access the department information systems. When a password owner terminates employment or is reassigned to duties that do not require such access, the immediate supervisor shall, without delay, notify the applicable party of the change.

  • The authority to access department computers entails a significant risk to the department’s ability to function. Such authority is restricted to persons with a demonstrated need for access. Because that need is, by definition, a function of the person’s specific job duties, any change in those duties requires a reevaluation of the need for access. If the duties change such that the need for access no longer exists, the access shall be revoked.

  • If any password owner changes job duties (via resignation, promotion, transfer, reorganization, separation, etc.), that individual’s immediate supervisor shall initiate the following:

    • Reevaluate whether the person’s new duties still require the authority to access the department’s computers

    • Notify the local ITInformation Technology support staff or the access management group if the person no longer requires access authority.

    • Notify the owner of the relevant departmental information so that the appropriate paperwork can be initiated to document the removal of the person’s access privileges if the person no longer requires access authority.

  • The lack of use of the access authority is assumed to be proof that the authority is no longer required. Access authority to information assets may be revoked without notice if they are not used regularly.

49020.10.3 Requesting Authority to Access Department Mainframe Environments

  • Access to an entire mainframe environment shall not be authorized. Access to specific portions of that environment, such as, but not limited to, the system development facilities, shall be authorized for specific organizations. Access to a specific application can be authorized by the information owner as a means of meeting a specific request for specific information.

49020.10.4 Unattended Workstations

  • Active workstations or terminal sessions must not be left unattended. Any authorized or unauthorized activity on an unattended workstation will be attributed to the person whose logon and password activated the terminal or workstation. All sessions shall either be terminated when leaving the immediate area, or protected with a password-activated screensaver.

49020.10.5 Reassignment of Workstations

  • The local computer coordinators shall erase all electronic documents from the hard drive of a computer once any staff member of the department has ceased using that computer. All forms of electronic documents that the previous staff member created, received, or used shall be removed. As needed, the electronic documents may be transferred to another computer. Notification of the previous staff member’s being placed on litigation hold or being under investigation requires that the information be stored and properly secured until further notification. All department employees shall also be made aware of the events and activities that constitute threats to the organization for which they work and of the actions to be taken when confronted by those events or activities.

49020.11 Information Systems Acquisitions, Development and Maintenance

  • Information systems include operating systems, infrastructure, business applications, off-the-shelf products, services, and user-developed applications. The design and implementation of the information system supporting the business process can be crucial to security. Security requirements shall be identified and agreed upon prior to the development and/or implementation of information systems. All security requirements shall be identified at the requirements phase of a project and justified, agreed upon, and documented as part of the overall business case for an information system.

49020.11.1 Cryptographic Controls

  • Cryptographic controls should be considered to achieve:

    • Confidentiality: using encryption of information to protect sensitive or critical information either stored or transmitted;

    • Authenticity and Integrity: using digital signatures or message authentication codes to protect the authenticity and integrity of stored or transmitted sensitive or critical information;

    • Non-repudiation: using cryptographic techniques to obtain proof of the occurrence or non-occurrence of an event or action.

  • Based on a risk assessment, the required level of protection shall be identified taking into account the type, strength, and quality of the encryption algorithm required. All cryptographic keys shall be protected against modification, loss, and/or destruction.

49020.11.2 Security of System Files

  • To minimize the risk of corruption to operation systems, the following procedures shall be implemented:

    • The updating of operation software, applications, and program libraries, shall only be performed by trained administrators upon management authorization;

    • Operational systems shall only contain approved executable code, and not development code or compilers;

    • A rollback strategy shall be in place before changes are implemented;

    • An audit log shall be maintained of all updates to operational program libraries;

    • Previous versions of application software shall be retained as a contingency measure.

  • Decisions to upgrade to a new software release should take into account the business requirements for the change, and the security of the release, i.e. the introduction of new security functionality or the number and severity of security problems affecting this version. Software patches and system upgrades shall be applied when they can help to remove or reduce security weaknesses, unless there are unacceptable risks and impacts to business operations.

  • Physical or logical access shall only be given to non-department employees for support services when necessary, and with approval from the AISO. Access to the department information resources should be monitored. Computer software that relies on externally supplied software and modules shall be monitored and controlled to avoid unauthorized changes, which could introduce security weaknesses.

49020.11.3 Protection of System Data

  • The use of operational databases containing personal information or any other sensitive information for testing purposes should be avoided. If personal or otherwise sensitive information is used for testing purposes, all sensitive details and content should be removed or modified beyond recognition before use.

49020.11.4 Access Control to Program Source Code

  • Access to program source code and associated items (such as designs, specifications, verification plans and validation plans) shall be strictly controlled, in order to prevent the introduction of unauthorized functionality and to avoid unintentional changes.

49020.11.5 Security in Development and Support Processes

  • Ensuring the security of application system software and information is essential. As such, production environments shall be strictly controlled.

49020.12 Collection of Evidence

  • When misconduct is discovered which constitutes an information security incident in conjunction with a possible violation of departmental policy or criminal violation, precaution must be taken to avoid contamination of the possible electronic evidence. Prior to taking action, the discoverer should contact the Hiring Authority or OIAOffice of Internal Affairs for direction, if the misconduct could lead to an administrative investigation. If the misconduct rises to the level of criminal misconduct, the OIAOffice of Internal Affairs must be notified immediately prior to any action being taken.

  • When there is any incident that involves the preservation of any evidence and after the first responder has consulted with the Hiring Authority or OIAOffice of Internal Affairs, the first responder is responsible to preserve the electronic crime scene and recognize, collect, and safeguard the digital evidence, non-digital evidence, or both. First responders and managers who supervise personnel who process such events should be familiar with the information in this section and perform their duties.

  • Digital evidence includes all information and data of value to an investigation that is stored on, received, or transmitted by an electronic device. All other evidence is non-digital evidence.

  • When dealing with digital evidence, general forensic and procedural principles should be applied:

    • The process of collecting, securing, and transporting digital evidence should never change the evidence and integrity of the chain of evidence must be maintained.

    • Digital evidence should only be examined and/or acquired by those trained specifically for that purpose. First responders without proper training, equipment, or skills should not attempt to explore the contents of or to recover information from any electronic device.

    • Everything done during the seizure, transportation, and storage of digital evidence should be fully documented, and preserved. Documentation should include the specific location of the evidence found, how it was collected, labeled, and preserved.

    • Package and transport digital evidence in a secure manner consistent with chain of evidence procedures.

    • Any forensic work shall be performed on copies of the digital evidence. The original device(s) shall be secured and protected for the entire process until a matter has been determined closed. The original drive shall not be imaged or cloned without consulting first with the OIAOffice of Internal Affairs.

  • When dealing with all other forms of non-digital evidence:

    • The original evidence shall be kept securely with a record of the individual who located it.

    • The individual who located the original evidence shall prepare a record of the location of the evidence, when the evidence was found, who witnessed the discovery of the evidence.

    • Package and transport of non-digital evidence in a secure manner consistent with chain of evidence procedures.

49020.12.1 Incident Report Format

  • The following information concerning each incident shall be reported to the ISOInformation Security Officer Information Security Office within three working days of becoming aware of the occurrence of the incident:

    • Date and time.

    • Location.

    • Description of what happened.

    • Estimated damages.

    • Description of corrective action taken or planned.

    • Estimated costs associated with corrective actions.

    • If known, identity of those responsible for the incident.

    • Descriptions of actions taken or planned against those responsible for the incident.

    • Contact name and phone number of the person reporting the incident.

  • The report submitted to the ISOInformation Security Officer Information Security Office shall be signed by the appropriate Warden, Regional Parole Administrator, Director, or Assistant Secretary.

  • Incidents involving the following shall be forwarded to the State Office of Information Services (OIS) within five business days of the initial report, and shall be signed by the AISO and Secretary or there authorized delegate:

    • CDCRCalifornia Department of Corrections and Rehabilitation-owned or CDCRCalifornia Department of Corrections and Rehabilitation managed data, without authorization, was damaged, destroyed, deleted, shared, altered, or copied, or used for non-state business. This includes computer documentation and configuration information, as well as electronic and non-electronic data and reports.

    • Unauthorized parties accessed one or more CDCRCalifornia Department of Corrections and Rehabilitation computers, computer systems, or computer networks. This includes deliberate and unauthorized uses of CDCRCalifornia Department of Corrections and Rehabilitation-owned computer services, as well as, “hacker attacks.”

    • Someone has accessed and without permission added, altered, damaged, deleted, or destroyed any computer programs which reside or exist internal or external to a CDCRCalifornia Department of Corrections and Rehabilitation computer, computer system, or computer network.

    • Disruption of CDCRCalifornia Department of Corrections and Rehabilitation computer services or denial of computer services occurred in a manner that appears to have been caused by deliberate and unauthorized acts.

    • A contaminant was introduced into a CDCRCalifornia Department of Corrections and Rehabilitation computer, computer system, or computer network. This includes, but is not limited to, viruses, Trojans, worms, and other types of malicious attacks.

    • Internet domain names and/or users account names have been used without permission in connection with the sending of one or more electronic mail messages, and thereby caused damage to a CDCRCalifornia Department of Corrections and Rehabilitation computer, computer system, or computer network, or misrepresented CDCRCalifornia Department of Corrections and Rehabilitation or CDCRCalifornia Department of Corrections and Rehabilitation employees in electronic communications.

    • Damage or destruction of CDCRCalifornia Department of Corrections and Rehabilitation information processing facilities has occurred.

    • Physical intrusions into CDCRCalifornia Department of Corrections and Rehabilitation facilities have occurred that may have resulted in the compromise of CDCRCalifornia Department of Corrections and Rehabilitation data or computer systems.

    • Lost, damaged, or stolen devices used for information processing.

  • The California Highway Patrol’s Emergency Notification and Tactical Alert Center (ENTAC) shall be notified of the occurrence of an incident within one day of receipt of the initial report. Incidents involving “Personally Identifiable Information” (PII) or “Personal Health Information” (PHI) involving more than 500 California Residents shall be reported to the Attorney General.

49020.12.2 Collection of Evidence

  • When misconduct is discovered which constitutes an information security incident in conjunction with a possible violation of departmental policy or criminal violation, precaution must be taken to avoid contamination of the possible electronic evidence. Prior to taking action, the discoverer should contact the Hiring Authority and/or the Office of Internal Affairs (OIAOffice of Internal Affairs) for direction, if the misconduct could lead to an administrative investigation. If the misconduct rises to the level of criminal misconduct, the OIAOffice of Internal Affairs must be notified immediately prior to any action being taken.

  • When there is any incident that involves the preservation of any evidence and after the first responder has consulted with the Hiring Authority/OIAOffice of Internal Affairs, the first responder is responsible to preserve the electronic crime scene and recognize, collect, and safeguard the digital evidence and/or non-digital evidence. First responders and managers who supervise personnel who process such events should be familiar with the information in this section and perform their duties.

  • Digital evidence includes all information and data of value to an investigation that is stored on, received, or transmitted by an electronic device. All other evidence is non-digital evidence.

  • When dealing with digital evidence, general forensic and procedural principles should be applied:

    • The process of collecting, securing, and transporting digital evidence should never change the evidence and integrity of the chain of evidence must be maintained.

    • Digital evidence should only be examined and/or acquired by those trained specifically for that purpose. First responders without proper training, equipment, or skills should not attempt to explore the contents of or to recover information from any electronic device.

    • Everything done during the seizure, transportation, and storage of digital evidence should be fully documented, and preserved. Documentation should include the specific location of the evidence found, how it was collected, labeled, and preserved.

    • Package and transport digital evidence in a secure manner consistent with chain of evidence procedures.

    • Any Forensic work shall be performed on copies of the digital evidence. The original device(s) shall be secured and protected for the entire process until a matter has been determined closed. The original drive shall not be imaged or cloned without consulting first with the OIAOffice of Internal Affairs.

  • When dealing with all other forms of non-digital evidence:

    • The original evidence shall be kept securely with a record of the individual who located it.

    • The individual who located the original evidence shall prepare a record of the location of the evidence, when the evidence was found, who witnessed the discovery of the evidence.

    • Package and transport of non-digital evidence in a secure manner consistent with chain of evidence procedures.

49020.13 Failure to Correct Information Security Deficiencies

  • Should any audit indicate that the State’s security policies are not established or that the department has not taken corrective action with respect to security deficiencies, the department may be subject to any or all of the following:

    • Further audit and review by the Department of Finance (DOFDepartment Of Finance), Bureau of State Audits (BSA), State Controller’s Office (SCOState Controller’s Office), and/or Department of Justice (DOJDepartment Of Justice).

    • Revocation by the DOFDepartment Of Finance of delegated approval authority for ITInformation Technology projects.

    • Application of penalties specified in GCGovernment Code, section 1222.

49020.14 Technical Vulnerabilities Management

Revised May 20, 2026
  • Technical vulnerability management shall be implemented in an effective, systematic, and repeatable way with measurements taken to confirm its effectiveness.

  • A current and complete inventory of information assets will be maintained. Specific information gathered should include software vendor, version numbers, software installed and person(s) responsible for the software installation. Appropriate timely action shall be taken in response to the identification of potential technical vulnerabilities. The following should be established:

    • EISEnterprise Information Services (formerly Information Services Division) shall define and establish the roles and responsibilities associated with technical vulnerability management, including vulnerability monitoring, vulnerability risk assessment, patching, asset tracking, and any coordination responsibilities required.

    • Information resources that will be used to identify relevant technical vulnerabilities and to maintain awareness about them should be identified for software and other technology (based on the asset inventory list,); these information resources should be updated based on changes in the inventory, or when other new or useful resources are found.

    • A timeline should be defined to react to notifications of potentially relevant technical vulnerabilities.

    • Once a potential technical vulnerability has been identified, EISEnterprise Information Services (formerly Information Services Division) shall identify the associated risks and the actions to be taken.

    • Depending on the urgency of which a technical vulnerability needs to be addressed, the action taken shall be carried out according to change control procedures or by following the Department’s information security incident response procedures.

    • If a patch is available, the risks associated with installing the patch should be assessed (the risks posed by the vulnerability should be compared with the risk of installing the patch).

    • Patches should be tested and evaluated before they are installed to ensure they are effective and do not result in side effects that cannot be tolerated; if no patch is available, other controls should be considered, such as:

      • Turning off services or capabilities related the vulnerability.

      • Adapting or adding access controls, e.g., firewall rules, at the network border.

      • Increased monitoring to detect or prevent actual attacks.

      • Raising awareness of the vulnerability.

  • Employees, contractors, and third-party users of information systems and services shall not attempt to prove suspected security vulnerabilities. Testing vulnerabilities may be interpreted as a potential misuse of the system and could cause damage to the information system or service and result in disciplinary actions for the individual performing the test.

49020.14.1 Software Controls on Department Workstations

  • The following software controls shall be established for all department workstations:

    • Only authorized personnel shall load, install, or activate approved software from ITInformation Technology standards on any department workstation.

    • Use of unauthorized software is prohibited.

49020.14.2 Data File Transfers

  • Transfer of information from one departmental computer to another does not alter the sensitive nature of the information or eliminate the need to protect the confidentiality of the information. An appropriate procedure shall be developed by EISEnterprise Information Services (formerly Information Services Division) for use by each CDCRCalifornia Department of Corrections and Rehabilitation division that uses file transfer mechanisms. The procedure shall the following constraints:

    • User requirements for ensuring the confidentiality and integrity of the data transfer.

    • Approved connectivity and transfer mechanisms.

    • All file transfers shall be governed and approved prior to the execution of the transfer.

    • Any workstation performing file transfers shall be subject to endpoint security requirements as defined in DOMDepartment Operations Manual, Chapter 4, Article 51, Endpoint Security.

49020.15 Incarcerated Persons and Supervised Persons Use of Computers

  • For the purposes of this section, a computer is defined as any stationary, mobile and/or handheld device such as a desktop personal computer, laptop, or alternative mobile computer, tablet, or similar device as determined by the department.

  • It is the policy of the department to allow incarcerated persons and supervised persons access to computers, computer terminals, or computer keyboards only within the constraints of the policies contained in this article. For the purpose of this section, “incarcerated person” means a person who is committed under sentence to or confined in a penal or correctional institution under the authority of the department. Any request for exception shall be referred to the OISO for review.

49020.15.1 Restrictions on Computer – Knowledgeable Incarcerated Persons

  • Incarcerated persons who have a history of computer fraud or abuse, as defined in PCPenal Code, section 502, shall not be placed in any assignment that provides access to a computer.

  • Incarcerated persons that have documented histories of computer fraud or abuse, as noted during the initial classification process, shall be identified on the initial classification chrono. Any occurrence of computer abuse after admittance to the prison system shall also be recorded in the incarcerated person’s records.

  • The use of incarcerated persons as programmers and system experts shall be prohibited where there is a risk to the information assets of the department or public, as determined by the institution head or the AISO. Incarcerated persons shall not be used as programmers or system experts for departmental business applications, systems, and data, per CCRCalifornia Code of Regulations, Title 15, section 3041.3(c)(1). Staff assigned to supervise incarcerated persons using computers must be able to monitor incarcerated persons’ activities.

49020.15.2 Incarcerated Person’s Access to Computer – Based Tools

  • Incarcerated persons shall not be allowed access to any computer-based tools that could be utilized to create a virus, Trojan Horse, worm, or cause damage to data files or a computer’s operating system, except in an approved Computer Refurbishment Program.

49020.15.3 Incarcerated Person’s Access to Computers and Telecommunications Devices

  • Incarcerated persons may access workstations for the purpose of completing specific tasks or assignments only while under direct and constant supervision. The approved uses of workstations by incarcerated persons shall be carried out only under very tightly controlled circumstances:

    • Each computer shall be labeled to indicate whether incarcerated persons access is authorized.

    • Computers used by incarcerated persons shall not be used concurrently for any other purpose.

    • The local ISCInformation Security Coordinators shall approve or disapprove the movement of computers from an “incarcerated person use” status to other work and vice versa.

    • Any computer that is being repurposed from employee use to incarcerated person use shall have the hard drive erased of all data prior to the redeployment using the methods in the department’s data wiping standards.

    • Incarcerated persons with a work assignment involving a particular computer shall not be assigned to work on other computers.

    • Areas where incarcerated persons are authorized to work on computers shall be posted as such.

    • All incarcerated persons shall be under the supervision of a knowledgeable employee within a controlled, designated area when using computers.

    • There shall be no communications capabilities in the designated area, such as a telephone line, computer network line, telephone punch panel, cell phones, wireless communication devices such as pagers or handheld computers or radio communication devices without approval of the AISO.

    • Incarcerated persons shall not have access to computer utility programs used tomodify the functionality of the computer or to view system configuration information,except in an approved Computer Refurbishment Program.

    • Incarcerated persons shall not have electronic storage media in their possession except within an approved area.

    • Incarcerated persons may not have access to computer application development tools.

    • An inventory and appropriate controls shall be maintained on all portable storage media diskettes. All portable storage media diskettes for incarcerated person use shall be labeled “For Incarcerated Person Use.” Reports and other printed output from incarcerated person-utilized computers shall be reviewed closely by staff, and appropriate distribution of such output shall be monitored.

    • Incarcerated persons shall not have access to the operating system of any computer. Incarcerated persons shall not have access to any interface that allows access to the system configuration of any computer including, but not limited to, dialogue boxes, setup, and configuration screens. Additionally, incarcerated persons shall not have access to operating system commands that allow viewing or modification of any aspect of a computer operating system or the configuration of a computer, except in an approved Computer Refurbishment Program.

    • Incarcerated persons shall not be allowed to load software onto hard disks, except in an approved Computer Refurbishment Program.

    • No incarcerated persons shall have access to, or possession of, any telecommunication capability, including internet-accessible computers, wireless devices such as pagers or handheld computing devices or cell phones without approval from the AISO.

    • There shall be no incarcerated person access to a computer outside the incarcerated person’s authorized work, vocational, or educational areas, unless approved by the AISO.

49020.15.4 Operation of Computer Programs Created by Incarcerated persons

  • Any computer-based system that was created by incarcerated persons programmers that is used to accomplish or complete department-related work shall not be operated or maintained by any incarcerated persons.

49020.15.5 Supervision of Incarcerated Persons Using Computers

  • The persons responsible for supervising incarcerated persons’ use of computers shall certify in writing that these policies are being adhered to at their specific site.

    • A copy of this certification shall be kept on site by the local ISCInformation Security Coordinators.

49020.15.6 Education Computers

  • The use of computers for academic and vocational education is subject to the same requirement of due care applying to all personnel that use computers within applicability of the department’s information security and risk management program.

49020.15.7 CALCTRA Systems

  • Incarcerated person use of computers in CALCTRA and in CDCRCalifornia Department of Corrections and Rehabilitation facilities shall be in accordance with the departmental policies and institutional procedures.

49020.16 Information Security Warnings

  • All critical department systems shall display a criticality warning at the first screen that any user of the system will see when the computer system is accessed.

49020.17 Compliance

  • The department shall comply with the information security and privacy policies, standards and procedures issued by the California Department of Technology (CDT), Office of Information Security (OIS). In addition to compliance with the information security and privacy policies, standards, procedures, and filing requirements issued by the OIS, the department shall ensure compliance with all security and privacy laws, regulations, rules, and standards specific to and governing the administration of their programs. Program administrators shall work with their department legal counsel, ISOInformation Security Officer, and Privacy Program Officer or Coordinator to identify all security and privacy requirements applicable to their programs and ensure implementation of the requisite controls.

  • The consequences of negligence and non-compliance with state laws and policies may include department and personal:

    • Loss of delegated authorities.

    • Negative audit findings.

    • Monetary penalties.

    • Legal actions.

  • Non-compliance with this policy may result in disciplinary or adverse action as set forth in DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.

49020.18 Auditing

  • IThe department has the right to audit any activities related to the use of state information assets.

  • CDT, OIS and the department have the statutory right to audit department readiness to respond and recover from an incident.

49020.19 Reporting

  • Violations of this policy shall be reported to the department ISOInformation Security Officer.

49020.20 Security Variance Process

  • If compliance is not feasible, or if deviation from this policy is necessary to support abusiness function, the respective manager shall formally request a security variance asdefined by the ISOInformation Security Officer. Refer to DOMDepartment Operations Manual, Chapter 4, Article 70, Security Variance Policy.

49020.21 Authority

Revised November 4, 2013
  • This policy complies with GCGovernment Code, section 11549.3.

49020.22 Revisions

  • (a) The CIO or designee shall be responsible for ensuring the contents of this Article are kept current and accurate.

References

  • (1) CIV 1798.24(t).

  • (2) DOMDepartment Operations Manual, Chapter 1, Article 12, Telephone, Facsimiles, and Cellular Type Telephones.

  • (3) DOMDepartment Operations Manual, Chapter 1, Article 23, Records Management.

  • (4) DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.

  • (5) DOMDepartment Operations Manual, Chapter 4, Article 46, Risk Management Policy.

  • (6) DOMDepartment Operations Manual, Chapter 4, Article 50, Change and Configuration Management Policy.

  • (7) DOMDepartment Operations Manual, Chapter 4, Article 51, Endpoint Security.

  • (8) DOMDepartment Operations Manual, Chapter 4, Article 70, Security Variance Policy.

  • (9) DOMDepartment Operations Manual, Chapter 5, Article 22, §§ 52070.22-52070.24.

  • (10) FIPS 140-2, 140-3, 197.

  • (11) GCGovernment Code, §§ 1222, 3300 et seq, 7920.000 et seq, 7921.000-7921.010, 7927.700, 11546.1, and 11549.3.

  • (12) NIST SP 800-53: Access Control (AC); Planning (PL); Program Management (PM);
    System and Information Integrity (SI); System and Communications Protection (SC);
    Supply Chain Risk Management (SR).

  • (13) PCPenal Code, §§ 502, 2702, 11075-11081, and 13100-13104.

  • (14) SAMState Administrative Manual, §§ 1600-1624.1, 4989-4989.8, and 5300-5365.3.

  • (15) SIMM 5305-A, Information Security Program Standard.

  • (16) The California Public Records Act, GCGovernment Code § 7923.600(a).

  • (17) Title 15, §§ 3041.3(c)(1) and 3321.

Revision History

  • (1) Revised: May 20, 2013.

  • (2) Revised Sections 49020.21, 49020.18.1: November 4, 2013.

  • (3) Revised: May 20, 2026.