Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 45 – Information Security

View All Sections >

49020.4 Roles and Responsibilities

  • Secretary

    • The Secretary shall ensure the department’s information security has a risk management program to:

      • Assigns management responsibilities for an information security program.

      • Support the integrity and security of automated and paper information, produced or used in the course of agency operations.

      • Comply with state and audit requirements relating to the integrity of information assets.

  • Chief Information Officer (CIO) or Designee

    • The CIO or designee shall maintain an information security program within the department. It is the responsibility of the CIO or designee to assure that information assets are protected from the effects of damage and destruction, as well as from unauthorized or accidental modification, access, or disclosure. Specifically, the CIO or designee shall:he CIO or designee shall:

      • Enforce state-level security policies.

      • Establish and internal policies that provide for the security of ITInformation Technology facilities, software and equipment, and the integrity and security of the agency’s automated information.

      • Department compliance with reporting requirements related to security issues.

      • Appointment of a qualified Agency Information Security Officer (AISO).

      • The participation of management during the planning, development, modification, and implementation of security policies and procedures.

      • All department information asset-users are aware of this policy and acknowledge their individual responsibilities.

      • The policy is reviewed annually and updated accordingly.

      • The required audit and compliance assessments for this policy are completed at least once every two years.

  • AISO

    • Government Code (GCGovernment Code), section 11546.1 requires that each agency designate an AISO. Additionally, to avoid conflicts of interest, the AISO shall not:

      • Have direct responsibility for information processing.

      • Have direct responsibility for access management functions.

      • Have direct responsibility for any departmental computer-based systems.

      • Have any special allegiance or bias toward a particular program or organization.

    • The AISO is responsible for overseeing the department policies designed to protect its information assets. In accordance with state policy, the AISO shall be accountable to the Secretary and CIO with respect to the following responsibilities:

      • The department’s Information Security Office.

      • Establish and maintain security policies and programs designed to protect information assets.

      • Identify confidential, sensitive information, and critical applications.

      • Identify vulnerabilities that may cause inappropriate or accidental access, destruction or disclosure of information, and the establishment of security controls necessary to eliminate or minimize their potential effects.

      • Establish and maintain programs necessary to monitor and ensure the compliance of established security and risk management policies and procedures.

      • Coordinate with internal auditors to define their roles in automated information system planning, development, implementation, operations, and modifications relative to security.

      • Coordinate with the applicable data center’s Office of the Information Security Officer (OISO) or staff on matters related to the planning, development, implementation, or modification of information security policies and programs that affect the department.

      • Acquire appropriate security equipment and software.

      • Establish and maintain programs to comply with control agency reporting requirements.

      • Develop and maintain controls and safeguards to control user access to information.

      • Establish and maintain training programs to ensure CDCRCalifornia Department of Corrections and Rehabilitation staff (with particular emphasis on the owners, users, and custodians of information) are educated and aware of their roles and responsibilities relative to information security.

      • Report allegations of misconduct or criminal activity to the department’s Office of Internal Affairs (OIAOffice of Internal Affairs) and assist with investigations as necessary.

  • Department Owners of Information Assets and Program Management

    • In relation to the department’s security program, department owners of information assets and program managers shall ensure:

      • Procedures are established and maintained to comply with State information security policy in relation to ownership, user, and if appropriate, information asset custodian responsibilities.

      • State program policies and requirements are identified relative to security requirements.

      • Proper data classification of automated information for which the program is assigned ownership responsibility.

      • Participation of the OISO and technical staff in identifying and selecting appropriate and cost-effective security controls and procedures, and to protect information assets.

      • Appropriate security requirements for user access to automated information are defined for files or databases for which the program is assigned ownership responsibility.

      • Proper planning, development, and establishment of security policies and procedures for files or databases for which the program has ownership responsibility, and for physical devices assigned to and located in the program area(s).

      • Information asset custodians are provided the appropriate direction to implement the security controls and procedures that have been defined.

      • Procedures are established to comply with control agency reporting requirements.

  • EISEnterprise Information Services (formerly Information Services Division) Departmental Technical Management

    • Department technical management shall ensure:

      • Management, the OISO, assigned owners, custodians, and users are provided the necessary technical support services with which to define and select cost effective security controls, policies, and procedures.

      • Implementation of security controls and procedures as defined by the owners of information.

      • Implementation of system controls necessary to identify actual or attempted violations of security policies or procedures.

      • The owners of information and the OISO are notified of any actual or attempted violations of security policies and procedures.

  • Department Users

    • Department users have the following security responsibilities:

      • Implement and monitor data quality assurance functions to ensure the integrity of data for which the program is assigned ownership responsibility.

      • Comply with applicable federal, state, and department security policies and procedures.

      • Comply with applicable federal and state statutes.

      • Ensure management, OISO, and assigned owners, custodians, and other users are provided the necessary technical support services with which to define and select cost-effective security controls, policies, and procedures.

      • Ensure implementation of security controls and procedures as defined by the owners of information.

      • Ensure implementation of system controls necessary to identify actual or attempted violations of security policies or procedures.

      • Ensure the owners of information and the Information Security Office are notified of any actual or attempted violations of security policies and procedures.

      • Be aware of and adhere to all department information security and privacy policies.

  • Information Security Coordinators

    • Every organizational entity that uses computer systems, or uses computer applications shall designate an Information Security Coordinator (ISCInformation Security Coordinators) for each site maintained by that entity. The designated ISCInformation Security Coordinators shall be responsible for ensuring that applicable CDCRCalifornia Department of Corrections and Rehabilitation policies and procedures are followed, and shall act as the security liaison to the Information Security Office. The OISO will serve as the ISCInformation Security Coordinators for EISEnterprise Information Services (formerly Information Services Division) staff that do not have a designated ISCInformation Security Coordinators.

    • A procedure shall be developed by each of these organizational entities, subject to approval by the department OISO. The procedure shall adhere to the following guidelines:

      • The designation of an ISCInformation Security Coordinators for the decentralized or control entity shall be in writing and shall identify the name, work address, and telephone number of the ISCInformation Security Coordinators.

      • The department OISO shall maintain a file of all current and past designated ISCs.

      • The designated ISCInformation Security Coordinators shall be made aware that they are the designated ISCInformation Security Coordinators and the responsibility that the designation entails.

      • The designated ISCInformation Security Coordinators shall ensure compliance with information security policies and procedures, and with any security guidelines issued by the owners of decentralized automated systems.