Article 45 – Information Security
49020.5.2 Classification of Information
-
The department’s records, automated files, and databases are essential public resources that must be given appropriate protections from unauthorized use, access, disclosure, modification, loss, or deletion. The discovery and classification of CDCRCalifornia Department of Corrections and Rehabilitation information assets is a continuing endeavor and requires the ongoing support of information owners and other stakeholders.
-
The EISEnterprise Information Services (formerly Information Services Division) Enterprise Architecture organization is responsible for maintaining and facilitating the processes and procedures for enterprise governance of CDCRCalifornia Department of Corrections and Rehabilitation information assets and engaging information owners and stakeholders for information security classification decision-making and governance.
-
Information owners are responsible for reviewing and classifying information, solely or with others, for information they own or share ownership of, and for participating in the department information governance process; the final ruling for security classification decisions rests with the information owners.
-
Stakeholders are responsible for raising Information security concerns with respect to information security classification and ensuring information is treated appropriately based on duly made classification decisions.
-
All users of departmental information are responsible for protecting CDCRCalifornia Department of Corrections and Rehabilitation Information under their control or influence from unauthorized use, access, disclosure, modification, loss, or deletion, including notifying appropriate CDCRCalifornia Department of Corrections and Rehabilitation authorities when vulnerabilities to department information is noticed or when security classifications or protections for department information appear inadequate.
-
-
The department will classify each record, file, and database using the following classification structure:
-
Public Information – information maintained by CDCRCalifornia Department of Corrections and Rehabilitation that is not exempt from disclosure under the provisions of the California Public Records Act (Gov Code, sections 7920.000 et seq.) or other applicable state or federal laws.
-
Confidential Information – information maintained by CDCRCalifornia Department of Corrections and Rehabilitation that is exempt from disclosure under the provisions of the California Public Records Act (Gov Code, sections 7920.000 et seq.) or other applicable state or federal laws.
-
High Risk Confidential Information (HRCI) – Non-public information that could result in a significant harm (including financial, legal, risk to life and safety or reputational damage) to the department or individual(s) if compromised through alteration, corruption, loss, misuse, or unauthorized disclosure. Examples of HRCI include, but are not limited to, information such as the following:
-
Personally identifiable information such as a person’s name in conjunction with the person’s social security number, credit or debit card information, individual financial account, driver’s license number, state identity document (IDInstitutions Division (see DAI)) number, or passport number, or a name in conjunction with biometric information;
-
Personal health information such as any information about health status, provisions of health care, or payment for health care information as protected under the Health Insurance Portability and Accountability Act of 1996;
-
Correctional Offender Record Information as defined in California Penal Code (PCPenal Code), sections 13100-13104;
-
All ITInformation Technology infrastructure information that would reveal vulnerabilities to, or otherwise increase the potential for an attack on, an information technology system of a public agency, including but not limited to firewall and router configurations, server names, internet protocol (IP) addresses, and other system configurations;
-
Any document which contains information identifying any confidential informant, or confidential information provided, as defined in California Code of Regulations (CCRCalifornia Code of Regulations), Title 15, section 3321;
-
Any documentation of information which contains information or data within any Gang Data Base as defined in the Department Operations Manual (DOMDepartment Operations Manual), sections 52070.22-52070.24;
-
Records of investigations, intelligence information, or security procedures as specified in the California Public Records Act (PRAPublic Records Act), section 7923.600(a).
-
Personnel, medical, or similar files, the disclosure of which would constitute an unwarranted invasion of personal privacy protected under the California GCGovernment Code, section 7927.700 or the Peace Officers Bill of Rights under GCGovernment Code, sections 3300, et seq.
-
Sensitive Information – information maintained by the department that requires a higher than normal assurance of accuracy and completeness. Thus the key factor for sensitive information is that of integrity. Typically, sensitive information includes records of financial transactions and regulatory actions.
-
-
-
Personal Information requested by researchers not under the authority of CDCRCalifornia Department of Corrections and Rehabilitation may only be received by University of California or other non-profit educational institutions and in accordance with the provisions set forth in law, including the prior review and approval by the Committee for the Protection of Human Subjects (CPHS) of the California Health and Human Services Agency before such information is released. See Civil Code (CIV), section 1798.24(t).