Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 45 – Information Security

View All Sections >

49020.8.1 High Risk Confidential Information

  • No HRCI shall be present on any computer resource, including workstations that are not under the department’s direct control. Any exceptions must be authorized on a case-by-case basis by the AISO and the owner of the information, unless encrypted using a department approved encryption standard. HRCI is defined as non-public information that if disclosed could result in a significant harm (including financial, legal, risk to life and safety or reputational damage) to the department or individual(s) if compromised through alternation, corruption, loss, misuse, or unauthorized disclosure. Examples of HRCI include, but are not limited to:

    • Personally identifiable information such as a person’s name in conjunction with the person’s social security number, credit or debit card information, individual financial account, driver’s license number, State IDInstitutions Division (see DAI) number, or passport number, or a name in conjunction with biometric information;

    • Protected health information such as any information about health status, provisions of health care, or payment for health care information as protected under the Health Insurance Portability and Accountability Act of 1996;

    • An incarcerated person’s or supervised person’s correctional criminal record information, as defined in California PCPenal Code, sections 13100-13104 regarding “criminal offender record information;”

    • All ITInformation Technology infrastructure information that would reveal vulnerabilities to, or otherwise increase the potential for an attack on, an information technology system of a public agency, including but not limited to firewall and router configurations, server names, IP addresses, and other system configurations;

    • Any document which contains information identifying any confidential informant, or confidential information, as defined in CCRCalifornia Code of Regulations, Title 15, section 3321;

    • Any documentation of information which contains information or data within any Gang Data Base as defined in the DOMDepartment Operations Manual, Chapter 5, Article 22, sections 52070.22-52070.24;

    • Records of investigations, intelligence information, or security procedures as specified in the PRAPublic Records Act, section 7923.600(a).