Article 45 – Information Security
49020.9 Mobile Computing and Storage Devices
-
All mobile computing and storage devices that access the department network or store department data must be compliant with CDCRCalifornia Department of Corrections and Rehabilitation information security policies and standards. All storage devices that may contain CDCRCalifornia Department of Corrections and Rehabilitation data must also be compliant (e.g., repurposed equipment). The following provisions shall be followed:
-
HRCI stored on any computing and storage devices must be encrypted.
-
Any and all mobile computing devices used within the CDCRCalifornia Department of Corrections and Rehabilitation information and computing environments must meet all applicable department encryption standards. Mobile computing devices shall be tracked in an information assets inventory.
-
CDCRCalifornia Department of Corrections and Rehabilitation information security policies applicable to desktop or workstation computers apply to mobile computing devices.
-
Employees will delete information from their portable device or portable storage media once it is no longer needed.
-
All department laptops shall connect to the CDCRCalifornia Department of Corrections and Rehabilitation network at a minimum of 42 days or another designated time frame to receive updates.
-
Personal long distance calls shall not be made from state-issued handheld devices except as authorized in DOMDepartment Operations Manual, Chapter 1, Article 12, Telephones, Facsimiles, and Cellular Type Telephones.
-
Personal local calls shall not be made from state-issued handheld devices except as authorized in DOMDepartment Operations Manual, Chapter 1, Article 12, Telephones, Facsimiles, and Cellular Type Telephones.
-