Article 46 – Information Systems Risk Management
49030.1 Policy
Revised June 17, 2026-
The California Department of Corrections and Rehabilitation (CDCRCalifornia Department of Corrections and Rehabilitation or the department), the California Correctional Health Care Services (CCHCS), and the California Correctional Training and Rehabilitation Authority (CALCTRA) shall maintain the requirements to perform risk assessment management. The risk management information in the context of this policy is used to protect against the likelihood of departmental loss of information assets or the occurrence of a security breach.
49030.2 Objective
Revised June 17, 2026-
The department conducts risk assessments to identify risks to its operations (including mission, functions, or reputation), organizational assets, individuals, other organizations, and the state and federal government entities arising from the operation of information assets. As components of the risk management process, risk assessments consider threats, vulnerabilities, and business impact analyses. They also evaluate risk mitigations provided by planned and implemented security controls.
-
Risk assessments shall be performed at one or more of the following levels, as determined by the classification process:
-
Organizational level;
-
Mission/Business process level;
-
Information asset level.
-
49030.3 Scope and Applicability
-
The scope of this policy extends to all information assets owned or operated by the department.
-
This policy applies to the department Chief Information Officer (CIO) or designee, program management, owners of information assets, and information asset custodians.
49030.4 Policy Directives
-
The department shall ensure:
-
The department’s risk management strategy and approach is defined, implemented, and documented.
-
The department’s risk assessment methodology to address security risks is based on the National Institute of Standards and Technology (NIST) Risk Management Framework for Information Systems and Organizations (SP 800-37R2), Managing Information Security Risk: Organization, Mission and Information System View NIST (SP 800-39), and Guide for Conducting Risk Assessments (SP 800-30R1).
-
Risk assessment standards, methodologies, processes, and procedures are defined and documented.
-
The department performs comprehensive department-wide risk assessments every two years or when there are significant changes to business processes or the operational environment of the department’s risk management strategy for all three tier levels of risk.
-
All department information assets critical to program operations are identified and assessed from a security risk perspective.
-
Risk assessments include evaluation of the likelihood and magnitude of harm from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information system or asset and the information it processes, stores, or transmits.
-
Risk management decisions (e.g. risk tolerance or acceptance) consider cost-effective risk mitigation controls to reduce residual risk to levels acceptable to the department.
-
Individual risk assessment results are documented and securely maintained as long as the risk assessment is applicable (e.g. identified end date on the assessment decision) or in support of compliance audits by oversight entities as required by federal or state laws and regulations.
-
Records of all management decisions (i.e. risk tolerance or acceptance) related to medium and high risks are documented and securely maintained as required for compliance with State Information Management Manual (SIMM) 5305-C.
-
Controls, processes, and procedures to continuously report, monitor, and review risks at all three tier levels are implemented and maintained.
-
49030.5 Roles and Responsibilities
-
The department CIO or designee is responsible for:
-
Retaining non-transferable accountability for security of department information assets and the risks associated with them; however, implementation of this program may be delegated to a designee or representative in writing.
-
Defining roles and responsibilities for risk assessments and risk management decisions (i.e. risk tolerance or acceptance).
-
Reviewing and monitoring department-wide information security risks.
-
Ensuring consistent risk assessment frameworks and methods are defined and used department-wide.
-
Ensuring risk assessments are performed consistent with state and department requirements.
-
Ensuring department-wide risk management decisions (i.e. risk tolerance or acceptance) are consistent with state and department requirements.
-
Ensuring risks related to the operation of information assets are continually identified, assessed, mitigated, and monitored.
-
Ensuring all users of department information assets are aware of this policy and acknowledge their individual responsibilities.
-
Ensuring this policy shall be reviewed annually and updated accordingly.
-
Periodic auditing and assessment of compliance with this policy at least once every two years.
-
-
The department Information Security Officer (ISOInformation Security Officer) or designee shall:
-
Facilitate department risk assessments in collaboration with respective owners of information assets and information asset custodians.
-
Maintain records of completed risk assessments, and resulting risk decisions.
-
Monitor risk mitigation plans, and communicate updates as required.
-
-
The department owners of information assets and program management shall ensure:
-
This policy is implemented, and implementation is reviewed annually.
-
Residual or unmitigated risks are documented and approved by the department’s ISOInformation Security Officer prior to implementation.
-
Risk decision records and results of risk assessments are securely maintained.
-
Additionally, in collaboration with information asset custodians the owners of information assets shall ensure:
-
Risk assessments of information assets and ITInformation Technology environments under their purview are performed.
-
Risk assessments are performed throughout information asset development life cycles to identify and address security risks.
-
Records of completed risk assessments and resulting risk decisions, and status of risk mitigation plans are provided to the department ISOInformation Security Officer in a timely manner.
-
-
-
The department information asset custodians shall:
-
Participate and assist owners of information assets in risk assessment activities.
-
Implement and maintain risk mitigation controls as defined by owners of information assets.
-
Continuously monitor and communicate information asset risks and vulnerabilities.
-
Collaborate with owners of information assets to ensure risk controls implemented are commensurate with the sensitivity or criticality of the assets under their purview.
-
-
The department technology recovery coordinator shall assist program management and owners of information assets with business impact analyses and technology recovery planning.
-
Each department user shall be aware of and adhere to all department information security and privacy policies.
49030.6 Compliance
-
The department shall comply with the information security and privacy policies, standards and procedures issued by the California Department of Technology (CDT), Office of Information Security (OIS). In addition to compliance with the information security and privacy policies, standards, procedures, and filing requirements issued by the OIS, the department shall ensure compliance with all security and privacy laws, regulations, rules, and standards specific to and governing the administration of their programs. Program administrators shall work with their general counsel, Office of the Information Security Officer (OISO), and Privacy Program Officer or Coordinator to identify all security and privacy requirements applicable to their programs and ensure implementation of the requisite controls.
-
The consequences of negligence and non-compliance with state laws and policies may include department and personal:
-
Loss of delegated authorities.
-
Negative audit findings.
-
Monetary penalties.
-
Legal actions.
-
-
Non-compliance with this policy may result in disciplinary or adverse action as set forth in Department Operations Manual (DOMDepartment Operations Manual), Chapter 3, Article 22, Employee Discipline.
49030.7 Auditing
Revised June 17, 2026-
The department has the right to audit any activities related to the use of state information assets.
-
CDT, OIS and the department have the statutory right to audit department readiness to respond and recover from an incident.
49030.8 Reporting
-
Violations of this policy shall be reported to the department ISOInformation Security Officer.
49030.9 Security Variance Process
Revised June 17, 2026-
If compliance is not feasible, or if deviation from this policy is necessary to support a business function, the respective manager shall formally request a security variance as defined by the ISOInformation Security Officer.the ISOInformation Security Officer.
49030.10 Authority
-
This policy complies with Government Code (GCGovernment Code), section 11549.3.
49030.11 Revisions
-
The CIO or designee shall be responsible for ensuring the contents of this Article are kept current and accurate.
References
Revised June 17, 2026-
(1) DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.
-
(2) GCGovernment Code, § 11549.3.
-
(3) Information Security Programs (Appendix J), PM-9 Risk Management Strategy.
-
(4) SIMM, § 5305-A, Information Security Program Management Standard.
-
(5) SIMM, § 5305-B, Risk Register and Plan of Action and Milestones Instructions.
-
(6) SIMM, § 5305-C Risk Register and Plan of Action and Milestones.
-
(7) SAMState Administrative Manual, §§ 5305.5-5305-7, and 5315.9.
-
(8) NIST SP 800-53, Risk Assessment, RA-1 to RA-6.
-
(9) NIST SP 800-53, Configuration Management, CM-8.
-
(10) NIST SP 800-53, Media Protection, MP-4.
-
(11) NIST SP 800-53, Systems and Communications Protection, SC-7.
-
(12) NIST SP 800-37R2, Risk Management Framework for Information Systems and Organizations.
-
(13) NIST SP 800-39, Managing Information Security Risk: Organization, Mission and Information System View.
-
(14) NIST SP 800-30R1, Guide for Conducting Risk Assessments.
Revision History
Revised June 17, 2026-
(1) Effective: November 30, 1992.
(2) Revised Section 49030.1: April 16, 1993.
(3) Effective: June 17, 2026.