Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 46 – Information Systems Risk Management

View All Sections >

References

Revised June 17, 2026
  • (1) DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.

  • (2) GCGovernment Code, § 11549.3.

  • (3) Information Security Programs (Appendix J), PM-9 Risk Management Strategy.

  • (4) SIMM, § 5305-A, Information Security Program Management Standard.

  • (5) SIMM, § 5305-B, Risk Register and Plan of Action and Milestones Instructions.

  • (6) SIMM, § 5305-C Risk Register and Plan of Action and Milestones.

  • (7) SAMState Administrative Manual, §§ 5305.5-5305-7, and 5315.9.

  • (8) NIST SP 800-53, Risk Assessment, RA-1 to RA-6.

  • (9) NIST SP 800-53, Configuration Management, CM-8.

  • (10) NIST SP 800-53, Media Protection, MP-4.

  • (11) NIST SP 800-53, Systems and Communications Protection, SC-7.

  • (12) NIST SP 800-37R2, Risk Management Framework for Information Systems and Organizations.

  • (13) NIST SP 800-39, Managing Information Security Risk: Organization, Mission and Information System View.

  • (14) NIST SP 800-30R1, Guide for Conducting Risk Assessments.