Article 46 – Information Systems Risk Management
49030.2 Objective
Revised June 17, 2026-
The department conducts risk assessments to identify risks to its operations (including mission, functions, or reputation), organizational assets, individuals, other organizations, and the state and federal government entities arising from the operation of information assets. As components of the risk management process, risk assessments consider threats, vulnerabilities, and business impact analyses. They also evaluate risk mitigations provided by planned and implemented security controls.
-
Risk assessments shall be performed at one or more of the following levels, as determined by the classification process:
-
Organizational level;
-
Mission/Business process level;
-
Information asset level.
-