Article 46 – Information Systems Risk Management
49030.4 Policy Directives
-
The department shall ensure:
-
The department’s risk management strategy and approach is defined, implemented, and documented.
-
The department’s risk assessment methodology to address security risks is based on the National Institute of Standards and Technology (NIST) Risk Management Framework for Information Systems and Organizations (SP 800-37R2), Managing Information Security Risk: Organization, Mission and Information System View NIST (SP 800-39), and Guide for Conducting Risk Assessments (SP 800-30R1).
-
Risk assessment standards, methodologies, processes, and procedures are defined and documented.
-
The department performs comprehensive department-wide risk assessments every two years or when there are significant changes to business processes or the operational environment of the department’s risk management strategy for all three tier levels of risk.
-
All department information assets critical to program operations are identified and assessed from a security risk perspective.
-
Risk assessments include evaluation of the likelihood and magnitude of harm from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information system or asset and the information it processes, stores, or transmits.
-
Risk management decisions (e.g. risk tolerance or acceptance) consider cost-effective risk mitigation controls to reduce residual risk to levels acceptable to the department.
-
Individual risk assessment results are documented and securely maintained as long as the risk assessment is applicable (e.g. identified end date on the assessment decision) or in support of compliance audits by oversight entities as required by federal or state laws and regulations.
-
Records of all management decisions (i.e. risk tolerance or acceptance) related to medium and high risks are documented and securely maintained as required for compliance with State Information Management Manual (SIMM) 5305-C.
-
Controls, processes, and procedures to continuously report, monitor, and review risks at all three tier levels are implemented and maintained.
-