Article 46 – Information Systems Risk Management
49030.5 Roles and Responsibilities
-
The department CIO or designee is responsible for:
-
Retaining non-transferable accountability for security of department information assets and the risks associated with them; however, implementation of this program may be delegated to a designee or representative in writing.
-
Defining roles and responsibilities for risk assessments and risk management decisions (i.e. risk tolerance or acceptance).
-
Reviewing and monitoring department-wide information security risks.
-
Ensuring consistent risk assessment frameworks and methods are defined and used department-wide.
-
Ensuring risk assessments are performed consistent with state and department requirements.
-
Ensuring department-wide risk management decisions (i.e. risk tolerance or acceptance) are consistent with state and department requirements.
-
Ensuring risks related to the operation of information assets are continually identified, assessed, mitigated, and monitored.
-
Ensuring all users of department information assets are aware of this policy and acknowledge their individual responsibilities.
-
Ensuring this policy shall be reviewed annually and updated accordingly.
-
Periodic auditing and assessment of compliance with this policy at least once every two years.
-
-
The department Information Security Officer (ISOInformation Security Officer) or designee shall:
-
Facilitate department risk assessments in collaboration with respective owners of information assets and information asset custodians.
-
Maintain records of completed risk assessments, and resulting risk decisions.
-
Monitor risk mitigation plans, and communicate updates as required.
-
-
The department owners of information assets and program management shall ensure:
-
This policy is implemented, and implementation is reviewed annually.
-
Residual or unmitigated risks are documented and approved by the department’s ISOInformation Security Officer prior to implementation.
-
Risk decision records and results of risk assessments are securely maintained.
-
Additionally, in collaboration with information asset custodians the owners of information assets shall ensure:
-
Risk assessments of information assets and ITInformation Technology environments under their purview are performed.
-
Risk assessments are performed throughout information asset development life cycles to identify and address security risks.
-
Records of completed risk assessments and resulting risk decisions, and status of risk mitigation plans are provided to the department ISOInformation Security Officer in a timely manner.
-
-
-
The department information asset custodians shall:
-
Participate and assist owners of information assets in risk assessment activities.
-
Implement and maintain risk mitigation controls as defined by owners of information assets.
-
Continuously monitor and communicate information asset risks and vulnerabilities.
-
Collaborate with owners of information assets to ensure risk controls implemented are commensurate with the sensitivity or criticality of the assets under their purview.
-
-
The department technology recovery coordinator shall assist program management and owners of information assets with business impact analyses and technology recovery planning.
-
Each department user shall be aware of and adhere to all department information security and privacy policies.