Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 46 – Information Systems Risk Management

View All Sections >

49030.5 Roles and Responsibilities

  • The department CIO or designee is responsible for:

    • Retaining non-transferable accountability for security of department information assets and the risks associated with them; however, implementation of this program may be delegated to a designee or representative in writing.

    • Defining roles and responsibilities for risk assessments and risk management decisions (i.e. risk tolerance or acceptance).

    • Reviewing and monitoring department-wide information security risks.

    • Ensuring consistent risk assessment frameworks and methods are defined and used department-wide.

    • Ensuring risk assessments are performed consistent with state and department requirements.

    • Ensuring department-wide risk management decisions (i.e. risk tolerance or acceptance) are consistent with state and department requirements.

    • Ensuring risks related to the operation of information assets are continually identified, assessed, mitigated, and monitored.

    • Ensuring all users of department information assets are aware of this policy and acknowledge their individual responsibilities.

    • Ensuring this policy shall be reviewed annually and updated accordingly.

    • Periodic auditing and assessment of compliance with this policy at least once every two years.

  • The department Information Security Officer (ISOInformation Security Officer) or designee shall:

    • Facilitate department risk assessments in collaboration with respective owners of information assets and information asset custodians.

    • Maintain records of completed risk assessments, and resulting risk decisions.

    • Monitor risk mitigation plans, and communicate updates as required.

  • The department owners of information assets and program management shall ensure:

    • This policy is implemented, and implementation is reviewed annually.

    • Residual or unmitigated risks are documented and approved by the department’s ISOInformation Security Officer prior to implementation.

    • Risk decision records and results of risk assessments are securely maintained.

    • Additionally, in collaboration with information asset custodians the owners of information assets shall ensure:

      • Risk assessments of information assets and ITInformation Technology environments under their purview are performed.

      • Risk assessments are performed throughout information asset development life cycles to identify and address security risks.

      • Records of completed risk assessments and resulting risk decisions, and status of risk mitigation plans are provided to the department ISOInformation Security Officer in a timely manner.

  • The department information asset custodians shall:

    • Participate and assist owners of information assets in risk assessment activities.

    • Implement and maintain risk mitigation controls as defined by owners of information assets.

    • Continuously monitor and communicate information asset risks and vulnerabilities.

    • Collaborate with owners of information assets to ensure risk controls implemented are commensurate with the sensitivity or criticality of the assets under their purview.

  • The department technology recovery coordinator shall assist program management and owners of information assets with business impact analyses and technology recovery planning.

  • Each department user shall be aware of and adhere to all department information security and privacy policies.