Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 55 – Acceptable Use Policy

View All Articles >

49120.1  Introduction and Overview

  • Information assets owned by the California Department of Corrections and Rehabilitation (CDCRCalifornia Department of Corrections and Rehabilitation), California Correctional Health Care Services (CCHCS), and California Prison Industry Authority (CALPIACalifornia Prison Industry Authority (formerly PIA)) (including but not limited to department  data and information, laptops, cell phones, and removable storage devices) are strategic assets intended for official business use, and are entrusted to State personnel in the performance of their job-related duties.

  • Inappropriate use of the department’s information assets could negatively affect the confidentiality, integrity, or availability of the information, information systems, or other information assets of the department and the State of California. Consequently, it is important for all users to access or use information assets in a responsible, ethical, and legal manner that safeguards department data and information.

  • Additionally, the appropriate use of information assets benefits the state and the department by strengthening the protection of the department, its personnel, and its business partners.ivities.

49120.2  Objectives

  • This policy defines and establishes the requirements for the appropriate use and safeguarding of department information assets.

49120.3  Ownership of Information

  • Data and information in hard copy format and that which is electronically created, sent, received, processed, or stored on information assets owned, leased, administered, or otherwise under the custody and control of the department are the property of the state. Any information, that is transmitted, processed, or stored on the department and business partner Information Technology (ITInformation Technology) facilities and resources (including e-mail, messages, and files) is considered the property of the department, unless specifically identified as the property of other third parties within contracts.

  • Individual access and use of department information assets is neither personal nor private. As such, department management reserves the right to monitor and log all employee use of department information assets with or without advanced notice.

49120.4  Scope and Applicability

  • The scope of this policy extends to all information assets owned or operated by the department and to all personnel authorized to use these assets.

49120.5  Policy Directives

  • The department shall ensure users:

    • Only access their department provisioned accounts from department-authorized equipment while performing departmental-related tasks.

    • Report the unauthorized use or disclosure of confidential and sensitive department data to the Information Security Officer (ISOInformation Security Officer).

  • The department shall ensure that users do not:

    • Use department information assets to engage in or solicit the performance of any activity that violates laws, regulations, rules, policies, standards, and other applicable requirements issued by the federal government, the State of California, and the department.

    • Use department information assets for personal enjoyment, private gain or advantage, personal gain, political activity, unsolicited advertising, unauthorized fundraising, or an outside endeavor not related to department business.

    • Engage in any activity that attempts to circumvent or alter the function of the department’s security controls (e.g., spoofing email, anonymous proxies, or unauthorized encryption), or other activities that may degrade the performance of information resources or may deprive an authorized user the access to department assets.

    • Share their work-related account(s), passwords, Personal Identification Numbers (PIN), security questions/answers, security tokens (e.g., smartcard, key fob), or similar information or devices used for authentication and authorization purposes.

    • Use department information assets to send or arrange to send emails or intentionally access sites that contain pornographic, racist, or offensive material, chain letters or unauthorized mass mailings, and malicious code.

    • Connect or otherwise attach unauthorized devices or equipment to department information assets.

    • Download or install unauthorized software.

    • Access or transport department information assets and department data outside of the continental United States unless approved by a hiring authority (HA).

49120.6 Roles and Responsibilities

  • The department Chief Information Officer (CIO) or Designee:

    • Owns this policy and is responsible for ensuring that all users of department information assets are aware of this policy and acknowledge their individual responsibilities.

    • Is responsible for ensuring that this policy is reviewed annually and updated accordingly.

    • Is required to audit and assess compliance with this policy at least once every two years.

  • Department information asset users or ISOInformation Security Officer shall:

    • Ensure that the department monitors the use of information assets for acceptable use.

    • Ensure that security incidents involving department information assets are properly documented and reported to California Compliance and Security Incident Reporting System as necessary.

  • Department owners of information assets and program management shall ensure the personnel under their purview:

    • Use only departmentally provisioned accounts on departmentally approved equipment for state work.

  • Department information asset users shall:

    • Use and protect department information assets in accordance with this policy.

    • Know and adhere to all department information security and privacy policies.

    • Report any suspected or actual activities or events indicating misuse or violation of this policy to the department ISOInformation Security Officer, designee, appropriate security staff or their immediate supervisor.

    • Acknowledge that they have read and understood this policy and all applicable information security and privacy policies annually.

49120.7 Compliance

  • The department shall comply with the information security and privacy policies, standards, and procedures issued by the California Department of Technology (CDT), Office of Information Security (OIS). In addition to compliance with the information security and privacy policies, standards, procedures, and filing requirements issued by the OIS, the department shall ensure compliance with all security and privacy laws, regulations, rules, and standards specific to and governing the administration of their programs. Program administrators shall work with their general counsel, ISOInformation Security Officer, and Privacy Program Officer or Coordinator to identify all security and privacy requirements applicable to their programs and ensure implementation of the requisite controls.

  • Non-compliance with this policy may result in disciplinary or adverse action as set forth in DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.

  • The consequences of negligence and non-compliance with State laws and policies may include department and personal:

    • Loss of delegated authorities.

    • Negative audit findings.

    • Monetary penalties.

    • Legal actions.

49120.8  Auditing

  • The department has the right to audit any activities related to the use of State information assets.

  • CDT, OIS, and the department have the statutory right to audit department readiness to respond and recover from an incident.

49120.9  Reporting

  • Violations of this policy shall be reported to the department ISOInformation Security Officer.

49120.10  Security Variance Process

  • If compliance is not feasible, or if deviation from this policy is necessary to support a business function, the respective manager shall formally request a security variance as defined by the department ISOInformation Security Officer.

49120.11  Authority

  • This policy complies with the Government Code (GCGovernment Code), Section 11549.3.

49120.12  Revisions

  • The CIO or designee shall ensure that the contents of this article are current and accurate.

References

  • DOMDepartment Operations Manual, Chapter 3, Article 22, Employee Discipline.

  • DOMDepartment Operations Manual, Chapter 4, Article 38, § 47110.8, Article 39, and Article 41, § 48010.5.

  • GCGovernment Code § 11549.3.

  • Health Care Department Operations Manual (HCDOM) 5.3.4 Digital Signature Security.

  • SAMState Administrative Manual, §§ 4983.1, 4986.12, 5305.3, 5320.4, and 5330.2.

  • SIMM §§ 66-B and 5305-A.

Revision History

  • Effective: March 14, 2022.

  • Revised: May 28, 2026.