Department of Corrections and Rehabilitation - Operations Manual

Chapter 4 – Information Technology

Article 55 – Acceptable Use Policy

View All Sections >

49120.6 Roles and Responsibilities

  • The department Chief Information Officer (CIO) or Designee:

    • Owns this policy and is responsible for ensuring that all users of department information assets are aware of this policy and acknowledge their individual responsibilities.

    • Is responsible for ensuring that this policy is reviewed annually and updated accordingly.

    • Is required to audit and assess compliance with this policy at least once every two years.

  • Department information asset users or ISOInformation Security Officer shall:

    • Ensure that the department monitors the use of information assets for acceptable use.

    • Ensure that security incidents involving department information assets are properly documented and reported to California Compliance and Security Incident Reporting System as necessary.

  • Department owners of information assets and program management shall ensure the personnel under their purview:

    • Use only departmentally provisioned accounts on departmentally approved equipment for state work.

  • Department information asset users shall:

    • Use and protect department information assets in accordance with this policy.

    • Know and adhere to all department information security and privacy policies.

    • Report any suspected or actual activities or events indicating misuse or violation of this policy to the department ISOInformation Security Officer, designee, appropriate security staff or their immediate supervisor.

    • Acknowledge that they have read and understood this policy and all applicable information security and privacy policies annually.