RCW 43.105.215 Security standards and policiesState agencies' information technology security programs.
(1) The office shall establish security standards and policies to ensure the confidentiality, availability, and integrity of the information transacted, stored, or processed in the state's information technology systems and infrastructure. The director shall appoint a state chief information security officer. Each state agency, institution of higher education, the legislature, and the judiciary must develop an information technology security program.
(2) Each state agency information technology security program must adhere to the office's security standards and policies. Each state agency must review and update its program annually and certify to the office that its program is in compliance with the office's security standards and policies. The office shall require a state agency to obtain an independent compliance audit of its information technology security program and controls at least once every three years to determine whether the state agency's information technology security program is in compliance with the standards and policies established by the agency and that security controls identified by the state agency in its security program are operating efficiently.
(3) In the case of institutions of higher education, the judiciary, and the legislature, each information technology security program must be comparable to the intended outcomes of the office's security standards and policies.
[2015 3rd sp.s. c 1 § 202; 2013 2nd sp.s. c 33 § 8. Formerly RCW 43.41A.027.]
NOTES:
Effective date2015 3rd sp.s. c 1 §§ 101-109, 201-224, 406-408, 410, 501-507, 601, and 602: See note following RCW 43.105.007.