110 likes | 231 Views
What’s New!. Updates. We’ve Moved Again! Information Sheets MM 08-07 on OCIO’s IT Capital Planning Process Forthcoming Privacy Policy Releases Feasibility Study Report (FSR) Questionnaire for Security/Privacy Components Data Exchange Agreement Workgroup
E N D
What’s New! www.infosecurity.ca.gov
Updates • We’ve Moved Again! • Information Sheets • MM 08-07 on OCIO’s IT Capital Planning Process • Forthcoming Privacy Policy Releases • Feasibility Study Report (FSR) Questionnaire for Security/Privacy Components • Data Exchange Agreement Workgroup • Information Security Leader Academy • Online Information Security and Privacy Training www.infosecurity.ca.gov
We’ve Moved Again • Effective June 30, 2008, we moved into our permanent office at: 1325 J Street, Suite 1650 IMS Code G7 Sacramento, CA 95814 • Our main phone line remains the same – (916) 445-5239 • Our direct lines have changed www.infosecurity.ca.gov
Information Sheets • OISPP has released four different Information Sheets • Secure Coding Practices • Software Security Checklists • Web Application Vulnerabilities: More Than A Mere Nuisance • Web Service Offerings www.infosecurity.ca.gov
MM 08-07 on OCIO’s Information Technology Capital Planning Process • IT Capital Plan Preparation Instructions (SIMM Section 57) – Appendix B • Requires Designated Information Security Officer (ISO) • ISO Involvement in Projects • Core Business Principles, Policies and Standards Regarding Information Integrity, Confidentiality, and Availability and the Protection of Information Assets • Data Sharing Agreements • Best Practices for Web, Application, and System Development • IT Capital Plan requires ISO signoff www.infosecurity.ca.gov
Forthcoming Policy Releases • Safeguarding Against And Responding To A Breach Of Personal Information • Personal Information Breach Notification:Requirements and Decision Making Criteria For State Agencies (SIMM 65D) • Requests For And Approval To Release Personal Information For Research www.infosecurity.ca.gov
FSR Questionnaire for Security/ Privacy Components • In the works…… • Provides guidance to agencies who are developing project-related documents • Helps to avoid unnecessary questions • Helps to ensure agencies are addressing security up front www.infosecurity.ca.gov
Data Exchange Agreement Workgroup • Charter – develop general approach, recommendations, guidance and tools for the development of agreements between government entities on the use of data • Resulted from GTC’s Partner in Learning Forum • 21 representatives from various government entities participating • Timeline for completion – October 2008 www.infosecurity.ca.gov
Information Security Leader Academy • Program will provide practical business skills and technical skills necessary for information security professionals to be strategic members of their organization’s leadership. • Partnership between OISPP and SacState • Academy Sponsors identified • Establishing Advisory Committee • First class scheduled for first quarter of 2009 • Open to all government employees www.infosecurity.ca.gov
Online Information Security and Privacy Training Purpose: Develop a statewide online training system and make it available to all government entities • Result of Grant Funds • In process of writing internal FSR and RFP • Timeline for completion is FY 09/10 www.infosecurity.ca.gov
Questions? www.infosecurity.ca.gov