July 10, 2008www.infosecurity.ca.gov1 What’s New!
July 10, 2008www.infosecurity.ca.gov2 We’ve Moved Again! Information Sheets MM on OCIO’s IT Capital Planning Process Forthcoming Privacy Policy Releases Feasibility Study Report (FSR) Questionnaire for Security/Privacy Components Data Exchange Agreement Workgroup Information Security Leader Academy Online Information Security and Privacy Training Updates
July 10, 2008www.infosecurity.ca.gov3 We’ve Moved Again Effective June 30, 2008, we moved into our permanent office at: 1325 J Street, Suite 1650 IMS Code G7 Sacramento, CA Our main phone line remains the same – (916) Our direct lines have changed
July 10, 2008www.infosecurity.ca.gov4 Information Sheets OISPP has released four different Information Sheets Secure Coding Practices Software Security Checklists Web Application Vulnerabilities: More Than A Mere Nuisance Web Service Offerings
July 10, 2008www.infosecurity.ca.gov5 MM on OCIO’s Information Technology Capital Planning Process IT Capital Plan Preparation Instructions (SIMM Section 57) – Appendix B Requires Designated Information Security Officer (ISO) ISO Involvement in Projects Core Business Principles, Policies and Standards Regarding Information Integrity, Confidentiality, and Availability and the Protection of Information Assets Data Sharing Agreements Best Practices for Web, Application, and System Development IT Capital Plan requires ISO signoff
July 10, 2008www.infosecurity.ca.gov6 Forthcoming Policy Releases Safeguarding Against And Responding To A Breach Of Personal Information Personal Information Breach Notification: Requirements and Decision Making Criteria For State Agencies (SIMM 65D) Requests For And Approval To Release Personal Information For Research
July 10, 2008www.infosecurity.ca.gov7 FSR Questionnaire for Security/ Privacy Components In the works…… Provides guidance to agencies who are developing project-related documents Helps to avoid unnecessary questions Helps to ensure agencies are addressing security up front
July 10, 2008www.infosecurity.ca.gov8 Data Exchange Agreement Workgroup Charter – develop general approach, recommendations, guidance and tools for the development of agreements between government entities on the use of data Resulted from GTC’s Partner in Learning Forum 21 representatives from various government entities participating Timeline for completion – October 2008
July 10, 2008www.infosecurity.ca.gov9 Information Security Leader Academy Program will provide practical business skills and technical skills necessary for information security professionals to be strategic members of their organization’s leadership. Partnership between OISPP and SacState Academy Sponsors identified Establishing Advisory Committee First class scheduled for first quarter of 2009 Open to all government employees
July 10, 2008www.infosecurity.ca.gov10 Online Information Security and Privacy Training Purpose: Develop a statewide online training system and make it available to all government entities Result of Grant Funds In process of writing internal FSR and RFP Timeline for completion is FY 09/10
July 10, 2008www.infosecurity.ca.gov11 Questions?