36 MAC Pt. 1, R. 14.1

Risk Assessments

Year: 2026Length: 638 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 14.1

Risk Assessments A. Each agency must periodically assess the risk to agency operations resulting from the operation of agency systems and the associated processing, storage, or transmission of data. B. Each agency must conduct a risk assessment that considers threats, vulnerabilities, likelihood, and impact to agency operations and assets, individuals, other organizations, and state government. 1. Identify threats and vulnerabilities to agency systems. i. An inventory of all hardware, software, and user access must be established and maintained as an agency experiences any substantive change. Please refer to Part 1, Chapter 2, 2.1 System and Physical Device Inventory. 2. Identify threats and vulnerabilities from third parties, including, but not limited to, third parties who operate systems on behalf of the agency and/or process, store, or transmit information on behalf of the agency. i. Identify all third parties which provide functionality to the organization via either hardware or software. Agencies will inventory and document the data and network resource access that all third parties are provided access. ii. Determine the sensitivity of data that each third party is provided access to and incorporate said access into its risk assessment. iii. Define the legal and regulatory standards that the data accessible to the third party is subject to and establish contracts or other Service Level Agreements to describe the ability and expectation of the vendor to satisfy the applicable standard. iv. Monitor and ensure (to the extent possible) that the third party meets the expectations of any agreement or contractual obligation regarding information security and/or privacy. 3. Determine the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, loss, or destruction of/to the system and/or the information it processes, stores, or transmits, and any related information. 4. Determine the likelihood and impact of adverse effects on individuals arising from the collection and/or processing of personally identifiable information (PII). i. ITS recommends agencies conduct privacy impact and/or privacy risk assessments to help determine the likelihood and impact of adverse effects for PII. A privacy risk and/or privacy impact assessment evaluates the risks, controls, and consequences associated with collecting, maintaining, using, and/or disclosing personally identifiable information (within and outside of the agency) so that the agency can make informed decisions regarding risk mitigation, protection of the data, and compliance with applicable legal requirements and best practices. 5. Integrate risk assessment results and risk management decisions from the agency and mission or business process perspectives with system-level risk assessments. 6. Document risk assessment results in appropriate agency security and privacy plans. 7. Respond to findings from security and privacy assessments, monitoring, and audits in accordance with agency risk tolerance and update the risk assessment as needed. 8. Review and update the risk assessment, as needed, in accordance with agency risk tolerance based on security and privacy assessments, monitoring, and audits; supply chain issues; security incidents or breaches; changes in law, executive orders, directives, regulations, policies, standards, or guidelines; and changes to and/or availability of new technologies, individuals, external parties, and assets in accordance with agency risk tolerance. C. Each agency must perform automated vulnerability scans for vulnerabilities in agency systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. 1. Perform automated vulnerability scans of internal agency assets on a monthly, or more frequent, basis. Conduct both authenticated and unauthenticated scans, using a SCAP-compliant vulnerability scanning tool. The agency must maintain the results of vulnerability scans for a period of at least one year. 2. Perform automated vulnerability scans of externally exposed agency assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis. The agency must maintain the results of vulnerability scans for a period of at least one year. D. Each agency must remediate detected vulnerabilities on a monthly, or more frequent, basis, based on the remediation process.
36 MAC Pt. 1, R. 14.1: Risk Assessments | Justis AI