36 MAC Pt. 1, R. 1.11
Policy Compliance and Auditing
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.11
Policy Compliance and Auditing
A. Each agency shall adhere to the more restrictive policy when conflicts exist between
this policy and agency policies.
B. Each agency shall regularly review the level of compliance with this policy,
document where compliance with the requirements of this policy is not met and
develop a plan for addressing the deficiencies.
C. The following information is provided to clarify the role of the Mississippi Office of
the State Auditor (OSA) and the Mississippi Department of Information Technology
Services (ITS) in auditing compliance:
1. The State Auditor will review how well agencies comply with security
policies as part of their normal agency information systems auditing activities.
2. As a component of their standard Information Systems audit process, the State
Auditor will consider the State of Mississippi Enterprise Security Policy in the
review of the systems, processes, and procedures that they will examine.
3. The State Auditor may determine a special audit of an agency’s information
system processing is warranted; in which case they will proceed under their
existing authority. Each agency must maintain documentation showing the
results of its review or audit and the plan for correcting identified deficiencies.
To the extent that the audit documentation includes valuable formulae,
designs, drawings, computer source code, object codes or research data, or
that disclosure of the audit documentation would be contrary to the public
interest and would irreparably damage vital government functions, such audit
documentation is exempt from public disclosure.
4. The State Auditor may request the assistance of ITS in the performance of this
normal audit function.
5. The State Auditor may request and review copies of an agency’s IT Security
Risk Assessment separately or in conjunction with the normal agency audit
process.
6. The State Auditor may request and review the agency’s compliance document
that identifies the agency’s current compliance level with the State of
Mississippi Enterprise Security Policy.
7. Upon determination of any non-compliance, the State Auditor may instruct
the agency and/or ITS to take necessary steps to become compliant.
8. Agencies should understand that failure to comply with this policy could
result in a finding in the agency’s audit report from the State Auditor.
D. In addition to complying with this policy, it is the responsibility of each agency to
determine whether there are any guidelines, regulations, or laws (Federal, State, and
Local) outside this policy they are required to meet. These guidelines, regulations, or
laws may include, but are not limited to:
1. Health Insurance Portability and Accountability Act of 1996 (HIPAA)
2. The Privacy Act of 1974, 5 U.S.C. § 552 a, Public Law No. 93-579
3. Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. § 1232g; 34
CFR Part 99)
4. Payment Card Industry Data Security Standard (PCI/DSS)
5. Internal Revenue Service (IRS) Publication 1075
6. Criminal Justice Information Services (CJIS)
7. Miss. Code Ann. § 75-24-29 Breach of Security; Require Notice
8. Children’s Internet Protection Act (CIPA)
9. Federal Information Security Management Act of 2002 (FISMA)
10. Miss. Code Ann. § 25-1-111 Prevention of Disclosure by State Agencies of
Social Security Numbers
11. Driver’s Privacy Protection Act (DPPA)
12. The Fair Credit Reporting Act (FCRA)
13. The Gramm-Leach-Bliley Act (GLBA)
14. Miss. Code Ann. § 25-53-193 National Security on State Devices and
Networks Act
15. Children’s Online Privacy Protection Act (COPPA)