36 MAC Pt. 1, R. 1.11

Policy Compliance and Auditing

Year: 2026Length: 552 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 1.11

Policy Compliance and Auditing A. Each agency shall adhere to the more restrictive policy when conflicts exist between this policy and agency policies. B. Each agency shall regularly review the level of compliance with this policy, document where compliance with the requirements of this policy is not met and develop a plan for addressing the deficiencies. C. The following information is provided to clarify the role of the Mississippi Office of the State Auditor (OSA) and the Mississippi Department of Information Technology Services (ITS) in auditing compliance: 1. The State Auditor will review how well agencies comply with security policies as part of their normal agency information systems auditing activities. 2. As a component of their standard Information Systems audit process, the State Auditor will consider the State of Mississippi Enterprise Security Policy in the review of the systems, processes, and procedures that they will examine. 3. The State Auditor may determine a special audit of an agency’s information system processing is warranted; in which case they will proceed under their existing authority. Each agency must maintain documentation showing the results of its review or audit and the plan for correcting identified deficiencies. To the extent that the audit documentation includes valuable formulae, designs, drawings, computer source code, object codes or research data, or that disclosure of the audit documentation would be contrary to the public interest and would irreparably damage vital government functions, such audit documentation is exempt from public disclosure. 4. The State Auditor may request the assistance of ITS in the performance of this normal audit function. 5. The State Auditor may request and review copies of an agency’s IT Security Risk Assessment separately or in conjunction with the normal agency audit process. 6. The State Auditor may request and review the agency’s compliance document that identifies the agency’s current compliance level with the State of Mississippi Enterprise Security Policy. 7. Upon determination of any non-compliance, the State Auditor may instruct the agency and/or ITS to take necessary steps to become compliant. 8. Agencies should understand that failure to comply with this policy could result in a finding in the agency’s audit report from the State Auditor. D. In addition to complying with this policy, it is the responsibility of each agency to determine whether there are any guidelines, regulations, or laws (Federal, State, and Local) outside this policy they are required to meet. These guidelines, regulations, or laws may include, but are not limited to: 1. Health Insurance Portability and Accountability Act of 1996 (HIPAA) 2. The Privacy Act of 1974, 5 U.S.C. § 552 a, Public Law No. 93-579 3. Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. § 1232g; 34 CFR Part 99) 4. Payment Card Industry Data Security Standard (PCI/DSS) 5. Internal Revenue Service (IRS) Publication 1075 6. Criminal Justice Information Services (CJIS) 7. Miss. Code Ann. § 75-24-29 Breach of Security; Require Notice 8. Children’s Internet Protection Act (CIPA) 9. Federal Information Security Management Act of 2002 (FISMA) 10. Miss. Code Ann. § 25-1-111 Prevention of Disclosure by State Agencies of Social Security Numbers 11. Driver’s Privacy Protection Act (DPPA) 12. The Fair Credit Reporting Act (FCRA) 13. The Gramm-Leach-Bliley Act (GLBA) 14. Miss. Code Ann. § 25-53-193 National Security on State Devices and Networks Act 15. Children’s Online Privacy Protection Act (COPPA)
36 MAC Pt. 1, R. 1.11: Policy Compliance and Auditing | Justis AI