36 MAC Pt. 1, R. 1.3
Scope
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.3
Scope
This policy applies to all state agencies; State of Mississippi employees; ITS trusted partners
(e.g., subcontractors, vendors, third-parties, temporary workers, etc.); or any entity, as provided
by law, authorized to operate, manage, or use SOM Assets. Agency is defined as and includes all
the various state agencies, officers, departments, boards, commissions, offices, and institutions of
the state.
A. This policy includes a subset of technical requirements that are only applicable to
agencies participating in the Enterprise State Network. Agencies that do not
participate in the Enterprise State Network, and thus do not have the benefit of the
technical controls in place, must develop agency-specific security policies that are:
1. Appropriate to their respective environments and information, and
2. Consistent with the intent of this policy.
B. This policy addresses information regardless of what form it takes (i.e., electronic,
printed, etc.), what technology is used to handle it, the location of the data or
resources, or what purpose(s) it serves.
C. This policy encompasses all data and information technology resources (i.e., data and
information technology systems (automated and manual), services, products, etc.) for
which the agencies have administrative responsibility, including data and information
technology resources managed, provided, and/or hosted by third parties on behalf of
the agencies.
D. Beyond the requirements of this policy, state agencies must also comply with other
applicable security standards and policies for state data and IT resources established
by ITS. This includes, but is not limited to, the State of Mississippi Enterprise Cloud
and Offsite Security Policy, which outlines additional security requirements for cloud
and offsite hosting services. Additional policies, requirements, and/or
recommendations for state agencies can be found on the ITS website.