36 MAC Pt. 1, R. 1.5
Enterprise Security Program
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.5
Enterprise Security Program
The Enterprise Security Program is focused on providing the resources, guidance, and oversight
needed for improving the cybersecurity posture of the enterprise network for state government.
ITS has designated a Chief Information Security Officer (CISO) to manage the program and
develop, maintain, and communicate the State of Mississippi Enterprise Security Policy and
State of Mississippi Enterprise Security Standards. The ITS CISO and ITS cybersecurity
professionals will execute the Program mission by:
A. Administering the Enterprise Security Program to execute the statutory duties and
responsibilities of ITS.
B. Researching and selecting enterprise technology solutions capable of improving the
cybersecurity posture in the function of any agency, institution, or function of state
government as a whole.
C. Establishing and maintaining the security standards and policies for all state data and
IT resources that state agencies shall implement, to the extent that they apply.
D. Coordinating and promoting efficiency and security with all applicable laws and
regulations in the acquisition, operation, and maintenance of state data, cybersecurity
systems, and services used by agencies of the State.
E. Managing, planning, and coordinating all enterprise cybersecurity systems under the
jurisdiction of the state.
F. Developing, in coordination with state agencies, enterprise cybersecurity systems and
services for all governmental organizations within the purview of ITS.
G. Providing ongoing analysis of enterprise cybersecurity systems and services costs,
facilities, and systems within state government.
H. Organizing an advisory council of Information Security Officers from each state
agency and coordinating the activities of the advisory council to provide education
and awareness, identify cybersecurity-related issues, set future direction for
cybersecurity plans and policy, and provide a forum for inter-agency communications
regarding cybersecurity.
I. Requiring a cooperative effort for the utilization of enterprise cybersecurity systems
and services among MS state agencies.