36 MAC Pt. 1, R. 1.6
Agency Heads
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.6
Agency Heads
The Executive Director and/or Agency Head of each state agency is solely responsible for the
security of all data and IT resources under said agency’s purview, irrespective of the location of
the data or resources. Locations include data residing at agency sites, on agency real property
and tangible and intangible assets; in the State Data Centers; in transit between locations; or at a
third-party location on behalf of the agency. The Executive Director/Agency Head will ensure
that an organizational structure is in place for overseeing security risk management, but is
ultimately accountable for:
A. Ensuring that an agency-wide cybersecurity program is in place.
B. Designating an information security officer to administer the agency’s security
program.
C. Ensuring the agency adheres to the requirements established by the Enterprise
Security Program, to the extent that they apply.
D. Participating in all Enterprise Security Program initiatives and services in lieu of
deploying duplicate services specific to the agency.
E. Developing, implementing, and maintaining written agency policies and procedures
to ensure the security of data and IT resources.
1. The agency policies and procedures are confidential information and exempt
from public inspection, except that the information must be available to the
Mississippi’s Office of the State Auditor and/or ITS in performing auditing
duties.
F. Implementing policies and standards to ensure that all of the agency’s data and IT
resources are maintained in compliance with state and federal laws and regulations, to
the extent that they apply.
G. Implementing appropriate cost-effective safeguards to reduce, eliminate, or recover
from identified threats to data and IT resources.
H. Ensuring that internal assessments of the security program are conducted.
1. The results of the internal assessments are confidential and exempt from
public inspection, except that the information must be available to the
Mississippi’s Office of the State Auditor and/or ITS in performing auditing
duties.
I. Including all appropriate cybersecurity requirements in the specifications for the
agency's solicitation of state contracts for procuring data and information technology
systems and services.
J. Including a general description of the security program and future plans for ensuring
security of data in the agency long-range information technology plan.
K. Participating in annual information security training designed specifically for the
agency head to ensure that the agency head has an understanding of: the information
and information systems that support the operations and assets of the agency; the
potential impact of common types of cyber-attacks and data breaches on the agency’s
operations and assets; how cyber-attacks and data breaches on the agency’s
operations and assets could impact the operations and assets of other state agencies on
the Enterprise State Network; how cyber-attacks and data breaches occur; steps the
executive director or agency head and agency employees should take to protect their
information and information systems; and the annual reporting requirements required
of the executive director or agency head.