36 MAC Pt. 1, R. 1.7
Agency Cybersecurity Programs
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.7
Agency Cybersecurity Programs
Agencies must develop and maintain an agency-wide cybersecurity program to address security
for information and information systems that support the operations and assets of the agency,
including those provided or managed by another organization, contractor, or other source.
Agency controls in the management of the cybersecurity program include:
A. Ensuring that an agency-wide cybersecurity program plan is developed, disseminated,
and maintained.
B. Ensuring the resources needed to implement the cybersecurity program are
documented and available.
C. Developing, monitoring, and reporting on the results of security measures of
performance.
D. Ensuring the information technology architecture is designed with consideration for
information security and the resulting risk to agency operations, agency assets,
individuals, other organizations, and the State.
E. Providing insider threat awareness training to detect and prevent malicious insider
activity.
F. Establishing an information security workforce development and improvement
program.
G. Developing and maintaining a process for conducting security testing, training, and
monitoring activities.
H. Ensuring participation with the Enterprise Security Program to assist the agency with
1. Facilitating ongoing security education and training for agency employees.
2. Maintaining knowledge of recommended security practices, techniques, and
technologies.
3. Sharing current security-related information including threats, vulnerabilities,
and incidents with appropriate stakeholders.