36 MAC Pt. 1, R. 1.8
Agency Information Security Officer
Cite as 36 Miss. Admin. Code Pt. 1, R. 1.8
Agency Information Security Officer
Each agency must designate an Information Security Officer (ISO) that will manage information
security tasks and activities within the agency. The ISO responsibilities include:
A. Providing oversight of the agency-wide cybersecurity program within their agency.
B. Collaborating with agency staff on the development, implementation, and
maintenance of agency-specific security plans, policies, and procedures.
C. Ensuring that their agency is adhering to the State of Mississippi enterprise security
policies and standards; agency-specific policies; and any other security policies,
guidelines, regulations, or laws (Federal, State, and Local) their agency is required to
comply with.
D. Ensuring that regular assessments and evaluations of the agency’s security posture are
performed.
E. Recommending a course of action where security risks are not adequately addressed.
F. Reporting security compliance status and advising the agency head and the agency
Chief Information Officer (CIO) on the completeness and adequacy of agency
security measures.
G. Monitoring and reporting the performance of security measures within their agency.
H. Ensuring all information as required in State of Mississippi enterprise policies and
standards are developed and submitted.
I. Ensuring agency participation in the Enterprise Security Program activities, Security
Council meetings hosted by ITS, and other security-related activities organized by
ITS.