36 MAC Pt. 1, R. 3.2

Cybersecurity Program

Year: 2026Length: 353 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 3.2

Cybersecurity Program A. Each agency must develop and implement an agency-wide cybersecurity program plan. All agency personnel should have an understanding of the cybersecurity program; however, the level of detail may vary depending on the employee's role and the sensitivity of the information. 1. The plan shall describe the agency’s current security posture, include an assessment of current risk, and a plan of action and milestones that describe current gaps in the security program and summarize the goals of the agency to address those gaps. 2. The plan shall include the assignment of roles and responsibilities, including the contact information for the designated agency Information Security Officer. 3. Each agency must provide a letter of compliance as a component of its cybersecurity program plan which describes applicable State, Federal, and Local regulations, laws, and standards it is required to satisfy. This includes compliance with the State of MS Enterprise Security Program. i. Letters of compliance must be signed by the agency head, who is responsible for the oversight of IT security. Letters of compliance must indicate that the agency head has observed, reviewed, and approved agency security processes, procedures, and practices. 4. Each agency must annually review and revise (as needed) its cybersecurity program plan to reflect relevant changes that impact the plan. B. Each agency must have a security program maturity assessment performed at least once every two (2) years. This assessment will determine the current level of compliance with the State of MS Enterprise Security Policy, identify security threats to their environment, and learn about remediation opportunities that may help to strengthen their ability to protect SOM assets from cyberthreats. 1. The program assessment must utilize an ITS-defined set of criteria to evaluate the effectiveness of the agency security program and the controls that protect the assets that support the agency. 2. The results of the assessment must be provided to ITS. 3. The cybersecurity program maturity assessment must be performed by an ITS- approved third-party cybersecurity assessment provider and can be included as part of the required comprehensive cybersecurity assessment as defined in the cybersecurity assessment chapter of this policy.
36 MAC Pt. 1, R. 3.2: Cybersecurity Program | Justis AI