36 MAC Pt. 1, R. 3.2
Cybersecurity Program
Cite as 36 Miss. Admin. Code Pt. 1, R. 3.2
Cybersecurity Program
A. Each agency must develop and implement an agency-wide cybersecurity program
plan. All agency personnel should have an understanding of the cybersecurity
program; however, the level of detail may vary depending on the employee's role and
the sensitivity of the information.
1. The plan shall describe the agency’s current security posture, include an
assessment of current risk, and a plan of action and milestones that describe
current gaps in the security program and summarize the goals of the agency to
address those gaps.
2. The plan shall include the assignment of roles and responsibilities, including
the contact information for the designated agency Information Security
Officer.
3. Each agency must provide a letter of compliance as a component of its
cybersecurity program plan which describes applicable State, Federal, and
Local regulations, laws, and standards it is required to satisfy. This includes
compliance with the State of MS Enterprise Security Program.
i. Letters of compliance must be signed by the agency head, who is
responsible for the oversight of IT security. Letters of compliance
must indicate that the agency head has observed, reviewed, and
approved agency security processes, procedures, and practices.
4. Each agency must annually review and revise (as needed) its cybersecurity
program plan to reflect relevant changes that impact the plan.
B. Each agency must have a security program maturity assessment performed at least
once every two (2) years. This assessment will determine the current level of
compliance with the State of MS Enterprise Security Policy, identify security threats
to their environment, and learn about remediation opportunities that may help to
strengthen their ability to protect SOM assets from cyberthreats.
1. The program assessment must utilize an ITS-defined set of criteria to evaluate
the effectiveness of the agency security program and the controls that protect
the assets that support the agency.
2. The results of the assessment must be provided to ITS.
3. The cybersecurity program maturity assessment must be performed by an ITS-
approved third-party cybersecurity assessment provider and can be included
as part of the required comprehensive cybersecurity assessment as defined in
the cybersecurity assessment chapter of this policy.