N.D. Cent. Code § 54-10-29

54-10-29. Audits of computer systems - Penalty

Year: 2026Length: 244 wordsOfficial source
54-10-29. Audits of computer systems - Penalty 1. The state auditor may: a. Pursuant to the powers and duties outlined in this chapter, conduct a review and assessment of computer systems and related security systems. Computer systems subject to this section include the computer systems of a state agency or political subdivision that is subject to audit by the state auditor. Tests conducted in connection with this review and assessment may include an assessment of system vulnerability, network penetration, potential security breach, and susceptibility to cyber attack or cyber fraud. b. Disclose any findings to the chief information officer of the state or to any state official or legislative committee. Working papers and preliminary drafts of reports created in connection with the review of computer systems and the security of the systems are exempt from section 44-04-18. Those parts of findings and working papers that identify the methods of the state auditor or that may cause or perpetuate vulnerability of the computer system reviewed are exempt from section 44-04-18 and protected from disclosure until the state auditor directs otherwise. c. Procure the services of a specialist in information security systems or other contractors deemed necessary in conducting a review under this section. The procurement of these services is exempt from the requirements of chapter 54-44.4. 2. An outside contractor hired to provide services in the review of the security of a computer system is subject to the confidentiality provisions of this section and section
N.D. Cent. Code § 54-10-29: 54-10-29. Audits of computer systems - Penalty | Justis AI