Code of Maryland Regulations
Title 10 - MARYLAND DEPARTMENT OF HEALTH
Part 3
Subtitle 10 - LABORATORIES
Chapter 10.10.11 - Biological Agents Registry Program
Section 10.10.11.22 - BAR Information Security - Technical Security Measures
Current through Register Vol. 51, No. 19, September 20, 2024
A trusted partner shall establish a system of technical security measures to protect BAR information integrity, confidentiality, and availability, which include:
A. A BAR information security assessment to determine the sensitivity, vulnerabilities, and security of the trusted partner's programs and operations related to the BAR information the trusted partner:
B. An information system certification based on a technical evaluation as part of and in support of the security process, which establishes the extent to which the trusted partner's computer system used for BAR information meets the security requirements of this chapter;
C. Establishing and utilizing procedures and processes to guard against unauthorized access to BAR information by using:
D. Establishing procedures and processes for computer system authorization control for an individual to obtain access for the use and disclosure of BAR information, which include:
E. A security configuration management plan that includes:
F. Security incident procedures that describe how to:
G. Sanction policies and procedures describing the disciplinary actions and notice of possible civil or criminal penalties an individual may be subject to for misuse or misappropriation of BAR information.