Oregon Administrative Rules
Chapter 128 - DEPARTMENT OF ADMINISTRATIVE SERVICES, OFFICE OF THE STATE CHIEF INFORMATION OFFICER
Division 20 - STATE INFORMATION TECHNOLOGY ASSET PROTECTION - COVERED VENDORS
Section 128-020-0020 - Designation Criteria

Universal Citation: OR Admin Rules 128-020-0020

Current through Register Vol. 63, No. 9, September 1, 2024

The State Chief Information Officer will consider one or more of the following criteria when determining if a corporate entity is a national security threat:

(1) The corporate entity owns or otherwise provides a product or service that was developed or provided by a covered vendor.

(2) The extent to which the corporate entity is affiliated with a covered vendor.

(3) The corporate entity owns or otherwise provides a product or service that collects user data, including but not limited to personal information, browsing history, and location history, that is not required for or grossly exceeds the minimum necessary user data for the product or service.

(4) The corporate entity owns or otherwise provides a product or service that collects user data, such as biometric data, contact information, GPS locations, chat logs, photos and browser histories, personal information, browsing history, and location history, that is potentially or currently accessible by foreign governments or foreign state actors.

(5) The corporate entity owns or otherwise provides a product or service that has security vulnerabilities that, if unresolved, could expose state information technology assets to malicious actors.

(6) The corporate entity owns or otherwise provides a product or service developed or provided by a corporate entity that has been designated a national security threat or otherwise meets the criteria of a covered vendor under OAR 128-020-0010.

(7) The corporate entity owns or otherwise provides a product or service that supports the administrative use of algorithmic modifications to conduct misinformation, disinformation, or malinformation campaigns.

(8) The corporate entity owns or otherwise provides a product or service that has the potential to control or compromise state information technology assets.

Statutory/Other Authority: ORS 276A.300

Statutes/Other Implemented: Or Laws 2023, ch 256 (HB 3127)

Disclaimer: These regulations may not be the most recent version. Oregon may have more current or accurate information. We make no warranties or guarantees about the accuracy, completeness, or adequacy of the information contained on this site or the information linked to on the state site. Please check official sources.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.