Oregon Administrative Rules
Chapter 291 - DEPARTMENT OF CORRECTIONS
Division 5 - NETWORK INFORMATION SYSTEM ACCESS AND SECURITY
Section 291-005-0025 - Access Authorization
Current through Register Vol. 63, No. 9, September 1, 2024
(1) Only authorized users shall be allowed access to Department of Corrections information systems.
(2) Authorized users shall be granted access to Department of Corrections information systems on a need-to-use basis. Such access will be controlled by a password. MFA will be required in some instances to access agency information systems.
(3) Requests for user access and termination of user access shall be accepted by the Department of Corrections ISO or designee from functional unit managers or their designees only. These personnel shall handle all requests for access and termination for their functional unit. Letters of agreement with external organizations for access to Department of Corrections information systems shall clearly indicate the process and authority for user access authorization. Users from external organizations must comply with this rule.
(4) No person presently or previously under the custody, control, or supervision of Department of Corrections or its agents shall be granted access to any computers or systems which contain data or are connected to any Department of Corrections information system unless the request for access has been recommended by the functional unit manager to the ISO for review and initial approval. Final approval for such access will be determined by the Assistant Director of Administrative Services.
(5) Functional unit managers or their designees shall identify their staff who have a need to use Department of Corrections information systems and shall be responsible for the following process for authorization:
Statutory/Other Authority: ORS 179.040, 423.020, 423.030 & 423.075
Statutes/Other Implemented: ORS 179.040, 423.020, 423.030 & 423.075