Texas Administrative Code
Title 1 - ADMINISTRATION
Part 10 - DEPARTMENT OF INFORMATION RESOURCES
Chapter 202 - INFORMATION SECURITY STANDARDS
Subchapter B - INFORMATION SECURITY STANDARDS FOR STATE AGENCIES
Section 202.26 - Security Control Standards Catalog
Current through Reg. 50, No. 13; March 28, 2025
(a) Mandatory Requirements. Mandatory security controls shall be defined by the department in a Control Standards document published on the department's website.
(b) Minimum Requirements for Security Controls. The controls required by subsection (a) of this section shall include:
(c) A review of the agency's information security program for compliance with these standards will be performed at least biennially, based on business risk management decisions, by individual(s) independent of the information security program and designated by the agency head or their designated representative(s).
(d) Development of Control Standards. Prior to publishing new or revised standards as required by subsections (a) and (b) of this section, the department shall:
(e) Application of More Stringent Standards. The agency head may employ standards for the cost-effective information security of information, information resources, and applications within or under the supervision of that state agency that are more stringent than the standards the department prescribes under this section if the more stringent standards: