Hawaii Revised Statutes 27-43.5 Additional Duties of the Chief Information Officer Relating to Security of Government Information.

[§27-43.5] Additional duties of the chief information officer relating to security of government information. (a) The chief information officer shall provide for periodic security audits of all executive branch departments and agencies regarding the protection of government information and data communication infrastructure.

(b) Security audits may include on-site audits as well as reviews of all written security procedures and documented practices. The chief information officer may contract with a private firm or firms that specialize in conducting security audits; provided that information protected from disclosure by federal or state law, including confidential tax information, shall not be disclosed. All executive branch departments, agencies, boards, or commissions subject to the security audits authorized by this section shall fully cooperate with the entity designated to perform the audit. The chief information officer may direct specific remedial actions to mitigate findings of insufficient administrative, technical, and physical controls necessary to protect state government information or data communication infrastructure.

(c) This section shall not infringe upon responsibilities assigned to the comptroller or the auditor by any state or federal law. [L 2013, c 265, §2]

Note

Office of information management and technology:

(1) Responsibilities regarding executive branch information technology systems; annual and quarterly reports to legislature. L 2014, c 122, §4(34); and

(2) Service level agreements; audits; annual and quarterly reports. L 2015, c 119, §42.

Section: Previous  27-31  27-32  27-36  27-41  27-41.1  27-42  27-43  27-43.5  27-44  27-44.1  27-44.2  27-44.3  27-45  27-51  27-52  Next

Last modified: October 27, 2016