GroundRules
← Search the law
Oregon · Through 2025 Edition

ORS 276A.344: Policies and standards; national security threat; rules.

Read at publisher ↗
Where this section sits in the code
  1. 07 - Public Facilities and Finance
  2. 26. Public Facilities, Contracting and insurance
  3. Chapter 276A — Information Technology

(1) The State Chief Information Officer shall adopt:

      (a) Rules pertaining to the designation of a corporate entity as a covered vendor under ORS 276A.340 (3)(g); and

      (b) Policies and standards for state agencies to implement the provisions of ORS 276A.342.

      (2) The rules adopted under this section must include:

      (a) The definition of “national security threat” for purposes of protecting state information technology assets;

      (b) Criteria and a process for determining when a corporate entity poses a national security threat; and

      (c) Criteria and a process for determining when a corporate entity no longer poses a national security threat.

      (3) The policies and standards adopted under this section must include:

      (a) The procedures for providing state agencies, the Secretary of State and the State Treasurer notice that a corporate entity is designated or no longer designated a covered vendor under ORS 276A.340 (3)(g);

      (b) The time schedules for implementing the requirements under ORS 276A.342 with regard to a corporate entity that is designated a covered vendor by the State Chief Information Officer; and

      (c) The time schedules for incorporating the requirements under ORS 276A.342 into a state agency’s information security plans, standards or measures.

Collected 2026-09-03T23:50:13Z. Source file · JSON

Browse this collection