{"data":{"id":"us-nc/n.c.-gen.-stat.-143b-1320","jurisdiction":"us-nc","citation":"N.C. Gen. Stat. § 143B-1320","heading":"Definitions; scope; exemptions.","body":"(a)\tDefinitions. - The following definitions apply in this Article:\n(1)\tCGIA. - Center for Geographic Information and Analysis.\n(2)\tRepealed by Session Laws 2021-180, s. 19A.7A(d), effective January 1, 2022.\n(3)\tCommunity of practice. - A collaboration of organizations with similar requirements, responsibilities, or interests.\n(4)\tCooperative purchasing agreement. - An agreement between a vendor and one or more states or state agencies providing that the parties may collaboratively or collectively purchase information technology goods and services in order to increase economies of scale and reduce costs.\n(4a)\tCybersecurity incident. - An occurrence that does either of the following:\na.\tActually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system.\nb.\tConstitutes a violation or imminent threat of violation of law, security policies, privacy policies, security procedures, or acceptable use policies.\n(5)\tDepartment. - The Department of Information Technology.\n(6)\tDistributed information technology assets. - Hardware, software, and communications equipment not classified as traditional mainframe-based items, including personal computers, local area networks, servers, mobile computers, peripheral equipment, and other related hardware and software items.\n(7)\tEnterprise solution. - An information technology solution that can be used by multiple agencies.\n(8)\tExempt agencies. - An entity designated as exempt in subsection (b) of this section.\n(9)\tGDAC. - Government Data Analytics Center.\n(10)\tGICC. - North Carolina Geographic Information Coordinating Council.\n(11)\tInformation technology or IT. - Set of tools, processes, and methodologies, including, but not limited to, coding and programming; data communications, data conversion, and data analysis; architecture; planning; storage and retrieval; systems analysis and design; systems control; mobile applications; and equipment and services employed to collect, process, and present information to support the operation of an organization. The term also includes office automation, multimedia, telecommunications, and any personnel and support personnel required for planning and operations.\n(12)\tRecodified as subdivision (a)(4a) at the direction of the Revisor of Statutes.\n(13)\tLocal government entity. - A local political subdivision of the State, including a city, a county, a local school administrative unit as defined in G.S. 115C-5, or a community college.\n(14)\tParticipating agency. - Any agency that has transferred its information technology personnel, operations, projects, assets, and funding to the Department of Information Technology. The State CIO is responsible for providing all required information technology support to participating agencies.\n(14a)\tRansomware attack. - A cybersecurity incident where a malicious actor introduces software into an information system that encrypts data and renders the systems that rely on that data unusable, followed by a demand for a ransom payment in exchange for decryption of the affected data.\n(15)\tRecodified as subdivision (a)(16a) at the direction of the Revisor of Statutes.\n(16)\tSeparate agency. - Any agency that has maintained responsibility for its information technology personnel, operations, projects, assets, and funding. The agency head shall work with the State CIO to ensure that the agency has all required information technology support.\n(16a)\tSignificant cybersecurity incident. - A cybersecurity incident that is likely to result in demonstrable harm to the State's security interests, economy, critical infrastructure, or to the public confidence, civil liberties, or public health and safety of the residents of North Carolina. A significant cybersecurity incident is determined by the following factors:\na.\tIncidents that meet thresholds identified by the Department jointly with the Department of Public Safety that involve either of the following:\n1.\tInformation that is not releasable to the public and that is restricted or highly restricted according to Statewide Data Classification and Handling Policy.\n2.\tThe exfiltration, modification, deletion, unauthorized access, or lack of availability to information or systems within certain parameters to include (i) a specific threshold of number of records or users affected as defined in G.S. 75-65 or (ii) any additional data types with required security controls.\nb.\tIncidents that involve either of the following:\n1.\tInformation that is not recoverable or cannot be recovered within defined time lines required to meet operational commitments defined jointly by the State agency and the Department.\n2.\tInformation that can be recovered only through additional measures and that has a high or medium functional impact to the mission of an agency.\n(17)\tState agency or agency. - Any agency, department, institution, commission, committee, board, division, bureau, office, unit, officer, or official of the State. The term does not include the legislative or judicial branches of government, the Community Colleges System Office, or The University of North Carolina.\n(18)\tState Chief Information Officer or State CIO. - The head of the Department, who is a Governor's cabinet level officer.\n(19)\tState CIO approved data center. - A data center designated by the State CIO for State agency use that meets operational standards established by the Department.\n(b)\tExemptions. - Except as otherwise specifically provided by law, this Article does not apply to the following entities: the General Assembly, the Judicial Department, the Community Colleges System Office, The University of North Carolina and its constituent institutions, the Office of the State Auditor, the State Board of Elections, the State Highway Patrol, and the Department of State Treasurer. These entities may elect to participate in the information technology programs, services, or contracts offered by the Department, including information technology procurement, in accordance with the statutes, policies, and rules of the Department. The election shall be made in writing, as follows:\n(1)\tFor the General Assembly, by the Legislative Services Commission.\n(2)\tFor the Judicial Department, by the Chief Justice.\n(2a)\tFor the Community Colleges System Office, by the State Board of Community Colleges.\n(3)\tFor The University of North Carolina, by the Board of Governors.\n(4)\tFor the constituent institutions of The University of North Carolina, by the respective boards of trustees.\n(5)\tFor the Office of the State Auditor, by the State Auditor.\n(6)\tFor the State Board of Elections, by the Executive Director of the State Board of Elections.\n(7)\tFor the State Highway Patrol, by the Commander of the State Highway Patrol.\n(8)\tFor the Department of State Treasurer, other than the Investment Authority under Part 1 of Article 6 of Chapter 147 of the General Statutes, by the State Treasurer.\n(9)\tFor the Investment Authority under Part 1 of Article 6 of Chapter 147 of the General Statutes, by the Board of Directors of the Authority.\n(c)\tDeviations. - Any State agency may apply in writing to the State Chief Information Officer for approval to deviate from this Article. If granted by the State Chief Information Officer, any deviation shall be consistent with available appropriations and shall be subject to any terms and conditions specified by the State CIO.\n(d)\tReview. - Notwithstanding subsection (c) of this section, any State agency shall review and evaluate any deviation authorized and shall, in consultation with the Department of Information Technology, adopt a plan to phase out any deviations that the State CIO determines to be unnecessary in carrying out functions and responsibilities unique to the agency having a deviation. The plan adopted by the agency shall include a strategy to coordinate its general information processing functions with the Department of Information Technology in the manner prescribed by this Article and shall provide for its compliance with policies, procedures, and guidelines adopted by the Department of Information Technology. Any agency receiving a deviation shall submit its plan to the Office of State Budget and Management as directed by the State Chief Information Officer. (2015-241, s. 7A.2(b); 2019-200, s. 6(d); 2021-180, ss. 19A.7A(d), 38.13(b); 2025-25, s. 39.7; 2025-62, s. 2; 2025-83, s. 2; 2025-89, s. 4.1(a), (a1); 2025-97, s. 7.2(a).)","path":["Chapter 143B. Executive Organization Act of 1973.","Article 15. Department of Information Technology.","Part 1. General Provisions."],"source_url":"https://www.ncleg.gov/EnactedLegislation/Statutes/HTML/BySection/Chapter_143B/GS_143B-1320.html","current_through":"S.L. 2026-30","vintage":"","retrieved_at":"2026-08-27T18:22:43Z","sha256":"a8a00745341145ac48cbb5c14e7e15b146db5adfaf51c46d96a715437a4f88d9","source_id":"us-nc","stale":false,"prev":"us-nc/n.c.-gen.-stat.-143b-1319","next":"us-nc/n.c.-gen.-stat.-143b-1321"},"notice":"GroundRules: Original legal text. Not legal advice."}
