{"data":{"id":"us-ok/okla.-stat.-tit.-62-62-34.32","jurisdiction":"us-ok","citation":"Okla. Stat. tit. 62, § 62-34.32","heading":"Standard security risk assessment and audit of state","body":"agency information technology systems.\n\nA. The Information Services Division of the Office of\n\nManagement and Enterprise Services shall create a standard security\n\nrisk assessment for state agency information technology systems that\n\ncomplies with the International Organization for Standardization\n\n(ISO) and the International Electrotechnical Commission (IEC)\n\nInformation Technology - Code of Practice for Security Management\n\n(ISO/IEC 27002).\n\nB. Each state agency that has an information technology system\n\nshall obtain an information security risk assessment to identify\n\nvulnerabilities associated with the information system. The\n\nInformation Services Division of the Office of Management and\n\nEnterprise Services shall approve not less than two firms which\n\nstate agencies may choose from to conduct the information security\n\nrisk assessment.\n\nC. A state agency with an information technology system that is\n\nnot consolidated under the Information Technology Consolidation and\n\nCoordination Act or that is otherwise retained by the agency shall\n\nadditionally be required to have an information security audit\n\nconducted by a firm approved by the Information Services Division\n\nthat is based upon the most current version of the NIST Cyber-\n\nSecurity Framework, and shall submit a final report of the\n\ninformation security risk assessment and information security audit\n\nfindings to the Information Services Division each year on a\n\nschedule set by the Information Services Division. Agencies shall\n\nalso submit a list of remedies and a timeline for the repair of any\n\ndeficiencies to the Information Services Division within ten (10)\n\ndays of the completion of the audit. The final information security\n\nrisk assessment report shall identify, prioritize, and document\n\ninformation security vulnerabilities for each of the state agencies\n\nassessed. The Information Services Division may assist agencies in\n\nrepairing any vulnerabilities to ensure compliance in a timely\n\nmanner.\n\nD. Subject to the provisions of subsection C of Section 34.12\n\nof this title, the Information Services Division shall report the\n\nresults of the state agency assessments and information security\n\naudit findings required pursuant to this section to the Governor,\n\nthe Speaker of the House of Representatives, and the President Pro\n\nTempore of the Senate by the first day of January of each year. Any\n\nstate agency with an information technology system that is not\n\nconsolidated under the Information Technology Consolidation and\n\nCoordination Act that cannot comply with the provisions of this\n\nsection shall consolidate under the Information Technology\n\nConsolidation and Coordination Act.\n\nE. This section shall not apply to state agencies subject to\n\nmandatory North American Electric Reliability Corporation (NERC)\n\ncybersecurity standards and institutions within The Oklahoma State\n\nSystem of Higher Education, the Social Security Disability\n\nDetermination Services Division of the Department of Rehabilitation\n\nServices, and the Oklahoma State Regents for Higher Education and\n\nthe telecommunications network known as OneNet that follow the\n\nInternational Organization for Standardization (ISO), the Oklahoma\n\nMilitary Department (OMD) and the International Electrotechnical\n\nCommission (IEC)-Security techniques-Code of Practice for\n\nInformation Security Controls or National Institute of Standards and\n\nTechnology.","path":["OK Code","Title 62"],"source_url":"https://www.oklegislature.gov/OK_Statutes/CompleteTitles/os62.pdf","current_through":"2026-08-14","vintage":"open-us-law v2026.08, retrieved 2026-09-14","retrieved_at":"2026-09-14T18:32:36Z","sha256":"fe6cda34b0bf3d34d6310dd0a528eb47246529d9b4e0f972bfa1bc114b7ecf88","source_id":"us-ok","stale":false,"prev":"us-ok/okla.-stat.-tit.-62-62-34.31.2","next":"us-ok/okla.-stat.-tit.-62-62-34.33"},"notice":"GroundRules: Original legal text. Not legal advice."}
