{"data":{"id":"us-or/ors-276a.344","jurisdiction":"us-or","citation":"ORS 276A.344","heading":"Policies and standards; national security threat; rules.","body":"(1) The State Chief Information Officer shall adopt:\n      (a) Rules pertaining to the designation of a corporate entity as a covered vendor under ORS 276A.340 (3)(g); and\n      (b) Policies and standards for state agencies to implement the provisions of ORS 276A.342.\n      (2) The rules adopted under this section must include:\n      (a) The definition of “national security threat” for purposes of protecting state information technology assets;\n      (b) Criteria and a process for determining when a corporate entity poses a national security threat; and\n      (c) Criteria and a process for determining when a corporate entity no longer poses a national security threat.\n      (3) The policies and standards adopted under this section must include:\n      (a) The procedures for providing state agencies, the Secretary of State and the State Treasurer notice that a corporate entity is designated or no longer designated a covered vendor under ORS 276A.340 (3)(g);\n      (b) The time schedules for implementing the requirements under ORS 276A.342 with regard to a corporate entity that is designated a covered vendor by the State Chief Information Officer; and\n      (c) The time schedules for incorporating the requirements under ORS 276A.342 into a state agency’s information security plans, standards or measures.","path":["07 - Public Facilities and Finance","26. Public Facilities, Contracting and insurance","Chapter 276A — Information Technology"],"source_url":"https://www.oregonlegislature.gov/bills_laws/ors/ors276A.html","current_through":"2025 Edition","vintage":"","retrieved_at":"2026-09-03T23:50:13Z","sha256":"b079d113318cabb7bbc37f3cf402a6c16f6b96edc378c039f450b2e365ff4d57","source_id":"us-or","stale":false,"prev":"us-or/ors-276a.342","next":"us-or/ors-276a.346"},"notice":"GroundRules: Original legal text. Not legal advice."}
