Document Category: Policies
ITA Policies
| Categories | Title | Summary | Link | hf:doc_categories | hf:doc_tags |
|---|---|---|---|---|---|
| 1000 - General, Policies | P1070 – Geographic Information Systems | ITA Policy P1070 defines GIS as a key part of Idaho’s IT architecture, promoting data compatibility and interoperability among state agencies. | 1000-general ita-policies | general gis policy | |
| 3000 - Telecommunications, Policies | P3020 – Connectivity and Transport Protocols | ITA Policy P3020 mandates the use of compatible network protocols for connectivity, ensuring reliable and economical communication across state agencies. | 3000-telecommunications ita-policies | connectivity network policy protocols telecommunications | |
| 4500 - Security - Computer and Operations Management, Policies | P4502 – Privilege Access Management | ITA Policy P4502 mandates the use of multifactor authentication for privileged accounts to reduce the risk of compromise to agency information and assets. | 4500-security ita-policies | managed-access mfa policy privileged-accounts security | |
| 4500 - Security - Computer and Operations Management, Policies | P4590 – Cybersecurity Incident and Breach Response Management and Reporting | ITA Policy P4590 mandates the establishment of an incident response program within state agencies, ensuring timely reporting and management of cybersecurity incidents and breaches. | 4500-security ita-policies | breach cybersecurity incident policy reporting security | |
| 1000 - General, Policies | P1010 – IT Policies, Standards, and Guidelines Framework | ITA Policy P1010 ensures statewide integration of information resources, providing seamless access to data, computer services, and communication resources. | 1000-general ita-policies | framework general guidelines policy standards | |
| 1000 - General, Policies | P1090 – Cloud Services | ITA Policy P1090 establishes a cloud services security policy to ensure the wise use of state resources while mitigating risks and legal liabilities. | 1000-general ita-policies | cloud-services general policy | |
| 3000 - Telecommunications, Policies | P3030 – Wide Area Networks (WAN) | ITA Policy P3030 mandates the use of ITS’s statewide hardware and service contracts for WAN services, ensuring cost-effective and efficient connectivity. | 3000-telecommunications ita-policies | policy telecommunications wan wide-area-network | |
| 4500 - Security - Computer and Operations Management, Policies | P4503 – Identity and Access Management | ITA Policy P4503 mandates identity and access management practices to protect state agency assets with best practice authentication standards. | 4500-security ita-policies | authentication identity managed-access security | |
| 5000 - Information and Data, Policies | P5010 – Web Publishing | ITA Policy P5010 mandates the use of the State Web Design Template, ensuring a consistent look and navigation experience across all State of Idaho websites. | 5000-information-data ita-policies | information-and-data policy publishing website | |
| 1000 - General, Policies | P1015 – IT Policies, Standards, and Guidelines Development | ITA Policy P1015 outlines the process for developing IT policies, standards, and guidelines, ensuring consistency and effectiveness statewide. | 1000-general ita-policies | development general guidelines policies standards | |
| 2000 - IT Planning, Policies | P2010 – IT Planning Process | ITA Policy 2010 outlines the Information Technology Planning Process, ensuring strategic alignment and effective resource management. | 2000-it-planning ita-policies | it-planning policy | |
| 3000 - Telecommunications, Policies | P3040 – State 911 Multi-line Telephone Systems Policy | ITA Policy P3040 ensures that state 911 multi-line telephone systems meet safety standards, providing accurate location information during emergencies. | 3000-telecommunications ita-policies | 911 phone policy system telecommunications | |
| 4500 - Security - Computer and Operations Management, Policies | P4505 – Cybersecurity Awareness Training | ITA Policy P4505 mandates cybersecurity awareness training for all state agency personnel, ensuring they understand and mitigate cybersecurity risks. | 4500-security ita-policies | cybersecurity policy security training | |
| 5000 - Information and Data, Policies | P5020 – .gov Domain | ITA Policy P5020 establishes a framework for a single, integrated enterprise domain for all Idaho government entities, ensuring official state website identification. | 5000-information-data ita-policies | gov domain information-and-data policy website | |
| 1000 - General, Policies | P1020 – Idaho.gov Portal Privacy Notice | ITA Policy P1020 outlines the privacy notice, ensuring protection of user data and privacy across the state’s web portal. | 1000-general ita-policies | general idaho-gov policies privacy | |
| 2000 - IT Planning, Policies | P2020 – Business Recovery Planning | ITA Policy P2020 establishes a statewide business recovery planning policy, ensuring agencies can continue mission-critical IT services during disruptions. | 2000-it-planning ita-policies | business-recovery it-planning planning policy | |
| 4000 - Security - General, Policies | P4110 – Agency Cybersecurity Coordinator | ITA Policy P4110 mandates the designation of an Agency Cybersecurity Coordinator to oversee and implement cybersecurity measures within state agencies. | 4000-security ita-policies | agency coordinator cybersecurity policy security | |
| 4500 - Security - Computer and Operations Management, Policies | P4520 – Patching and Vulnerability Management | ITA Policy P4520 establishes guidelines for managing IT vulnerabilities, ensuring timely deployment of patches to prevent exploitation. | 4500-security ita-policies | patching policy security vulnerability-management | |
| 5000 - Information and Data, Policies | P5030 – Framework Standards Development Policy | ITA Policy P5030 sets the process for developing framework standards, ensuring consistency and compliance across Idaho’s spatial data infrastructure. | 5000-information-data ita-policies | data framework gis information-and-data infrastructure policy spatial-data | |
| 1000 - General, Policies | P1030 – Electronic Document Management | ITA Policy P1030 outlines the management of electronic documents, ensuring compliance with state records management policies and statutes. | 1000-general ita-policies | electronic-document-management general policy | |
| 2000 - IT Planning, Policies | P2030 – Information Technology Large-Scale Project Review | ITA Policy P2030 mandates the review of large-scale IT projects by state agencies to ensure alignment with statewide IT plans and standards. | 2000-it-planning ita-policies | it-planning planning policy project | |
| 4000 - Security - General, Policies | P4130 – Information Systems Classification Policy | ITA Policy P4130 establishes information systems classification categories for state agencies, promoting effective management and security of information. | 4000-security ita-policies | classification policy security | |
| 4500 - Security - Computer and Operations Management, Policies | P4530 – Cleansing Data from Surplus Computer Equipment | ITA Policy P4530 defines requirements for data removal from surplus computer equipment, ensuring sensitive information is unrecoverable. | 4500-security ita-policies | data-cleansing devices policy security | |
| 5000 - Information and Data, Policies | P5040 – Use of Social Networking Sites | ITA Policy P5040 provides guidelines for the use of social networking sites by state agencies, ensuring secure, consistent, and effective communication. | 5000-information-data ita-policies | information-and-data policy social-media | |
| 1000 - General, Policies | P1040 – Electronic Mail and Messaging | ITA Policy P1040 ensures proper and efficient use of Idaho’s email and messaging systems by employees, promoting ethical and lawful communication. | 1000-general ita-policies | electronic-messaging email general policy | |
| 2000 - IT Planning, Policies | P2040 – Risk Assessment | ITA Policy P2040 mandates risk assessments for large-scale IT projects, ensuring agencies minimize potential failures and maintain project success. | 2000-it-planning ita-policies | assessment it-planning policy risk | |
| 4000 - Security - General, Policies | P4140 – Cybersecurity Framework | ITA Policy P4140 mandates the adoption of the NIST Cybersecurity Framework by state agencies to enhance cybersecurity posture and risk management. | 4000-security ita-policies | cybersecurity framework nist policy security | |
| 4500 - Security - Computer and Operations Management, Policies | P4540 – Wireless Security for State Local Area Network | ITA Policy P4540 defines security requirements for state agency wireless networks, ensuring secure communications and restricted access. | 4500-security ita-policies | lan network security wireless | |
| 1000 - General, Policies | P1050 – Internet Use and Control | ITA Policy P1050 ensures responsible and secure internet use, monitoring, and filtering to protect state resources and enhance productivity. | 1000-general ita-policies | general internet policy | |
| 2000 - IT Planning, Policies | P2045 – Risk Management Program | ITA Policy P2045 requires state agencies to adopt a risk management program to manage risks to the confidentiality, integrity, and availability of data. | 2000-it-planning ita-policies | it-planning management policy program risk | |
| 4000 - Security - General, Policies | P4150 – Privacy Policy | ITA Policy P4150 mandates the protection of Personally Identifiable Information (PII) by state agencies, ensuring data privacy and security. | 4000-security ita-policies | data policy privacy security | |
| 4500 - Security - Computer and Operations Management, Policies | P4550 – Mobile Device Management | ITA Policy P4550 ensures mobile device use does not compromise state information security, defining minimum security requirements for all devices. | 4500-security ita-policies | management mobile-device policy security | |
| 1000 - General, Policies | P1060 – State-Issued IT Devices | ITA Policy P1060 outlines the expectations for the use of state-issued IT devices, ensuring proper management and security. | 1000-general ita-policies | devices general policy | |
| 3000 - Telecommunications, Policies | P3010 – Telecommunications Equipment, Local and Long Distance Services | ITA Policy P3010 mandates the use of ITS’s central statewide system for telecommunications, ensuring cost-effective and efficient services. | 3000-telecommunications ita-policies | policy telecommunications | |
| 4500 - Security - Computer and Operations Management, Policies | P4501 – Least Privilege and Least Functionality | ITA Policy P4501 mandates the principles of least privilege and least functionality, minimizing vulnerabilities to information and assets. | 4500-security ita-policies | least-functionality least-privilege policy security | |
| 4500 - Security - Computer and Operations Management, Policies | P4570 – Firewall Security | ITA Policy P4570 defines security requirements for state agency firewalls, ensuring secure network communications and restricted access. | 4500-security ita-policies | firewall policy security |