North Carolina Statutes

§ 143B-1377 — State CIO approval of security standards and risk assessments

North Carolina·Ch. 143B Executive Organization Act of 1973·Art. 15 Department of Information Technology
(a)Notwithstanding G.S. 143-48.3, 143B-1320(b), or 143B-1320(c), or any other provision of law, and except as otherwise provided by this Article, all information technology security goods, software, or services purchased using State funds, or for use by a State agency or in a State facility, shall be subject to approval by the State CIO in accordance with security standards adopted under this Part.
(b)The State CIO shall conduct risk assessments to identify compliance, operational, and strategic risks to the enterprise network. These assessments may include methods such as penetration testing or similar assessment methodologies. The State CIO may contract with another party or parties to perform the assessments. Detailed reports of the risk and security issues identified shall be kept co

Free access — add to your briefcase to read the full text and ask questions with AI

North Carolina § 143B-1377 (State CIO approval of security standards and risk assessments) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Nearby Sections

15
View on official source ↗