Help
Location:Home >Statutes & Constitution >View Statutes
February 09, 2010
Print This PagePrint This Page
  *
Session:
Bill #:
Session:
Chamber: View Search Tips
Year: View Search Tips
Enter Your Zip+4 Code:
Get detailed information on how to find your Legislator.

go to myflorida.com
go to myfloridahouse.gov
Select Year:
The Florida Statutes

The 1999 Florida Statutes

Title XIX
PUBLIC BUSINESS
Chapter 282
Communications and Data Processing
View Entire Chapter

282.318  Security of data and information technology resources.--

(1)  This section may be cited as the "Security of Data and Information Technology Resources Act."

(2)(a)  Each agency head is responsible and accountable for assuring an adequate level of security for all data and information technology resources of the agency and, to carry out this responsibility, shall, at a minimum:

1.  Designate an information security manager who shall administer the security program of the agency for its data and information technology resources.

2.  Conduct, and periodically update, a comprehensive risk analysis to determine the security threats to the data and information technology resources of the agency. The risk analysis information is confidential and exempt from the provisions of s. 119.07(1), except that such information shall be available to the Auditor General in performing his or her postauditing duties.

3.  Develop, and periodically update, written internal policies and procedures to assure the security of the data and information technology resources of the agency. The internal policies and procedures which, if disclosed, could facilitate the unauthorized modification, disclosure, or destruction of data or information technology resources are confidential information and exempt from the provisions of s. 119.07(1), except that such information shall be available to the Auditor General in performing his or her postauditing duties.

4.  Implement appropriate cost-effective safeguards to reduce, eliminate, or recover from the identified risks to the data and information technology resources of the agency.

5.  Ensure that periodic internal audits and evaluations of the security program for the data and information technology resources of the agency are conducted. The results of such internal audits and evaluations are confidential information and exempt from the provisions of s. 119.07(1), except that such information shall be available to the Auditor General in performing his or her postauditing duties.

6.  Include appropriate security requirements, as determined by the agency, in the written specifications for the solicitation of information technology resources.

(b)  In those instances in which the Department of Management Services develops state contracts for use by state agencies, the department shall include appropriate security requirements in the specifications for the solicitation for state contracts for procuring information technology resources.

History.--ss. 1, 2, 3, ch. 84-236; s. 28, ch. 87-137; s. 1, ch. 89-14; s. 7, ch. 90-160; s. 13, ch. 91-171; s. 234, ch. 92-279; s. 55, ch. 92-326; s. 22, ch. 94-340; s. 863, ch. 95-148; s. 131, ch. 96-406; s. 15, ch. 97-286.

Site Map
Session:    Bills ·   Calendars ·   Journals ·   Citator ·   Search ·   Appropriations ·   Redistricting ·   Bill Information Reports
Committees:    Committee Pages ·   Committee Publications
Senators:    President's Page ·   Member Pages ·   District Information ·   Find Your Legislators
Information Center:    Introduction ·   About the Legislature ·   Publications ·   Glossary ·   Frequently Asked Questions ·   Employment ·   Links
Statutes & Constitution:    Introduction ·   View Statutes ·   Search Statutes ·   Constitution ·   Laws of Florida ·   Order
Video Broadcasts
Disclaimer: The information on this system is unverified. The journals or printed bills of the respective chambers should be consulted for official purposes.    Copyright © 2000-2010 State of Florida.    Privacy Statement.     Contact Us.