13.01.2014 Views

Appendices - Hampton Roads Transportation Planning Organization

Appendices - Hampton Roads Transportation Planning Organization

Appendices - Hampton Roads Transportation Planning Organization

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Information Security Policy<br />

SUBJECT: Information Security Policy Development<br />

POLICY STATEMENT:<br />

VDOT Information Security policies will be compliant with legislation, VITA policies and<br />

other VDOT policies.<br />

VDOT Information Security policies are initiated to address a security vulnerability or to<br />

implement best practices and will follow a prescribed process that includes extensive<br />

planning activities, a standard format and appropriate due diligence. Information<br />

Security policies will be published only after thorough review and advice of the<br />

Information Security Advisory Committee.<br />

SCOPE:<br />

This Policy is applicable to all VDOT employees, contractors, consultants, and all<br />

others, including outsourced third parties, which have access to, or manage VDOT<br />

information, networks, or applications.<br />

This Policy encompasses all systems, automated and manual, for which the VDOT<br />

Commissioner has administrative responsibility, including systems managed or hosted<br />

by third parties on behalf of VDOT.<br />

In all cases, applicable Federal and State statutes and regulations that guarantee either<br />

protection or accessibility of VDOT information will take precedence over this Policy.<br />

This policy is in addition to VITA policies.<br />

RESPONSIBILITIES:<br />

The Security and Emergency Management Division, Information Security Office (ISO)<br />

will determine the need, develop, review, modify, publish and interpret VDOT’s<br />

Information Security Policies. The ISO will ensure that new and revised policies and<br />

procedures have been properly reviewed and approved prior to issuance.<br />

VDOT employees may request the ISO to develop and/or modify Information Security<br />

policies and may offer recommended content.<br />

VDOT’s Information Security Advisory Committee will recommend publication of all<br />

Information Security policies and procedures.<br />

25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!