Name: Colleen Pedroza for the Office of Information Security and Privacy Protection staff who developed the restructured State Administrative Manual (SAM) security sections and this site – Rosa Umbach and Michele Robinson
E-Mail: colleen.pedroza@oispp.ca.gov or security@oispp.ca.gov
Department or Agency: Office of Information Security and Privacy Protection (OISPP)
Idea/initiative Name: Government Online for Responsible Information Management (GoRIM)
Goal: Educate state employees about their role in responsible information management and their responsibility in ensuring it is secure and protected against misuse, unauthorized access, theft, and loss.
Short Description: The Web site provides a central location for information security standards, authority, guidance, forms, tools, and definitions related to California information security policy. These components augment the State Administrative Manual (SAM) security policies identified in SAM Sections 5300-5390 by providing state agencies with access to:
- Baseline security standards that support these policies, as well as other standards when applicable to a specific policy area;
- Laws, regulations, and other related federal and state policies that provide the authority for the State's policy requirements;
- Guidance documents that provide directions, instructions, and best practices to aid in policy compliance;
- Standardized and required forms associated with meeting policy requirements;
- Tools that include samples, templates, and other important resources to help a state agency implement a particular policy or standard;
- Definitions for clarification in the meaning of terms, words or phrases referred to in the policy or standards
GoRIM can be accessed at the OISPP's Web site at http://www.oispp.ca.gov/government/go_rim/default.asp
Results: A series of Web pages directly tied to SAM that provide users a one-stop location for complete descriptions regarding information security policies, standards, authority, guidance, forms, tools and definitions.
This Web site was unveiled in March 2008. It resulted from an OISPP project to restructure the SAM security sections and involved over a year’s worth of work by the OISPP staff, key stakeholders, and subject matter experts. As the site matures, the OISPP staff plan to enhance it with a focus on certain user groups, such as network administrators, application developers, managers and supervisors, auditors, and general users.
Lessons learned/I Wish I Had…done this sooner!