Listing policies

Name File Division Last Revision Date Summary
Restricted Account Indirect Cost Recovery AC_156_A-56_Restricted_Account_Indirect_Cost_Recovery.pdf OAC 2006-05-01 guidelines instructing state agency compliance with restrict accounts that are subject to deposit into the Rhode Island General Fund.
Restricted Account Indirect Cost Recovery Assessment A-56_RestrictedAccountIndirectCostRecoveryAssessment.pdf OAC 2016-10-19
RIFANS Delegation A-60_RIFANS_Delegation_Revised_Jan_2022.pdf OAC 2022-02-14 Policy explaining the delegation of approval authority when utilizing RIFANS
RIFANS Open Invoice Report A-72_OpenInvoiceReportRIFANS.pdf OAC 2018-02-01 Policy provides guidance for agencies using RIFANS regarding the use of the Open Invoice Report.
Risk Assessment Policy ETSS_Policy_300.2_Risk_Assessment__RA_.pdf ETSS 2022-11-08 This policy establishes the requirements for effectively managing risk to State of Rhode Island information systems and data through security categorization, risk assessment, vulnerability monitoring and scanning, risk response, and criticality analysis.
Security Planning Policy ETSS_Policy_300.12_Security_Planning.pdf ETSS 2026-06-22 This policy establishes the requirements for security planning across State of Rhode Island information systems. Security planning ensures that information systems are designed, implemented, operated, and maintained with appropriate security and privacy controls, and that the security posture of each system is documented, reviewed, and authorized. This policy defines the requirements for developing and maintaining System Security Plans (SSPs), establishing rules of behavior, managing security and privacy architectures, and selecting and tailoring control baselines.
Sexual Harassment Sexual_Harassment_Policy_Executed.pdf DHR 2018-04-02 Sexual harrasment is not tolerated and is grounds for progressive disciplinary action.
SFRF Reporting to US Treasury Policy PRO_GMO_SFRF_Reporting_to_US_Treasury_Policy.pdf PRO 2022-06-07 The purpose of this policy is to document the State’s strategy for meeting U.S. Treasury’s (UST) quarterly and annual reporting requirements for the State Fiscal Recovery Fund (SFRF), to support consistent, accurate reporting. This policy also outlines respective reporting responsibilities of the Pandemic Recovery Office, Grants Management Office, and SFRF Designated State Agencies.
Social Networking Policy IT-10-09_Policy_on_Social_Networking.pdf ETSS 2018-02-28 This policy is aimed at allowing state agencies and departments the benefit of using social networking for the performance of state business, to communicate with the public, protect the infrastructure and legal interests of the State of Rhode Island and assure that adequate bandwidth is available to conduct State business without interruption
State Fleet Operations Policy DCAMM_State_Fleet_Operations_Policy_7-19-19_Updated_with_new_header_07_21_22_.pdf DCAMM 2026-03-12 This policy governs the operations of State Fleet including the use, management, maintenance, and disposal of state-owned motor vehicle and related equipment.
State Network Device Security Policy 10-04 ETSS_Policy_10-04_State_Network_Device_Security.pdf ETSS 2025-04-20 Establish policy and guidance for appropriately managing and securing State Network Devices. Protect employees and the workplace environment through reducing the risk of compromising state data, disruption of network resources, and legal-related issues. The intent of this policy is to maintain the confidentiality and integrity of state data, ensure the availability of network resources, and assist in the reduction of financial and legal penalties associated with non-compliance of federal and state programs.
State-Additional Business Transponder Request Form AC_167_A-67B_State-Additional_Business_Transponder_Request_Form.pdf OAC 2014-12-01 Rhode Island Turnpuike and Bridge Authority Form for additional businesses E-Z Passes
Statewide Adverse Weather Policy DOA_State_Adverse_Weather_Policy3-14-19.pdf DOA 2019-03-14 To establish parameters and expectations in the event of adverse weather.
Substance Free Workplace Policy Substance_Free_Workplace_Policy.pdf DHR 2023-01-12 This policy is intended to detail the State's commitment to providing a safe, healthy and productive environment for all employees through the assurance that the workplace is free of illegal drugs, establish restrictions on the workplace-related use of legal substances, address fitness for duty behaviors, explain steps to protect and support employees, and assist in providing pathways to treatment.
Supply Chain Risk Management Policy ETSS_Policy_800.2_Supply_Chain_Risk_Management__SR_.pdf ETSS 2026-07-14 This policy establishes the requirements for identifying, assessing, and mitigating risks associated with the information and communications technology (ICT) supply chain.
System and Communications Protection Policy ETSS_Policy_300.4_System_and_Communications_Protection_.pdf ETSS 2026-07-14 This policy establishes the requirements for protecting State of Rhode Island information systems, networks, and communications to ensure the confidentiality, integrity, and availability of information resources. It defines controls for system segmentation, boundary protection, transmission and data-at-rest encryption, cryptographic key management, network session management, DNS security, and other communications protection mechanisms.
System and Information Integrity Policy ETSS_Policy_300.5_System_and_Information_Integrity__SI_.pdf ETSS 2026-07-14 This policy establishes the requirements for maintaining the integrity of State of Rhode Island information systems and data. It defines controls for flaw remediation, malicious code protection, system monitoring, security alerts, software and firmware integrity verification, spam protection, information input validation, error handling, information retention, and memory protection.
System and Services Acquisition Policy ETSS_Policy__800.1_System_and_Services_Acquisition.pdf ETSS 2026-07-14 This policy establishes the requirements for acquiring, developing, and managing information systems and services with adequate security controls to safeguard the State’s information, infrastructure, and data. It defines requirements for resource allocation, system development lifecycle integration, acquisition processes, system documentation, security engineering principles, external system services, developer configuration management and testing, and the management of unsupported system components.
System Maintenance Policy ETSS_Policy_100.2_System_Maintenance__MA_.pdf ETSS 2026-07-14 This policy establishes the requirements for the effective and secure maintenance, repair, and diagnostic servicing of State of Rhode Island information systems and system components. It defines requirements for controlled maintenance activities performed on-site or off-site, the management and inspection of maintenance tools, non-local (remote) maintenance, the authorization of maintenance personnel, and timely maintenance support.
Teleworking HR_Teleworking_Policy.pdf DHR 2023-02-24 The Policy defines the State's telework program, provides guidelines for operation. It contains general framework for assessing and approving telework agreements.