Listing policies

Name File Division Last Revision Date Summary
Access Control Policy ETSS_Policy_300.1_Access_Control__AC_.pdf ETSS 2026-06-22 This policy ensures that only authorized users, devices, and processes gain access commensurate with business need; that privileged actions are tightly governed and auditable; and that accountability for user actions is maintained.
Annual Cybersecurity Awareness Training CYBER_Awareness_Training_10-1-18.pdf ETSS 2018-10-01 State employees must complete annual cybersecurity awareness training.
Assessment, Authorization, and Continuous Monitoring Policy ETSS_Policy_300.6_Assessment_Authorization_and_Continuous_Monitoring__CA_.pdf ETSS 2026-07-29 To establish policy for the effective implementation of security controls to safeguard State of Rhode Island IT system resources, infrastructure, and data.
Audit and Accountability Policy ETSS_Policy_300.3_Audit_and_Accountability__AU_.pdf ETSS 2026-06-22 Establish policy for effectively managing and monitoring audit and accountability controls to ensure there are sufficient information system logs of actions performed to determine accountability.
Awareness and Training Policy ETSS_Policy_950.2_Awareness_and_Training__AT_.pdf ETSS 2026-07-21 Establish policy for implementing a comprehensive security awareness and training program that ensures all Network Resource privileged users, administrators, or users with access to Non-Public Classified Data systems understand their security responsibilities, recognize current threats, and are adequately trained to perform their assigned roles in a secure manner.
Bring Your Own Device Security Policy DOIT_Bring_Your_Own_Device_Security_Policy_4-1-16.pdf ETSS 2016-04-01 To establish a Bring Your On Device Security Policy for the effective management of personally owned mobile devices used to access State networks, applications and/or data and to ensure the confidentiality, integrity, and availability of State networks, applications and data.
Configuration Management Policy ETSS_Policy_500.1_Configuration_Management.pdf ETSS 2026-07-14 This policy establishes the requirements for managing the configuration of State of Rhode Island information systems and their components throughout the system development lifecycle.
Contingency Planning Policy ETSS_Policy_100.6_Contingency_Planning__CP_.pdf ETSS 2026-06-22 This policy establishes the requirements for contingency planning across State of Rhode Island information systems. Contingency planning enables the restoration and continuity of operations of mission-critical assets and business functions following a disruption, compromise, or failure. This policy defines requirements for contingency plan development, testing, and training, system backup and recovery, and the establishment of alternate storage, processing, and telecommunications capabilities.
Cybersecurity and Risk Program Management ETSS_Policy_300.13_Cybersecurity_and_Risk_Program_Management__PM_.pdf ETSS 2026-07-29 The Security and Risk Management Program defines the foundation for information technology security in Rhode Island. It establishes the Statewide information security standards, providing direction for the Chief Information Security Officer (CISO) to establish a set of standards for information technology security to maximize the functionality, security, and interoperability of the State’s distributed information technology assets, including, but not limited to, data classification and management, communications, and encryption technologies. These standards apply to all executive branch agencies.
Cybersecurity Incident Handling and Response Policy ETSS_Policy_300.8_Cybersecurity_Incident_Handling_and_Response.pdf ETSS 2026-07-29 To establish policy for the effective and timely management of IT security related incidents to safeguard State of Rhode Island IT resources, infrastructure, and data.
Federal Tax Information Access and Data Handling Policy ETSS_Policy_400.2_FTI_Access_and_Data_Handling.pdf ETSS 2026-07-14 This policy establishes the requirements for the access, handling, processing, storage, retention, and disposal of Federal Tax Information (FTI), Personally Identifiable Information (PII), and other classified data throughout its lifecycle.
Identification and Authentication Policy ETSS_Policy_300.7_Identification_and_Authentication__IA_.pdf ETSS 2026-06-22 This policy ensures that user access is authorized prior to system access, classified data is protected through strong authentication mechanisms, and accountability is maintained through unique identification and centralized identity services.
Information Technology Project Approval Policy IT-07-02_Information_Technology_Project_Approval_Policy_2022.pdf ETSS 2022-03-22 Prior to the expenditure of State resources, the State CDO/CIO will ensure that all major information technology (IT) efforts are consistent with the State of Rhode Island's strategic direction and will be delivered within the DoIT Project Management Framework.
Media Protection Policy ETSS_Policy_300.10_Media_Protection__MP__2026.pdf ETSS 2026-06-22 This policy establishes enterprise requirements for the protection of information stored on digital and non-digital media throughout its lifecycle. It defines controls for media access, marking, storage, transport, sanitization, and use to protect the confidentiality, integrity, and availability of State information.
Mobile Devices Service and Support Policy 09-01 ETSS_Policy_09-01_Mobile_Devices_Service_and_Support_Policy.pdf ETSS 2025-04-21 Identify the process and procedures for the procurement and support of cellular telephones and mobile broadband devices (commonly referred to as air cards or hotspots).
Network Resource Acceptable Use Policy ETSS_Policy_950.1_Network_Resource_Acceptable_Use_Policy.pdf ETSS 2026-07-31 To establish policy for the acceptable use of State network resources. Protect employees and the workplace environment through reducing the risk of compromising State data, disruption of network resources, and legal related issues.
Personnel Security Policy ETSS_Policy_300.14_Personnel_Security__PS_.pdf ETSS 2026-06-22 To establish a personnel security policy that provides effective governance of personnel to ensure the security of sensitive information systems and data.
Physical and Environmental Security Policy ETSS_Policy_100.11_Physical_and_Environmental_Security.pdf ETSS 2026-06-22 This policy establishes the requirements for physical and environmental security controls at facilities that house State of Rhode Island information systems and support infrastructure. It provides a framework for protecting information systems and their components from physical threats, environmental hazards, and unauthorized physical access.
Risk Assessment Policy ETSS_Policy_300.2_Risk_Assessment__RA_.pdf ETSS 2022-11-08 This policy establishes the requirements for effectively managing risk to State of Rhode Island information systems and data through security categorization, risk assessment, vulnerability monitoring and scanning, risk response, and criticality analysis.
Security Planning Policy ETSS_Policy_300.12_Security_Planning.pdf ETSS 2026-06-22 This policy establishes the requirements for security planning across State of Rhode Island information systems. Security planning ensures that information systems are designed, implemented, operated, and maintained with appropriate security and privacy controls, and that the security posture of each system is documented, reviewed, and authorized. This policy defines the requirements for developing and maintaining System Security Plans (SSPs), establishing rules of behavior, managing security and privacy architectures, and selecting and tailoring control baselines.