Oregon Revised Statutes

Chapter 276A — Information Technology

62 sections

276A.200 Legislative findings on information resources

The Legislative Assembly finds and declares that: Information is a strategic asset of the state that must be managed as a valuable state resource. The expanding need, use and importance of information resources in this state require strong and effective management by both individual agencies and the state as a whole. The state must establish management pr…

276A.203 State Chief Information Officer; qualifications; duties; Enterprise Information Resources Management Strategy; rules

The office of Enterprise Information Services is established in the Oregon Department of Administrative Services. The office shall be managed by the State Chief Information Officer. The office shall direct, coordinate and oversee state information technology and telecommunications in accordance with ORS 276A.206 and other statutes, rules and policies that go…

276A.206 Oversight of state information and telecommunications technology by State Chief Information Officer; policy; rules; application for designation as community of interest

The State Chief Information Officer shall oversee and coordinate the planning, budgeting, architecture and standardization, consolidation, acquisition and oversight of all information and telecommunications technology by state government and agencies of state government so that statewide and individual state agencies’ plans and activities are addressed in th…

276A.209 State Information Technology Operating Fund

There is established the State Information Technology Operating Fund in the State Treasury, separate and distinct from the General Fund. The moneys in the State Information Technology Operating Fund may be invested as provided in ORS 293.701 to 293.857. Interest earnings on the fund assets must be credited to the fund. The Director of the Oregon Department …

276A.223 Requirement that state agency or public corporation obtain quality management services when implementing information technology initiative; reports; exceptions

As used in this section: “Information technology initiative” means a project to develop or provide, with a state contracting agency’s or public corporation’s own personnel and resources, or to obtain by means of a procurement or set of related procurements: New hardware, software or services for data processing, office automation or telecommunications; An…

276A.226 State agency funding requests for information technology; review by State Chief Information Officer and Enterprise Information Services; priority rankings; biennial report

As used in this section: “Information technology” means all present and future forms of hardware, software and services for data processing, office automation and telecommunications. “State agency” means a board, commission, department, division, office or other entity within the executive department, as defined in ORS 174.112, except: The Secretary of St…

276A.230 Definitions

As used in ORS 276A.233 and 276A.236: “Executive department” has the meaning given that term in ORS 174.112. “Information technology” includes, but is not limited to, all present and future forms of hardware, software and services for data processing, office automation and telecommunications. “State agency” means a board, commission, department, division,…

276A.233 Information technology portfolio-based management; inventory; standards; rules; exception

The purposes of information technology portfolio-based management are to: Ensure that state agencies link the state agencies’ information technology investments with business plans; Facilitate risk assessment of information technology projects and investments; Ensure that state agencies justify information technology investments on the basis of sound busi…

276A.236 Enterprise information resources management; adoption and implementation of strategy; state agency information technology initiatives costing more than $1 million

The purpose of enterprise information resources management is to create a plan and implement a state government-wide approach for managing distributed information technology assets to minimize total ownership costs from acquisition through retirement, while realizing maximum benefits for transacting the state’s business and delivering services to the residen…

276A.239 Portfolio-based management of information technology resources for Secretary of State

The Secretary of State shall implement portfolio-based management of information technology resources, as described in this section, to: Ensure that the Office of the Secretary of State links its information technology investments with business plans; Facilitate risk assessment of information technology projects and investments; Ensure that the office jus…

276A.242 Portfolio-based management of information technology resources for State Treasurer

The State Treasurer shall implement portfolio-based management of information technology resources, as described in this section, to: Ensure that the office of the State Treasurer links its information technology investments with business plans; Facilitate risk assessment of information technology projects and investments; Ensure that the office justifies…

276A.250 Definitions

As used in ORS 276A.250 to 276A.262, “state agency” means any officer, board, commission, department, division or institution of state government, as defined in ORS 174.111.

276A.253 Oregon transparency website

The State Chief Information Officer shall maintain and make available an Oregon transparency website. The website must allow any person to view information that is a public record and is not exempt from disclosure under ORS 192.311 to 192.478, including but not limited to information described in subsection (3) of this section. The State Chief Information Of…

276A.256 Reports of tax expenditures connected to economic development

For each statute that authorizes a tax expenditure with a purpose connected to economic development and that is listed in subsection (2) of this section, the state agency charged with certifying or otherwise administering the tax expenditure shall submit a report to the State Chief Information Officer. If a statute does not exist to authorize a state agency …

276A.259 Transparency Oregon Advisory Commission; members; duties; terms; reports

There is created the Transparency Oregon Advisory Commission consisting of nine members appointed as follows: The President of the Senate shall appoint two members from among members of the Senate, one from the majority party and one from the minority party. The Speaker of the House of Representatives shall appoint two members from among members of the Hou…

276A.262 Transparency Oregon Advisory Commission Fund

The Transparency Oregon Advisory Commission may accept contributions of moneys and assistance from the United States Government or its agencies or from any other source, public or private, and agree to conditions placed on the moneys not inconsistent with the duties of the commission. There is established in the State Treasury, separate and distinct from th…

276A.270 Definitions

As used in this section and ORS 276A.273 and 276A.276: “Electronic government portal” means an electronic information delivery system accessible by means of the Internet that a state agency designates officially as a means by which the state agency delivers information, products or services. “Electronic government portal provider” means a person that on be…

276A.273 Electronic Government Portal Advisory Board

There is created the Electronic Government Portal Advisory Board consisting of 13 members appointed as follows: The President of the Senate shall appoint two nonvoting members from among members of the Senate. The Speaker of the House of Representatives shall appoint two nonvoting members from among members of the House of Representatives. The Governor sh…

276A.276 Ability to offer government services through portal; portal provider fee; rules

The State Chief Information Officer, with the advice of the Electronic Government Portal Advisory Board, shall provide the ability for state agencies to offer government services by means of an electronic government portal. The electronic government portal must be secure and must comply with the information security rules, policies and standards that the Sta…

276A.300 Information systems security in executive department; rules

As used in this section: “Executive department” has the meaning given that term in ORS 174.112. “Information systems” means computers, hardware, software, storage media, networks, operational procedures and processes used in collecting, processing, storing, sharing or distributing information within, or with any access beyond ordinary public access to, the…

276A.303 Information systems security for Secretary of State, State Treasurer and Attorney General

Notwithstanding ORS 276A.300, the Secretary of State, the State Treasurer and the Attorney General have sole discretion and authority over information systems security in their respective agencies, including the discretion and authority to take all measures that are reasonably necessary to protect the availability, integrity or confidentiality of information…

276A.306 Information security incidents and assessments; reports

As used in this section: “Information resources” means data and the means for storing, retrieving, connecting or using data, including but not limited to records, files, databases, documents, software, equipment and facilities that a state agency owns or leases. “Information security assessment” means: An organized method to determine a risk to or a vulne…

276A.323 State agency coordination

As used in this section: “Executive department” has the meaning given that term in ORS 174.112, except that “executive department” does not include: The Secretary of State. The State Treasurer. The Attorney General. The Oregon State Lottery. Public universities listed in ORS 352.002. “State agency” means an agency, as defined in ORS 183.310, in the ex…

276A.326 [2017 c.513 §3; 2021 c.17 §4; 2021 c.539 §29; repealed by 2023 c.489 §2 (276A.560 enacted in lieu of 276A.326)]

276A.329 [2017 c.513 §4; repealed by 2023 c.489 §6 (276A.555 enacted in lieu of 276A.329)]

276A.332 Authority of State Chief Information Officer to enter into agreements

Notwithstanding any other provision of law, the State Chief Information Officer may: Enter into any agreement, or any configuration of agreements, relating to state cybersecurity with any private entity or unit of government, or with any configuration of private entities and units of government. The subject of agreements entered into under this section may …

276A.335 Moneys from federal government and other sources

The State Chief Information Officer may accept from the United States Government or any of its agencies any funds that are made available to the state for carrying out the purposes of ORS 276A.323 to 276A.335, 276A.555 and 276A.560, regardless of whether the funds are made available by grant, loan or other financing arrangement. Under the authority granted b…

276A.340 Definitions

As used in ORS 276A.340 to 276A.344: “Artificial intelligence” means a machine-based system that is capable, for a given set of human-defined objectives, of making predictions, recommendations or decisions influencing real or virtual environments and uses machine- or human-based inputs to: Perceive real or virtual environments; Abstract the perceptions in…

276A.342 State agencies prohibited from using covered products; risk mitigation; exceptions

A covered product may not be: Installed or downloaded onto a state information technology asset; or Used or accessed by a state information technology asset. A state agency shall: Remove any covered product that is installed or downloaded onto a state information technology asset that is under the management or control of the state agency; and Implement…

276A.344 Policies and standards; national security threat; rules

The State Chief Information Officer shall adopt: Rules pertaining to the designation of a corporate entity as a covered vendor under ORS 276A.340 (3)(g); and Policies and standards for state agencies to implement the provisions of ORS 276A.342. The rules adopted under this section must include: The definition of “national security threat” for purposes of…

276A.346 Secretary of State prohibited from using covered products; risk mitigation; exceptions

As used in this section: “Artificial intelligence” means a machine-based system that is capable, for a given set of human-defined objectives, of making predictions, recommendations or decisions influencing real or virtual environments and uses machine- or human-based inputs to: Perceive real or virtual environments; Abstract the perceptions into models th…

276A.348 State Treasurer prohibited from using covered products; risk mitigation; exceptions

As used in this section: “Artificial intelligence” means a machine-based system that is capable, for a given set of human-defined objectives, of making predictions, recommendations or decisions influencing real or virtual environments and uses machine- or human-based inputs to: Perceive real or virtual environments; Abstract the perceptions into models th…

276A.350 Definitions

As used in ORS 276A.350 to 276A.371: “Data” means final versions of statistical or factual information, including statistical or factual data about image files, that: Is in alphanumeric form reflected in a list, table, graph, chart or other nonnarrative form that can be digitally transmitted or processed; Is controlled by and regularly created or maintain…

276A.353 Chief Data Officer; duties; rules

The State Chief Information Officer shall appoint a Chief Data Officer. The Chief Data Officer shall: Maintain a central web portal for the publication of publishable data under ORS 276A.362. Establish the open data standard as provided in ORS 276A.356. Prepare and publish the technical standards manual as provided in ORS 276A.359. Create an enterprise …

276A.356 Open data standard

The Chief Data Officer appointed under ORS 276A.353 shall establish an open data standard for state agencies publishing publishable data on the web portal maintained under ORS 276A.353. A local or tribal government may adopt the standard. The standard must include: A format that permits public notification of updates whenever possible. Requirements to upda…

276A.359 Technical standards manual

The Chief Data Officer appointed under ORS 276A.353 shall prepare and publish a technical standards manual for publishing data through the web portal maintained under ORS 276A.353. The manual must: Enable state agencies to make publishable data available to the greatest number of users and for the greatest number of applications and emphasize that state age…

276A.362 Release of publishable data on web portal; exemptions; rules

A state agency that releases publishable data shall release the data on the web portal maintained under ORS 276A.353 in accordance with the open data standard and technical standards manual established by the Chief Data Officer under ORS 276A.356 and 276A.359. If a state agency cannot make all publishable data available on the web portal, the state agency sh…

276A.365 Information management by state agencies

A state agency shall manage information as a strategic asset throughout the information’s life cycle. To improve the management of information resources and reinforce the state’s presumption of openness, an agency shall: Collect or create information in a way that supports downstream processing and dissemination activities, including: Using machine-readabl…

276A.368 Purpose of data; limitation of liability; publishable data in public domain

Publishable data available on the web portal maintained under ORS 276A.353 is provided for informational purposes only. The state does not warrant the completeness, accuracy, content or fitness for any particular purpose or use of publishable data made available on the web portal. No warranties may be implied or inferred with respect to the publishable data …

276A.371 Obligations of state agency under public records law

ORS 276A.350 to 276A.371 do not supersede any obligation imposed on a state agency by ORS 192.311 to 192.478.

276A.374 Application to Secretary of State and State Treasurer; rules

The Secretary of State and the State Treasurer shall by rule adopt for each respective office requirements related to data that are the same as, or are similar to, the requirements established by ORS 276A.350 to 276A.371 and by rules adopted by the State Chief Information Officer or the Chief Data Officer under ORS 276A.350 to 276A.371. TELECOMMUNICATIONS A…

276A.400 Policy

The Legislative Assembly declares it to be the policy of the State of Oregon: To use information technology in education, health care, economic development and government services to improve economic opportunities and quality of life for all Oregonians regardless of location or income. To stimulate demand to encourage and enable long-term infrastructure in…

276A.403 Coordination of telecommunications systems

The State Chief Information Officer shall coordinate, in a manner that is consistent with plans, standards, policies, goals, directives and rules that the State Chief Information Officer sets, specifies or adopts, the consolidation and operation of all telecommunications systems, including emergency telecommunications systems, that the state and state agenci…

276A.406 Acquisition of broadband and communications services

As used in this section and ORS 276A.412 and 276A.421: “Broadband” means wide bandwidth communications transmissions over coaxial cable, optical fiber, radio or twisted pair with an ability to simultaneously transport multiple signals and traffic types at a minimum transmission speed established by the State Chief Information Officer by rule, but in no even…

276A.409 Use of agency travel and transportation funds for telecommunications services

The State Chief Information Officer annually shall review each state agency’s budget, in conjunction with the state agency, to identify funds that the state agency uses for travel and transportation that the state agency could instead use for telecommunications. If the State Chief Information Officer determines that a state agency could use a portion of the …

276A.412 Contracts for telecommunications equipment and services not to exceed 10 years; exception for broadband infrastructure; contract benefits for designated communities of interest

For the purposes of ORS 276A.400 to 276A.412, the State Chief Information Officer may, in a manner that is consistent with the State Chief Information Officer’s rules, policies and standards, enter into a contract or contracts with telecommunications providers and equipment manufacturers for purchasing, using or operating telecommunications equipment and ser…

276A.415 Agreements to fund or acquire telecommunications equipment and services

The State Chief Information Officer may, in a manner that is consistent with the State Chief Information Officer’s rules, policies and standards, enter into an agreement or agreements to fund or otherwise acquire telecommunications equipment and services by installment purchase or lease purchase contracts.

276A.418 Public contracts for broadband Internet access service; prohibitions; exceptions; rules

As used in this section: “Broadband Internet access service” means: A mass-market retail Internet access service provided by wire or radio that enables a person to transmit data to or receive data between the person’s customer premises equipment, including mobile devices, and all, or substantially all, Internet endpoints; Any service that the Public Utili…

276A.421 Provision of broadband services that compete with services of private telecommunications provider; circumstances of competition; broadband services advisory committee; rules

If the State Chief Information Officer determines that the broadband services and operations proposed to be provided by the State Chief Information Officer under ORS 276A.406 (2)(b) would directly compete with services already offered by a telecommunications provider, the State Chief Information Officer may only provide those services pursuant to the rules d…

276A.424 Connecting Oregon Schools Fund; rules

The Connecting Oregon Schools Fund is established in the State Treasury, separate and distinct from the General Fund. Interest earned by the Connecting Oregon Schools Fund shall be credited to the fund. The Connecting Oregon Schools Fund consists of any moneys deposited in the fund from whatever source and may include moneys appropriated, allocated, deposit…

276A.500 Definitions

As used in ORS 276A.500 to 276A.515: “Critical infrastructure information” means information about infrastructure that is so vital to this state or the United States that the incapacity or destruction of the infrastructure would detrimentally affect the personal and economic security, health or safety of residents of this state, including information about …

276A.503 Oregon Geographic Information Council; establishment; purposes; membership; terms of office

The Oregon Geographic Information Council is established within the office of Enterprise Information Services. The State Chief Information Officer shall provide administrative and staff support and facilities that are necessary for the council to carry out the purposes set forth in this section. The purposes of the council are to: Serve as the statewide gov…

276A.506 Powers of council; advisory committees

The Oregon Geographic Information Council has the exclusive power to: Serve as the statewide governing body for sharing and managing geospatial framework data that public bodies share under ORS 276A.500 to 276A.515; Develop and update every four years a strategic plan to manage geospatial framework data that aligns as closely as possible with the Enterpris…

276A.509 Public body duty to share geospatial framework data with council; conditions and exceptions; methods for sharing; limitations of liability

Subject to ORS 192.311 to 192.478 and except as provided in paragraph (b) of this subsection, a public body shall share all geospatial framework data that the Oregon Geographic Information Council designates for sharing if: The public body does not incur costs other than the costs that the public body would incur as a custodian of the geospatial framework d…

276A.512 Oregon Geographic Information Council Fund; records and reports

The Oregon Geographic Information Council Fund is established in the State Treasury, separate and distinct from the General Fund. All moneys that the State Chief Information Officer collects or receives for the purposes set forth in ORS 276A.500 to 276A.515 must be paid into the State Treasury and credited to the Oregon Geographic Information Council Fund. M…

276A.515 State geographic information officer; qualifications; duties

The State Chief Information Officer shall establish and appoint an individual as a state geographic information officer to fill a full-time equivalent position that manages and oversees the daily operations of the office of Enterprise Information Services that concern or are related to geographic information and geospatial framework data. The individual tha…

276A.550 Definitions

As used in this section and ORS 276A.555, 276A.560 and 276A.575: “Education service district” means a district created under ORS 334.010 that provides regional educational services to component school districts. “Library” means a public agency that provides free and equal access to library and information services that are suitable for persons of all ages.…

276A.555 Oregon Cybersecurity Center of Excellence; purpose; operating agreement; strategic plan; biennial report

The Oregon Cybersecurity Center of Excellence is established at Portland State University. The center shall operate under the joint direction and control of Portland State University, Oregon State University and the University of Oregon. A director shall be appointed to oversee the center pursuant to procedures set forth in the charter developed and adopted …

276A.560 Oregon Cybersecurity Advisory Council

The Oregon Cybersecurity Advisory Council is established within the Oregon Cybersecurity Center of Excellence. The council consists of 21 members appointed as follows: The Governor, after consultation with the State Chief Information Officer and the director of the Oregon Cybersecurity Center of Excellence or the director’s designee, shall appoint 15 voting…

276A.565 Oregon Cybersecurity Center of Excellence Operating Fund; biennial report

The Oregon Cybersecurity Center of Excellence Operating Fund is established in the State Treasury, separate and distinct from the General Fund. Interest earned by the Oregon Cybersecurity Center of Excellence Operating Fund must be credited to the fund. Moneys in the fund shall consist of: Amounts donated to the fund; Amounts appropriated or otherwise tra…

276A.570 Oregon Cybersecurity Workforce Development Fund; biennial report

The Oregon Cybersecurity Workforce Development Fund is established in the State Treasury, separate and distinct from the General Fund. Interest earned by the Oregon Cybersecurity Workforce Development Fund must be credited to the fund. Moneys in the fund shall consist of: Amounts donated to the fund; Amounts appropriated or otherwise transferred to the fu…

276A.575 Oregon Cybersecurity Grant Program Fund; standards and requirements; biennial report

The Oregon Cybersecurity Grant Program Fund is established in the State Treasury, separate and distinct from the General Fund. Interest earned by the Oregon Cybersecurity Grant Program Fund must be credited to the fund. Moneys in the fund shall consist of: Amounts donated to the fund; Amounts appropriated or otherwise transferred to the fund by the Legisl…