Chapter 276A — Information Technology
ORS 276A.342 State agencies prohibited from using covered products; risk mitigation; exceptions
A covered product may not be:
Installed or downloaded onto a state information technology asset; or
Used or accessed by a state information technology asset.
A state agency shall:
Remove any covered product that is installed or downloaded onto a state information technology asset that is under the management or control of the state agency; and
Implement all measures necessary to prevent the:
Installation or download of a covered product onto a state information technology asset that is under the management or control of the state agency; or
Use or access of a covered product by a state information technology asset that is under the management or control of the state agency.
Notwithstanding subsections (1) and (2) of this section, a state agency may, for investigatory, regulatory or law enforcement purposes, permit the:
Installation or download of a covered product onto a state information technology asset; or
Use or access of a covered product by a state information technology asset.
A state agency that permits the installation, download, use or access of a covered product under this subsection shall adopt risk mitigation standards and procedures related to the installation, download, use or access of the covered product.
The State Chief Information Officer shall coordinate with and oversee state agencies to implement the provisions of this section in accordance with the policies and standards adopted under ORS 276A.344 (3).
Official sources · 1Tap to view provenance details
Provenance
2025 Oregon Revised Statutes — official online source
Official online edition
- Source
- oregonlegislature.gov
- SHA-256
b4adecc9…5494b22f- Review
- auto verified
Version history
2025 Oregon Revised Statutes — official online source