Chapter 276A — Information Technology
ORS 276A.344 Policies and standards; national security threat; rules
The State Chief Information Officer shall adopt:
Rules pertaining to the designation of a corporate entity as a covered vendor under ORS 276A.340 (3)(g); and
Policies and standards for state agencies to implement the provisions of ORS 276A.342.
The rules adopted under this section must include:
The definition of “national security threat” for purposes of protecting state information technology assets;
Criteria and a process for determining when a corporate entity poses a national security threat; and
Criteria and a process for determining when a corporate entity no longer poses a national security threat.
The policies and standards adopted under this section must include:
The procedures for providing state agencies, the Secretary of State and the State Treasurer notice that a corporate entity is designated or no longer designated a covered vendor under ORS 276A.340 (3)(g);
The time schedules for implementing the requirements under ORS 276A.342 with regard to a corporate entity that is designated a covered vendor by the State Chief Information Officer; and
The time schedules for incorporating the requirements under ORS 276A.342 into a state agency’s information security plans, standards or measures.
Official sources · 1Tap to view provenance and version history
Provenance
2025 Oregon Revised Statutes — official online source
Official online edition
- Source
- oregonlegislature.gov
- SHA-256
b4adecc9…5494b22f- Review
- auto verified
Version history
Prior statutory text is not available in the ingested published editions. Consult an earlier official ORS edition or the cited Oregon Laws chapter.
2025 Oregon Revised Statutes — official online source · active · operative text
Official source