The State of Indiana’s Policy and Standards define the fundamental principles for the protection of State of Indiana information resources, the proper controls needed to ensure compliance with internal and external regulations, and to uphold the State of Indiana’s reputation with its clients. All personnel are responsible for ensuring compliance with the State of Indiana’s Policy and Standards.
Provides an overview of the State of Indiana's Policy and Standards and an introduction to its format and structure.
00.1 Security Policy Overview
State of Indiana Control Standards must have owners who are responsible for their maintenance and review according to a defined process.
00.2 Review and Evaluation of State Policy
Compliance with the State’s Policy and Standards is mandatory.
00.3 Compliance with the State's Policy and Standards
Establishes requirements for acknowledged receipt and understanding of the State's Policy and Standards by personnel, third party consultants, contractors and vendors.
00.4 Acceptable Use Policy (The IRUA)
Defines requirements for requesting and granting exceptions to the State's Policy and Standards.
00.5 Exceptions
Access to assets and associated facilities is limited to authorized users, processes, or devices, and to authorized activities and transactions.
Network integrity is protected, incorporating network segregation where appropriate.
06.5.1 Confidential System Architecture
06.5.1 System Isolation