State of Ohio IT Rules, Policies,

Standards, Procedures & Bulletins

 
  red line
About Us
Enterprise IT Architecture & Policy Home
IT Policy Management Section
IT Standards Management Section
IT Law & Policy Section
 
Resources
Rules, Policies, Standards, Procedures & Bulletins
Enterprise IT Architecture & Policy News
Electronic Signature Rule
IT Policy FAQs
IT Rule FAQs
Policy Resources
Standards Resources
Contact Us
 
Please Note
To view information in portable document format (.pdf), you must have Adobe Reader installed on your computer. Click here to download a free copy of Adobe Reader.
------------------
To view information in MS Word, you must have MS Word 2003 or later or Word Viewer 2003 installed on your computer. Click here to download a free copy of Word Viewer 2003.
   
 
   
 
Click the links above to go to the section of this page on Ohio's IT-related statutes and administrative rules, enterprise IT policies, standards, procedures or bulletins.
   
   
  This site is the official register of State of Ohio information technology (IT) policies, standards and bulletins and OIT enterprise procedures. In addition, the Enterprise IT Architecture & Policy program publishes Ohio IT statutes and administrative rules on this page as a convenience to state agencies. Statutes are referred to as the Ohio Revised Code (ORC), and administrative rules are referred to as the Ohio Administrative Code (OAC).
   
  Recent Additions
   
  New publications added to this page since June 1, 2008, include the following:
   
    blue bullet ITB-2008.01 Encryption and Investigatory Needs (.pdf)
         
    blue bullet ITB-2008.02 Privacy Impact Assessments (.pdf)
         
    blue bullet Data Classification Resource Kit (.pdf)
       
   
 

Ohio IT Statutes & Administrative Rules

  red line
   
  ORC 125.18 Office of Information Technology
         
  ORC 1306 Uniform Electronic Transactions Act
           
  State Agency-Specific Provisions:
       
  1306.20   State agency provisions
           
    1306.21   Rules for state agency use of electronic records or 
      electronic signatures
         
    1306.23   Exemptions to public records laws
         
    Administrative Rule on Electronic Signatures:
   
    OAC 123: 3-1-01  Use of Electronic Signatures and Records
      Important additional information
       
  ORC 1347 Personal Information Systems
         
    Back to top
   
 

State of Ohio IT Policies

  red line
   
  IT Governance Policies — A Series
   
  ITP-A.1 Authority of the State Chief Information Officer to Establish Policy Regarding the Acquisition and Use of Computer and Telecommunications Products and Services (.pdf)
   
  ITP-A.5 RESCINDED Software Copies and Copyrights (.pdf)
   
  ITP-A.26 Software Licensing (.pdf)
       
  Security Policies — B Series
       
  ITP-B.1 Information Security Framework (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.2 Boundary Security (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.3 Password-PIN Security (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.4 Malicious Code Security (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.5 Remote Access Security (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.6 Internet Security (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.7 Security Incident Response (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.8 Security Education and Awareness (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.9 Portable Computing Security (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.10 Security Notifications (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
   
  ITP-B.11 Data Classification (.pdf)
  Audit Checklist  Tips  White Paper  User Requirements
    Data Classification Resource Kit (.pdf)
         
  ITP-B.12 Intrusion Prevention and Detection (.pdf)
    Audit Checklist  Tips  White Paper  User Requirements
       
  IT Project Lifecycle Policies — D Series
         
  ITP-D.4 Information Technology Planning (.pdf)
         
  IT Asset Management Policies — E Series
         
  ITP-E.1 Disposal, Servicing and Transfer of IT Equipment (.pdf)
  Audit Checklist
     
  ITP-E.7 Business Resumption Planning (.pdf)
  IT Business Continuity Planning Guideline (replaces ITP-E.7)
     
  ITP-E.8 Use of Internet, E-mail and Other IT Resources (.pdf)
  Audit Checklist
     
  ITP-E.30 Electronic Records (.pdf)
  Audit Checklist
         
  Internet/Intranet Policies — F Series
       
  ITP-F.1 Registration of Internet Domain Names (.pdf)
     
  ITP-F.3 Web Site Accessibility (.pdf)
     
  ITP-F.4 Executive Branch Cabinet Agency Web Site Standardization (.pdf)
     
  ITP-F.35 Advertisements, Endorsements, and Sponsorship on State-Controlled Web Sites (.pdf)
   
  Telecommunication Policies — H Series
         
  ITP-H.2 Use of State Telephones (.pdf)
     
  ITP-H.6 Telecommunications Utility Services (.pdf)
           
    Back to top
           
       
 

State of Ohio IT Standards

  Red line
       
  Network Standards  NET Series
       
ITA-NET-01 802.11 Wireless Local Area Network Technical Architecture (.pdf)
     
  ITS-NET-01 802.11 Wireless Local Area Network Standard (.pdf)
 
  Platform Standards PLF Series
 
  ITS-PLF-01 Enterprise Client Computer Hardware Standard (.pdf)
       
  ITS-PLF-02      RESCINDED  Enterprise Notebook Hardware Standard (.pdf)
  (see ITS-PLF-01)
   
  ITS-PLF-03 Printer Total Cost of Ownership (.pdf)
  Printer TCO Tools
       
  Security Standards SEC Series
 
  ITS-SEC-01 Data Encryption and Cryptography (.pdf)
       
  Systems Management Standards — SYS Series
       
  ITS-SYS-01 Bar Code Standards for Automated Inventory Systems Used by State of Ohio Government Agencies (.pdf)
           
    Back to top
         
       
OIT Enterprise Procedures
  red line
       
  Security Procedures — SEC Series
       
  OEP-SEC.4001     Statewide Incident Response Reporting
       
  OEP-SEC.4002     Review of Sensitive Data Bulletin Exception Request
       
    Back to top    
       
       
 

State of Ohio IT Bulletins

  red line
       
  ITB-2008.02     Privacy Impact Assessments (.pdf)
      PTA Template (.doc)   PIA Template (.doc)
   
  ITB-2008.01     Encryption and Investigatory Needs (.pdf)
        Statement of Responsibility (.doc)
     
  ITB-2007.02     Data Encryption and Securing Sensitive Data (.pdf)
     
  ITB-2007.01     Electronic Communication and Public Records (.pdf)
     
  ITB-2006.01     Public Records Requests Concerning IT and Telecommunications
        Systems (.pdf)
         
      Back to top
   
   
     
 
 

Enterprise IT Architecture & Policy Home  It Policy Management  IT Standards Management 

IT Law  & Policy Rules, Policies, Standards, Procedures & Bulletins Enterprise IT Architecture & Policy News  Electronic Signature Rule  IT Policy FAQs  IT Rule FAQs   Policy Resources 

Standards Resources  Contact Us