Government Technology
Government Technology: State & Local Government News Articles

California Issues Telework Policy to Curb Cyber-Security Risks

Bookmark and Share
Comment

Telework diagram

Mar 3, 2010, By Russell Nichols, Staff Writer

To bolster security and create consistency in California's IT infrastructure, the Office of the State Chief Information Officer (OCIO) issued a new policy Tuesday, March 2, that includes telework and remote access security standards as well as a compliance form that state agencies must submit by July 1.

The policy letter aims to help state agencies develop robust and secure telework and remote access arrangements for state employees, while minimizing cyber-security risks. The standard highlights several measures that IT agencies must adopt to certify telework programs, including the use of up-to-date operating system software and security software (anti-virus, anti-spyware, firewall and host intrusion prevention) for every remote connection.

The standard also notes that all computing equipment connected to the state IT infrastructure network for teleworking purposes must be state-owned with secure configurations. Teleworkers can only connect to the infrastructure through secure, encrypted channels authorized by agency management. The security measures also apply to paper files and mobile devices, and all relevant material must be kept in secured locations.

"We know that departments are interested in maintaining the highest security standards for the state's networks," said OCIO spokesman Bill Maile. "When it comes to protecting sensitive data and our network infrastructure, no department wants a security breach."

At a time when governments at all levels are looking to cut costs and boost efficiency, telework programs have proved useful: Research shows that such arrangements can improve productivity, and virtual employees are more satisfied with their jobs; state workers who don't commute also help reduce traffic congestion and air pollution. But unmanaged telework programs can hurt services and increase costs. Not only that, but with viruses lurking in cyber-space, IT agencies must take proper precautions to keep the government's information secure.

Maile said the OCIO has been working with partnering departments for the past several months to craft the policy, which includes the Telework and Remote Access Security Standard SIMM Section 66A. "This state is always working to implement the highest security standards for our IT infrastructure," Maile said.

According to the information policy letter, agency heads must comply with the following:

  • Making sure authorized users permitted to telework have been trained regarding their roles and responsibilities, security risks and the requirements included in the standard.
  • Adopting and implementing the requirements in the standard and certifying their agency's compliance. If an agency has a telework program already in place that does not meet the standard, it must establish a timeline and a deadline for achieving compliance.
  • Completing and submitting the Agency Telework and Remote Access Security Compliance Certification form included in SIMM Section 70E to the OCIO-Office of Information Security (OIS) no later than July 1, and annually thereafter beginning Jan. 31, 2011.

In a joint effort, the Department of General Services released a new statewide model Telework Program Policy and Procedures on Jan. 29, 2010.

The OCIO's new policy fits with best practices for telework programs, which require comprehensive support from IT representatives, HR and management, and information security specialists to address security and privacy issues, according to Liza Lowery Massey, who served as a public-sector IT executive for nearly 20 years. "The best telework programs," Massey wrote in a column for Public CIO last year, "have well developed evaluation procedures, strong- yet-flexible policies and a training program for everyone."

California is among the first governments in the country to write enterprisewide policies for telework, joining states such as Virginia and Arizona, and the federal government.

 

MJ

Comments

By George on Mar 11, 2010

Yah what do you people know about cyber crime?Oh I know shot a big hole in the users pc.ROFL with Microsoft watching your back now you all can act like you know something about cyber crime but the truth still remains you know nothing.

Respond to a comment.

Latest Government Technology News


Industry Solutions for Government

Read real world deployments of technology in government from our sponsors.

View All Industry Solutions

Related Products and Services

Marketplace


Get Govtech's Daily Newsletter

Video

  • Warning to Vendors
    Warning to Vendors

    Vendors charging high maintenance fees are put on notice to cut their rates by Steve Emanuel, CIO of Montgomery County, Md.


  • Virtual Beverly Hills 1
    Virtual Beverly Hills 1

    Spanning earthquakes to water meters, Beverly Hills rolled out an interactive and interoperable Web-based GIS portal for emergency operations and public information.


  • Virtual Beverly Hills 2
    Virtual Beverly Hills 2

    Virtual Beverly Hills was recently challenged when a crowd of more than 20,000 ran through town.


More Video >

Government Jobs

Browse hundreds of public sector career opportunities in GovTech's new jobs section. Popular job searches: government IT, public safety, GIS, transportation, CIO, security, health