The Department of Technology shall improve the governance and implementation of information technology by standardizing reporting relationships, roles, and responsibilities for setting information technology priorities.
(a) (1) Each state agency shall have a chief information officer who is appointed by the head of the state agency, or by the head’s designee, subject to the approval of the Department of Technology.
(2) A chief information officer appointed under this subdivision shall do all of the following:
(A) Oversee the information technology portfolio and information technology services within his or her state agency through the operational oversight of information technology budgets of departments, boards, bureaus, and offices within the state agency.
(B) Develop the enterprise architecture for his or her state agency, subject to the review and approval of the Department of Technology, to rationalize, standardize, and consolidate information technology applications, assets, infrastructure, data, and procedures for all departments, boards, bureaus, and offices within the state agency.
(C) Ensure that all departments, boards, bureaus, and offices within the state agency are in compliance with the state information technology policy.
(b) (1) Each state entity shall have a chief information officer who is appointed by the head of the state entity.
(2) A chief information officer appointed under this subdivision shall do all of the following:
(A) Supervise all information technology and telecommunications activities within his or her state entity, including, but not limited to, information technology, information security, and telecommunications personnel, contractors, systems, assets, projects, purchases, and contracts.
(B) Ensure the entity conforms with state information technology and telecommunications policy and enterprise architecture.
(c) Each state agency shall have an information security officer appointed by the head of the state agency, or the head’s designee, subject to the approval by the Department of Technology. The state agency’s information security officer appointed under this subdivision shall report to the state agency’s chief information officer.
(d) Each state entity shall have an information security officer who is appointed by the head of the state entity. An information security officer shall report to the chief information officer of his or her state entity. The Department of Technology shall develop specific qualification criteria for an information security officer. If a state entity cannot fund a position for an information security officer, the entity’s chief information officer shall perform the duties assigned to the information security officer. The chief information officer shall coordinate with the Department of Technology for any necessary support.
(e) (1) For purposes of this section, “state agency” means the Transportation Agency, Department of Corrections and Rehabilitation, Department of Veterans Affairs, Business, Consumer Services, and Housing Agency, Natural Resources Agency, California Health and Human Services Agency, California Environmental Protection Agency, Labor and Workforce Development Agency, and Department of Food and Agriculture.
(2) For purposes of this section, “state entity” means an entity within the executive branch that is under the direct authority of the Governor, including, but not limited to, all departments, boards, bureaus, commissions, councils, and offices that are not defined as a “state agency” pursuant to paragraph (1).
(f) A state entity that is not defined under subdivision (e) may voluntarily comply with any of the requirements of Sections 11546.2 and 11546.3 and may request assistance from the Department of Technology to do so.
(Amended by Stats. 2012, Ch. 147, Sec. 9. (SB 1039) Effective January 1, 2013. Operative July 1, 2013, by Sec. 23 of Ch. 147.)