11546.1
. The Department of Technology shall improve the governance
and implementation of information technology by standardizing
reporting relationships, roles, and responsibilities for setting
information technology priorities.
(a) (1) Each state agency shall have a chief information officer
who is appointed by the head of the state agency, or by the head's
designee, subject to the approval of the Department of Technology.
(2) A chief information officer appointed under this subdivision
shall do all of the following:
(A) Oversee the information technology portfolio and information
technology services within his or her state agency through the
operational oversight of information technology budgets of
departments, boards, bureaus, and offices within the state agency.
(B) Develop the enterprise architecture for his or her state
agency, subject to the review and approval of the Department of
Technology, to rationalize, standardize, and consolidate information
technology applications, assets, infrastructure, data, and procedures
for all departments, boards, bureaus, and offices within the state
agency.
(C) Ensure that all departments, boards, bureaus, and offices
within the state agency are in compliance with the state information
technology policy.
(b) (1) Each state entity shall have a chief information officer
who is appointed by the head of the state entity.
(2) A chief information officer appointed under this subdivision
shall do all of the following:
(A) Supervise all information technology and telecommunications
activities within his or her state entity, including, but not limited
to, information technology, information security, and
telecommunications personnel, contractors, systems, assets, projects,
purchases, and contracts.
(B) Ensure the entity conforms with state information technology
and telecommunications policy and enterprise architecture.
(c) Each state agency shall have an information security officer
appointed by the head of the state agency, or the head's designee,
subject to the approval by the Department of Technology. The state
agency's information security officer appointed under this
subdivision shall report to the state agency's chief information
officer.
(d) Each state entity shall have an information security officer
who is appointed by the head of the state entity. An information
security officer shall report to the chief information officer of his
or her state entity. The Department of Technology shall develop
specific qualification criteria for an information security officer.
If a state entity cannot fund a position for an information security
officer, the entity's chief information officer shall perform the
duties assigned to the information security officer. The chief
information officer shall coordinate with the Department of
Technology for any necessary support.
(e) (1) For purposes of this section, "state agency" means the
Transportation Agency, Department of Corrections and Rehabilitation,
Department of Veterans Affairs, Business, Consumer Services, and
Housing Agency, Natural Resources Agency, California Health and Human
Services Agency, California Environmental Protection Agency, Labor
and Workforce Development Agency, and Department of Food and
Agriculture.
(2) For purposes of this section, "state entity" means an entity
within the executive branch that is under the direct authority of the
Governor, including, but not limited to, all departments, boards,
bureaus, commissions, councils, and offices that are not defined as a
"state agency" pursuant to paragraph (1).
(f) A state entity that is not defined under subdivision (e) may
voluntarily comply with any of the requirements of Sections 11546.2
and 11546.3 and may request assistance from the Department of
Technology to do so.