1 Tex. Admin. Code § 202.75 - Managing Security Risks
A risk assessment of the institution's information, information systems, and applications shall be performed and documented.
(1) Risks and impact impacts will be ranked, at a minimum, as either "High," "Moderate," or "Low."
(2) The schedule of the future risk assessments will be documented.
(3) Risk assessment results, vulnerability reports, and similar information shall be documented and presented to the Information Security Officer or their designated representative(s).
(4) Approval of the security risk acceptance, transference, or mitigation decisions shall be the responsibility of:
(A) the Information Security Officer or their designee(s), in coordination with the information owner, for systems identified with Low or Moderate residual risk.
(B) The institution of higher education head for all systems identified with a High residual risk.
Notes
State regulations are updated quarterly; we currently have two versions available. Below is a comparison between our most recent version and the prior quarterly release. More comparison features will be added as we have more versions to compare.
No prior version found.