OAR 407-014-0320
User Responsibility

The organization or user shall not make any root level changes to any Department or State of Oregon network and information system. The Department recognizes that some application users have root level access to certain functions to allow the user to diagnose problems (such as startup or shutdown operations, disk layouts, user additions, deletions or modifications, or other operation) that require root privileges. This access does not give the user the right to make any changes normally restricted to root without explicit, written permission from the Department.


Use and disclosure of any Department information asset is strictly limited to the minimum information necessary to perform the requested and authorized service.


The organization shall have established privacy and security measures that meet or exceed the standards set forth in the Department’s privacy and information security policies, available from the Department, regarding the disclosure of an information asset.


The organization or user shall comply with all security and privacy federal and state laws, rules, and regulations applicable to the access granted.


The organization shall make the security risk plan available to the Department for review upon request.


The organization or user shall report to the Department all privacy or security incidents by the user that compromise, damage, or cause a loss of protection to Department information assets or network and information systems. The incident report shall be made no later than five business days from the date on which the user becomes aware of such incident. The user shall provide the Department a written report which must include the results of the incident assessment findings and resolution strategies.


Wrongful use of a network and information system or wrongful use or disclosure of a Department information asset by the organization or user may cause the immediate suspension or revocation of any access granted at the sole discretion of the Department without advance notice.


The organization or user shall comply with the Department’s request for corrective action concerning a privacy or security incident and with laws requiring mitigation of harm caused by the unauthorized use or disclosure of confidential information, if any.

Source: Rule 407-014-0320 — User Responsibility, https://secure.­sos.­state.­or.­us/oard/view.­action?ruleNumber=407-014-0320.

Last Updated

Jun. 8, 2021

Rule 407-014-0320’s source at or​.us