OAR 943-014-0320
User Responsibility
(1)
Use and disclosure of any Authority information asset is strictly limited to the minimum information necessary to perform the requested and authorized service.(2)
The organization shall have established privacy and security measures that meet or exceed the standards set forth in the Authority privacy and information security policies, available from the Authority, regarding the disclosure of an information asset.(3)
The organization or user shall comply with all security and privacy federal and state laws, rules, and regulations applicable to the access granted.(4)
The organization shall make the security risk plan available to the Authority for review upon request.(5)
The organization or user shall report to the Authority all privacy or security incidents by the user that compromise, damage, or cause a loss of protection to the Authority information assets or the network and information systems. The incident report shall be made no later than five business days from the date on which the user becomes aware of such incident. The user shall provide the Authority a written report which must include the results of the incident assessment findings and resolution strategies.(6)
Wrongful use of a network and information system, or wrongful use or disclosure of an Authority information asset by the organization or user may cause the immediate suspension or revocation of any access granted, at the sole discretion of the Authority without advance notice.(7)
The organization or user shall comply with the Authority’s request for corrective action concerning a privacy or security incident and with laws requiring mitigation of harm caused by the unauthorized use or disclosure of confidential information, if any.
Source:
Rule 943-014-0320 — User Responsibility, https://secure.sos.state.or.us/oard/view.action?ruleNumber=943-014-0320
.