(1) All state agencies subject to Section 25-53-201 shall:(a) Comply with all cybersecurity policies, standards and controls established under Section 25-53-201;(b) Report suspected cybersecurity incidents to both the Enterprise Security Program and the SSOC within timeframes set by ITS;(c) Cooperate with SSOC monitoring, incident response and vulnerability remediation efforts; and(d) Implement corrective actions or risk mitigation measures required by the Chief Information Security Officer (CISO) under Section 25-53-201, informed by SSOC operational findings.
(a) Comply with all cybersecurity policies, standards and controls established under Section 25-53-201;
(b) Report suspected cybersecurity incidents to both the Enterprise Security Program and the SSOC within timeframes set by ITS;
(c) Cooperate with SSOC monitoring, incident response and vulnerability remediation efforts; and
(d) Implement corrective actions or risk mitigation measures required by the Chief Information Security Officer (CISO) under Section 25-53-201, informed by SSOC operational findings.
(2) The reporting requirement under this section is in addition to Section 25-53-201(4).