The Official Portal for the State of Georgia

Georgia Technology Authority

All Policies and Standards

# A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

A

pdf file Access Control PS-08-009.01
Access to state information assets is to be controlled and monitored to protect from authorized access and disclosure.

pdf file Accountability of Assets PS-08-002.01
Establishes accountability for all hardware and software acquired using public funds.

pdf file Acquisition and Use of Telecom Services and Equipment, PM-04-002.01
Procedures governing the acquisition and use of telecommunications services and equipment.

pdf file Active Directory, SA-03-009.01
Specifies the Active Directory (AD) requirements, topology and design.

pdf file Appropriate Use and Monitoring SS-08-001.01
Establishes an enterprise standard regarding appropriate use and monitoring of State of Georgia information technology (IT) resources.

pdf file Appropriate Use of IT Resources PS-08.003.01
Establishes an enterprise policy regarding appropriate use of State of Georgia information technology (IT) resources.

pdf file Authorization and Access Management SS-08-010.01
Agencies must limit access to state facilities and information resources and manage access once granted.

Bback to top

pdf file Bluetooth Standard, SO-06-004.02
Deployment of wireless technology.

pdf file Business Continuity and Disaster Recovery PS-08.025.01
Requires agencies to develop a plan to maintain continuity (recovery and restoration) of essential state government operations and services during or following an emergency.

Cback to top

pdf file Change Management PS-08-015.01
Establishes requirement for agencies to establish a formal change management process.

pdf file Classification of Personal Information SS-08-002.01
Establishes a statewide standard for categorizing personal information

pdf file Computer Operations Center Security SS-08.016.01
Establishes minimum security requirements for computer operations centers.

pdf file Computer Security Incident Management PS-08-004.01
Establishes a requirement that each agency establish a process for detecting and responding to security incidents.

pdf file Contingency Planning SS-08-045.01
Each agency must have a plan to sustain or recover/restore critical operations in the event of a system disruption or disaster.

Dback to top

pdf file Data Categorization - Impact Level SS-08-014.01
Establishes Impact Level definitions and standards to be assigned to information assets throughout the enterprise.

pdf file Data Security - Electronic Records SS-08-003.01
Establishes a standard that electronic records (1) are relied upon as official records and (2) must adhere to records retention requirements.

pdf file Data Sharing, PM-07-003.02
Promotes sharing of data among agencies.

pdf file Data and Asset Categorization PS-08-012.01
Establishes a policy requirement to inventory and classify all state data and information processing systems throughout the enterprise.

pdf file Design Criteria for e-Records Management Applications, SA-06-006.01
Defines the standards used when purchasing a records management application in the state of Georgia.

pdf file Disaster Recovery - System Backups SS-08-046.01
Requires agencies to establish backup and recovery procedures for critical software and data.

Eback to top

pdf file E-Mail Use and Protection SS-08-011.01
Sets standards for appropriate use and security of state e-mail systems.

pdf file E-mail Calendaring, SA-07-004.01
Establishes the state standard for the calendaring format for users of email systems.

pdf file E-mail Distribution Lists, SA-07-010.01
Standard regarding the creation and use of large inter-agency and all multi-agency e-mail distribution lists.

pdf file E-mail Naming, SA-07-005.01
Establishes the state standard for the email address for users of email systems.

pdf file Electronic Communications Accountability SS-08-009.01
Provides a standard of responsibility for the content and transfer of information through electronic communications from state information systems.

pdf file Enterprise Architecture, PM-03-003.02
Defines Enterprise Architecture technology infrastructure policy.

pdf file Enterprise Information Security Charter PS-08-005.01
Commits the State of Georgia to protecting information systems and data from unauthorized disclosure, modification, use or destruction.

Fback to top

pdf file Facilities Security SS-08-015.01
Establishes minimum requirements to incorporate security of facilities into the overall measures to protect information assets.

Gback to top

Hback to top

Iback to top

pdf file IBM Mainframe Batch Job Processing, SO-04-001-.03
Batch run times, automated scheduler and tools to modify batch job data.

pdf file IBM Mainframe Production Acceptance - Batch Jobs, SO-04-003.02
Standard to ensure batch jobs are consistently packaged to meet production acceptance requirements, thereby resulting in a quick turnover into the production environment.

pdf file IT Strategic Plan, SM-09-003.01
Establishes requirements for an agency information technology strategic planning process.

pdf file Implementing Cryptographic Controls SS-08-040.01
Establishes the minimum requirements for the use of cryptographic controls.

pdf file Incident Response and Reporting SS-08-004.01
Sets minimum requirements for information security incident response and reporting.

pdf file Independent Security Assessments SS-08-042.01
Establishes requirement for agencies to have IT systems assessed by an independent third-party.

pdf file Independent Verification and Validation, SM-06-001.02
Requires that agencies use GTA to contract for services to independently verify and validate information technology projects with budgets of $1 million or greater.

pdf file Information Security - Risk Management PS-08-031.01
Establishes a requirement for agencies to implement a risk-based approach to cost-effective information security management.

pdf file Information Security Infrastructure SS-08-005.01
Sets standards for creating an information security program and infrastructure.

pdf file Information Security Management Organization SS-08-006.01
Sets minimum standards for an information security management organization.

pdf file Information Security Reporting SS-08-053.01
Requires agencies to report the status of their information security program annually to GTA.

pdf file Information Technology Policies, Standards and Guidelines, PM-04-001.03

pdf file Information Technology Policies, Standards and Guidelines, PM-04-001.03
GTA’s statutory authority and approach for setting technology policies, standards and guidelines.

pdf file Integration Middleware, SA-7-020.02
Promotes a uniform middleware platform for enterprise integration.

Jback to top

Kback to top

Lback to top

pdf file Log Management Infrastructure SS-08-036.01
Requires agencies to monitor and analyze systems logs to record events and detect anomalies.

Mback to top

pdf file Malicious Code Incident Prevention SS-08-033.01
Establishes controls to protect systems against malicious software.

pdf file Management of IT Operations, PO-09-002.01
This policy establishes the IT Infrastructure Library (ITIL) as the basis for IT infrastructure management, service delivery and support.

pdf file Media Controls PS-08.026.01
Establishes requirement for agencies to implement media controls and procedures to protect system media from unauthorized disclosure, modification, destruction or loss.

pdf file Media Protection and Handling SS-08-043.01
Establishes protection requirements for system media.

pdf file Media Sanitization - Vendor Return SS-08-035.01
Establishes standards for sanitization and disposal of all electronic media subject to vendor return.

Nback to top

pdf file Network Access and Session Controls SS-08-048.01
Establishes requirements for agencies to control and monitor network sessions.

pdf file Network Boundary Controls SS-08-047.01
Establishes requirements for agencies to implement network boundary protection strategies.

pdf file Network Security - Information Flow PS-08-030.01
Establishes a requirement for agencies to control the flow of information traversing their networks.

pdf file Network Security Controls PS-08-027.01
Establishes requirement for agencies to implement network security controls.

Oback to top

pdf file Operational Change Control SS-08-026.01
Establishes a requirement for changes to operational systems be controlled and monitored.

pdf file Outsourced Facilities Management PS-08-019.01
Establishes requirements around the outsourcing of data processing facilities.

pdf file Outsourced IT Services SS-08-044.01
Establishes requirements for agencies to ensure adherence to established security requirements by third-party IT service providers and/or interconnections.

Pback to top

pdf file Password Authentication PS-08-006.01
Establishes use of passwords as the primary authentication mechanism.

pdf file Password Security SS-08-007.01
Establishes standards for protecting passwords.

pdf file Personal Identity Verification and Screening SS-08-017.01
Establishes standards for verifying the identities of state personnel and contractors.

pdf file Personnel Security PS-08-014.01
Establishes a requirement for identityproofing of all state employees and contractors.

pdf file Physical and Environmental Security PS-08-013.01
Establishes physical security as an essential element to the overall security posture of state information resources.

pdf file Portfolio Management, GM-09-002.01
Guidelines to implement an IT portfolio management methodology.

pdf file Project Charter Template, GM-09-003.01
A project charter is a statement of the scope, objectives and participants in a project. It delineates roles and responsibilities, outlines the project objectives, identifies the main stakeholders and defines the authority of the project manager.

pdf file Project Charter, SM-09-004.01
A project charter is required for projects that have an information technology component.

pdf file Project Financial Management, GM-09-001.01
Guidelines for technology project financial management.

pdf file Project Financial Management, SM-09-001.01
Project expenditures shall be planned and tracked with a financial management process.

pdf file Project Management Glossary, GM-08-104.01

pdf file Protection from Malicious Software PS-08-021.01
Establishes requirement to protect systems against malicious software.

pdf file Public Access Systems PS-08-028.01
Requires agencies to implement security controls on public-facing systems.

Qback to top

Rback to top

pdf file Radio Communications: Non-Public Safety, SO-04-004.02
Non-public safety radio communications systems design standard.

pdf file Radio Public Safety, SO-04-005.02
Public safety radio communications systems design standard.

pdf file Reliance on Electronic Records PS-08-007.01
Establishes the state’s intent to rely on electronic data as a form of official record and to adhere to proscribed records retention requirements.

pdf file Remote Access PS-08-023.01
Establishes a requirement to protect internal state information systems from the risks associated with remote access.

pdf file Risk Management Framework SS-08-041.01
Adopts the risk management framework developed by NIST for managing risk and implementing security.

Sback to top

pdf file Secure Remote Access SS-08-038.01
Establishes a requirement to protect internal state information systems from risks associated with remote access.

pdf file Security Awareness Program PS-08-010.01
Establishes a requirement to increase user security awareness through an awareness and training program.

pdf file Security Controls Review and Assessments PS-08-029.01
Establishes a requirement for agencies to assess security controls for IT systems.

pdf file Security Education and Awareness SS-08-012.01
Establishes a requirement for all state of Georgia employees and contractors to attend annual security awareness training.

pdf file Security Log Management PS-08-022.01
Requires agencies to implement log management practices.

pdf file Separate Production and Development Environments SS-08-031.01
Establishes requirements for separating production/operational and development/test environments.

pdf file Separation of Production and Test Environments PS-08-020.01
Establishes a policy for the separation of production from development and test environments.

pdf file Strong Password Use SS-08-008.01
Establishes standards for creating and using strong passwords.

pdf file Surplus Electronic Media Disposal SS-08-034.02
Establishes a statewide standard on disposition of surplus electronic media.

pdf file System Implementation and Acceptance SS-08-032.01
Requires agencies to establish criteria for accepting a system from development to operations.

pdf file System Lifecycle Management SS-08-025.01
Requires agencies to implement a formal lifecycle management program for systems in development or operation.

pdf file System Operations Documentation SS-08-027.01
Requires agencies to document system operational procedures.

pdf file System Security Plans SS-08-028.01
Requires data and system owners to create and maintain system security plans.

pdf file Systems and Development Lifecycle PS-08-018.01
Requires agencies to implement a formal lifecycle management program for systems in development or operation.

Tback to top

pdf file Technology Project Management, GM-08-101.01
GTA recommends a project management methodology to be used for projects with a $100,000 or greater investment in technology.

pdf file Technology Project Management, SM-03-006.03
Sets forth the requirement that agencies utilize and apply a project management methodology to those projects that have a $100,000 or greater investment in technology.

pdf file Technology Review (eAPR), SM-08-103.01
GTA reviews all IT initiatives for compliance with state and agency strategic goals and with enterprise policies and standards.

pdf file Technology Review, PM-06-001.04
This policy establishes GTA's process for review and recommendation of all information technology initiatives.

pdf file Telecom Technology Review, SM-05-001.03
Administering enterprise and agency open contracts for telecommunications systems and long distance services.

pdf file Teleworking and Remote Access SS-08-037.01
Establishes minimum security requirements for teleworking and remotely accessing state information systems.

pdf file Third-Party Access PS-08-011.01
Establishes provisions for third-party access to state facilities and information systems.

pdf file Third-Party Security Requirements SS-08-013.01
Establishes security requirements for state agencies when conducting business with and/or sponsoring engagement contractors, outsourcing vendors and/or other third-parties.

Uback to top

pdf file Use of Cryptography PS-08-024.01
Where the confidentiality, authenticity, or integrity of information is critical, the use of cryptographic controls may be warranted.

Vback to top

Wback to top

pdf file Web and E-Commerce Security SS-08-049.01
Establishes a requirement for agencies to control and manage web services.

pdf file Wireless and Mobile Computing SS-08-039.01
Establishes minimum security requirements for wireless network implementation.

pdf file Workstation Operating System, SO-03-010.02
Establishes a standard desktop and laptop/notebook OS.

Xback to top

pdf file XML, SA-03-004.01
Establishes XML standards for state agencies based upon W3C Consortium XML open standard recommendations.

Yback to top

Zback to top

pdf file georgia.gov Doman Name, SA-03-007.02
Domain naming convention and federal dot-gov final rule.

pdf file georgia.gov Intellectual Property Display, SA-03-005.03
Relating to third-party intellectual property displays on georgia.gov.

pdf file georgia.gov Linking, SA-03-008.02
Relating to the appropriate use, placement and removal of links on georgia.gov.