What happens when an agency does not submit a Risk Management and Privacy Program Compliance Certification (SIMM 70C)?
The California Office of Information Security has enhanced its Risk Management and Privacy Program Compliance Certification compliance review process. The Director and Agency Director for the agency will be notified when an agency has failed to meet this reporting requirement. The OIS is to report to the Office of the State Chief Information Officer any state agency found to be noncompliant with information security program requirements. Non-compliance may impact the agency’s procurement and information technology (IT) project delegated authority.
Related Questions
- When must the Risk Management and Privacy Program Compliance Certification (SIMM 70C) be submitted to the California Office of Information Security?
- Why is the director of an agency required to sign the Risk Management and Privacy Program Compliance Certification (SIMM 70C)?
- What happens when an agency does not submit a Risk Management and Privacy Program Compliance Certification (SIMM 70C)?