You have
Employee Resources
Employee Resources
- News
- Events
- Winter Storm Event 2023
-
- Deferred Compensation
- Employee Assistance Program
- eForms
- Email Services
- Benefits
- Employee Self Service
- Lactation Accommodation Request Form
- Dimensions System
- VHR Program
- Employee Safety and Health
- Staying Connected
- Kaiser Occ Health
- Flexible Spending Account
- Disaster Worker
- Trainings
- Drug-Free Workplace
-
- Preface
- 1-1 Advisory Bodies Roles and Relationships
- 1-2 Providing County Support of Grant Applications from Outside Agencies
- 2-1 Policy for Submitting Agenda Items
- 2-2 Departmental Representation at BOS Meetings
- 2-3 Policy for Board Chambers Security
- 3-1 Policy for Appropriation Transfers
- 3-2 Travel and Meal Reimbursements
- 3-3 Interdepartmental Billings for Services Policy
- 3-4 Policy for Memberships to Professional Associations & Organizations – Use of Public Funds
- 4-1 Performance Evaluations
- 4-2 Policy for Position Allocation List
- 4-3 Position Reclassifications
- 4-4 EEO Policy
- 4-5 Departmental/Internal Reorganizations
- 4-6 Policy for Hiring/Retaining Personnel Services in EMP or Ind. Contractor Status - See Civil Service Rules
- 4-7 Policy for Flexible Merit Increases
- 4-8 Advanced Salary Step Appointments
- 4-9 Policy for Relocation Incentives
- 4-10 Medical Leave Policy
- 4-11 Preemployment Preplacement Screening Policy
- 4-12 COVID-19 Vaccination and Testing Policy
- 4-13 Telework Policy
- 4-14 Lactation Policy
- 5-1 Vehicle Use
- 5-2 Policy for Capital Project and Asset Responsibility
- 5-3 Public Art Policy
- 6-1 Records Retention Storage Destruction Policy
- 6-2 Incompatible Activities Policy
- 6-3 TTrD Policy
- 6-4 Safety Management Policy
- 6-5 Identity Theft Prevention Program
- 7-1 Purchasing Policy
- 7-2 Real Property Acquisition and Management Policy
- 8-1 Investigations of Alleged Inappropriate Activities
- 8-2 Reasonable Suspicion Policy
- 8-3 Safety and Security for County Employees
- 8-4 Policy for Receipt and Distribution of Tickets or Passes
- 9-1 Official Use of Social Media Sites Policy
- 9-2 IT Use and Security Policy
- 9-3 Website Accessibility Policy
- 9-4 Information Technology Professionals Policy
- 9-5 Information Technology Governance Policy
- 9-6 Information Technology Artificial Intelligence (AI) Policy
- Employee & Volunteer Engagement & Recognition (EVER)
- Combined Fund Drive
- Website Accessibility Assistance
- Back to Administrative Policy Manual
9-4 Information Technology Professionals Policy - Section XIII: Third Party Security Policy
Return to Information Technology Professionals Policy Table of Contents
What’s on this Page
Section XIII: Third Party Security Policy
Read next: Section XIV: User Access Management Policy
XIII. Third Party Security Policy
This Policy establishes information security requirements for Third Party agreements and access to Local Agency IT resources and data.
- Third Party Access
- The Data Owner/Steward or designee must authorize physical or logical access by third parties in advance. This access must adhere to the Principle of Least Privilege, which allows only the access needed to perform their duties.
- Third party devices must be configured to all applicable Local Agency and County policies and standards before being allowed to connect to a Local Agency network.
- Third party personnel requiring access to Local Agency IT resources and data must adhere to all applicable Local Agency and County policies
- Third Party Service Delivery Agreements
To implement and maintain the appropriate level of information security and service delivery, agreements with third parties must be established and include the following:- Necessary controls to ensure Local Agency IT resource and/or data protection;
- A clear and specific process of change management;
- Agreements for reporting, notification and investigation;
- Levels of acceptable/unacceptable service and service continuity;
- Definitions of verifiable performance criteria;
- Rights to monitor and audit activities;
- Problem resolution processes, including escalation steps;
- Intellectual property rights and ownership of data;
- Policies regarding subcontractors;
- Conditions for renegotiation/termination and
- Establishment of Third Party agreements must also adhere to guidelines set forth in County of Sonoma Purchasing policies (7-1 & 7-2) and procedures.
- Third Party Exchange of Information Agreements
To maintain the security of information exchanged with any Third Party, agreements must be established and include the following:- Evaluate the sensitivity of the Local Agency data to be released or shared;
- Identified responsibilities of each party for protecting the Local Agency data;
- Identified responsibility and liability of each party in the event of an information security incident;
- Minimum security controls required to transmit and use the Local Agency data;
- Security measures that each party has in place to protect the Local Agency data;
- Methods for compliance measurements;
- A schedule and procedure for reviewing the security controls.
- Insurance Requirements
Third Party agreements must incorporate insurance requirements as determined by County of Sonoma Risk Management standards. - Background Checks and Non-Disclosure Agreements
- All third party personnel must sign a Non-Disclosure Agreement.
- As required, Local Agency verification of a background check for all third party personnel accessing Confidential or Restricted data.