Utah Administrative Code Topic - Technology Services
Overview
The Technology Services topic within the Utah Administrative Code (UAC) covers the rules and standards for the management, operation, and security of technology services used by state agencies. This includes information technology (IT) systems, networks, data management, cybersecurity, and digital service delivery.
The goal is to ensure efficient, secure, and standardized technology services across all state government operations, while protecting sensitive information and maintaining public trust.
Key Areas Covered in Technology Services
1. Governance and Authority
Defines the role of the Utah Department of Technology Services (DTS) in providing centralized IT services to state agencies.
Establishes responsibilities for agency CIOs (Chief Information Officers) and IT leadership.
Rules for approval, oversight, and reporting of technology projects.
2. IT Procurement and Project Management
Guidelines for acquiring software, hardware, and IT services.
Rules for contracting with vendors, including competitive bidding and compliance with state procurement laws.
Standards for project planning, budgeting, and lifecycle management.
3. Data Management and Privacy
Rules for collecting, storing, and managing state data, including personally identifiable information (PII) and sensitive information.
Guidelines for data retention, access controls, and secure disposal.
Requirements for compliance with state and federal privacy laws.
4. Cybersecurity and Risk Management
Establishes policies for network security, encryption, access management, and incident response.
Rules for vulnerability assessment, penetration testing, and risk reporting.
Procedures for security breach notification and mitigation.
5. System Standards and Interoperability
Technical standards for software development, system integration, and interoperability between agencies.
Rules promoting open standards, accessibility, and digital inclusion.
Guidelines for using cloud services and shared infrastructure.
6. Service Delivery and Support
Requirements for helpdesk support, system maintenance, and user training.
Standards for service level agreements (SLAs) and performance monitoring.
Rules for reporting system outages and performance issues.
7. Compliance and Enforcement
Procedures for auditing technology systems and reviewing agency compliance.
Penalties or corrective actions for violations of IT standards or security policies.
Reporting requirements to ensure accountability and transparency.
Purpose of UAC – Technology Services
Ensure efficient and reliable IT services across all state agencies.
Protect sensitive state and citizen data.
Establish uniform technology standards and security protocols.
Promote cost-effective and accountable technology management.
Practical Impact
State Agencies: Must follow IT governance rules, security standards, and project management requirements.
IT Vendors: Must comply with state procurement, security, and service standards.
Citizens: Gain confidence that their personal information is protected and state services are reliable.
State Oversight: DTS and auditors monitor compliance, manage risks, and enforce standards.
✅ In short: The UAC Technology Services topic sets the rules for managing Utah’s government IT infrastructure, covering procurement, data security, project management, system standards, and compliance to ensure reliable, secure, and standardized technology services.
0 comments