Colorado § 24-37.5-403 - Chief information security officer - duties and responsibilities.
Full text of Colorado Colorado Revised Statutes § 24-37.5-403 — Chief information security officer - duties and responsibilities., with citation guidance and answers to common questions.
§ 24-37.5-403. Chief information security officer - duties and responsibilities.
(1) The chief information officer shall appoint a chief information security officer who shall serve at the pleasure of the chief information officer. The security officer shall report to and be under the supervision of the chief information officer. The security officer shall exhibit a background and expertise in security and risk management for information technology resources. In the event the security officer is unavailable to perform the duties and responsibilities under this part 4, all powers and authority granted to the security officer must be exercised by the chief information officer.
(2) The chief information security officer shall:
(a) Develop and update information security policies, standards, and guidelines for public agencies;
(b) Promulgate rules pursuant to article 4 of this title containing information security policies, standards, and guidelines;
(c) Ensure the incorporation of and compliance with information security policies, standards, and guidelines in the information security plans developed by public agencies pursuant to section 24-37.5-404;
(d) Direct information security audits and assessments in public agencies in order to ensure program compliance and adjustments;
(e) Establish and direct a risk management process to identify information security risks in public agencies and deploy risk mitigation strategies, processes, and procedures;
(f) Approve or disapprove and review annually the information security plans of public agencies;
(g) Conduct information security awareness and training programs;
(h) In coordination and consultation with the office of state planning and budgeting and the chief information officer, review public agency budget requests related to information security systems and approve such budget requests for state agencies other than the legislative department;
(i) Coordinate with the Colorado commission on higher education to review and comment on information security plans adopted by institutions of higher education that are submitted pursuant to section 24-37.5-404.5 (3);
(j) Submit to the joint technology committee, on or before November 1, 2027, and on or before November 1 of each year thereafter, a written information technology security compliance report that includes the following information:
(I) The office's current compliance status with applicable security standards;
(II) All open audit recommendations made by the office of the state auditor and the date on which each recommendation was made;
(III) A timeline for remediation for each open recommendation made by the office of the state auditor; and
(IV) A mitigation plan or compensating controls for the remediation of each open recommendation made by the office of the state auditor; and
(k) (I) Submit to the joint technology committee, on or before November 1, 2027, and on or before November 1 of each year thereafter, a written statewide information technology security risk report that assesses the overall security risk posture of state agency information technology systems.
(II) To support the preparation of the security risk report required by subsection (2)(k)(I) of this section, the chief information security officer may conduct evaluations of state agency information technology systems as the chief information security officer deems necessary, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews.
(III) Each state agency shall provide to the chief information security officer, upon request, the access and information necessary to conduct evaluations pursuant to subsection (2)(k)(II) of this section, including system access, product information, and architecture information.
(3) It is the intent of the general assembly that the cost of the services provided by the chief information security officer to a public agency be adequately funded in fiscal years commencing on and after July 1, 2007, through an appropriation to the public agency to pay for such services.
(4) The chief information security officer, or the chief information officer if the security officer is unavailable, shall perform the duties and uphold the responsibilities assigned to the chief information security officer pursuant to this part 4. The chief information officer shall not delegate the duties, responsibilities, or powers of the chief information security officer to any person other than the chief information security officer. Nothing in this section prevents the chief information security officer from directing personnel within the information security office to carry out security functions under the chief information security officer's supervision and accountability. The chief information security officer is responsible for the accuracy of the compliance report required in subsection (2)(j) of this section and the security risk report required in subsection (2)(k) of this section, regardless of which personnel contributed to the preparation of the reports.
Source: L. 2006: Entire part added, p. 1715, § 1, effective June 6. L. 2008: (1) and (2)(h) amended, p. 1121, § 8, effective May 22. L. 2011: (1), (2)(b), and (3) amended, (SB 11-062), ch. 128, p. 429, § 6, effective April 22. L. 2026: (1), (2)(h), and (2)(i) amended and (2)(j), (2)(k), and (4) added, (SB 26-185), ch. 314, p. 1842, § 4, effective August 12.
Source: official Colorado text · Last verified 2026-08-27
Frequently Asked Questions About Colorado § 24-37.5-403
What does Colorado Revised Statutes § 24-37.5-403 cover?
Section 24-37.5-403 ("Chief information security officer - duties and responsibilities.") is part of the Colorado Revised Statutes, the codified statutory law of Colorado. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.
How do I cite Colorado § 24-37.5-403?
A common citation format is "Colorado Revised Statutes § 24-37.5-403" (Colorado). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.
Is this the official text of Colorado law?
No. This page is for research and education and may not include the most recent amendments. For official current law, check the Colorado official source linked on this page or consult a licensed Colorado attorney.
How does Colorado § 24-37.5-403 apply to my situation?
Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Colorado can advise on how this section applies to you. Contact your state or local bar association for a referral.
Sources & Verification
Not legal advice. Verify against the official source and consult a licensed attorney in Colorado.