Governance & Planning
GTA has consolidated and streamlined data submission for three different IT reports with a Web-based reporting system.
The new approach makes it quicker and easier for agencies to comply with data submission requirements for the:
- Agency Information Security Report
- IT Expenditures Report
- IT Governance Report
The reports share much of the same data, so agencies now need to enter information only once.
For most agencies, all required information is gathered using the Agency Information Security Report process. Information reported in the security report is detailed in Information Security Reporting Standard SS-08-053.2.
The deadline for submitting all required data was August 28, 2009. Information can be submitted only through the Web-based reporting system due to the large amount of information collected and processed.
Agencies participating in GAIT 2010
The 12 agencies participating in Georgia Infrastructure Transformation (GAIT) 2010 submitted most of the information required in the three reports as part of the IT transition and transformation initiative. GTA completed as much of the reports as possible on behalf of these agencies, then notified them to review the reports and submit additional or updated data as needed.
Questions? E-mail GTA’s Enterprise Information Security Office at gta-eis@gta.ga.gov.
GTA has merged Enterprise Technology Planning and the Office of Information Security into a single organization: Enterprise Governance and Planning (EGAP). Mr. Mark Reardon has been named EGAP Director. He also retains his position as Chief Information Security Officer (CISO).
The organizational change enables us to improve coordination among related enterprise activities. EGAP’s goal is to provide value by:
- supporting agencies in doing a better job of governing their IT initiatives, and
- gathering IT metrics from agencies and reporting them to state leaders.
EGAP has four work units.
-
Enterprise Information Security (EIS), led by Walter Tong
EIS continues to focus on security awareness and training for state agencies as they implement requirements based on the Federal Information Security Management Act (FISMA). It develops related policy statements and standards, works with vendors and agencies to conduct risk-management assessments, and coordinates enterprise security with law enforcement agencies, the state Attorney General’s office and the Department of Homeland Security.
-
Enterprise Policy, Standards and Architecture (EPSA), led by Sree Shama
EPSA works with EGAP work units and other stakeholders to develop IT policy statements and standards. It ensures they are consistent, their impacts have been fully considered, and they have simple compliance mechanisms and metrics.
-
Enterprise Strategic Planning (ESP), led by Mike Curtis
ESP works closely with the Office of Planning and Budget to ensure IT portions of agency strategic plans are properly created. It develops policy statements and standards to ensure an agency’s IT strategy aligns with its overall business strategy and business continuity planning.
-
Enterprise Program and Project Management Office (EPMO), led by Tom Fruman
EPMO continues to develop policies and standards to ensure IT projects of all sizes and costs are properly managed within agencies.
Enterprise Information Security
