chapter-480•NAC Chapter 480 — Security of Information Systems
NAC Chapter 480 — Security of Information Systems
chapter-480NAC Chapter 480Regulation
NAC 480.100 Definitions.
As used in this chapter, unless the context otherwise requires, the words and terms defined in NAC 480.110 to 480.175, inclusive, have the meanings ascribed to them in those sections.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.110 “Certification” defined.
“Certification” means to attest authoritatively in a written statement.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.115 “Cybersecurity incident response plan” defined.
“Cybersecurity incident response plan” means a cybersecurity incident response plan that satisfies the requirements of NAC 480.200.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.120 “Data breach” defined.
“Data breach” means an incident where protected or sensitive information is, without limitation, copied, transmitted, viewed, stolen or used by a person not authorized to do so.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.125 “Detect” defined.
“Detect” means to discover or identify the presence or existence of a cybersecurity threat.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.130 “Distributed denial of service” defined.
“Distributed denial of service” means a malicious attempt to disrupt the normal traffic of a targeted server, service or network by overwhelming the target or the surrounding infrastructure of the target with a flood of Internet traffic.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.135 “Incident” defined.
“Incident” means an occurrence that:
-
Actually or potentially results in adverse consequences to an information system or the information such a system processes, stores or transmits and may require an incident response to mitigate the actual or potential adverse consequences.
-
Is a violation or imminent threat of violation of a security policy or procedure or acceptable use policy of a political subdivision.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.140 “Incident response” defined.
“Incident response” means the activities that address an incident within the pertinent domain to mitigate immediate and potential adverse consequences or threats.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.145 “Information system” defined.
“Information system” means any equipment or interconnected system or subsystem of equipment that processes, transmits, receives or interchanges data or information.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.150 “Office” defined.
“Office” means the Nevada Office of Cyber Defense Coordination of the Department of Public Safety.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.155 “Political subdivision” defined.
“Political subdivision” means a city or county of this State.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.160 “Protected information” defined.
“Protected information” means information about any person protected by law or regulation.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.165 “Ransomware” defined.
“Ransomware” means a type of malware that attempts to deny or denies access to the data of a user of an information system until a ransom is paid.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.170 “Sensitive information” defined.
“Sensitive information” means any information the loss, misuse, modification or unauthorized access of which could adversely affect the public, the privacy of persons as provided by law or regulation or the interests of this State.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.175 “Threat” and “cybersecurity threat” defined.
“Threat” and “cybersecurity threat” mean a circumstance or event that has or indicates the potential to exploit vulnerabilities and to adversely impact the operations or assets, including, without limitation, information and information systems, of a political subdivision, person, other governmental entity or the public.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.200 Cybersecurity incident response plan: Contents and requirements.
A cybersecurity incident response plan must include:
- Measures that preemptively build, reinforce and improve the capability to prevent, protect against, detect, respond to and recover from an incident, including, without limitation:
(a) A statement of purpose and a statement of objectives that summarize the scope of the cybersecurity incident response plan and associated policies and procedures;
(b) A list of common cybersecurity terms and associated definitions;
(c) Written metrics for measuring:
(1) The impacts of an incident on the political subdivision; and
(2) The capability and effectiveness of the political subdivision to engage in an incident response;
(d) A list of management and leadership personnel who will support an incident response;
(e) A list of internal and external contacts and associated contact information to support an incident response;
(f) A written plan for all personnel, including, without limitation, employees and contractors, regarding reporting computer anomalies and incidents to the proper personnel;
(g) A written plan for all personnel who will be involved in an incident response, including, without limitation, employees and contractors, that outlines the roles, responsibilities, job titles and contact information of such personnel;
(h) Procedures for sharing information, both internally and externally, to ensure appropriate communication and minimize information disclosure to unauthorized parties;
(i) Procedures to contact law enforcement or a regulatory body, as applicable, in a manner consistent with legal requirements; and
(j) Procedures to contact and inform any external entity that may be impacted by an incident due to a networked connection between the political subdivision and the entity affected by such an incident.
- Documented methodology, procedures and tools to detect, identify, classify and communicate current or potential cybersecurity threats to information systems, including, without limitation:
(a) Defined phases of handling an incident;
(b) A written method of documenting the attack vector used in an incident;
(c) A written method of documenting the indicators that triggered an incident or incident report;
(d) Procedures for analyzing and documenting the scope and impact of an incident;
(e) Procedures to prioritize and handle concurrent incidents in one or more physical locations; and
(f) Procedures outlining which persons will be notified of an incident and the phase during the handling of an incident that such persons will be notified.
- Procedures to prevent the damage to and spread of damage to information systems from a threat, including, without limitation:
(a) Recurring cybersecurity training programs for all personnel, including, without limitation, employees and contractors, who use the information systems of a political subdivision;
(b) Written standards for the time required for administrators of information systems and other personnel to report anomalous events to the proper personnel, the mechanisms for such reporting and the information that should be included in such a report; and
(c) Procedures for isolating information systems and gathering and storing evidence.
-
Processes and procedures to eradicate the threat from a compromised information system.
-
Processes and procedures to restore information systems impacted by an incident back to a state of production, including, without limitation, verification of data and the integrity of information systems.
-
Procedures to document information learned from an incident, including, without limitation, procedures to document:
(a) Areas of incident response successes and failures; and
(b) Recommendations on the prevention of future incidents.
- A statement of commitment by management to an incident response.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.205 Cybersecurity incident response plan: Political subdivision authorized to include certain internal groups into plan.
In addition to information technology, cybersecurity and management groups, a political subdivision may consider incorporating legal, public affairs, human resources, physical security and facilities management groups of the political subdivision into the cybersecurity incident response plan.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.210 Cybersecurity incident response plan: Effective upon certification.
A cybersecurity incident response plan becomes effective upon certification by a city manager or county manager, as applicable.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.215 Cybersecurity incident response plan: Administrative or nonsubstantive change does not require filing of revised plan.
A purely administrative or nonsubstantive change to a cybersecurity incident response plan shall not be deemed a revision for the purpose of any requirement to file a revised plan pursuant to NRS 480.935.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.230 Political subdivision required to document actions taken to mitigate or recover from incident.
A political subdivision shall document any actions taken to mitigate or recover from an incident, including, without limitation, documenting current baselines of information systems and the location of backups and network diagrams.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.235 Political subdivision required to report significant information learned from incident; use of information.
A political subdivision shall report any significant information learned from an incident to a city manager or county manager, as applicable, within 90 days after an incident. Such information may be used to update policies, procedures, guidelines and cybersecurity incident response plans.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
NAC 480.240 Political subdivision required to report certain types of cybersecurity incidents; contents of report.
- A political subdivision shall report to the Office within 1 business day after a known or suspected incident that is:
(a) A data breach;
(b) A distributed denial of service incident;
(c) A ransomware incident; or
(d) Any other incident that disrupts the delivery of essential services for more than 1 business day or directly affects life or property.
- The report submitted pursuant to subsection 1 must contain information on:
(a) The date and time of the incident;
(b) The type of incident;
(c) The type of information system or data affected by the incident;
(d) The known and projected impact of the incident to the political subdivision;
(e) Whether law enforcement, a regulatory body or an external entity that could be affected by an incident have been notified of the incident, if applicable; and
(f) Any additional resources that are needed by the political subdivision to respond to the incident, if applicable.
History
- Authority: NRS 480.935, 480.950
- (Added to NAC by Office of Cyber Defense Coord. by R088-19, eff. 12-29-2020)
Poursuivez vos recherches dans ChatGPT ou Claude
Connectez Omnilex pour rechercher dans le corpus juridique depuis votre assistant IA.