chapter-128•OAR Chapter 128 — Department of Administrative Services, Office of the State Chief Information Officer
OAR Chapter 128 — Department of Administrative Services, Office of the State Chief Information Officer
chapter-128OAR Chapter 128Regulation
Division 10 Providing Broadband Services and Operations to Non-State Entities
Or. Admin. R. 128-010-0005 Purpose
(1) The Office of the State Chief Information Officer (Office) operates and maintains the State Private Communications Network comprised of State owned facilities; facilities and services that the Office has acquired or leased, or may acquire or lease from or share with other government entities; or facilities and services that the Office has acquired or leased, or may acquire or lease, from communications providers. The Office wishes to continue to operate and maintain the State’s Private Communications Network, as well as to further develop and expand, the State’s Private Communications Network, for the benefit of the State Agencies, local, federal and tribal government entities, and communities of interest. The primary purpose of these rules is to establish the process by which the Office will determine if Broadband services and operations proposed to be provided to Non-State Entities are already offered by Telecommunications Providers and, if not, to establish the process by which the Office may provide Broadband services and operations to Non-State Entities.
(2) Nothing in these Division 10 rules is intended or shall be construed to prohibit a Non-State Entity from providing Broadband services and operations to itself and others in compliance with applicable law, or from acquiring Broadband services and operations in compliance with applicable law from a Telecommunications Provider at any time, on terms and conditions agreed to by the Non-State Entity and the Telecommunications Provider.
History
- Statutory/Other Authority: ORS 183.325-410, ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0010 Definitions
For the purposes of these rules, the following definitions apply:
(1) “Broadband” means wide bandwidth communications transmissions over coaxial cable, optical fiber, radio, twisted pair or other transmission medium with an ability to simultaneously transport multiple signals and traffic types at no less than the minimum transmission speed established for Tier 1 services as set forth in Section 20 of these rules.
(2) “Communications” means media that communicate voice, data, text or video over a distance using electrical, electronic or light wave transmissions.
(3) “Community of Interest” means an entity so designated by the Office pursuant to these rules.
(4) “Nonprofit Organization” means an organization that demonstrates to the Office that it meets all requirements to achieve tax exempt status under Section 501(c)(3) of the Internal Revenue Code of 1986.
(5) “Non-State Entity” means:
(a) any public body, as defined in ORS 174.109, other than a State Agency; or
(b) any federally recognized Indian tribe in Oregon; or
(c) any nonprofit organization designated as a Community of Interest under these rules.
(6) “Public body” means a public body, as defined in ORS 174.109, in this state.
(7) “Office” means the Office of the State Chief Information Officer established pursuant to ORS 276A.203(1).
(8) “Service Request” means a request for Broadband services submitted to the Office by a Non-State Entity for purposes of the Office evaluating whether it may, and is willing and able to pursue Broadband services and operations to the Non-State Agency.
(9) “Site” means a specific location within an area at which a Non-State Entity desires to receive Broadband services and operations.
(10) “State Agency” has the meaning given that term in ORS 279A.010.
(11) “State’s Private Communications Network” means the communications network operated and maintained by the Office for the benefit of State Agencies, comprised of equipment, software, hardware, facilities and services owned by the State, or as provided to or acquired by the Office through agreements with communications providers or other government entities.
(12) “Telecommunications Provider” means any person that is capable of providing Broadband and communications services including, but not limited to, a telecommunications utility as defined in ORS 759.005, a competitive Telecommunications Provider as defined in ORS 759.005, a cooperative Telecommunications Provider, a cable television provider or an interstate Telecommunications Provider.
(13) “Unserved” means, with respect to a particular area, that there is no Telecommunications Provider offering the Broadband services that meet the minimum specifications for Tier 1 services as set forth in Section 20 of these Division 10 rules.
History
- Statutory/Other Authority: ORS 183, ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0015 Duties of the Office
(1) The Office shall:
(a) Operate and maintain the State’s Private Communications Network and take such actions as the Office desires to further develop and expand the State’s Private Communications Network;
(b) Provide Broadband services and operations over the State’s Private Communications Network to State Agencies;
(c) Create and maintain a web-based mechanism that allows any interested party to register to receive notices issued by the Office under these Division 10 rules. In addition, an interested party may notify the Office in writing of its interest in receiving notice of Service Requests and Opportunity Notices provided under these Division 10 rules;
(d) Maintain a list of interested parties or those parties who have advised the Office in writing that they wish to receive information about any Service Request or Opportunity Notice;
(e) Provide notice of and make available to the interested parties the following:
(A) the Office’s preliminary list of eligible Non-State Entities and areas, and any modifications to the preliminary list;
(B) any Service Request(s) submitted to the Office; and
(C) any Opportunity Notices.
(f) Develop and maintain a network map diagramming the State’s Private Communications Network;
(g) Develop and maintain a Services Catalog, listing the Broadband services and operations that the Office may provide, as well as the minimum specifications for such services; and
(h) Enter into agreements with Telecommunications Providers in compliance with applicable law.
(2) The Office may:
(a) Install new equipment, build or construct the State’s Private Communications Network on its own, or, in the alternative, enter into agreements or otherwise acquire equipment, software, hardware, facilities or services for the State’s Private Communications Network from Telecommunications Providers, governmental entities, or other providers;
(b) Subject to the process described in these rules, provide the Broadband services and operations over the State’s Private Communications Network to Non-State Entities.
History
- Statutory/Other Authority: ORS 183, ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0020 Minimum Specifications
(1) Specifications Generally. The specifications set forth below are the minimum specifications of Broadband services and operations that the Office may offer to Non-State Entities.
(2) From time to time, as necessary, the Office shall review the minimum specifications set forth in these rules and determine whether any revision is required. If the Office determines that a change is necessary, the Office shall engage in the appropriate procedures under the Oregon Administrative Procedures Act (ORS Chapter 183) to amend these rules.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0025 Eligibility
(1) Eligibility. The Office may only provide Broadband services and operations to Non-State Entities under Oregon Laws 2018, chapter 51, section 5, in accordance with these rules, and only to eligible Non-State Entities at eligible Sites.
(2) A particular Site is an eligible Site if it is in an area that is Unserved.
(3) The Office may develop and maintain a preliminary list of eligible Non-State Entities and areas. If the Office develops a preliminary list of eligible Non-State Entities and areas, the Office may make an initial determination of whether areas are Unserved for the purposes of its preliminary list based on, without limitation, the following sources of information:
(a) Federal Communications Commission, Form 477 carrier filings;
(b) Oregon Public Utility Commission communications provider filings, including tariffs and price lists;
(c) Broadband connectivity lists maintained by the Oregon State Library;
(d) Current state contracts;
(e) State and carrier network maps;
(f) Requests for service;
(g) Telecommunications Provider information; or
(h) Historical information.
(4) The Office will maintain such list as a means for making a preliminary assessment of the need for Broadband services and operations by Non-State Entities in particular areas for administrative convenience. Non-State Entities are not required to be on the list of eligible Non-State Entities, and Sites are not required to be in an area on the list of eligible areas in order for a Non-State Entity to make a Service Request pursuant to Section 30 of these Division 10 rules. The Office may consider an entity or area for inclusion on the preliminary list of eligible Non-State Entities or areas either on the Office’s own initiative, or in response to a request from a Non-State Entity for the entity or a particular area to be included on the preliminary list of eligible Non-State Entities and areas, provided, however, that a Non-State Entity may not obtain Broadband services from the Office under Or Laws 2018, ch 51 without submitting a Service Request and engaging in the process set forth in these Division 10 rules.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0030 Service Request by a Non-State Entity
(1) A Non-State Entity or group of Non-State Entities may, at any time, submit a Service Request to the Office.
(2) The Service Request must include the following information:
(a) Identification of the Non-State Entity or group of Non-State Entities;
(A) The entity must submit to the Office information necessary to allow the Office to make an initial determination that the requesting entity is an eligible Entity.
(B) If the entity wishes to be designated as a Community of Interest, the entity must complete the application and approval process set forth in these Division 10 rules, and obtain a Designation as a Community of Interest.
(b) Identification of the Site;
(c) A description of the Broadband services and operations requested, including specification of the Tier of services required, based on the minimum specifications for Tiers set forth in Section 20 of these Division 10 rules;
(d) A list of the applications, use cases, anticipated network load or other information to assist the Office in evaluating and validating the specifications of the Broadband services and operations requested;
(e) When the Broadband services are needed;
(f) Identification of the entity’s current Telecommunications Provider, if any;
(g) Identification of any other communication providers that may offer the requested Broadband services and operations to the area in which the Site is located;
(h) Whether the entity contacted the local exchange carrier or any other Telecommunications Provider and requested the services, and if so, when. The entity shall include a copy of the response in its Service Request;
(i) Additional information that the entity believes is relevant to its request, including, for example, the entity’s purpose, size, annual budget, existing facilities, existing infrastructure and communication assets, nature and need of its served population, and the consequence of not receiving the services. A requestor is not bound by the minimum specifications set forth in Section 20 of these Division 10 rules.
(3) Upon receipt of a Service Request, the Office will post the Service Request and notify Telecommunications Providers and other interested parties as provided in Section 15(1)(e) of these Division 10 rules. The notice will identify the Non-State Entity submitting the Service Request, and the Site at which the Non-State Entity is requesting Broadband services and operations. Telecommunications Providers and other interested parties that receive the notice of a Service Request are not prohibited from contacting the Non-State Entity that submitted the Service Request, or from contacting the Office regarding the Service Request.
(4) Telecommunications Providers or other interested parties shall have ten (10) calendar days from the date of the notice to submit an initial response relevant to the question of whether the Site described in the Service Request is an eligible Site because it is in an Unserved area. The Office will notify the requestor, the Telecommunications Provider and other interested persons of any such responses and will conduct an initial review. In conducting such review, the Office may solicit additional information from, or consider information provided by, the requestor, any Telecommunications Provider or other interested person, and any other source that the Office determines is relevant to the determination of whether the Site for which the requestor desires Broadband services is in an Unserved area in accordance with these rules.
(5) If the Office determines that the requesting entity is not an eligible Non-State Entity or that the site is not an eligible Site, then the Office shall notify the requesting entity that the Office cannot provide the requested Broadband services.
(6) If the Office elects to proceed, the Office will conduct a network feasibility analysis for purposes of determining if the Office wishes to and is able to provide the requested Broadband services and operations. The analysis will include, without limitation, review of the following:
(a) The current architecture of the State’s Private Communications Network;
(b) Any plans the Office has to further develop or expand the State’s Private Communications Network;
(c) The nature of the entity requesting the Services;
(d) The area of the requested services;
(e) The costs of providing the requested services;
(f) The schedule by which the Office would be able to fulfill the Service Request; and
(g) Whether there are other providers capable of providing the requested services in the area;
(7) Based upon its analysis, the Office will determine whether it wishes to or is able to provide the Broadband services and operations.
(8) If the Office determines that it does not wish to or is unable to provide the requested Broadband services and operations, the Office will notify the requestor that the Office will not seek to fulfill the Service Request.
(9) If the Office does wish to seek to provide the Broadband services and operations that are the subject of a Service Request submitted to the Office by a Non-State Entity, the Office will provide a proposed plan that:
(a) Defines the area in which the requested Services will be provided. (In defining the area of a requested Service to be provided to a Non-State Entity, the Office will define the area relative to the Broadband services and operations proposed to be provided); and
(b) Establishes the Tier of the Broadband services and operations the Office is able to provide (based on the Tiered minimum specifications as set forth in these rules) and the Non-State Entities that the Office proposes to receive the Broadband services and operations; and
(c) Confirms the Office’s initial determination that the Site is in an Unserved area with respect to the particular Broadband services and operations the Office proposes to provide.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0035 Opportunity Notice to Telecommunications Providers and Other Interested Parties
(1) The Office will provide an Opportunity Notice to Telecommunications Providers and other interested parties that the Office seeks information to determine if any proposed Broadband services and operations are already offered by a Telecommunications Provider(s) in the area meeting or exceeding the proposed plan developed by the Office.
(2) The Office will provide notice of an Opportunity Notice as provided in Section 15(1)(e) of these Division 10 rules and to any parties that the requestor associated with an Opportunity Notice asks to be notified of the Opportunity Notice.
(3) The Opportunity Notice may include a request for information or a request for quotes from Telecommunications Providers that are intended to allow Telecommunications Providers to demonstrate their ability to provide the Broadband services and operations proposed by the Office to the Site proposed to be served within a reasonable time and for a reasonable cost.
(4) The Office may amend an Opportunity Notice at any time either on its own initiative, or in response to a request to amend the Opportunity Notice by the requestor.
(5) Any Telecommunications Provider or interested parties may submit a notice that it intends to submit an offer to provide the requested services within thirty (30) calendar days of the date of the Opportunity Notice or any later date set forth in the Opportunity Notice. The Telecommunications Provider or other interested party must submit an offer to provide the requested services within such time as set forth in the Opportunity Notice.
(6) The Office may cancel an Opportunity Notice at any time, and for any reason. However, the Office may not provide Broadband services to any Site of a Non-State Entity that has been the subject of a cancelled Opportunity Notice unless it follows the procedures set forth in these Division 10 rules.
(7) Nothing in these Division 10 rules shall be construed to prohibit a telecommunication provider or any other person from communicating with requestor regarding an Opportunity Notice.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0040 Review of the Telecommunications provider Offer
(1) The Office will review all the offers submitted by the Telecommunications Providers to determine if the proposed Broadband services and operations are “already offered” by a Telecommunications Provider.
(2) The proposed Broadband services and operations are “already offered” within a reasonable time and at a reasonable cost and within an area to a particular Site if a Telecommunications Provider offers to provide the Broadband services and operations to the Non-State Entity:
(a) With reasonably equivalent specifications to those proposed to be provided by the Office; and
(b) At local or regional market rate or at a cost reasonably equal to the Office’s estimated costs as set forth in the Opportunity Notice to provide the Broadband services and operations. For purposes of making this determination, the Office may consider total cost of ownership over a specified number of years, as set forth in the Opportunity Notice; and
(c) Within 30 calendar days of the date that the Office proposes to provide the Broadband services and operations.
(3) In making a determination of whether the proposed Broadband services are “already offered” in accordance with Section 2 above, the Office may consult with and seek the advice of the Non-State Entity that is requesting the Broadband services and operations.
(4) If the Office determines that a proposed Broadband services and operations are already offered to the Site within the proposed area, then the Office will notify the Non-State Entity and the Telecommunications Providers that responded to the Opportunity Notice, and the Non-State Entity may acquire the Broadband services, in compliance with applicable law, from one or more of the Telecommunications Providers that demonstrate in their response to the Opportunity Notice that they are able to provide the requested services to the Site.
(a) If more than one Telecommunications Provider demonstrates that it already offers the requested Broadband services and operations, then the requestor may select, in accordance with applicable law, which among those Telecommunications Providers it will contract with to provide the Broadband services and operations. The requestor shall advise the Office upon award of any contract.
(b) If the requestor and a Telecommunications Provider fail to reach an agreement that requires the Telecommunication Provider to provide the proposed Broadband services and operations for the same or better specifications, costs or schedule of delivery, or if the Telecommunications Provider fails to perform under any contract with the requestor, then the requestor may initiate a new Service Request as set forth in Section 30 of these Division 10 rules.
(5) If, following submission of a response to an Opportunity Notice, the Office determines that the requested Broadband services are not already offered by a Telecommunications Provider, the Office may provide the requested Broadband services and operations to the Non-State Entity.
(6) The Office may not provide the Broadband services and operations to a Non-State Entity at a particular Site if a Telecommunications Provider demonstrates in its response to an Opportunity Notice that the Broadband services and operations specified in the Opportunity Notice are already offered to the Site, as set forth in Section 2 above.
(7) Nothing in these Division 10 rules shall be construed to limit a Non-State Entity’s rights under applicable law to refuse to contract with a Telecommunications Provider.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0045 Community of Interest
(1) Community of Interest. An entity may apply to the Office to be classified as a Community of Interest for purpose of these rules by submitting an application to the Office that includes the following items and required information:
(a) Applicant’s name, home and office addresses and telephone numbers.
(b) Applicant’s mailing address, if different from its listed home and office addresses.
(c) Evidence of applicant’s nonprofit and tax exempt status under section 501(c)(3) of the Internal Revenue Code of 1986 (a copy of the Internal Revenue Service determination letter, or advance ruling, indicating that applicant is a section 501(c)(3) tax exempt organization shall meet this requirement).
(d) Evidence that applicant has complied with the relevant provisions of ORS 65.001 to 65.990, and is registered with the Oregon Secretary of State to do business in Oregon as a nonprofit corporation.
(e) Statement and supporting evidence that applicant’s mission is primarily to conduct activities for the direct benefit or good to the public or community-at-large in Oregon in one or more of the following public service areas:
(A) Educational
(B) Economic Development
(C) Health Care
(D) Human Services
(E) Public Safety
(F) Library
(f) Identification of the community-at-large served, if not readily apparent from the applicant’s mission and activity statement and description.
(g) Evidence of applicant’s current affiliation with a federal, state or local governmental unit within the State of Oregon, if any.
(h) Signature of applicant or its authorized representative.
(2) The Office shall approve or deny a submitted application within twenty (20) business days from actual receipt of the application. Following the Office’s approval of a submitted application, a written Community of Interest designation (“Designation”) shall be issued to the successful applicant. Upon receipt of the Designation, a Community of Interest may enter into a formal agreement with the Office to extend to the Community of Interest certain benefits of communications contracts for networks, equipment and services negotiated and executed by the State of Oregon.
(3) A Community of Interest Designation is a privilege, not a right. Designation expires one (1) year from the date of issuance. However, the Office may cancel a Designation prior to its normal expiration for cause based upon clear and convincing evidence of either of the following:
(a) A finding that the designee is abusing, or has abused, its status as a Community of Interest. Abuse of Community of Interest status includes, but is not limited to, the designee’s resale of extended state telecommunications contract benefits.
(b) A finding that the designee can no longer satisfy the criteria under these rules to continue qualifying as a Community of Interest.
(4) Organizations seeking Community of Interest redesignation must follow the same process and are subject to the same eligibility requirements as if applying for an initial Designation. Organizations seeking redesignation must submit their completed applications thirty (30) business days prior to the annual expiration date for their current Designation. Timely submissions will operate to extend the current Designation to cover the period necessary to review and take action on the new application for redesignation.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Or. Admin. R. 128-010-0050 Appeals
A Telecommunications Provider or other interested party may appeal any determination made by the Office under these rules pursuant to the Administrative Procedures Act.
History
- Statutory/Other Authority: ORS 276A
- Statutes/Other Implemented: Or Laws 2018, ch 51 (HB 4023)
- OSCIO 1-2019, adopt filed 03/26/2019, effective 03/26/2019
Division 20 State Information Technology Asset Protection - Covered Vendors
Or. Admin. R. 128-020-0005 Purpose
(1) The State Chief Information Officer has responsibility for and authority over executive department information systems security in accordance with ORS 276A.300, including responsibility for taking all measures that are reasonably necessary to protect the availability, integrity or confidentiality of information systems or the information stored in information systems.
(2) The primary purpose of these rules is to establish the criteria and processes by which the State Chief Information Officer will determine when a corporate entity poses a national security threat, and when a corporate entity no longer poses a national security threat. These rules define “national security threat” and “artificial intelligence” for purposes of protecting state information technology assets.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: ORS 276A.340-276A.344 & Or Laws 2025, ch 396 (HB 3936)
- OSCIO 1-2025, amend filed 12/04/2025, effective 01/01/2026
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Or. Admin. R. 128-020-0010 Definitions
For the purposes of these Chapter 20 rules, the following definitions apply:
(1) "Artificial intelligence" means a machine-based system that is capable, for a given set of human-defined objectives, of making predictions, recommendations or decisions influencing real or virtual environments and uses machine- or human-based inputs to:
(a) Perceive real or virtual environments;
(b) Abstract the perceptions into models through analysis in an automated manner; and
(c) Use model inference to formulate options for information or action.
(2) "Corporate entity" means any type of organization or legal entity other than an individual natural person, such as a corporation, partnership, limited liability company, or other organization, whether incorporated or unincorporated.
(3) "Covered product" means:
(a) Any form of hardware, software or service provided by a covered vendor; and
(b) Any hardware, software or service that uses artificial intelligence and the artificial intelligence is developed or owned by a covered vendor.
(4) "Covered vendor" means any of the following corporate entities, or any parent, subsidiary, affiliate, or successor entity of:
(a) The following corporate entities:
(A) Ant Group Co., Limited;
(B) ByteDance Limited;
(C) Huawei Technologies Company Limited;
(D) Kaspersky Lab;
(E) Tencent Holdings Limited; and
(F) ZTE Corporation.
(b) Any other corporate entity designated by the State Chief Information Officer as a covered vendor because it is a national security threat.
(c) Any corporate entity that has been prohibited or had its products or services prohibited from use by a federal agency pursuant to the Secure and Trusted Communications Networks Act of 2019, 47 USC 1601, et seq, including as amended.
(5) "National security threat" means, for purposes of protecting state information technology assets, a corporate entity that has been designated as a covered vendor because its covered product(s) pose(s) an unacceptable risk of harm to the operations of government, business entities, or the economy, or an unacceptable risk of harm to the rights and privacy of individuals, because of its engagement in a pattern or serious instance(s) of conduct significantly adverse to the security of federal or state infrastructure, government operations or systems, public and private institutions, law enforcement or military intelligence, individuals' personal information, or other sensitive or protected information.
(6) "State agency" means any board, commission, department, division, office, or other entity of state government, as defined in ORS 174.111, except that state government does not include the Secretary of State or State Treasurer.
(7) "State information technology asset" means any form of hardware, software or service for data processing, office automation, or telecommunications that is used directly by a state agency or used to a significant extent by a contractor in the performance of a contract with a state agency.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: ORS 276A.340-276A.344 & Or Laws 2025, ch 396 (HB 3936)
- OSCIO 1-2025, amend filed 12/04/2025, effective 01/01/2026
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Or. Admin. R. 128-020-0015 Covered Vendor List
(1) The State Chief Information Officer shall establish a list of covered vendors on its publicly accessible website, inclusive of information sufficient to identify covered products, and the date that each covered vendor was designated as a national security threat. The State Chief Information Officer shall maintain and update this list in accordance with the policies and procedures adopted pursuant to OAR 128-020-0025, Designation Process.
(2) Subject to allowable investigatory, regulatory, or law enforcement exceptions, and all applicable policies and procedures, no covered products of a corporate entity listed as a covered vendor on the list maintained by the State Chief Information Officer under this Division 20 may be installed or downloaded onto a state information technology asset that is under the management or control of a state agency, or used or accessed by a state information technology asset.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: Or Laws 2023, ch 256 (HB 3127)
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Or. Admin. R. 128-020-0020 Designation Criteria
The State Chief Information Officer will consider one or more of the following criteria when determining if a corporate entity is a national security threat:
(1) The corporate entity owns or otherwise provides a product or service that was developed or provided by a covered vendor.
(2) The extent to which the corporate entity is affiliated with a covered vendor.
(3) The corporate entity owns or otherwise provides a product or service that collects user data, including but not limited to personal information, browsing history, and location history, that is not required for or grossly exceeds the minimum necessary user data for the product or service.
(4) The corporate entity owns or otherwise provides a product or service that collects user data, such as biometric data, contact information, GPS locations, chat logs, photos and browser histories, personal information, browsing history, and location history, that is potentially or currently accessible by foreign governments or foreign state actors.
(5) The corporate entity owns or otherwise provides a product or service that has security vulnerabilities that, if unresolved, could expose state information technology assets to malicious actors.
(6) The corporate entity owns or otherwise provides a product or service developed or provided by a corporate entity that has been designated a national security threat or otherwise meets the criteria of a covered vendor under OAR 128-020-0010.
(7) The corporate entity owns or otherwise provides a product or service that supports the administrative use of algorithmic modifications to conduct misinformation, disinformation, or malinformation campaigns.
(8) The corporate entity owns or otherwise provides a product or service that has the potential to control or compromise state information technology assets.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: Or Laws 2023, ch 256 (HB 3127)
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Or. Admin. R. 128-020-0025 Designation Process
(1) Enterprise Information Services shall adopt and implement a policy and procedure that establishes the schedule for review of corporate entities associated with hardware, software, and services against the criteria in OAR 128-020-0020, and under which Enterprise Information Services will update its covered vendor list to reflect designations made pursuant to the Secure and Trusted Communications Networks Act of 2019, 47 USC 1601, et seq, including as amended. If review or other update identifies that a corporate entity is or may be a national security threat, the State Chief Information Officer will determine if the corporate entity should be designated as a covered vendor.
(2) The determination of the State Chief Information Officer will be reflected in an update of the covered vendor list on the publicly accessible Enterprise Information Services website.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: Or Laws 2023, ch 256 (HB 3127)
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Or. Admin. R. 128-020-0030 De-Designation Criteria
The State Chief Information Officer will consider one or more of the designation criteria in OAR 128-020-0020 when de-designating or re-evaluating a corporate entity’s status as a national security threat.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: Or Laws 2023, ch 256 (HB 3127)
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Or. Admin. R. 128-020-0035 De-Designation Process
(1) If review or other update received pursuant to the process and procedure established under OAR 128-020-0025, Designation Process, identifies that a corporate entity may no longer pose a national security threat, the State Chief Information Officer will determine if the corporate entity should be removed from the covered vendor list.
(2) The determination of the State Chief Information Officer will be reflected in an update of the covered vendor list on the publicly accessible Enterprise Information Services website.
History
- Statutory/Other Authority: ORS 276A.300
- Statutes/Other Implemented: Or Laws 2023, ch 256 (HB 3127)
- OSCIO 1-2024, adopt filed 01/29/2024, effective 02/01/2024
Division 30 State Information Security
Or. Admin. R. 128-030-0005 Purpose, Application, and Authority
These rules are adopted under 2005 Oregon Laws Chapter 739. These rules set forth the policies for state government-wide information security.
History
- Statutory/Other Authority: ORS 182.122 & 291.038
- Statutes/Other Implemented: ORS 182.122
- DAS 2-2026, renumbered from 125-800-0005, filed 04/28/2026, effective 05/01/2026
- DAS 8-2006, f. & cert. ef. 12-28-06
Or. Admin. R. 128-030-0010 Definitions
(1) “Incident” means any material adverse event that impairs the confidentiality, integrity or availability of information resources.
(2) “Information Resources” means all categories of automated or non-automated systems and data, including but not limited to, records, files, and databases, information technology equipment, facilities, and software owned or leased by the state.
(3) “Material adverse event” means an adverse event whereby some aspect of computer security could be threatened: loss of data confidentiality, disruption of data or system integrity, or disruption or denial of availability.
(4) “Ordinary Public Access” means unauthenticated access to systems or online resources intentionally provided for public use, such as an agency’s public web site.
(5) “Publicly addressable interfaces” means any network device or software application using Internet protocols that can be accessed using addresses that are routable over the public Internet infrastructure, including the state's backbone network.
(6) “Privately addressed interfaces” means any network device or software application using Internet protocols accessed using addresses that are not routable over the public Internet infrastructure, including the state's backbone network.
(7) “State Information Security Plan” means a compilation of documents including, but not limited to, statutes, administrative rules, policies, and plans, prescribing the information security practices of the State of Oregon.
(8) “Security Assessment” means any organized method of determining the risk or vulnerability including, but not limited to: risk assessment; vulnerability assessment; security penetration test, and security audits and reviews.
(9) “State Shared Computing and Network Infrastructure” means all network and information assets under the direct control or maintained by the Executive Department.
History
- Statutory/Other Authority: ORS 184.305; 182.122
- Statutes/Other Implemented: 2005 Oregon Laws Chapter 739
- DAS 2-2026, renumbered from 125-800-0010, filed 04/28/2026, effective 05/01/2026
- DAS 8-2006, f. & cert. ef. 12-28-06
Or. Admin. R. 128-030-0020 State Information Security
(1) Duties:
(a) Department of Administrative Services (Department): The Department shall serve as the primary point of accountability and coordination for information security in state government except for elected offices as identified in section 4, Elected Offices Exception. The Department, in collaboration with state agencies, shall routinely take necessary actions, proactive and reactive, to protect and verify protection of the state’s shared computing and network infrastructure including, but not limited to: active scanning and monitoring; intrusion prevention and detection; scheduled and unscheduled security reviews and compliance audits; protection, containment and mitigation actions taken to address threats, vulnerabilities, and security problems; termination or filtering of connections to mitigate problematic network traffic or unauthorized access; quarantine of infected systems to allow for the forensic identification and analysis of system threats; and the application of other steps and practices as may be required.
(A) Leadership. The Department shall provide central leadership for state government-wide information security including, but not limited to: centrally directing and coordinating all enterprise information security activities; determining security risks to the state’s Information assets and collaboratively working with state agencies in taking those actions required to mitigate unacceptable risks; collaboratively work with state agencies to determine appropriate state and agency security activities to maintain appropriate levels of security preparedness and competency; reducing the cost of providing security by implementing an enterprise approach; detecting and eliminating unnecessary duplication of efforts and obstacles to forward progress in information security; creating the processes and process linkages necessary to maintain a fully functional state government security capability; and creating and maintaining the tools and practices necessary to manage the host of simultaneous and interoperable activities that comprise information security.
(B) Planning. The Department, in collaboration with state agencies, shall direct information security planning including, but not limited to: determining strategic security objectives and associated performance measures; analyzing and evaluating state, agency and trusted partner security practices; proposing and subsequently prescribing solutions for information security challenges; establishing a process to determine, prioritize and schedule security enhancements on a state government-wide basis; ensuring through validation that information security is an essential part of state and agency business planning and operations; determining essential state information security roles and responsibilities; and identifying opportunities for security master contracting and other procurement efficiencies. The Department may plan, manage and undertake enterprise-level information security projects and initiatives.
(C) Policy. The Department, in collaboration with state agencies, shall develop, recommend, implement and maintain the full spectrum of administrative rules, policies, architecture, standards, guidelines, and procedures necessary to create and maintain an appropriate state government-wide information security competency.
(D) Coordination. The Department shall coordinate the security activities of state government including, but not limited to: providing the security communications, coordination, planning and development hub for state government; establishing collaborative partnerships with local and regional governments and the Federal government in the realm of security planning and implementation; and enterprise coordination of all information security-related activities and initiatives across state government.
(E) Security Assessments. The Department shall work collaboratively with state agencies to conduct information security assessments and testing within Oregon state government including, but not limited to: determining when it is appropriate to outsource security testing of state or agency Information assets; coordinating security assessments and tests; establishing standards for the timing and nature of agency information security assessments and tests including, but not limited to internal and external, third-party assessments; provide oversight for agency vulnerability and risk mitigation planning and actions; and ensuring the dissemination of any security assessment and test report data is restricted to only those who, in the judgment of the State Chief Information Security Officer, Agency Director, and/or appropriate state agency staff, have a business need for such information. The Department shall determine qualifications for vendors contracted to perform security assessments.
(F) Incident Response. The Department shall create a state incident response capability including, but not limited to: appointing a standing, multi-agency State Incident Response Team (SIRT) as described in section (2) of this rule; ensuring the SIRT, in collaboration with state agencies, prescribes and takes those actions necessary to immediately assemble and deploy the coordinated expertise, tools, communications infrastructure, methodologies and controls required to prevent or mitigate damage caused by an Incident. SIRT will perform a structured investigation into the nature and cause of an Incident; document evidence of computer crime, misuse or Incident; employ forensic techniques and controls; evaluate Incidents for improvement of information security; perform any duties required to appropriately defend against an Incident and subsequently prosecute the perpetrator; and cooperate with law enforcement and other authorities.
(G) System Management. The Department, in collaboration with state agencies, shall provide policies, standards and consultation on systems management associated with information security including, but not limited to management of: firewalls; routers; intrusion detection and protection mechanisms; identity and access management; patch/configuration management; digital certificates; secure transmission and access controls (encryption); wireless devices; change controls, and automated system log aggregation and monitoring.
(H) Security Awareness and Training. The Department will provide the communications practices and tools necessary to form and maintain a viable information security community of practice across Oregon state government including, but not limited to: creation and maintenance of an information security knowledge and document repository; creation and maintenance of a enterprise level user awareness program, and participation with state and national stakeholder groups; provide the training or training curriculum required to: inform managers, users and technologists on the policies and practices of state information security; work with agencies to ensure all who have access to information assets are provided training on their security-related responsibilities and the specific security-related actions they are expected to take; and identifying, conducting or arranging appropriate security certification for key state and agency staff.
(I) Reporting. The Department shall continually track and share relevant enterprise security information including, but not limited to: creation and dissemination of standardized reports demonstrating the status and progress of information security efforts across state government. Keep state executive management and the Legislature appraised of the state’s information security posture.
(J) Performance Management. The Department shall identify, track, analyze, adjust and report information security performance measurement and management to the Legislature, state executive management.
(K) Compliance and Oversight. The Department shall require and enforce compliance with information security practices including, but not limited to: performing or directing compliance reviews to ensure agencies are taking appropriate information security actions and adhering to laws, rules, policies, architecture, standards, procedures and guidelines; routinely inventory and evaluate the information security capabilities of the agencies of state government; prescribing a standardized approach for responding to audit and security assessment issues; and taking appropriate action when there is a failure to adhere to information security practices.
(L) Financial Management. The Department shall develop budgets and manage the finances for enterprise security projects and initiatives.
(M) Procurement. The Department shall manage procurements for the enterprise information security program including, but not limited to: procurement of hardware, software and expertise; approving enterprise security-related procurements; and issuing and managing enterprise-level, information security program contracts; ensuring contract language regarding information security is properly addressed in contracts.
(N) Evaluation. The Department shall evaluate and report the risk, feasibility, effectiveness and cost implications of potential enterprise information security issues and provide recommendations for mitigation.
(O) State Chief Information Security Officer. The Department will designate a State Chief Information Security Officer to manage and promote information security across the agencies of state government.
(b) Agency Responsibilities. The chief executive of each agency is accountable for their agency’s information security. Each agency head must: provide active leadership for information security practices within the agency and be responsible for agency security practices; designate an agency security liaison to participate in the collaborative development and implementation of the state security plan, and ensure agency compliance with this rule and the state information security plan; support, cooperate with and participate in the state information security program; report security-related information including, but not limited to, incident reporting, security status reporting, security-related financial reporting, and security audit or risk mitigation action. The agency head may delegate his/her authority for information security to an agency Information Security Officer (ISO), although the overall responsibility for agency information system remains with the agency head.
(c) Approval of Agency Security Plans. The Department, in collaboration with state agencies, shall establish standards for agency information assets security plans. Should an agency security plan contradict or contravene, or fail to meet minimum standards established by the state information systems security plan, the Department shall have the right to return the plan to the agency for revision and may decline to certify such plans until the plan has been modified to satisfy the overarching objective of protecting the state’s information assets.
(d) Security Assessment. The Department shall notify an agency of any negative outcome of any security assessment. If, as a result of a security assessment, the Department determines that there are severe vulnerabilities, the agency must take appropriate actions in a timely fashion to mitigate identified vulnerabilities. Additionally, the agency shall draft and implement a Security Assessment mitigation plan, subject to the Department’s approval, to mitigate the risks identified in the security assessment. The Department shall ensure that the vulnerabilities described in the assessment are mitigated following the approved plan. The Department, in collaboration with the agency, may take any action prudently required to protect the states information assets from unacceptable risks. For the purposes of this rule, risks or vulnerabilities identified by a security assessment, test, or in some other way, may constitute an incident requiring an incident response. The Department shall determine if a risk or vulnerability constitutes an incident.
(e) Interagency Collaboration. The Department will work with other governmental jurisdictions within the State of Oregon including, but not limited to all state, local and regional governmental entities contingent upon their written request and an agreement for appropriate cost sharing. The objective of such interaction is development of a cost-effective, common approach resulting in optimization of limited resources and enhanced strategic capabilities.
(2) State Incident Response Team:
(a) Authority: The State Incident Response Team (SIRT) shall be advised by and collaborate with the State Chief Information Officer, the state Chief Information Security Officer, and appropriate advisory bodies. Each state agency is responsible for creating and implementing an agency-level incident response capability.
(b) SIRT Membership: The SIRT is appointed by the Department and is, at a minimum, comprised of: representatives from the Department, Office of Emergency Management (OEM) and Oregon State Police (OSP); agency information security experts; and resources dedicated to incident communications. The members of the SIRT will work collaboratively to develop procedures, rules of engagement, and resource commitments to the SIRT.
(c) SIRT Agency Duties: Each agency shall report incidents to the SIRT as prescribed in applicable rules, policies, and procedures. Agencies are required to report incidents, cooperate with and support SIRT activities, and adhere to SIRT policies and procedures.
(3)(a) Applicability to Oregon University System: Oregon University System computers, hardware, software, storage media, networks directly connected to the state’s computing and network infrastructure, and not exempted by the provisions of 2005 Oregon Laws Chapter 739, are subject to these rules. The Department, in conjunction with Oregon University System, shall determine when such connection has occurred.
(b) Applicability to Oregon Lottery: These rules shall apply only to Oregon Lottery computer systems and network devices directly connected to the state's backbone network using publicly addressable interfaces. The Department, in conjunction with the Oregon Lottery, shall determine when such connection has occurred. Subject to constitutional and statutory limitations, the Oregon Lottery will notify the Department in the event of any incident adversely affecting Lottery gaming systems and networks that could impact the state's shared computing and network infrastructure.
(4) Elected Offices Exception: The Department shall establish, in collaboration with Elected Officers, criteria to determine compatibility between the information security plans adopted by the Secretary of State, the State Treasurer and the Attorney General (elected officers) and the state information security plan and associated standards, policies and procedures. If a joint information security plan and associated operational standards and policies cannot be agreed upon by the Department and the elected officers, or if the Department determines the information security plans adopted by the elected officers are not compatible with the state information security plan and associated standards, policies and procedures, the Department will continue to work with the elected office agencies to resolve outstanding issues.
History
- Statutory/Other Authority: 291.038 & ORS 182.122
- Statutes/Other Implemented: ORS 182.122
- DAS 2-2026, renumbered from 125-800-0020, filed 04/28/2026, effective 05/01/2026
- DAS 8-2006, f. & cert. ef. 12-28-06
Division 40 Geographic Information
Or. Admin. R. 128-040-0005 Enterprise Geographic Information System (GIS) Software Standard
(1) Purpose. The purpose of this rule is to establish a common, enterprise GIS Software standard to promote the creation, use and exchange of inter-related and standards-based geographic data and geospatial business intelligence within and between state agencies. The objective of this standard is to provide a common geospatial software and data framework underpinning all future computer applications containing geospatial components thus increasing the value and use of those applications as state information technology assets. The GIS Software standard will also allow the State of Oregon the opportunity to leverage the buying power of the broadest possible user base. The GIS Software standard is anticipated to enable the most integrated, economic and efficient acquisition, installation and use of GIS across Oregon state government. These outcomes will be made possible through the:
(a) Current installed base of GIS software and trained expertise within state agencies.
(b) General technical benefits associated with the use of standardized software, including but not limited to:
(A) Simplified software and application infrastructure configurations.
(B) Ease of software installations and upgrades.
(C) Simplified application connectivity, security and data distribution architectures.
(D) The capacity for simultaneous multi-user editing, dataset versioning, and history retention.
(E) The ability to utilize existing geospatial business intelligence to ensure data integrity and consistency via the establishment of topology rules, data attribute domain rules, and data validation rules.
(c) Enterprise-oriented data and application accessibility offered by the use of common GIS software deployed across state agencies.
(d) Enhanced functionality and interoperability of related software components within a suite of software applications including the reduction of costly data translations between diverse software products and the ability to leverage data modeling and processing efforts for reuse between agencies.
(e) Ease of sharing geospatial data among agencies and with the public based on a common GIS software infrastructure.
(2) Definitions. For the purposes of this rule:
(a) “GIS” means geographic information systems which comprise the hardware, software, network, data, and human resources involved in creating, maintaining, managing, and distributing data, information, and knowledge about spatial objects and their relative positions.
(b) “GIS Software” means computer-language coding created specifically to facilitate the creation, management, distribution, accessibility, and promulgation of Spatial Data. For the purposes of this rule, “GIS Software” does not mean computer-language coding used for the purposes of computer aided design (CAD), simple address list management or similar business processes unless the purpose is to establish inter-agency Spatial Data.
(c) “Spatial Data” means digital information that identifies the geographic location of features and boundaries that are usually stored as coordinates and topology that can be mapped or used for comparative spatial analysis.
(d) “State Agency” or “Agency” means every state officer, board, commission, department, institution, branch or agency of the state government, whose costs are paid wholly or in part from funds held in the State Treasury, except:
(A) The Legislative Assembly, the courts and their officers and committees;
(B) The Public Defense Services Commission;
(C) The Secretary of State and the State Treasurer in the performance of the duties of their constitutional offices;
(D) The State Board of Higher Education or any state institution of higher education within the Oregon University System; and
(E) The State Lottery.
(3) Standard. To achieve the purposes described in section (1) of this rule the standard for GIS Software for Oregon state agencies is the scalable suite of Environmental Systems Research Institute, Inc (ESRI) software applications:
(a) Deployed at the desktop, server, or web interface levels and designed to enable the creation, manipulation, management, storage and distribution of digital maps, digital spatial objects and any associated spatial tabular databases; or,
(b) To manage shared spatially-referenced information.
(4)(a) GIS Software Inventory. All state agencies shall inventory and report use of all GIS Software in the format and at the time established by DAS Enterprise Information Strategy and Policy Division (EISPD). Upon conclusion of the inventory the exception process described in subsection (5) of this rule becomes effective.
(b) Continued use of existing, installed, non-standard GIS Software declared in inventory; assumed exception. Agencies currently using non-standard GIS Software described by the agency in the inventory required by subsection (a) of this section will be granted a written exception to the enterprise GIS Software standard until such time as any of the conditions described in section (5)(d) of this rule occur.
(5)(a) Exception. Notwithstanding the enterprise GIS Software standard established in subsection (3) of this rule, the State Chief Information Officer (CIO) or their designee may grant a written exception to an agency to the GIS Software standard.
(b) Considerations for evaluating an agency exception request. Considerations to be weighed by the State CIO or their designee in evaluating an agency request for an exception to the GIS software standard include, but are not limited to:
(A) Agency business rationale for use of non-standard GIS software;
(B) The degree to which the requested non-standard use of GIS software would materially inhibit the state from ensuring that its information resources fit together in a statewide system capable of providing ready access to and sharing of information, computing or telecommunication resources;
(C) The degree to which the requested non-standard use of GIS software would interfere with the state’s goal of acquiring and using enterprise information technology resources in the most integrated, interoperable, efficient and economical manner possible; and
(D) Other factors deemed to be relevant to consider by the State Chief Information Officer (CIO).
(c) Agency Exception Request. An agency may be granted an exception to the GIS Software standard by submitting a written exception request to DAS EISPD. An agency exception request must address each of the considerations described in subsection (b) of this section and contain the facts base necessary to justify agency conclusions.
(d) Conditions requiring agency to submit an exception request. An agency must submit a written agency exception request to DAS EISPD when the any of the following conditions arise:
(A) Use of excepted, non-standard GIS Software evolves over time. Any agency using excepted, non-standard GIS Software must submit a request to continue that exception whenever agency’s use of the non-standard GIS Software is anticipated to change. Changes include, but are not limited to:
(i) An expansion of the number of software licenses used within the agency.
(ii) Changing the license management system from desktop-oriented to network-oriented use.
(iii) Changing the software use model from a desktop to a client-server orientation.
(iv) Supplementing the existing GIS Software use with a web-based application for functionality, data creation, data sharing, or map product distribution.
(B) Initial acquisition of non-standard GIS Software. Before initial acquisition of non-standard GIS Software an agency must request an exception to the GIS Software standard.
(C) Non-standard GIS Software used for documented research or instructional purposes. Before initial or expanded use of non-standard GIS Software for research or instructional purposes an agency must request an exception to the GIS Software standard. A single exception request from an agency should be sufficient to cover all research and instruction conducted by any division, unit, or individual of that agency.
(e) Emergency exception. Notwithstanding the exception request process described in subsections (c) and (d) of this section, the State CIO may waive some or all of the requirements for written submission of an agency exception request when immediate action is required to address an agency’s emergency need to use non-standard GIS Software.
(f) Reconsideration. An agency may request reconsideration of a denial of a GIS Software standard exception request by submitting a subsequent request in writing to the State CIO containing additional supporting information that was not included in the original exception request.
(6) Biennial Review. At least once every two years the State CIO must issue a written report to the Oregon Geographic Information Council regarding the efficacy of the GIS Software standard and its accomplishment of the purposes described in subsection (1) of this rule.
History
- Statutory/Other Authority: ORS 291.038
- Statutes/Other Implemented: ORS 291.038
- DAS 2-2026, renumbered from 125-600-7550, filed 04/28/2026, effective 05/01/2026
- DAS 5-2008, f. 6-23-08, cert. ef. 6-30-08
Division 50 Identity Authentication/Electronic Signatures
Or. Admin. R. 128-050-0005 Guidelines for Use of Electronic Signatures by State Agencies
(1) The purpose of this rule is to implement the electronic signature provisions of the Uniform Electronic Signatures Act (UETA). The rule is not intended to apply to the other provisions of the act.
(2) This rule applies prospectively to new software applications with electronic transactions requiring signatures that are implemented after the effective date of this rule.
(3) Agencies shall follow the Information Resources Management Division policy which adopts the federal E-authentication process. The IRMD policy requires that agencies using electronic signatures:
(a) Determine the level of assurance the agency needs that the party signing an electronic transaction is authentic.
(b) Use only those tools and software applications approved by NIST and the Department of Administrative Services, Information Resources Management Services Division to mitigate the risks identified and provide the level of authentication needed.
(4) Agencies may request an exemption from these rules from the Department of Administrative Services.
History
- Statutory/Other Authority: ORS 184.305, 291.038, 84, 84.052, 84.055, 84.064 & 84.049
- Statutes/Other Implemented: Portions of 2001 HB 2112
- DAS 2-2026, renumbered from 125-600-0005, filed 04/28/2026, effective 05/01/2026
- DAS 11-2005, f. & cert. ef. 10-21-05
- DAS 10-2005(Temp), f. 8-31-05, cert. ef. 9-21-05 thru 3-18-06
Continua la tua ricerca in ChatGPT o Claude
Collega Omnilex per cercare nel corpus legale dal tuo assistente IA.