Wyoming Administrative Rules 077 — Enterprise Technology Services

agency-077Wyo. Code R. 077Regulation

Abrir fonte

323 Director's Office

Chapter 1 General Provisions

Wyo. Code R. 077.0001.1.06082016 General Provisions

CHAPTER 1

ELECTRONIC TRANSACTIONS

GENERAL PROVISIONS

Section 1. Authority. These Department of Enterprise Technology Services (ETS) rules are promulgated ​ ​ in accordance with W.S. §9-2-2501 (Lexis-Nexis 2005), W.S. 40-21-101 to 119 (Lexis-Nexis 2005).

Section 2. Purpose. Information in all its forms is a valued asset to the State of Wyoming (State). Public information should be available to our citizens and to State government. Disclosure restrictions required by Wyoming law must be observed regardless of the media or characteristics of the record or transaction. The value of public information can be maximized through consistent delivery to and expanded use by the citizens of Wyoming and State government. To ensure continued confidence in and reliance on State agencies and the information they collect and maintain State agencies must protect the privacy of citizens and ; ensure the integrity of State information in all forms.

The purpose of these rules is to:

(i) Facilitate electronic filing, acceptance, preservation, maintenance, and availability, and confidentiality of documents with State of Wyoming (State) agencies and ;

(ii) Promote efficient delivery of services from State agencies by means of reliable electronic records.

Section 3. Definitions. In addition to the definitions in W.S. §40-21-102, the following definitions apply:

(a) "Readable" means the quality of a group of letters, numbers or symbols is recognized as words, complete numbers or distinct symbols with a specific meaning.

(b) "Reliable" means the electronic record copy produced correctly reflects the initial record each time the system is requested to produce that record copy.

(c) "Structure" means the appearance or arrangement of the information in the record. "Structure" can include, but is not limited to, such elements as heading, body and form.

(d) "Digital Signature" means the result of cryptographic transformation of data ​ that, when properly implemented, provides a mechanism for verifying origin authentication, data integrity and signatory non­repudiation.

(e) "Availability" means assurance that the systems responsible for delivering, storing, and processing information are accessible when needed, by those who need them.

(f) "Confidentiality" means assurance that the information is shared only among authorized persons or organizations.

(g) "Integrity" means assurance that the information is authentic and complete. Ensuring that information can be relied upon to be sufficiently accurate for its purpose.

Section 4. Coverage. These rules shall apply to any authority, bureau, board, commission, department, division, institution or officer of the State, except the State legislature and the judiciary. Except as otherwise provided in W.S. §40-21-112(f), these rules do not require an agency of this State to use or permit the use of electronic records or electronic signatures. Nothing in these rules shall preclude a State agency from specifying additional requirements for items that are under the jurisdiction of such agency.

Section 5. Interpretation. The ETS shall be solely responsible for providing official interpretations of these rules when questions arise regarding the application of these rules to specific situations, procedures or policies or upon the request of an agency head.

Section 6. Enforcement.

(a) ETS Responsibility.

(i) The ETS shall ensure that these rules are enforced, and that the provisions of these rules are applied uniformly and fairly throughout the Executive Branch.

(b) Agency Responsibility.

(i) Agency heads are responsible for the application of these rules within their agency, and shall ensure that all agency employees comply with the provisions of these rules. Agency heads are responsible for the actions of their agency employees, when the employees are conducting any State agency business electronically on behalf of the agency.

(ii) Agency heads shall ensure that, as necessary, employees of the agency are knowledgeable of pertinent provisions of these rules, when such knowledge is required for proper execution of their duties.

Section 7. Policies. The ETS may issue written policy statements relating to the interpretation or application of these rules, procedures for the administration of electronic government functions and to other matters, which it may consider necessary for proper procedure. Agency heads shall ensure dissemination of, and compliance with, such policy statements.

Section 8. Severability. If any provision of these rules or its application to any person or circumstance is held invalid or in conflict with any other provision of these rules, the invalidity shall not affect other provisions or applications of these rules which can be given effect without the invalid provision or application, and to this end the provisions of these rules are severable.

Section 9. Effective Date. These rules are effective upon completion of all necessary procedures in accordance with W.S. §16-3-401.

History

  • Effective 2016-06-08

Chapter 3 Security

Wyo. Code R. 077.0001.3.06082016 Security

CHAPTER 3

ELECTRONIC TRANSACTIONS

SECURITY

Section 1. Secure Electronic Procedures and Records.

(a) An electronic record can be considered secure from a specified point in time to the point of verification if it can be shown that the record has not been altered during that time.

(b) Security procedures shall be:

(i) Commercially reasonable under the circumstances;

(ii) Applied in a trustworthy manner;

(iii) Reasonably and in good faith relied upon by the party utilizing the procedure;

(iv) Capable of providing reliable evidence that an electronic record has not been altered and;

(v) Consistent with the risks and consequences associated with the compromise of the information or transaction.

(c) A security procedure is acceptable for purposes of these rules if the security procedure (including any combination of technology and algorithms it employs) has been generally accepted in the applicable information security or scientific community as being suitable for the intended purpose and capable of satisfying the requirements of these rules as applicable, in a trustworthy manner.

Section 2. State Agency and Employee Responsibilities.

(a) State agencies shall protect information against unauthorized access, disclosure, modification or destruction, whether accidental or deliberate, as well as assure the availability, integrity, utility, authenticity, and confidentiality of information for the entire lifecycle of that information. Data shall be encrypted where appropriate using industry ​ ​ accepted encryption practices. Access to State information resources must be appropriately managed.

(b) All State agencies are required to have information resources security 1 practices consistent with these rules, including adequate controls and separation of duties for tasks that are susceptible to fraudulent or other unauthorized activity. The agency head is responsible for the protection of information resources.

(c) All State agency employees are accountable for their actions relating to information resources. Information resources shall be used only for intended purposes as defined by the agency and consistent with applicable laws.

(d) Risks to information resources must be managed. The expense of security safeguards must be commensurate with the value of the assets being protected.

(e) The integrity of data, its source, its destination, and the processes applied to it must be assured. Changes to data must be made only in an authorized and documented manner.

(f) Information resources must be available when needed. Continuity of information resources supporting critical governmental services must be ensured in the event of a disaster or business disruption.

(g) Security requirements shall be identified, documented, and addressed in all phases of development or acquisition of information resources.

History

  • Effective 2016-06-08

Chapter 4 Electronic Signatures

Wyo. Code R. 077.0001.4.06082016 Electronic Signatures

CHAPTER 4

ELECTRONIC TRANSACTIONS

ELECTRONIC SIGNATURES

Section 1. General Information.

(a) In accordance with W.S. 40­21­118 (b)(ii), this chapter applies to the electronic communications or transactions conducted with a State agency, for which a method of signing is required, where:

(i) a user or signer must be verified or signature authenticated; and

(ii) requires a capture of intent for legal purposes.

(b) This chapter does not apply to:

(i) The use of digital signatures where the conditions in Section 1 do not apply; or

(ii) The use of e­mail to conduct business with the State where the conditions in Section 1(a) do not apply; or

(iii) The processing of electronic transactions under rules adopted by the Wyoming State Auditor's Office pursuant to applicable law; or

(iv) The receipt of electronically filed documents pursuant to Wyoming statutes or other applicable statutory law where the purpose of the written electronic communication is to comply with statutory filing; or

(v) As otherwise excluded by Wyoming Statute, or applicable statutory law.

Section 2. State Agency and Employee Responsibilities.

(a) The agency is responsible for establishing adequate guidelines and procedures for the management and administration of technologies that are consistent with the risks and consequences associated with the compromise of the information or transaction in accordance with state policies and standards. An electronic signature:

(i) should be unique to the signer within the context in which it is Used;

(ii) should be used to objectively identify the person signing and transmitting the electronic record;

(iii) should provide reasonable assurance the electronic signature created by such identified person cannot be readily duplicated or compromised; and

(iv) should be linked to the electronic record to which it relates, in a manner such that if the record or the signature is intentionally or unintentionally changed after signing the electronic signature is invalidated.

(b) The integrity of the data or content contained in the communication or transaction must be:

(i)  maintained in verifiable form appropriate to the communication throughout the lifecycle of the data;

(ii)  provide reasonable assurance the transaction record data cannot be readily compromised; and

(iii)  linked to the electronic signature to which it relates, in a manner such that if the original transaction record data or the signature is intentionally or unintentionally changes after signing, the transaction record is invalidated.

(c) An Agency accepting an electronic transaction that contains an electronic signature, shall ensure that the level of security used to identify the sender and to authenticate the electronic signature is sufficient for the transaction being conducted, and in accordance with Chapter 3 Electronic Transactions Security.

(d)  A State agency shall not be required to accept an electronic signature for specific transactions if the State agency:

(i) Determines that the expense or resources required by the State agency to accept such an electronic signature are unreasonable; and

(ii) Provides reasonable notice to all interested persons of the fact that such electronic signatures will not be accepted, and of the basis for the determination that the expense or resources required for acceptance are unreasonable.

(e) Any agreements entered into between a sender and the receiving State agency after the effective date of these rules must comply with these rules.

(f) Except as provided by another applicable rule of law, a secure electronic signature is attributable to the person to whom it correlates, whether or not authorized, if:

(i) The electronic signature resulted from acts of a person that obtained the signature device or other information necessary to create the signature from a source under the control of the alleged signer, or the access or use occurred under circumstances constituting a failure to exercise reasonable care by the alleged signer; and

(ii) The receiving party relied reasonably and in good faith to their detriment on the apparent source of the electronic record.

Section 3. Policies. The Chief Information Officer may issue written policy statements relating to the interpretation or application of this chapter, to include electronic signature authentication procedures, attribution of signatures, electronic signatures technologies, transaction record authentication procedures, and supporting procedures as fit to ensure proper management of this service and technology. Agency heads shall ensure dissemination of, and compliance with, such policy statements.

History

  • Effective 2016-06-08

Chapter 5 Electronic Records Electronic Transactions

Wyo. Code R. 077.0001.5.05112007 Electronic Records Electronic Transactions

The document referenced in the rules database link is not available in an electronic format. If you are in need of this rule, please contact the Secretary of State's Office at: Rules Registrar Wyoming Secretary of State's Office Ph. 307.777.7378 Email: Rules@wyo.gov

History

  • Effective 2007-05-11

Chapter 7 Electronic Transactions, County Clerk Provisions

Wyo. Code R. 077.0001.7.11212016 Electronic Transactions, County Clerk Provisions

CHAPTER 7

ELECTRONIC TRANSACTIONS

COUNTY CLERK PROVISIONS

Section 1: Authority.

(a) These Department of Enterprise Technology Services (ETS) rules are

promulgated in accordance with W.S. §34-1-405.

Section 2. Definitions.

(a) In addition to the definitions in W.S. §34-1-402, the following definitions

apply:

(i) "Readable" means the quality of a group of letters, numbers or symbols is

recognized as words, complete numbers or distinct symbols with a specific meaning.

(ii) "Reliable" means the electronic record copy produced correctly reflects

the initial record each time the system is requested to produce that record copy.

(iii) "Structure" means the appearance or arrangement of the information in

the record. "Structure" can include, but is not limited to, such elements as heading, body and form.

(iv) "Digital Signature" means the result of cryptographic transformation of

data that, when properly implemented, provides a mechanism for verifying origin authentication, data integrity and signatory non-repudiation.

(v) "Availability" means assurance that the systems responsible for delivering,

storing, and processing information are accessible when needed, by those who need them.

(vi) "Confidentiality" means assurance that the information is shared only

among authorized persons or organizations.

(vii) "Integrity" means assurance that the information is authentic and

complete. Ensuring that information can be relied upon to be sufficiently accurate for its purpose.

Section 3. Security.

(a) A county clerk shall develop security standards and policies based on

industry accepted security practices and protocols.

(b) An electronic record can be considered secure from a specified point in time

to the point of verification if it can be shown that the record has not been altered during that time.

(c) Security procedures shall be:

(i) Commercially reasonable under the circumstances;

(ii) Applied in a trustworthy manner;

(iii) Reasonably and in good faith relied upon by the party utilizing

the procedure;

(iv) Capable of providing reliable evidence that an electronic record

has not been altered; and

(v) Consistent with the risks and consequences associated with the

compromise of the information or transaction.

(d) A security procedure is acceptable for purposes of these rules if the security

procedure including any combination of technology and algorithms it employs has been generally accepted in the applicable information security or scientific community as being suitable for the intended purpose and capable of satisfying the requirements of these rules as applicable, in a trustworthy manner.

Section 4. Integrity.

(a) A county clerk shall adopt procedures where necessary to provide safeguards

to protect the reliability, authenticity, integrity and usability of those records.

(b) To receive, index, store, archive and transmit an electronic record, a county

clerk must ensure the integrity of the information from the time it is first received and accepted, throughout the entire lifecycle of the record. The criteria for assessing integrity shall be whether the information has remained complete and unaltered, apart from the addition of any endorsement or other information that arises in the normal course of communication, storage and display. The standard of reliability required to ensure that information has remained complete and unaltered should be consistent with the risks and consequences associated with the compromise of the information or transaction.

Section 5. Technology.

(a) Electronic records systems require hardware (equipment) and software

(computer programs) to retrieve and translate information into a human readable format. Because the storage medium is not permanent, and because hardware and software evolve regularly, county clerks must select an appropriate system based on specific information/operational needs and operate it in a manner that allows retention and retrieval of information from the system over time as hardware and software change, technology enhancements evolve, and storage media physically deteriorate.

Section 6. Electronic Payment of Fees.

(a) Electronic payment of fees shall be collected as prescribed by state and local

statutes and in accordance with accepted industry standards without incurring unreasonable electronic processing fees.

(b) Electronic payment of fees shall be collected according to statute and in a

manner consistent with the promotion of electronic recording, and in accordance with accepted industry standards. Each county clerk may collect electronic recording fees in a manner compatible with its internal software and county financial practices.

History

  • Effective 2016-11-21

Chapter 8 Procedures, Fees, Costs & Charges for Inspecting, Copying & Producing Public Records

Wyo. Code R. 077.0001.8.06142017 Procedures, Fees, Costs & Charges for Inspecting, Copying & Producing Public Records

CHAPTER 8

PROCEDURES, FEES, COSTS AND

CHARGES FOR INSPECTING, COPYING AND

PRODUCING PUBLIC RECORDS

Section 1. Authority.

(a) The Department of Enterprise Technology Services (ETS) is required under W.S. 16-3-103(j)(ii) to adopt the Department of Administration and Information's uniform rules pertaining to procedures, fees, costs, and charges for inspecting, copying, and producing public records.

Section 2. Adoption of Uniform Rules.

(a) The Department of Enterprise Technology Services hereby incorporates by reference the following uniform rules:

(i) Chapter 2 - Uniform Procedures, Fees, Costs, and Charges for Inspecting, Copying, and Producing Public Records adopted by the Department of Administration and Information and effective on September 6, 2016.

(ii) For these rules incorporated by reference:

(A) The Department of Enterprise Technology has determined that incorporation of the full text in these rules would be cumbersome or inefficient given the length or nature of the rules;

(B) The incorporation by reference does not include any later amendments or editions of the incorporated matter beyond the applicable date identified in subsection (a) of this section; and

(C) The incorporated rules are maintained at the Department of Enterprise Technology Service's office and are available for public inspection and copying at the same location.

History

  • Effective 2017-06-14

Continue sua pesquisa no ChatGPT ou Claude

Conecte o Omnilex para pesquisar o corpus jurídico pelo seu assistente de IA.