Coordinate information technology planning through analysis of the long-term information technology plans for each agency;
Develop a statewide information technology plan with annual modifications to include, but not be limited to, individual agency plans and information systems plans for the statewide electronic information technology function;
Establish and enforce minimum mandatory standards for:
information systems planning,
systems development methodology,
documentation,
hardware requirements and compatibility,
operating systems compatibility,
acquisition of software, hardware and technology-related services,
information security and internal controls,
data base compatibility,
contingency planning and disaster recovery, and
imaging systems, copiers, facsimile systems, printers, scanning systems and any associated supplies.
The standards shall, upon adoption, be the minimum requirements applicable to all agencies. These standards shall be compatible with the standards established for the Oklahoma Government Telecommunications Network. Individual agency standards may be more specific than statewide requirements but shall in no case be less than the minimum mandatory standards. Where standards required of an individual agency of the state by agencies of the federal government are more strict than the state minimum standards, such federal requirements shall be applicable;
Develop and maintain applications for agencies not having the capacity to do so;
Operate a data service center to provide operations and hardware support for agencies requiring such services and for statewide systems;
Maintain a directory of the following which have a value of Five Hundred Dollars ($500.00) or more: application systems, systems software, hardware, internal and external information technology, communication or telecommunication equipment owned, leased, or rented for use in communication services for state government including communication services provided as part of any other total system to be used by the state or any of its agencies, and studies and training courses in use by all agencies of the state; and facilitate the utilization of the resources by any agency having requirements which are found to be available within any agency of the state;
Assist agencies in the acquisition and utilization of information technology systems and hardware to effectuate the maximum benefit for the provision of services and accomplishment of the duties and responsibilities of agencies of the state;
Coordinate for the executive branch of state government agency information technology activities, encourage joint projects and common systems, linking of agency systems through the review of agency plans, review and approval of all statewide contracts for software, hardware and information technology consulting services and development of a statewide plan and its integration with the budget process to ensure that developments or acquisitions are consistent with statewide objectives and that proposed systems are justified and cost effective;
Develop performance reporting guidelines for information technology facilities and conduct an annual review to compare agency plans and budgets with results and expenditures;
Establish operations review procedures for information technology installations operated by agencies of the state for independent assessment of productivity, efficiency, cost effectiveness, and security;
Establish data center user charges for billing costs to agencies based on the use of all resources;
Provide system development and consultant support to state agencies on a contractual, cost reimbursement basis; and
In conjunction with the Oklahoma Office of Homeland Security, enforce the minimum information security and internal control standards established by the Information Services Division. An enforcement team consisting of the Chief Information Officer of the Information Services Division or a designee, a representative of the Oklahoma Office of Homeland Security, and a representative of the Oklahoma State Bureau of Investigation shall enforce the minimum information security and internal control standards. If the enforcement team determines that an agency is not in compliance with the minimum information security and internal control standards, the Chief Information Officer shall take immediate action to mitigate the noncompliance including the removal of the agency from the infrastructure of the state until the agency becomes compliant, taking control of the information technology function of the agency until the agency is compliant, and transferring the administration and management of the information technology function of the agency to the Information Services Division or another state agency.