A risk assessment of the agencies' information and information systems shall be performed and documented.
(1) Risks and impacts will be ranked, at a minimum, as either "High," "Moderate," or "Low."
(2) The schedule of future risk assessments will be documented.
(3) Risk assessment results, vulnerability reports, and similar information shall be documented and presented to the Information Security Officer or their designated representative(s).
(4) Approval of the security risk acceptance, transference, or mitigation decision shall be the responsibility of:
(A) the Information Security Officer or their designee(s), in coordination with the information owner, for systems identified with a Low or Moderate residual risk.
(B) The agency head for all systems identified with a High residual risk.
Source Note: The provisions of this §202.25 adopted to be effective March 17, 2015, 40 TexReg 1357; amended to be effective November 17, 2021, 46 TexReg 7775