Tex. Government Code § 2063.408
CLOUD COMPUTING STATE RISK AND AUTHORIZATION MANAGEMENT PROGRAM
Texas · Texas Government Code · Status: effective
Cite this
- Citation
- Tex. Government Code § 2063.408, CLOUD COMPUTING STATE RISK AND AUTHORIZATION MANAGEMENT PROGRAM, Texas, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/662124
- Permanent ID
ys:prov:662124@1- SHA-256
0bbb0a3e55f00b0409c5849c4e7bb168bb41698cceb22c63904a37a159ca3927
The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.
Full text
(a) In this section, "cloud computing service" has the meaning assigned by Section 2157.007.
(b) The command shall establish a state risk and authorization management program to provide a standardized approach for security assessment, authorization, and continuous monitoring of cloud computing services that process the data of a state agency. The program must allow a vendor to demonstrate compliance by submitting documentation that shows the vendor's compliance with a risk and authorization management program of:
(1) the federal government; or
(2) another state that the command approves.
(c) The command by rule shall prescribe:
(1) the categories and characteristics of cloud computing services subject to the state risk and authorization management program; and
(2) the requirements for certification through the program of vendors that provide cloud computing services.
(d) A state agency shall require each vendor contracting with the agency to provide cloud computing services for the agency to comply with the requirements of the state risk and authorization management program. The command shall evaluate vendors to determine whether a vendor qualifies for a certification issued by the department reflecting compliance with program requirements.
(e) A state agency may not enter or renew a contract with a vendor to purchase cloud computing services for the agency that are subject to the state risk and authorization management program unless the vendor demonstrates compliance with program requirements.
(f) A state agency shall require a vendor contracting with the agency to provide cloud computing services for the agency that are subject to the state risk and authorization management program to maintain program compliance and certification throughout the term of the contract.