ITD's Top Five Goals

  1. Oversee Executive Department IT Consolidation
  2. Support Health IT and Healthcare Cost Containment
  3. Plan and implement e-Government and access enhancements 
  4. Drive IT Financial Reform
  5. Implement Springfield Data Center

Featured Content

  • link to innovation council press release

    Governor’s Council for Innovation Members Sworn In

    Learn More »

  • link to NASCIO story

    Commonwealth IT and Political Leaders Meet in Baltimore

    Learn More »

  • Governor Patrick Highlights Importance of Technology

    Learn More »

  • Springfield Data Center

    Springfield Data Center

    The Springfield Data Center (SDC) will serve as one of Massachusetts' two primary data centers.

    Learn More »

 

Getting to Our Content

This page will assist you in navigating through ITD's main categories of content grouped under, "Research & Technology" from the tab above.

Enterprise Access Control Policy and Standards Published

All Executive Department agencies are required to comply with this policy and the supporting standards in addition to any agency or third party that connects to the Commonwealth’s wide area network (MAGNet). Entities outside the Executive Department are encouraged to adopt these or similar policies and standards. This policy is effective as of the date of publication and is available on this web site under the section Security Policies & Standards .  

The Enterprise Access Control Policy and supporting standard, Enterprise Access Control Security Standards have been drafted together as a suite with sections that are aligned with each other as well as with ISO 27k.  The Policy is generally higher level and relies on the associated Standards to elaborate into the detail required for further technical use.  The suite was written in this fashion to make the overall document suite more consumable. 

The Enterprise Access Control Policy effort has been an comprehensive effort to consolidate and reorganize many of the Commonwealth’s Enterprise security access policies and standards and align them with the structure of Section 11 “Access Control” of the ISO/IEC 27002:2005, “Information technology - Security techniques - Code of practice for information security management”.

.