Handbook

Handbook  Enterprise Information Security Policies

A compilation of Enterprise Information Security Policies

Organization: Cybersecurity and Enterprise Risk Management
Date published: January 1, 2025
Last updated: March 24, 2025

Overview

The EOTSS Enterprise Risk Management Office is responsible for writing, publishing, and updating all Enterprise Information Security Policies that apply to all Executive Department offices and agencies. This is a compilation of those policies. 

EOTSS Standards may be located at:

EOTSS Technology Standards and Guidelines

While the EOTSS Standards were historically located on the ERM Information Security webpage,  they are currently undergoing revisions by EOTSS’ Operations, Security (SOC) and Technology teams.  In 2025 the ownership of these Standards will transfer from ERM to our Operations, SOC and Technology teams.  The ownership of the Enterprise Information Security Policies will remain with the Commonwealth CISO and the ERM team.  Please check back for updates.

Contact

Online

For cybersecurity or risk management questions: ERM@mass.gov

Address

McCormack Building
1 Ashburton Place, 8th Floor
Boston, MA 02108

Phone

Main Office (617) 626-4400

Open Monday through Friday 8:30 a.m. - 4:30 p.m.

EOTSS End-User Service Desk (844) 435-7629

Online

EOTSS End-User Service Desk Log in to ServiceNow 
Security Operations Center eotss-soc@mass.gov

Address

McCormack Building - Main Office
1 Ashburton Place
8th Floor
Boston, MA 02108

Help Us Improve Mass.gov  with your feedback

Please do not include personal or contact information.
Feedback