Skip to main content

An official website of the State of Georgia.

Language icon English Organizations

The .gov means it’s official.

Local, state, and federal government websites often end in .gov. State of Georgia government websites and email systems use “georgia.gov” or “ga.gov” at the end of the address. Before sharing sensitive or personal information, make sure you’re on an official state website.

Still not sure?

Call 1-800-GEORGIA to verify that a website is an official website of the State of Georgia.

Georgia.gov logo Enterprise Policies, Standards, and Guidelines

Main navigation

  • About PSGs
    • FAQs
    • Creating or Revising PSGs
    • Approving and Publishing PSGs
    • Reviewing PSGs to Determine Continuing Need
    • How PSG Numbering Works
    • PSG Management System
    • Related Forms
  • Policies, Standards, and Guidelines
    • PSGs Sorted by Name
    • All Security Policies
    • All Security Standards
    • PSGs by Number
  • Request an Exemption
  • Glossary of Terms
  • PSG Mappings
    • PSGs Mapped to PMBOK PROJECT Management Standards
    • PSGs Mapped to PMBOK PROGRAM Management Standards
    • PSGs Mapped to PBMOK PORTFOLIO Management Standards
    • PSGs Mapped to ITIL
Header Utility Narrow

Search this site

Popular searches

  • Mission Statement
  • Organization of the office
  • History
  • Meeting Requests
  • Key Staff
  • Duties of the Office
  • Event Requests
  • Contact

Breadcrumb

  • Home
  • Browse by Topic

Select a Topic

- Any -
3rd Party Hosted Solutions
access
accessibility
accreditation
agency reports
AI
AI tools
alarms
annual training
appropriate use
artificial intelligence
assessment
Assessments
assurance
Audit
Audits
authentication
authority
authorization
authorization to operate
authorizing official
availability
awareness
backup media
boundary
building security
business continuity
business owner
BYOD
categorization
certification
change
charter
Cloud
cloud
confidentiality
constituent data
continuity
contract
contractor
cryptography
Cybersecurity Capability Maturity Model
data center
data classification
data lifecycle
data owner
data sharing
data steward
data storage location
decommission
defense-in-depth
deployment
development lifecycle
disaster recovery
disposal
document management
electronic record
email
employee
enterprise application
enterprise operational environment (EOE)
EOE
escalation
facilities
financial
framework
frequency
Generative AI
go-live
governance charter
GTA review
IaaS
incident
Information Security
integration
integrator
integrity
interconnection security agreement
investment
ISA
ITIL
IV&V
legal hold
license
lifecycle
log
logical access
malicious software
media
memorandum of agreement
middleware
mobility
MOU
NADC
network security
new systems
NIST
non-disclosure
non-state IT
operations
outsourced
PaaS
password
performance lifecycle
personal information
physical access
physical security
Policy for the cost effective implementation and management of agency projects that involve a substantial information technology system (“IT”) component.
privacy
procurement
production acceptance
production facility
project assurance
project integrator
project management
project request
PSG exemption
public access
public record
purge
radio
records management
refresh
remote access
reporting
request for exemption
Responsibility for Risk
retention schedule
risk
SaaS
sanitized
screening
sdlc
SEAC
Section 508
security
Security and Compliance
security awareness
Security Controls
security framework
security level
security organization
security plan
security policy
security requirements
security review
security training
service agreement
Share-Services
Shared-Services
SOC
social media
Software Licensing and Management
Software Licensing and Management (SM-19-001)
spectrum
state business
state data center
State Enterprise Application Council
Statewide Policy
steward
strategic plan
surplus
technology resources
technology review
telecommunications
telework
Terms and Conditions
test facility
third-party
training
trusted partner
unescorted
upgrade
Use Case
validation
vendor return
verification
voicemail
W3C
WCAG
web applications
web methods
website
website design

Browse by Topic

Authorization and Access Management (SS-08-010)

Requires managed access to state facilities and information resources

Personnel Identity Verification and Screening (SS-08-017)

Standards for verifying identities of state personnel and contractors

Personnel Security (PS-08-014)

Provides for identity verification of IT employees and contractors

Security Awareness Program (PS-08-010)

Establishes a need to increase user security awareness through an awareness and training program

Security Education and Awareness (SS-08-012)

Requires all employees and contractors to attend annual security awareness training

Third-Party Security Requirements (SS-08-013)

Establishes security requirements for conducting business with contractors, outsourcing vendors and/or other third-parties

Select a Topic

- Any -
3rd Party Hosted Solutions
access
accessibility
accreditation
agency reports
AI
AI tools
alarms
annual training
appropriate use
artificial intelligence
assessment
Assessments
assurance
Audit
Audits
authentication
authority
authorization
authorization to operate
authorizing official
availability
awareness
backup media
boundary
building security
business continuity
business owner
BYOD
categorization
certification
change
charter
Cloud
cloud
confidentiality
constituent data
continuity
contract
contractor
cryptography
Cybersecurity Capability Maturity Model
data center
data classification
data lifecycle
data owner
data sharing
data steward
data storage location
decommission
defense-in-depth
deployment
development lifecycle
disaster recovery
disposal
document management
electronic record
email
employee
enterprise application
enterprise operational environment (EOE)
EOE
escalation
facilities
financial
framework
frequency
Generative AI
go-live
governance charter
GTA review
IaaS
incident
Information Security
integration
integrator
integrity
interconnection security agreement
investment
ISA
ITIL
IV&V
legal hold
license
lifecycle
log
logical access
malicious software
media
memorandum of agreement
middleware
mobility
MOU
NADC
network security
new systems
NIST
non-disclosure
non-state IT
operations
outsourced
PaaS
password
performance lifecycle
personal information
physical access
physical security
Policy for the cost effective implementation and management of agency projects that involve a substantial information technology system (“IT”) component.
privacy
procurement
production acceptance
production facility
project assurance
project integrator
project management
project request
PSG exemption
public access
public record
purge
radio
records management
refresh
remote access
reporting
request for exemption
Responsibility for Risk
retention schedule
risk
SaaS
sanitized
screening
sdlc
SEAC
Section 508
security
Security and Compliance
security awareness
Security Controls
security framework
security level
security organization
security plan
security policy
security requirements
security review
security training
service agreement
Share-Services
Shared-Services
SOC
social media
Software Licensing and Management
Software Licensing and Management (SM-19-001)
spectrum
state business
state data center
State Enterprise Application Council
Statewide Policy
steward
strategic plan
surplus
technology resources
technology review
telecommunications
telework
Terms and Conditions
test facility
third-party
training
trusted partner
unescorted
upgrade
Use Case
validation
vendor return
verification
voicemail
W3C
WCAG
web applications
web methods
website
website design
Georgia.gov logo Enterprise
Policies, Standards, and Guidelines

How can we help?

  • Email Us

    [email protected]
  • © Georgia.gov
  • Accessibility
  • Privacy/Security
  • Website powered by GovHub
  • Human Trafficking Notice
  • Georgia Web Analytics