Skip to main content

Policies

Policy Approach

DoIT operates within a policy framework that establishes guidelines and operational requirements.   Services and products are provided and supported while adhering to standards that facilitate risk awareness, a security based focus and operational consistency while leveraging a wide range of information technology resources. 

The IT Policies included herein document a best practice based approach to conducting the business of state government that relies on information technology based resources in supporting and promoting the missions of various agencies and associated activities related to an effective state government operation. 

DoIT intends to follow, and expects its customers and partners who utilize DoIT provided solutions and associated resources to also adhere to, the policies that support our collective missions in a consistent and secure manner.

DoIT Website Privacy Information

Access to the Department of Innovation & Technology website is provided subject to the terms and conditions found on the Illinois Privacy Information page. Please read these terms carefully as use of this site constitutes acceptance of  these terms.

Enterprise Information Security Policies

Name

Effective Date

Revised Date
     
Acceptable Use Policy
​11.15.2018 9.27.2024
Access Control Policy
​11.29.2018 2.16.2024
Accountability, Audit, and Risk Management Privacy Policy 10.08.2018 9.27.2024
Audit and Accountability Policy
​10.08.2018 9.27.2024
​Awareness and Training Policy
10.08.2018​ 9.27.2024
​CJIS Security Supplemental Policy
​10.08.2018 9.27.2024
​Configuration Management Policy
​11.05.2018 9.27.2024
Contingency Planning Policy
​10.08.2018 9.27.2024
Data Minimization and Retention Privacy Policy ​​10.08.2018 9.27.2024
​​Data Quality and Integrity Privacy Policy ​10.08.2018​ 9.27.2024
FTI Supplemental Policy
​10.08.2018 9.27.2024
Identification and Authentication Policy
​10.08.2018 9.27.2024
​Individual Participation and Redress Privacy Policy ​10.08.2018 9.27.2024
Information Security Incident Management Policy
​10.08.2018 9.27.2024
​Media Protection Policy
10.08.2018​ 9.27.2024
Overarching Enterprise Information Security Policy
​11.29.2018 3.18.2022
​PCI Data Security Policy
​10.08.2018 9.27.2024
​Personnel Security Policy
​12.10.2018 9.27.2024
PHI Supplemental
​11.05.2018 9.27.2024
Physical and Environmental Protection Policy
​10.08.2018 9.27.2024
Privacy Security Policy
​11.05.2018 9.27.2024
Program Management Policy
10.08.2018​ 9.27.2024
​Risk Assessment Policy
​10.08.2018 9.27.2024
Security Assessment and Authorization Policy
​10.08.2018 9.27.2024
Security Planning Policy
​10.08.2018 9.27.2024
​System and Communication Protection Policy
​10.08.2018 9.27.2024
System and Information Integrity Policy
​10.08.2018 9.27.2024
System and Services Acquisition Policy
​10.08.2018 9.27.2024
System Maintenance Policy 
​10.08.2018 9.27.2024
Transparency, Authority, and Purpose Privacy Policy
​10.08.2018 9.27.2024
Use Limitation Privacy Policy​
​10.08.2018 9.27.2024

Supporting Definitions

Name
Effective Date Revised Date
​DoIT Enterprise Information Security Policy Terminology Glossary ​10.24.2018 ​9.27.204
DoIT Terminology Glossary 11.01.2008
9.27.2024

General Policies

Name Effective Date Revised Date
Identity Protection Policy 06.01.2011 11.19.2019

Footer