Cal. Code Regs. tit. 11 § 999.108

Current through Register 2024 Notice Reg. No. 38, September 20, 2024
Section 999.108 - Definitions
(a) The following definitions shall apply throughout all the articles within this chapter:
(1) "Agent" means a representative and their employees who are authorized to submit documents on behalf of an Authorized Submitter who is eligible to enter into a contract with a County Recorder, and, be assigned a role by the County Recorder, to deliver, and, when applicable, return the submitted ERDS payloads via an ERDS. An Agent may not be a Computer Security Auditor, County Recorder Designee, ERDS Account Administrator, ERDS System Administrator, or Certified Vendor of ERDS Software.
(2) "Attorney General" means the Attorney General of the State of California.
(3) "Availability" means as that term is defined in United States Code, Title 44, Section 3552, subdivision (b)(3)(C).
(4) "Certified Vendor of ERDS Software" means an entity that sells, leases, or grants use of, with or without compensation therefore, a software program for use by counties for establishing an ERDS. A Certified Vendor of ERDS Software may not be a Computer Security Auditor, Authorized Submitter, Agent, ERDS Account Administrator, ERDS System Administrator, or County Recorder Designee.
(5) "Confidentiality" means as that term is defined in United States Code, Title 44, Section 3552, subdivision (b)(3)(B).
(6) "County Recorder" means a public official responsible for administering an ERDS and ensuring that all ERDS requirements are met, and who oversees the assignment and delegation of those responsibilities by determining the necessary resources and means.
(7) "County Recorder Designee" means a Secure Access role assigned by the County Recorder to retrieve, and, when applicable, return submitted ERDS payloads. A County Recorder Designee may not be a Computer Security Auditor, Authorized Submitter, Agent, or Certified Vendor of ERDS Software. This role requires fingerprinting.
(8) "Developer" means a person or personnel, supporting and/or acting on behalf of the County Recorder and/or Certified Vendor of ERDS Software.
(9) "DOJ" means the California Department of Justice.
(10) "Electronic Signature of the Notary" means a field, or set of fields, containing information about the electronic signature of the notary who notarized a digital or digitized record.
(11) "ERDA" means the Electronic Recording Delivery Act of 2004, as amended.
(12) "ERDS" means an Electronic Recording Delivery System certified by the ERDS Program to deliver digitized and/or digital records to a County Recorder, and, when applicable, return those records to the Agent or Authorized Submitter.
(13) "ERDS Account Administrator" means a Secure Access role assigned by the County Recorder to an individual who is authorized to configure accounts, assign roles, and issue credentials. An ERDS Account Administrator may not be a Computer Security Auditor, Authorized Submitter, Agent, or Certified Vendor of ERDS Software. This role requires fingerprinting.
(14) "ERDS Payload" means an electronic structure designed for the purpose of delivering digital or digitized records to a County Recorder via an ERDS. The structure is also used to return, when applicable, digital or digitized records to an Agent or Authorized Submitter via an ERDS.
(15) "ERDS Program" means the program within DOJ designated by the Attorney General to certify, implement, regulate, and monitor an ERDS.
(16) "ERDS Server" means computer hardware, software, and storage media used by the County Recorder to implement an ERDS. The ERDS Server(s) execute(s) the primary functionality of the application software associated with an ERDS.
(17) "ERDS System Administrator" means a Secure Access role assigned by the County Recorder to an individual who is authorized to configure hardware, software, and network settings, and to maintain ERDS security functions. An ERDS System Administrator may not be a Computer Security Auditor, Authorized Submitter, Agent, or Certified Vendor of ERDS Software. This role requires fingerprinting.
(18) "FIPS" means Federal Information Processing Standards.
(19) "Hardened" means a security configuration checklist (also called a lockdown, hardening guide, or benchmark) is a series of instructions or procedures for configuring an IT product to a particular operational environment, for verifying that the product has been configured properly, and/or for identifying unauthorized changes to the product.
(20) "HMAC" means Hash Message Authentication Code.
(21) "Incident" means an event that may have compromised the security of an ERDS.
(22) "Integrity" means as that term is defined in United States Code, Title 44, Section 3552, subdivision (b)(3)(A).
(23) "Lead County" means the County Recorder in a Multi-County ERDS responsible for administering that ERDS, ensuring that all ERDS requirements are met, and who oversees the assignment and delegation of those responsibilities by determining the necessary resources and means.
(24) A "Licensed and Supported Operating System" means that the operating system is commercially supported and licensed so that security patches and fixes are available.
(25) "Live Scan" means a DOJ system used for the electronic submission of applicant fingerprints.
(26) "Logged" means an auditable ERDS event.
(27) "Logical" means the way data or systems are organized. For example, a logical description of a file is that it is a collection of data stored together.
(28) "MAC" means Message Authentication Codes.
(29) "Multi-County" means an ERDS application in which County Recorders collaborate and make use of a single ERDS serving multiple counties.
(30) "NIST" means National Institute of Standards and Technology.
(31) "Non-Substantive Modification" means a change that does not affect the functionality of an ERDS.
(32) "Physical Access" means access granted to an individual who has physical access to an ERDS server. This level of access requires fingerprinting with the exception of a county data center or an outsourced county data center in which physical access is already managed by security controls.
(33) "Public Entity" includes the state, the Regents of the University of California, the Trustees of the California State University and the California State University, a county, city, district, public authority, public agency, and any other political subdivision or public corporation in the state. As provided in this chapter, "public entity" also includes federal government entities.
(34) "Reportable" means an incident that has compromised the security of an ERDS and shall be reported to the ERDS Program.
(35) "Role" means a security mechanism, method, process, or procedure that defines specific privileges dictating the level of access to an ERDS.
(36) "Secure Access" means a role assigned by the County Recorder to an individual which requires fingerprinting and includes:
1) an Authorized Submitter and Agent, if any, who are authorized to use an ERDS;
2) a Computer Security Auditor hired by the County Recorder to perform independent audits;
3) an ERDS System Administrator who is authorized to configure hardware, software and network settings;
4) an ERDS Account Administrator who is authorized to configure accounts, assign roles, and issue credentials;
5) an individual who is granted Physical Access to an ERDS server;
6) a County Recorder Designee authorized to retrieve, and, when applicable, return submitted ERDS payloads;
7) Certified Vendor of ERDS Software personnel who support or act on behalf of the Certified Vendor of ERDS Software; or
8) a Developer acting in lieu of a Certified Vendor of ERDS Software.
(37) "Single-County" means an ERDS application in which a County Recorder's Office connects to the ERDS system individually.
(38) "Source Code Materials" includes, but is not limited to, all of the following:
1) a copy of all source code that implements ERDS functionality;
2) a copy of the compiler needed to compile the ERDS source code in escrow;
3) instructions for installation and use of the ERDS source code compiler; and
4) instructions that facilitate reviews, modification, and/or recompiling the source code.
(39) "Sub-County" means a County Recorder(s) of a county other than the Lead County in a Multi-County ERDS.
(40) "Substantive Modification" means a change that affects the functionality of an ERDS.
(41) "Uniform Index Information" means information collected by a County Recorder in the recording process.
(42) "User" means a person who uses a computer to access, submit, retrieve, or, when applicable, return an ERDS payload.
(43) "Workstation" means a computer used to connect to, and/or interact with, an ERDS.

Cal. Code Regs. Tit. 11, § 999.108

1. New article 2 (section 999.108) and section filed 7-31-2007; operative 8-30-2007 (Register 2007, No. 31).
2. Amendment filed 10-7-2019; operative 1-1-2020 (Register 2019, No. 41).
3. Change without regulatory effect amending subsection (a)(1) filed 12-6-2021 pursuant to section 100, title 1, California Code of Regulations (Register 2021, No. 50).

Note: Authority cited: Section 27393, Government Code. Reference: Sections 27390(b), 27393(b)(4), 27395(f), 811.2, 15000 and 12510, Government Code.

1. New article 2 (section 999.108) and section filed 7-31-2007; operative 8-30-2007 (Register 2007, No. 31).
2. Amendment filed 10-7-2019; operative 1/1/2020 (Register 2019, No. 41).
3. Change without regulatory effect amending subsection (a)(1) filed 12-6-2021 pursuant to section 100, title 1, California Code of Regulations (Register 2021, No. 50).