(1) "Chief information officer" means the chief information officer appointed pursuant to section 24-37.5-103.
(1.3) Repealed.
(1.5) "Disaster recovery" means the provisioning of services for operational recovery, readiness, response, and transition of information technology applications, systems, or resources.
(1.6) "Enterprise agreement" means any agreement for the purchase of information technology or for the purchase of goods or services that are related to information technology that the office enters into for the benefit of the state and that is created in furtherance of the office's requirements or responsibilities specified in this article.
(1.7) "Enterprise facility" means any facility, including state offices, state warehouses, state leased spaces, and vendor facilities, that the office designates as a facility where state data, equipment, information technology, or goods related to information technology will be located or where services related to information technology will be performed.
(1.8) "Independent verification and validation" means ensuring that a product, service, or system meets required specifications and that it fulfills its intended purpose. The review of such product, service, or system is typically performed by an independent third party.
(1.9) "Information security" means the protection of communication and information resources from unauthorized access, use, disclosure, disruption, modification, or destruction in order to:
(a) Prevent improper information modification or destruction;
(b) Preserve authorized restrictions on information access and disclosure;
(c) Ensure timely and reliable access to and use of information; and
(d) Maintain the confidentiality, integrity, and availability of information.
(2) "Information technology" means information technology and computer-based equipment and related services designed for the storage, manipulation, and retrieval of data by electronic or mechanical means, or both. The term includes but is not limited to:
(a) Central processing units, servers for all functions, network routers, personal computers, laptop computers, hand-held processors, and all related peripheral devices configurable to such equipment, such as data storage devices, document scanners, data entry equipment, specialized end-user terminal equipment, and equipment and systems supporting communications networks;
(b) All related services, including feasibility studies, systems design, software development, system testing, external off-site storage, and network services, whether provided by state employees or by others;
(c) The systems, programs, routines, and processes used to employ and control the capabilities of data processing hardware, including operating systems, compilers, assemblers, utilities, library routines, maintenance routines, applications, application testing capabilities, storage system software, hand-held device operating systems, and computer networking programs; and
(d) The application of electronic information processing hardware, software, or telecommunications to support state government business processes.
(2.3) "Joint technology committee" means the joint technology committee created in section 2-3-1702, C.R.S.
(2.5) "Local government" means the government of any county, city and county, home rule or statutory city, town, special district, or school district.
(2.6) (a) "Major information technology project" means a project of state government, excluding the department of education through June 30, 2019, that has a significant information technology component, including, without limitation, the replacement of an existing information technology system.
(b) As used in this subsection (2.6), "significant" means the project has a specific level of business criticality and manifests either a security risk or an operational risk as determined by a comprehensive risk assessment performed by the office.
(3) "Office" means the office of information technology created pursuant to section 24-37.5-103.
(3.2) "Project manager" means a person who is trained and experienced in the leadership and management of information technology projects from the commencement of such projects through their completion.
(3.5) Repealed.
(4) "State agency" means all of the departments, divisions, commissions, boards, bureaus, and institutions in the executive branch of the state government. "State agency" does not include the legislative or judicial department, the department of law, the department of state, the department of the treasury, or state-supported institutions of higher education.