This guide contains everything you need to know about conducting an information security risk assessment questionnaire at your organization.
Isora GRC gives Arizona Budget Units a single platform to implement the P8000 Information Security Policy series. Categorize systems, document SSPs, track POA&Ms, and submit statewide reporting, all in one workspace.




























Arizona’s P8120 Information Security Program requires Budget Units to maintain complete system inventories, categorize every system as Standard or Protected, document controls in System Security Plans, and submit annual reporting to AZDOHS by July 1. Most agencies still manage these activities in spreadsheets, shared drives, and email chains.
Without centralized systems, SSPs become outdated, POA&Ms lose sync with actual remediation work, and vendor risk assessments happen in isolation. This slows statewide reviews, creates gaps in continuous monitoring, and leaves agencies scrambling when the State CISO requests updated documentation.
P8120 requires Budget Units to submit a complete system inventory with categorization and ownership details by July 1 annually. Isora maintains a connected inventory where each system links to assessments, risks, data classifications, and responsible units. Metadata captures business impact, control mappings, and P8000 policy requirements, ensuring agencies always work from current, statewide-aligned records that support categorization decisions and continuous monitoring.
Every Protected system requires a System Security Plan that describes boundaries, data types, categorization rationale, threats, controls, and dependencies. Isora structures SSP documentation by linking system records to assessments, control implementations, and risk items. Agencies can update SSPs as architecture or integrations change, ensuring documentation reflects current security posture and meets BU CIO approval requirements for statewide submission.
P8120 requires Budget Units to document all remediation actions in Plans of Action and Milestones, review them regularly, and submit them annually for Protected systems. Isora automates POA&M creation from assessment findings, assigns owners, sets completion dates, and monitors progress in real time. Leadership gains transparent visibility into open deficiencies, overdue tasks, and completed mitigations, ensuring agencies stay audit-ready for State CISO reviews.
P8120 requires Budget Units to implement continuous monitoring with defined metrics, ongoing control assessments, and quarterly reporting to the State CISO. Isora automates monitoring workflows by scheduling recurring assessments, tracking control effectiveness over time, and generating compliance dashboards. Agencies can correlate assessment results with vulnerability scans and POA&M remediation, producing clear, exportable reports that demonstrate security posture for AZDOHS oversight.
State Information Security Regulations: Complete Guide Across the U.S., all fifty state governments have issued their own state information security...
Complete guide for Ohio ORC § 9.64 requirements including deadlines, program components, incident reporting, and compliance strategies.
The P8000 series establishes statewide security, privacy, and supply-chain risk policies for Arizona’s executive branch. Within this series, P8120 defines the Information Security Program all Budget Units must implement. A Budget Unit includes any state department, board, commission, or agency that receives or expends state funds. The Arizona Board of Regents (ABOR) is covered, but universities under ABOR follow separate governance. Legislative and judicial branches are excluded.
Isora centralizes system inventories, SSP documentation, POA&M tracking, and continuous monitoring evidence so Budget Units can demonstrate alignment with P8120. It structures categorization decisions, maps controls to NIST SP 800-53, automates assessment cycles, and produces audit-ready reports for AZDOHS. Agencies use Isora to coordinate annual submissions, maintain accurate security posture records, and support State CISO oversight.
Budget Units must submit required documentation by July 1 annually, including: (1) a complete system inventory with categorization and system owners, (2) a System Security Plan and System Security Assessment Plan for each Protected system, and (3) a Plan of Action and Milestones for each Protected system. These artifacts allow AZDOHS and the State CISO to verify completeness, risk posture, and remediation progress.
Every SSP must describe the system boundary, mission purpose, information types, roles, categorization rationale, threats, risks, controls, architecture, external dependencies, and privacy impacts. The SSP must reflect current system state, map required controls to implementation details, and document tailoring or exceptions. It must be reviewed annually, updated as changes occur, and approved by the BU CIO before submission to AZDOHS.
Yes. Isora tracks vendor risk assessments, third-party security evaluations, and supply-chain reviews required under P8120. Budget Units can document supplier risks, maintain anti-counterfeit controls, record cloud-product assessments, and link vendor records to associated systems and risks. Each vendor assessment connects to the agency’s risk register, providing complete visibility into third-party compliance and supporting annual supply-chain reporting to the State CISO.
P8120 requires Budget Units to conduct ongoing control assessments, correlate security data, respond to identified risks, and report security status quarterly to the State CISO. Isora automates continuous monitoring by scheduling recurring assessments, tracking control effectiveness metrics, linking vulnerability scan results to POA&Ms, and generating real-time dashboards. Agencies can produce quarterly reports that demonstrate compliance progress, remediation activity, and current risk posture for statewide oversight.