What authority does the Office of Information Security have for issuing policy and directing state agencies on information security and privacy matters?

Government Code Section 11549.3 charges the Office of Information Security with responsibility for, among other things, the creation, updating, and publishing of information security and privacy policies, standards, and procedures directing state agencies to effectively manage security and risk for information and information technology.