# Oneida Business Committee (2026)

> Briefs, arguments, decisions, and more.

URL: https://www.frixlaw.com/law-library/documents/tribal%3Aoneida_nation%3A9a7271f98d7dc899

## Record

- **Collection:** Tribal code
- **Document type:** Tribal code

## Text

1 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~
ONEIDA

LEGISLATIVE OPERATING COMMITTEE MEETING AGENDA
Business Committee Conference Room - 2nd Floor Norbert Hill Center
August 19, 2026
9:00 a.m.

I.

Call to Order and Approval of the Agenda

II.

Minutes to be Approved
1. August 5, 2026 LOC Meeting Minutes (pg. 2)

III.

Current Business

IV.

New Submissions

V.

Additions

VI.

Administrative Updates
1. Certification of the Technology Resources Law Rules (pg. 4)
2. Certification of the Real Property Law Rule No. 3 – Easements Amendments (pg.63)
3. Legislative Operating Committee End of 2023-2026 Legislative Term Report (pg. 93)

VII.

Executive Session

VIII. Recess/Adjourn

A good mind. A good heart. A strong fire.

2 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

"'
ONEIDA
GOOODO

LEGISLATIVE OPERATING COMMITTEE MEETING MINUTES
Oneida Business Committee Conference Room-2nd Floor Norbert Hill Center
August 5, 2026
9:00 a.m.
Present: Jameson Wilson, Jonas Hill, Kirby Metoxen, Jennifer Webster
Others Present: Clorissa Leeman, Grace Elliott, Carolyn Salutz
Others Present on Microsoft Teams: Ashley Blaker, Rhiannon Metoxen, Fawn Cottrell, Melissa
Alvarado, Rae Skenandore, Kaylynn Biely, Kristal Hill, Fawn Billie, Thurston Denny, Lora
Danforth, Michelle Braaten, Jada Lassila, Peggy Helm-Quest, Derrick King, Isaiah Skenandore,
Kristin Jorgenson-Dann, Quailen Thao, Taryn Webster, Sidney White, Valerie Webster, Tina
Jorgenson, Lorna Skenandore, Michelle Tipple, Justin Nishimoto, David Jordan
I.

Call to Order and Approval of the Agenda
Jameson Wilson called the August 5, 2026, Legislative Operating Committee meeting to
order at 9:00 a.m.
Motion by Jennifer Webster to adopt the agenda; seconded by Jonas Hill. Motion carried
unanimously.

II.

Minutes to be Approved
1. July 15, 2026 LOC Meeting Minutes.
Motion by Jennifer Webster to approve the July 15, 2026, LOC meeting minutes and forward to the Oneida Business Committee; seconded by Kirby Metoxen. Motion carried
unanimously.

III.

Current Business
1. Safe Neighborhoods Law.
Motion by Jennifer Webster to approve the public meeting packet for the proposed Safe
Neighborhoods law and forward the Safe Neighborhoods law to a public meeting to be
held on September 10, 2026; seconded by Kirby Metoxen. Motion carried unanimously.
Motion by Kirby Metoxen to approve the emergency adoption extension packet for the
Safe Neighborhoods law and forward to the Oneida Business Committee for consideration;
seconded by Jennifer Webster. Motion carried unanimously.

~
G00DOC)
A good mind. A good heart. A strong fire.

Legislative Operating Committee Meeting Minutes of August 5, 2026
Page 1 of 2

ONEIDA

3 of 141

2. Petition: G. Powless-Buenrostro – Amend the Judiciary Law #2026-01.
Motion by Jennifer Websyer to approve the updated public comment review memorandum,
draft, and legislative analysis for the proposed amendments to the Boards, Committees,
and Commissions law; seconded by Jonas Hill. Kirby Metoxen opposed Motion carried.
3. Boards, Committees, and Commissions Law Amendments.
Motion by Jonas Hill to approve the adoption packet for the Boards, Committees, and
Commissions Law Amendments and forward to the Oneida Business Committee for consideration; seconded by Jennifer Webster. Motion carried unanimously.
4. Code of Ethics Amendments.
Motion by Jennifer Webster to approve the adoption packet for the proposed amendments
to the Code of Ethics and forward to the Oneida Business Committee for consideration;
seconded by Jonas Hill. Motion carried unanimously.
IV.

New Submissions

V.

Additions

VI.

Administrative Updates
1. Legislative Operating Committee Fiscal Year 2026 Third Quarter Report.
Motion by Jennifer Webster to approve the LOC Fiscal Year 2026 Third Quarter Report
and forward to the Oneida Business Committee; seconded by Kirby Metoxen. Motion carried unanimously.

VII.

Executive Session

VIII. Adjourn
Motion by Jennifer Webster to adjourn at 9:41 a.m.; seconded by Kirby Metoxen. Motion
carried unanimously.

Legislative Operating Committee Meeting Minutes of August 5, 2026
Page 2 of 2

4 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~

000000

ONEIDA

AGENDA REQUEST FORM
8/10/2026
1) Request Date: _____________________________________________________
...t
Jesse
Kujawa
2) Contact Person(s): ______________________________________
Digital Technology Services
Dept:____________________________
920-429-3234
jkujawa@oneidanation.org
Phone Number:_________________________
Email: __________________________________
Technology Resource Law Rule Amendments
3) Agenda Title:___________________________________________________________________
4) Detailed description of the item and the reason/justification it is being brought before the LOC:

The Technology Resources Law is a framework for identifying rules and
_______________________________________________________________________________
expectations to safeguard Oneida information. Additional rules are

_______________________________________________________________________________
required to outline compliance in accordance to the law.
_______________________________________________________________________________
_______________________________________________________________________________
List any supporting materials included and submitted with the Agenda Request Form
Rule Approval Memo with timeline
Public Meeting
1) ________________________________
3) ________________________________

Rule Packet
2) ________________________________

4) ________________________________

5) Please list any laws, policies or resolutions that might be affected:
Technology Reousrce Law
_______________________________________________________________________________
6) Please list all other departments or person(s) you have brought your concern to:
Oneida CEO's CFO, CISO, CIO, and DTS Staff
______________________________________________________________________________
7) Do you consider this request urgent?

Iii Yes

□ No

If yes, please indicate why:
The technology resource law requires further clarity and context due to recent events and incidents
________________________________________________________________

I, the undersigned, have reviewed the attached materials, and understand that they are subject to action by
the Legislative Operating Committee.
Signature of Requester:
Digitally signed by Jesse Kujawa

Jesse Kujawa
Date: 2026.08.10 11 :30:14 -05'00'
__________________________________________________________________________
Please send this form and all supporting materials to:
LOC@oneidanation.org
or
Legislative Operating Committee (LOC)
P.O. Box 365
Oneida, WI 54155
Phone 920-869-4376

A good mind. A good heart. A strong fire.

5 of 141

Oneida Nation

Legislative Operating Committee
Legislative Reference Office
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

TO:
FROM:
DATE:
RE:

"

000000

ONEIDA

Legislative Operating Committee (LOC)
Clorissa N. Leeman, Legislative Reference Office, Senior Staff Attorney
August 19, 2026
Certification of Technology Resources Law Rules

Background
The Legislative Operating Committee received the certification packet provided for the following
rules (“the Rules”) from the Digital Technology Services Department (DTS):
 Technology Resources Law Rule No. 1 – Acceptable Use;
 Technology Resources Law Rule No. 2 – Clear Desk/Screen;
 Technology Resources Law Rule No. 3 – Asset Management;
 Technology Resources Law Rule No. 4 – Security Awareness Training;
 Technology Resources Law Rule No. 8 – Third Party Providers; and
 Technology Resources Law Rule No. 9 – Generative AI Usage.
The Legislative Operating Committee is responsible for certifying a proposed rule after
determining the authorized agency has complied with the requirements for certification stated in
section 106.7-2 of the Administrative Rulemaking law, and forwarding the rule to the Oneida
Business Committee for consideration of adoption. [1 O.C. 106.7-3].
Certification by the Legislative Operating Committee means:
 The certification packets provided by DTS for the Rules contained all documentation
required by the Administrative Rulemaking law for a complete administrative record;
 The promulgation of the Rules complied with the procedural requirements contained in
the Administrative Rulemaking law; and
 The Rule did not exceed the rulemaking authority granted under the law for which the
Rule is being promulgated. [1 O.C. 106.7-2].
The Legislative Operating Committee is now being asked to consider the certification of the Rules.
Administrative Rulemaking Authority
The Technology Resources law regulates the usage of technology resources and processed data
owned and operated by the Nation. [2 O.C. 215.1-1]. It is the policy of the Nation to provide its
community and employees access to the tools necessary to participate in a technological society.
[2 O.C. 215.1-2].
The Technology Resources law provides that the Digital Technology Services (“DTS”) is
delegated administrative rulemaking authority in accordance with the Administrative Rulemaking
law to promulgate rules to govern technology resources of the Nation. [2 O.C. 215.1-2(b)].

Page 1 of 4

A good mind. A good heart. A strong fire.

6 of 141

Summary of Technology Resources Law Rules
DTS has brought forward six (6) Technology Resources law rules for certification and adoption.
Below please find a summary of the purpose of each Rule.
The purpose of the Technology Resources Law Rule No. 1 – Acceptable Use (Rule No. 1) is to
provide guidelines and techniques to promote effective use of Nation’s Digital Technology
Systems. [Rule 1.1-1]. It applies to all Nation systems located on, or accessed from, Nation
properties and systems provided by the Nation for use in the Nation’s business. Id. It is the policy
of the Nation to provide sophisticated computer and communications systems to support official
business activities, enabling effective and timely communication among staff, customers, partners,
and vendors. [Rule 1.1-2]. This rule establishes expectations for all staff regarding the access, use,
and disclosure of information via the Nation’s Information Systems, which are to be used solely
for official business purposes in accordance with these guidelines and other relevant policies. Id..
The purpose of the Technology Resources Law Rule No. 2 – Clear Desk/Screen (Rule No. 2) is to
improve security and confidentiality, whenever possible for papers, digital storage devices, and
screens which contain sensitive or confidential information. [Rule 2.1-1].
The purpose of the Technology Resources Law Rule No. 3 – Asset Management (Rule No. 3) is
to establish a comprehensive framework for the effective management, tracking, and security of
Information Technology assets within the organization. [Rule 3.1-1].
The purpose of the Technology Resources Law Rule No. 4 – Security Awareness Training (Rule
No. 4) is to ensure that security awareness and training measures safeguard Information Resources,
maintaining their availability, confidentiality, and integrity. [Rule 4.1-1].
The purpose of the Technology Resources Law Rule No. 8 – Third Party Providers (Rule No. 8)
is to establish guidelines to limit and control third party service providers to minimize risks such
as revenue loss, liability, loss of trust, and embarrassment to Oneida Nation, while ensuring the
responsible use of company information and resources. [Rule 8.1-1].
The purpose of the Technology Resources Law Rule No. 9 – Generative AI Usage (Rule No. 9) is
to establish proper use of Artificial Intelligence (AI) technologies while working for the Nation.
[Rule 9.1-1]. This Rule sets out to protect employees, clients, suppliers, customers, and the Nation
from harm, while leveraging AI to enhance efficiency, innovation, and competitive advantage. Id.
Eligibility for Certification by the Legislative Operating Committee
The materials submitted by DTS for the certification of the Rules have been reviewed, and this
section of the memorandum provides conclusions regarding the eligibility of the Rules for
certification by the Legislative Operating Committee.

A good mind. A good heart. A strong fire.

Page 2 of 4

~
ONEIDA

7 of 141

Complete Administrative Record
The certification packet provided by DTS for the Rules did contain all documentation required by
the Administrative Rulemaking law for a complete administrative record. Below, please find a
chart of the required documentation for the administrative record.
Administrative Record Documents
Submitted
Memo from the authorized agency’s highest level of management Yes
approving the proposed rule
and/or
Minutes from the authorized agency’s meeting during which the
proposed rule was an agenda item.
Memo provided by the authorized agency containing the rule’s Yes
procedural timeline including the dates the requirements of this law were
fulfilled.
Summary Report:
 Document containing summary information;
 Statement of Effect from Legislative Reference Office; and
 Fiscal Impact Statement.
Draft of proposed Rule
Draft of proposed rule that went to public meeting if the rule changed
after the public meeting.
If the rule is being amended, redline drafts from the currently effective
rule illustrating the proposed amendments.
Public Meeting Notice
Public Meeting Sign in sheet
A memorandum provided by the authorized agency containing the
public comments that were received, both orally and written, and the
authorized agency’s response to each comment
The effective dates of the original rule and any rule amendments
subsequently made as established by the authorized agency.

Yes

Yes
No change after
public meeting.
N/A
Yes
N/A
Yes

N/A

Compliance with Procedural Requirements
Based on the information provided for by DTS, the promulgation of the Rules did comply with the
procedural requirements contained in the Administrative Rulemaking law.
Compliance with Rulemaking Authority
Based upon a review of the Rules, the Rules did not exceed the rulemaking authority granted under
the Technology Resources law.

~

GDODOO
A good mind. A good heart. A strong fire.

Page 3 of 4

ONEIDA

8 of 141

Conclusion
The Rules provided by DTS are eligible for certification by the Legislative Operating Committee
under section 106.7-2 of the Administrative Rulemaking law.
Requested Action
Certify the following Rules and forward to the Oneida Business Committee:
 Technology Resources Law Rule No. 1 – Acceptable Use;
 Technology Resources Law Rule No. 2 – Clear Desk/Screen;
 Technology Resources Law Rule No. 3 – Asset Management;
 Technology Resources Law Rule No. 4 – Security Awareness Training;
 Technology Resources Law Rule No. 8 – Third Party Providers; and
 Technology Resources Law Rule No. 9 – Generative AI Usage.

A good mind. A good heart. A strong fire.

Page 4 of 4

~
ONEIDA

9 of 141

Digital Technology Services (DTS) Department
909 Packerland Drive
Green Bay, WI 54313

Memorandum
To:
From:
Date:
Re:

""

GDDDDC)

ONEIDA

Oneida Nation Legislative Operating Committee (LOC)
Jason W. Doxtator, Chief Information Officer
07/27/2026
Approval of Proposed Technology Resources Law - Security Rules

CC: Mark Powless, CEO Nation Services; Ralinda Ninham-Lamberies, CFO; James Petitjean, CEO Retail;
Taryn Webster, CEO Oneida Casino Hotel; Laura Laitinen-Warren, CEO Human Resources
Purpose:
Following a comprehensive review of the proposed security rules governing technology resources, I am formally
approving the framework as outlined. This decision is based on alignment with current Oneida Nation
cybersecurity directives, regulatory standards, and best practices in digital security governance.
Summary of Approval:
The proposed rules incorporate a robust structure of governance that is essential for maintaining the integrity,
confidentiality, and availability of our digital assets. These components are consistent with Oneida Nation’s
cybersecurity initiatives and legal mandates.
Key Elements of the Approved Rules:
1. Acceptable Use
a. Provides guidelines and techniques to promote effective use of Nation’s Technology Systems
2. Clear Desk
a. To improve security and confidentiality, whenever possible for papers, digital storage devices,
and screens which contain sensitive or confidential information.
3. Asset Management
a. Establishes a comprehensive framework for the effective management, tracking, and security
of Information Technology assets within the organization.
b. Ensures the protection of sensitive data, compliance with applicable laws and regulations, and
the efficient use of technology resources to support the mission and operations of the Nation.
4. Security Awareness
a. A robust security program necessitates that staff are trained in security policies, procedures, and
technical controls.
5. Password Management
a. Passwords play a crucial role in digital security, protecting user accounts and Oneida Nation’s
digital assets.
6. Generative AI Usage
a. Outlines the proper use of AI technologies while working at Oneida Nation the goal is to protect
employees, clients, suppliers, customers, and the Nation from harm, while leveraging AI to
enhance efficiency, innovation, and competitive advantage.
Oneida Digital Technology Services (DTS) Department
909 Packerland Drive - Green Bay, WI 54313
oneida-nsn.gov

10 of 141

Implementation and Oversight:
The Digital Security Office will oversee the implementation of these rules, upon the Oneida Nations LOC
acceptance and adoption.
Please consider this memo as formal approval to proceed with the implementation of the proposed security
rules. I appreciate the committee’s diligence in crafting a framework that strengthens our digital resilience while
upholding legal and ethical standards.
Rule Procedural Timeline:

• Statement of Effects Provided: March 3, 2026

• Public Meeting Notice Published in Kalihwisaks: July 2026 edition [Published on June 30, 2026]
• Public Meeting Held: July 23, 2026
• Public Comment Period Closure: August 4th, 2026

A good mind. A good heart. A strong fire.

~
ONEIDA

11 of 141

ONEIDA-NSN.GOV

NOTICES

JULY 2026 I 25

PUBLIC MEETING NOTICE - 9am, Thurs., July 23, 2026
In accordance w ith the Administrative Rulemaking
Law, the Digital Technology Services Department
is h osting this Public Meeting to gather feedback
from the community regarding THE FOLLOWING
PROPOSED RULES to the Techno logy
Reso urces Law

• 001- Acceptable Use
• 002- Clear Desk
• 003-Asset Management

• 004-Security Awareness
• 008- Third Party Provider
• 009-Generative Al Usage

Who would be aected:

• Employees and Contractors,
• Vendors, and Third-Party
Providers

This is a proposal to adopt rules which would:
Establish clear standards for responsible and secure use of
digital technology.
Promote data protection and reduce the risk of unauthorized
access or data breaches.
Ensure proper tracking and disposal of IT assets.
Require ongoing security awareness training for employees.
Regulate secure access and evaluate risk for vendors
and third-party providers.
Govern the ethical and secure use of generative
Al technologies.

PUBLIC COMMENT PERIOD OPEN UNTIL
TUESDAY, AUGUST 4, 2026
DTS DIGITAL SECURITY
909 PACKERLAND DR. • GREEN BAY, WI 54303
lnfoSec@OneidaNation.org • 920.869.4357
During the public comment period, anyone may submit
written comments, questions. or input. Comments may be
submitted to the Oneida Nation DTS Office or the
Skenandoah Front Desk in person, by U.S. mall, interoffice
mail, or e-mail.

lndiViduals may attend the public meeting for the proposed amendments to the Technology Resources Law in person
at the Skenandoah Complex or virtually throug h Microsoft Teams (MT). If you wish to attend the public meeting through
MT, email infosec@oneidanation.org
For more in formation on the proposed Technology Resources Law amendments. please review the public meeting
packet at www.oneida-nsn.gov/Register/PublicMeet ings or email infosec@oneidanation.org for electronic copies.

I

12 of 141

Digital Technology Services (DTS) Department
909 Packerland Drive
Green Bay, WI 54313

Memorandum
To:
From:
Date:
Re:

""

GDDDDC)

ONEIDA

Oneida Nation Legislative Operating Committee (LOC)
Jesse Kujawa, Digital Technology Services Security Analyst
08/10/2026
Public Comment Period for Amendments to the Technology Resources Law

This memorandum serves as documentation that the public comment period regarding the proposed
amendments to the Technology Resources Law was completed in accordance with applicable procedures and
timeframes.
Upon the close of the public comment period, no comments, concerns, recommendations, or objections were
received from members of the public, stakeholders, or other interested parties regarding the proposed
amendments.
As no public comments were submitted during the designated comment period, there are no comments
requiring review, response, or incorporation into the proposed amendments.
This memorandum is being provided for the official record and to document the completion of the public
comment process.

Oneida Digital Technology Services (DTS) Department
909 Packerland Drive - Green Bay, WI 54313
oneida-nsn.gov

13 of 141

Title 2. Employment
Tut~e
1Emp~oyme111t –
= Chapter
Clhlapterr 215
2 TI 5

rTechnology
echno~ogy Resources
ResolUI rrces Law
lLalw

Rule
Acceptable Use
RIUl~e #001
#00 ~ –
= Accepttab~e
1.1 Purpose and Authority
1.2 Adoption, Amendment and Repeal
1.3 Definitions
1.4 Purpose and Scope
1.5 Facilities and Equipment
1.6 Information Access, Content, and Use
1.7 Protecting Confidential Information
1.8 Copyrighted Information
1.9 Privacy and Monitoring
1.10 Storing and Archiving Information
1.11 Employee Usage
1.12 Email Etiquette
1.13 Enforcement
1.14 References

1.1 Purpose and Authority
1.1-1. Purpose. The purpose of this rule is to provide guidelines and techniques to promote
effective use of the Nation’s Digital Technology Systems. It applies to all of the Nation’s systems
located on, or accessed from, Nation properties and systems provided by the Nation for use in the
Nation’s business.
1.1-2. Policy. It is the policy of the Nation to provide sophisticated computer and communications
systems to support official business activities, enabling effective and timely communication
among staff, customers, partners, and vendors. This rule establishes expectations for all staff
regarding the access, use, and disclosure of information via the Nation’s Information Systems,
which are to be used solely for official business purposes in accordance with these guidelines and
other relevant policies.
1.1-3. Authority. The Technology Resources Law delegates rulemaking authority to the Digital
Technology Services Department pursuant to the Administrative Rulemaking law.
1.2. Adoption, Amendment and Repeal
1.2-1. This rule was adopted by the Oneida Business Committee in accordance with the procedures
of the Administrative Rulemaking law.
1.2-2. This rule may be amended or repealed by the Digital Technology Services Department
and/or the Oneida Business Committee pursuant to the procedures set out in the Administrative
Rulemaking law.
1.2-3. Should a provision of this rule or the application thereof to any person or circumstances be
held as invalid, such invalidity shall not affect other provisions of this rule which are considered
to have legal force without the invalid portions.
1.2-4. In the event of a conflict between a provision of this rule and a provision of another rule,
internal policy, procedure, or other regulation; the provisions of this rule shall control.
1.2-5. This rule supersedes all internal department rules, regulations, policies, or other
requirements relating to acceptable use as referenced in the Technology Resources Law.

Technology Resources Law Rule 001 –Acceptable Use
Page 1TI of 6
61

14 of 141

1.3. Definitions
1.3-1. This section shall govern the definitions of words and phrases used within this rule. All
words not defined herein shall be used in their ordinary and everyday sense.
(a) “Nation” means the Oneida Nation.
(b) “Confidential data” means any information that the Nation is obligated by law, policy,
or regulation to protect from unauthorized access, use, disclosure, modification, or
destruction.
(c) “Personal use” means any technology resource use that is conducted for purposes other
than accomplishing an authorized activity or official business of the Nation.
(d) “Technology resources” means any tools, systems, and applications that use technology
to fulfill their purposes. Technology resources may include, but are not limited to,
computers, tablets, telephones, facsimile machines, photocopiers, networks, virtual
applications, and software, such as internet connectivity and access to internet
services and electronic mail.
(e) “Staff” means any individual who uses the technology resources of the Nation,
including but not limited to employees, independent contractor personnel, interns,
members of boards, committees or commissions, volunteers, guests, and visitors.
1.4. Facilities and Equipment
1.4-1. The Nation maintains facilities, equipment, and communication systems (e.g., telephones,
email, computers, fax machines) to enhance operational efficiency. These systems, provided at
the Nation’s expense, are for official business only. Access is granted based on job
responsibilities, and use is subject to this rule.
1.4-2. Staff shall not remove equipment or software from the Nation’s premises or use personal
equipment for official business without prior express consent from the employee’s senior level
manager or director.
1.4-3. Alternate internet service provider connections to the Nation’s network are prohibited
unless approved by management and secured by appropriate security devices.
1.5 Information Access, Content, and Use
1.5-1. Technology and Resources. The Nation invests in advanced technology to support official
business. All staff with access to technology resources shall read, understand, and comply with
this rule.
15-2. Business Use.
(a) Information Systems are owned by the Nation and shall be used exclusively for
business purposes, serving customer interests, and supporting normal operations.
(b) Staff decisions to use these systems should be based on sound business practices,
reducing costs, or improving services measurably, while maintaining a professional image.
(c) Staff using the Nation’s accounts act as representatives of the Nation and shall avoid
damaging the organization’s reputation.
1.5-3. Acceptable Use. Use of the Nation’s facilities, equipment, or systems is limited to
acceptable use as defined in this rule. Incidental personal use is permitted if it is not excessive,
does not interfere with job performance, consume significant resources, or disrupt other staff
activities, as determined by the Nation.

Technology Resources Law Rule 001 –Acceptable Use
Page 2 of 6

15 of 141

1.5-4. Professional Conduct. Staff shall conduct official business consistent with the Nation’s
mission and comply with tribal, state, and federal laws, maintaining standards of integrity,
accountability, and legal sufficiency.
1.5-5. Information Accuracy.
(a) Staff shall disseminate current, accurate, complete, and compliant information.
(b) Information shared through technology resources shall be handled with the same level
of care as other forms of communication. Users should ensure that content respects
intellectual property rights, including copyrights, trademarks, and trade secrets.
(c) Staff using Internet information for strategic business decisions shall verify its
integrity, ensuring the source is regularly updated and valid.
1.5-6. Confidential and Proprietary Information.
(a) Staff shall protect confidential and proprietary information.
(b) Questions regarding the appropriate use of technology resources or handling of
information, staff should consult their area manager or director for guidance.
(c) Staff shall not discuss the Nation’s business prospects, financial condition, or future
products with third parties unless publicly disclosed by the Nation.
(d) Unauthorized disclosure of confidential or proprietary information may result in legal
action.
1.5-7. Public Accessibility.
(a) Designated staff may make information publicly accessible after management review
to verify accuracy and appropriateness.
(b) Publicly accessible information shall be periodically reviewed to remove inaccurate,
inappropriate, or nonpublic content.
1.6. Protecting Confidential Information
1.6-1. Importance and Procedures. Maintaining confidentiality is critical to the Nation’s success.
Staff shall follow appropriate procedures to protect confidential information, exercising caution
when communicating externally, as electronic communications are not fully secure.
1.6-2. Data Classification. Confidential data shall be marked with designations such as
“Confidential,” “Do not reproduce,” or “Do not forward.” Emails containing confidential
information shall include “Confidential” in the subject line.
1.6-3. Access Restrictions.
(a) Access to directories containing sensitive or confidential data is restricted.
(b) Unauthorized attempts to bypass restrictions, including hacking, violate this rule and
may lead to disciplinary action, including termination or legal action. Hacking may
also violate the Federal Electronic Communications Privacy Act (18 U.S.C. 2510).
1.6-4. Privacy of Communications. Staff shall respect the privacy of messages received, securing
voicemail and email accounts with proper password protection, closing messages after reading,
and deleting unnecessary messages.
1.6-5. Internet Privacy.
(a) The internet does not guarantee privacy. Staff shall exercise caution when transferring
sensitive material online by using secure methods (e.g., encrypted channels, approved
platforms) and avoiding public or unsecured networks. This helps prevent unauthorized
access or third-party interception.

Technology Resources Law Rule 001 –Acceptable Use
Page 3 of 6

16 of 141

(b) Staff shall not place the Nation’s materials—such as copyrighted software, internal
correspondence, or other proprietary content—on publicly accessible internet-connected
devices or platforms without prior approval from their area manager or director.
1.7. Copyrighted Information
1.7.1. Intellectual Property Rights.
(a) The Nation respects intellectual property rights. Staff shall comply with license terms
for copyrighted material (e.g., literature, software, graphics) and not assume
availability on electronic systems permits downloading or dissemination.
(b) Unauthorized or illegal use of third-party intellectual property, including downloading
copyrighted software, video, or audio clips, is prohibited.
(c) Employees/users shall consult with management if unsure about use of third=party
intellectual property.
1.7-2. Trademark and Copyright Notices.
(a) The Nation’s trademarked or copyrighted material shall be properly marked.
(b) Staff shall not remove third-party trademark or copyright notices.
1.7-3. Software Use.
(a) Software use shall comply with the Nation’s licensing agreements.
(b) Copying software, loading personal software, or downloading Internet software
without permission is prohibited.
(c) Software and firmware shall be digitally signed using a recognized, approved
certificate.
(d) All Nation-owned software remains with Nation upon staff departure.
1.8. Privacy and Monitoring
1.8-1. Expectation of Privacy. Staff have no reasonable expectation of personal privacy regarding
data, communications, or activities on the Nation systems, which may be monitored, accessed, or
reviewed by authorized personnel without notice to ensure compliance with policies, legal
requirements, and security protocols.
1.8-2. Monitoring and Inspection.
(a) The Nation reserves the right to access, inspect, or search all Information Systems,
including directories, files, emails, and communication systems, without prior notice.
Monitoring may occur to:
(1) Prevent transmission of discriminatory, harassing, or offensive messages.
(2) Detect illegal material or unlicensed software.
(3) Ensure communication tools are not used for unauthorized or disruptive
purposes.
(4) Investigate allegations of impropriety.
(5) Access information in staff absence.
(6) Respond to legal proceedings or court orders. Staff refusing to cooperate with
legitimate inspections or provide passwords may face disciplinary action,
including termination. The Nation may restrict or cancel staff access to systems
at any time.
1.8-3. System Ownership.
(a) All messages, data, and applications on Information Systems are Oneida Nation
property, subject to third-party intellectual property rights.

Technology Resources Law Rule 001 –Acceptable Use
Page 4 of 6

17 of 141

(b) The Nation may access, review, copy, delete, or disclose data for legitimate business
purposes.
1.9. Storing and Archiving Information
1.9-1. Electronic data is subject to routine backups and archival procedures, retaining copies for
extended periods. Deleting data does not ensure privacy, as archives remain property of the Nation
and may be used for business purposes.
1.9-2. Staff may need to preserve data for litigation or investigations per the Data Retention Rule.
Staff shall regularly delete or archive files to manage disk space, avoiding large file transfers
during prime hours to minimize network impact.
1.10. Employee Usage
1.10-1. Compliance. Staff shall comply with this rule. Violations of this rule may result in
disciplinary action, including termination or legal action.
1.10-2. Prohibited Activities.
(a) Personal use of technology resources for financial gain or soliciting for non-business
purposes (e.g., political, religious causes) is prohibited.
(b) Inappropriate use of technology resources includes accessing, storing, or transmitting
sexually explicit, illegal, or disruptive materials (e.g., defamatory, obscene, or
harassing content)
(c) Sending threatening, slanderous, or anonymous messages, or misrepresenting identity,
is prohibited.
(d) Staff shall not copy or transfer files without permission, disable virus protection,
circumvent security mechanisms, or share confidential information externally.
(e) Staff shall cooperate with authorized investigations.
(f) If offensive material is accessed, staff shall disengage immediately.
(g) The Nation is not responsible for offensive content on external servers.
1.10-3. System Awareness. Staff shall:
(a) Protect equipment from food and/or drink and know fire suppression equipment
locations.
(b) Keep unauthorized people away from equipment and data. Question strangers in areas.
(c) Report security violations, including unauthorized data changes or loss, to
management immediately.
1.11. Email Etiquette
(a) Email is for official business. Use of the Nation’s accounts for personal email use
should be limited to occasional use.
(b) Staff shall:
(1) Use descriptive subject lines and include contact information in signatures.
(2) Acknowledge receipt of important emails, even if unable to respond
immediately.
(3) Delete read or sent emails to conserve storage.
(4) Avoid sending unnecessary or large emails to preserve network resources.
(5) Refrain from harassing, offensive, anonymous, or all-caps messages, avoiding
terse or rude tones.

Technology Resources Law Rule 001 –Acceptable Use
Page 5 of 6

18 of 141

(6) Proofread messages, prioritize appropriately, and send to relevant recipients
only.
(7) Exercise caution with unencrypted emails and attachments, as email is
generally not secure.
(8) Reply carefully, avoiding unintended “Reply all,” and consider sender’s
intentions before forwarding.
1-12. Enforcement
1.12-1. Violations of this rule may result in disciplinary action, up to and including termination,
and potential legal action.
1.13. References
1.13-1. References include:
(a) COBIT APO01.02, APO01.11, APO07.03, APO07.05, APO13.01, APO13.02,
DSS04.05
(b) GDPR Article 32
(c) HIPAA 164.308(a)(1)(ii)(B), 164.312(a)(2)(iv)
(d) ISO 27001 7.3, A.5.4, A.5.10, A.5.12-13, A.6.3-4, A.8.16
(e) NIST SP 800-37 3.3
(f) NIST SP 800-53 AT-3.2, CA-3.4, PS-3.16
(g) NIST Cybersecurity Framework ID.AM-6, ID.GV-2, DE.DP-2
(h) PCI 12.1.1
End.
Original effective date: [add effective date established by authorized entity] (Certified by LOC on )

Technology Resources Law Rule 001 –Acceptable Use
Page 6 of 6

19 of 141

Summary Report for Acceptable Use Rule
Original effective date: Ten days after rule adoption.
Amendment effective date:

Name of Rule: Acceptable Use
Name of law being interpreted: Technology Resources Law
Rule Number: 1
Other Laws or Rules that may be affected: Proposed Data Classification Rule, proposed Data Retention
Rule, proposed Password Standard, & proposed BYOD Rule.
Brief Summary of the proposed rule: Provides guidelines and techniques for acceptable and effective
use of Oneida Nation’s Digital Technology Systems.
Statement of Effect: Obtained after requesting from the Legislative Reference Office.
Financial Analysis: See Attached.

Note: In addition- the agency must send a written request to each entity which may be affected by the
rule- asking that they provide information about how the rule would financially affect them.
The agency must include each entity’s response in the financial analysis. If the agency does not receive a
response within 10 business days after the request is made, the financial analysis can note which entities
did not provide a response.

20 of 141

Financial Analysis for Acceptable Use Rule

Start Up Costs

Type of Cost

N/A

Description/Comment

Dollar Amount
$0.00

Personnel

N/A

$0.00

Office

N/A

$0.00

Documentation Costs

N/A

$0.00

Estimate of time necessary for an individual
or agency to comply with the rule after
implementation

Estimated 3 months to 9 months

Other, please explain
Total Annual Net Revenue

$0.00

21 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~

GODOOO

ONEIDA

Statement of Effect
Technology Resources Law Rule No. 1 – Acceptable Use
Summary
The Technology Resources Law Rule No. 1 – Acceptable Use provides guidelines and techniques
to promote effective use of Nation’s Digital Technology Systems. [Rule 1.1-1].
Submitted by: Clorissa N. Leeman, Senior Staff Attorney, Legislative Reference Office
Date: March 5, 2026
Analysis by the Legislative Reference Office
The Administrative Rulemaking law provides authorized agencies the opportunity to promulgate
rules interpreting the provisions of any law enforced or administered by it; provided that, a rule
may not exceed the rulemaking authority granted under the law for which the rule is being
promulgated. [1 O.C. 106.4-1]. Rulemaking authority is defined as the delegation of authority to
authorized agencies found in the Nation’s laws, other than the Administrative Rulemaking law,
which allows authorized agencies to implement, interpret and/or enforce a law of the Nation. [1
O.C. 106.3-1(i)]. An authorized agency is defined as any board, committee, commission,
department, program or officer of the Nation that has been granted rulemaking authority.[1 O.C.
106.3-1(a)].
The Technology Resources law regulates the usage of technology resources and processed data
owned and operated by the Nation. [2 O.C. 215.1-1]. It is the policy of the Nation to provide its
community and employees access to the tools necessary to participate in a technological society.
[2 O.C. 215.1-2]. Allowing limited personal use of these tools helps enhance the quality of the
workplace and helps the Nation to retain highly qualified and skilled workers and officials, as well
as to develop the technological skills of the community. Id. Pursuant to this law, users are
permitted limited use of technology resources of the Nation for personal needs if the use does not
interfere with the authorized duties of the user or official business of the Nation. Id. The
Technology Resources law does not create a right to use technology resources of the Nation for
personal use. [2 O.C. 215.1-2(a)]. The Technology Resources law in no way limits use of
technology resources to fulfill authorized duties. [2 O.C. 215.9-1].
The Technology Resources law provides that the Digital Technology Services (“DTS”) is
delegated administrative rulemaking authority in accordance with the Administrative Rulemaking
law to promulgate rules to govern technology resources of the Nation. [2 O.C. 215.1-2(b)].
Page 1 of 2
A good mind. A good heart. A strong fire.

22 of 141

The Technology Resources law addresses acceptable use. The Technology Resources law provides
that users may utilize technology resources for authorized activities. [2 O.C. 215-4-1]. Users may
engage in personal use of technology resources when such use does not interfere with the mission
or operations of the entity in control of the resources and does not violate applicable laws, rules,
or standard operating procedures of the Nation. [2 O.C. 215-4-2]. Employees may engage in
limited personal use of technology resources if the usage does not violate section 215.5-1 of the
law regarding inappropriate personal use or standards enacted pursuant to section 215.7-1 of the
regarding limitations on use. [2 O.C. 215-4-3].
The purpose of the Technology Resources Law Rule No. 1 – Acceptable Use (“the Rule”) is to
provide guidelines and techniques to promote effective use of Nation’s Digital Technology
Systems. [Rule 1.1-1]. It applies to all Nation systems located on, or accessed from, Nation
properties and systems provided by the Nation for use in the Nation’s business. Id. It is the policy
of the Nation to provide sophisticated computer and communications systems to support official
business activities, enabling effective and timely communication among staff, customers, partners,
and vendors. [Rule 1.1-2]. This rule establishes expectations for all staff regarding the access, use,
and disclosure of information via the Nation’s Information Systems, which are to be used solely
for official business purposes in accordance with these guidelines and other relevant policies. Id.
The Rule addresses:
■

■

■

■

■

■

■

■

■

■

Facilities and Equipment [Rule 1.4];
Information Access, Content, and Use [Rule 1.5];
Protecting Confidential Information [Rule 1.6];
Copyrighted Information [Rule 1.7];
Privacy and Monitoring [Rule 1.8];
Storing and Archiving Information [Rule 1.9];
Employee Usage [Rule 1.10];
Email Etiquette [Rule 1.11];
Enforcement [Rule 1.12]; and
References [Rule 1.13].

Conclusion
There are no legal bars to adopting the Technology Resources Law Rule No. 1 – Acceptable Use.

Page 2 of 2

A good mind. A good heart. A strong fire.

~
ONEIDA

23 of 141

Title 2.
Tn1t~e
2. Employment
!Emp~oymen1t – Chapter
CChap1terr 215
2~5
TECHNOLOGY RESOURCES
T!ECCHNOlOGY
!R!E§OU!RCC!E§ LAW
~W
Rule
!Ru~e #002 – Clear
CC~earr Desk/Screen
Deslkj§crreen
=

=

2.1 Purpose and Authority
2.2 Adoption, Amendment and Repeal
2.3 Definitions
2.4 Digital Security Office Responsibilities
2.5 Staff Responsibilities
2.6 References

2.1 Purpose and Authority
2.1-1. Purpose. To improve security and confidentiality, whenever possible for papers, digital
storage devices, and screens which contain sensitive or confidential information.
2.1-2. Authority. The Technology Resources Law delegates rulemaking authority to the Digital
Technology Services Department pursuant to the Administrative Rulemaking law.
2.2. Adoption, Amendment and Repeal
2.2-1. This rule was adopted by the Oneida Business Committee in accordance with the procedures
of the Administrative Rulemaking law.
2.2-2. This rule may be amended or repealed by the Digital Technology Services Department
and/or the Oneida Business Committee pursuant to the procedures set out in the Administrative
Rulemaking law.
2.2.3. Shall a provision of this rule or the application thereof to any person or circumstances be
held as invalid, such invalidity shall not affect other provisions of this rule which are considered
to have legal force without the invalid portions.
2.2-4. In the event of a conflict between a provision of this rule and a provision of another rule,
internal policy, procedure, or other regulation; the provisions of this rule shall control.
2.2-5. This rule supersedes all prior rules, regulations, internal policies or other requirements
relating to clear desk/screens.
2.3. Definitions
2.3-1. This section shall govern the definitions of words and phrases used within this rule. All
words not defined herein shall be used in their ordinary and everyday sense.
(a) “Authorized Individual” means a person who has the proper authorization to access,
handle, or remove Sensitive Information from devices that transmit or print such
information.
(b) “Information Systems” means systems used to store, process, and manage information,
including computers, networks, and databases.
(c) “Removable Storage Media” means devices such as flash drives, removable media,
tablets, and cellular phones that can store electronic data and be physically removed
from a workstation.
(d) “Secure Storage Areas” means areas where sensitive information is stored that shall
remain locked or digitally secured when staff are away from their work areas.

Technology Resources Law Rule 002 – Clear Desk/Screen
Page 1TI of 3
.3

24 of 141

(e) “Sensitive Information” means information (both hardcopy and electronic) that shall

be protected from unauthorized access or disclosure. This includes private, non-public,
or confidential data.
(f) “Staff” means any individual who uses the technology resources of the Nation,
including but not limited to employees, independent contractor personnel, interns,
members of boards, committees or commissions, volunteers, guests, and visitors.
(g) “Unauthorized Access” means access to Sensitive Information by individuals who do
not have the proper authorization or clearance.
(h) “Unauthorized Disclosure” means the release or sharing of Sensitive Information to
individuals who are not authorized to receive it.
2.4. Digital Security Office Responsibilities
2.4-1. The Digital Security Office shall ensure processes are in place to:
(a) Identify Sensitive Information (hardcopy and electronic) that shall be protected from
unauthorized access or disclosure.
(b) Identify workstations that shall be shut down at the end of the workday and those to
remain powered on at night to receive security updates.
(c) Laptops/tablets/cellular phones containing Sensitive Information shall be secured per
the Mobile Device policy.
2.5. Staff Responsibilities
2.5-1. Oneida Staff shall ensure that:
(a) Sensitive or private/non-public electronic information is secured and/or removed from
unauthorized disclosure or access when they leave their work areas. Staff who work
with Sensitive Information shall have means to store information in a secure area when
not in use. Staff shall check with their immediate supervisor or Oneida management if
an employee is not sure what information shall be secured or what lockable storage is
available.
(b) Their desk and work area is clear (clear desk) of papers and removable storage media
when leaving their work area unsecured. In addition, monitors shall be cleared (clear
screen) to protect against unauthorized access to information or Information Systems.
Screen savers shall be automatically activated after a period of inactivity. See the
Workstation Security policy for more information.
(c) Papers and electronically stored Sensitive Information (e.g., flash drives, removable
media, tablets, cellular phones) shall be secured when Staff leave their work area.
Storage areas containing Sensitive Information shall remain locked or digitally secured
when Staff are away from their work areas. Keys to secure storage areas shall not be
left in the lock or accessible by unauthorized personnel.
(d) Devices that transmit or print (e.g., Fax machines, printers) Sensitive Information shall
have the documents immediately removed from the device by authorized staff to
prevent unauthorized disclosure or access.
(e) Documents waiting to be shredded shall not be accessible by unauthorized staff.
(f) Violations to this rule may be subject to disciplinary action, up to and including
termination.
2.6. References
(a) 2.6.1. COBIT EDM03.07, APO07.05, APO12.02, APO12.07, APO14.02, DSS06.07
(b) 2.6.2. GDPR Article 25, 32
Technology Resources Law Rule 002 – Clear Desk/Screen
Page 2 of 3

25 of 141

(c) 2.6.3. HIPAA 164.308(a)(1)(ii)(A), 164.308(a)(3)(ii)(B), 164.308(a)(4)(ii)(B)
(d) 2.6.4. ISO 27001 A.7.7
(e) 2.6.5.NIST SP 800-37 3.1, 3.3
(f) 2.6.6. NIST SP 800-53 AC-11, MP-2, MP-4
(g) 2,6.7. NIST Cybersecurity Framework ID.AM-6, ID.GV-4, ID.RA-3, PR.AC-2, PR.AT-1,

DE.DP-2
(h) 2.6.8. PCI 9.4.1, 12.1.1
End.
Original effective date: [add effective date established by authorized entity] (Certified by LOC on )

Technology Resources Law Rule 002 – Clear Desk/Screen
Page 3 of 3

26 of 141

Summary Report for Clear Desk Rule
Original effective date: Ten days after rule adoption.
Amendment effective date:

Name of Rule: Clear Desk
Name of law being interpreted: Technology Resources Law
Rule Number: 2
Other Laws or Rules that may be affected: Proposed Mobile device rule and proposed Workstation
security rule.
Brief Summary of the proposed rule: The Clear Desk Rule aims to enhance security and confidentiality
by ensuring that papers, digital storage devices, and screens containing sensitive or confidential
information are secured when not in use. This rule mandates that workspaces be kept clear of such
materials to prevent unauthorized access or disclosure.
Statement of Effect: Obtained after requesting from the Legislative Reference Office.
Financial Analysis: See Attached.

Note: In addition- the agency must send a written request to each entity which may be affected by the
rule- asking that they provide information about how the rule would financially affect them.
The agency must include each entity’s response in the financial analysis. If the agency does not receive a
response within 10 business days after the request is made, the financial analysis can note which entities
did not provide a response.

27 of 141

Financial Analysis for Clear Desk Rule

Start Up

Type of Cost

N/A

Description/Comment

Dollar Amount
$0.00

Personnel

N/A

$0.00

Office

N/A

$0.00

Documentation

N/A

$0.00

Estimate of time necessary for an individual
or agency to comply with the rule after
implementation

Estimated 3 months to 9 months

Other, please explain
Total Annual Net Revenue

$0.00

28 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~

GODOOO

ONEIDA

Statement of Effect
Technology Resources Law Rule No. 2 – Clear Desk/Screen
Summary
The Technology Resources Law Rule No. 2 – Clear Desk/Screen sets out to improve security and
confidentiality, whenever possible for papers, digital storage devices, and screens which contain
sensitive or confidential information.
Submitted by: Clorissa N. Leeman, Senior Staff Attorney, Legislative Reference Office
Date: March 5, 2026
Analysis by the Legislative Reference Office
The Administrative Rulemaking law provides authorized agencies the opportunity to promulgate
rules interpreting the provisions of any law enforced or administered by it; provided that, a rule
may not exceed the rulemaking authority granted under the law for which the rule is being
promulgated. [1 O.C. 106.4-1]. Rulemaking authority is defined as the delegation of authority to
authorized agencies found in the Nation’s laws, other than the Administrative Rulemaking law,
which allows authorized agencies to implement, interpret and/or enforce a law of the Nation. [1
O.C. 106.3-1(i)]. An authorized agency is defined as any board, committee, commission,
department, program or officer of the Nation that has been granted rulemaking authority.[1 O.C.
106.3-1(a)].
The Technology Resources law regulates the usage of technology resources and processed data
owned and operated by the Nation. [2 O.C. 215.1-1]. It is the policy of the Nation to provide its
community and employees access to the tools necessary to participate in a technological society.
[2 O.C. 215.1-2]. Allowing limited personal use of these tools helps enhance the quality of the
workplace and helps the Nation to retain highly qualified and skilled workers and officials, as well
as to develop the technological skills of the community. Id. Pursuant to this law, users are
permitted limited use of technology resources of the Nation for personal needs if the use does not
interfere with the authorized duties of the user or official business of the Nation. Id. The
Technology Resources law does not create a right to use technology resources of the Nation for
personal use. [2 O.C. 215.1-2(a)]. The Technology Resources law in no way limits use of
technology resources to fulfill authorized duties. [2 O.C. 215.9-1].

Page 1 of 2
A good mind. A good heart. A strong fire.

29 of 141

The Technology Resources law provides that the Digital Technology Services (“DTS”) is
delegated administrative rulemaking authority in accordance with the Administrative Rulemaking
law to promulgate rules to govern technology resources of the Nation. [2 O.C. 215.1-2(b)].
The purpose of the Technology Resources Law Rule No. 2 – Clear Desk/Screen (“the Rule”) is to
improve security and confidentiality, whenever possible for papers, digital storage devices, and
screens which contain sensitive or confidential information. [Rule 2.1-1]. The Rule addresses:
■

■

■

Digital Security Office Responsibilities [Rule 2.5];
Staff Responsibilities [Rule 2.6]; and
References [Rule 2.7].

Conclusion
There are no legal bars to adopting the Technology Resources Law Rule No. 2 – Clear
Desk/Screen.

Page 2 of 2

A good mind. A good heart. A strong fire.

~
ONEIDA

30 of 141

Title 2. Employment
Tutt~e
IEmp~oymen'lt –
= Chapter
Clhlap'lterr 215
2~5

TfECHNOlOGY
!R!E§OUC!E§ LAW
lAW
TECHNOLOGY RESOUCES
Rule
Asset Management
!Ru~e #003 –
= As$e1t
3.1 Purpose and Authority
3.2 Adoption, Amendment and Repeal
3.3 Definitions
3.4 Asset Management
3.5 Enforcement
3.6 References

3.1 Purpose and Authority
3.1-1. Purpose. The purpose of this rule is to establish a comprehensive framework for the effective
management, tracking, and security of Information Technology assets within the organization.
This ensures the protection of sensitive data, compliance with applicable laws and regulations, and
the efficient use of technology resources to support the mission and operations of the Nation.
3.1-2. Authority. The Technology Resources law delegates rulemaking authority to the Digital
Technology Services Department pursuant to the Administrative Rulemaking law.
3.2. Adoption, Amendment and Repeal
3.2-1. This rule was adopted by the Oneida Business Committee in accordance with the procedures
of the Administrative Rulemaking law.
3.2-2. This rule may be amended or repealed by the Digital Technology Services Department
and/or the Oneida Business Committee pursuant to the procedures set out in the Administrative
Rulemaking law.
3.2-3. Should a provision of this rule or the application thereof to any person or circumstances be
held as invalid, such invalidity shall not affect other provisions of this rule which are considered
to have legal force without the invalid portions.
3.2-4. In the event of a conflict between a provision of this rule and a provision of another rule,
internal policy, procedure, or other regulation; the provisions of this rule shall control.
3.2-5. This rule supersedes all prior rules, regulations, internal policies or other requirements
relating to Information Technology Asset Management.
3.3. Definitions
3.3-1. This section shall govern the definitions of words and phrases used within this rule. All
words not defined herein shall be used in their ordinary and everyday sense.
(a) “Active discovery tool” means a tool used to identify devices connected to the network.
(b) “Asset disposal” means the process of securely removing sensitive data from an asset
before disposal, based on the data’s sensitivity level (Public, Sensitive, Confidential).
(c) “Asset media” means small memory storage assets tracked by Data Owner rather than
location, including CD/DVD disks and portable storage devices (USB flash drives).
(d) “Asset tracking database” means a system used to track assets, including all
information from the Asset Transfer Form and the date of asset change. It shall be
maintained, accurate, and up-to-date.

Technology Resources Law Rule 003 – Asset Management
Page 1TI of 5
5

31 of 141

(e) “Asset transfer checklist” means a form filled out by the Data Owner and approved by
an authorized representative when an asset is transferred. It includes details such as asset
type, ID number, asset name, description, current and new locations, and data owner.
(f) “Asset types” means categories of devices that shall be tracked, including desktop
workstations, firewalls, handheld devices, mobile computers, electronic storage devices,
printers, copiers, fax machines, multifunction machines, routers, scanners, servers,
software (application and operating system), and network switches.
(g) “Asset value” means the cost threshold for tracking assets.
(h) “Data owner” means the person responsible for an asset, typically the most common
user for workstations or the primary person responsible for maintenance or supervision for
other equipment.
(i) “Digital security office” means the area responsible for approving technology used to
erase confidential data to ensure it is not readable.
(j) “DTS” means Digital Technology Services.
(k) “Enterprise software” means software used to configure systems to allow the use of
small storage devices on specific Information Systems.
(l) “Resource owners” means individuals responsible for checking the Database regularly
to ensure all applicable assets are included.
(m) “Software inventory tools” means tools used to identify and classify operating system
and application software on devices.
(n) “Storage device data owner agreement” means an agreement signed by staff to handle
portable storage devices and CD/DVD disks responsibly and in accordance with the rule.
(o) “Supported software” means software applications and operating systems currently
supported and receiving vendor updates, which are added to the Database.
(p) “Unauthorized assets” means assets not approved or tracked by the organization, which
shall be removed, quarantined, or updated in the inventory.
(q) “Unsupported software” means software that is no longer supported, which shall be
removed or classified as unsupported in the database.
3.4. Asset Management
3.4-1. Asset Types. The following devices shall be tracked if they meet the rule requirements:
(a) Desktop workstations;
(b) Firewalls;
(c) Handheld devices;
(d) Mobile computers;
(e) Electronic storage devices;
(f) Printers, copiers, fax machines, multifunction machines;
(g) Routers;
(h) Scanners;
(i) Servers;
(j) Software (application and operating system); and
(k) Network switches.
3.4-2. Asset Value. Assets with a value below a certain threshold set by Accounting shall not be
tracked. However, all data-storing assets shall be tracked, including:
(a) Hard drives;
(b) Temporary storage drives;

Technology Resources Law Rule 003 – Asset Management
Page 2 of 5

32 of 141

(c) Data tapes (including system backups); and
(d) Other storage devices like CD/DVD disks and USB flash drives are covered for
disposal and secure storage purposes.
3.4-3. Asset Media.
(a) Small memory storage assets are tracked by the data owner, not location. Enterprise
software should configure systems to allow specific Information Systems to use these
assets, including:
(1) CD/DVD disks; and
(2) Portable storage devices (USB flash drives).
(b) If permitted for staff, the data owner or area supervisor shall authorize these devices.
Staff shall handle these devices responsibly and follow the following guidelines:
(1) Do not place sensitive data on them without authorization. If sensitive data is
placed, obtain special permission and keep the device secure.
(2) Do not use these devices to transport executable programs from outside the
network without authorization and scanning with approved anti-virus and malware
scanners. Only use programs on the DTS department’s approved list.
(3) Staff shall sign the storage device data owner agreement, agreeing to handle
these devices per rule. This form is submitted when staff begin working with the
Nation’s data or receive portable storage devices or data backup drives.
3.4-4. Asset Tracking Requirements.
(a) All assets shall have a unique identifier, such as an internal tracking number or a
manufacturer-provided ID and a means to track them.
(b) An asset tracking database shall track assets, including all information from the Asset
Transfer Form and the date of asset change.
(c) The asset tracking system shall be maintained, accurate, and up-to-date, including all
hardware and software assets, whether connected to the network or not. Unauthorized
assets shall be removed, quarantined, or updated in the inventory. When an asset is
acquired, it will be assigned an ID and added to the asset tracking system.
(d) All assets shall have an assigned owner.
(e) Supported software applications and operating systems shall be added to the database.
(f) Unsupported software shall be removed or classified as unsupported.
3.4-5. Transfer Procedure.
(a) When an asset is transferred, the data owner shall complete an asset transfer checklist
and obtain approval from their supervisor or designated approver. The data owner is
responsible for the asset. For workstations, this is typically the primary user. For other
equipment, it is the individual responsible for its maintenance or oversight.
(b) The data owner shall complete the asset transfer checklist, indicating if the asset is
new, moving to a new location, being transferred to a new data owner, or being disposed
of. The following information shall be included on the asset transfer checklist:
(1) Asset Type
(2) ID number;
(3) Asset Name:
(4) Asset Description;
(5) Current Location;
(6) Designated Data Owner;
(7) New Location;

Technology Resources Law Rule 003 – Asset Management
Page 3
3 of 5
5i

33 of 141

(8) New Data Owner; and
(9) Locations of Sensitive Data.
(c) Approval. Once completed and signed by the data owner, a designated representative
shall sign the form.
(d) Data entry. The completed form is given to the database manager, who ensures the
information is entered into the database within one (1) week.
(e) Database. An active discovery tool shall identify devices connected to the network.
Software inventory tools shall classify operating system and application software. The
database shall be updated based on these tools’ results. Automated tools shall update the
database where possible. Resource owners shall regularly check the database to ensure all
applicable assets are included.
3.4-6. Asset Transfers.
(a) This rule applies to any asset transfers, including:
(1) Asset purchase;
(2) Asset relocation;
(3) Change of asset data owner (e.g., when staff leave or are replaced); and
(4) Asset disposal.
(b) In all cases, the asset transfer checklist shall be completed.
3.4-7. Asset Disposal and Repurposing.
(a) Procedures for secure disposal or repurposing of equipment and resources shall be
established before tenant assignment or jurisdictional transport.
(b) Sensitive data shall be removed before asset disposal. The user’s manager shall
determine the data’s maximum sensitivity level.
(c) Actions to be made based on data sensitivity:
(1) Public. No requirement to erase data, but normally erase using any means (e.g.,
reformatting or degaussing).
(2) Sensitive. Erase data using any means (e.g., reformatting or degaussing).
(3) Confidential. Erase data using approved technology to ensure it is unreadable,
as approved by the Digital Security Manager.
3.5. Enforcement
3.5-1. Any staff member found to have violated this rule may be subject to disciplinary action, up
to and including termination.
3.6. References
3.6-1. References include:
(a) COBIT APO01.06, APO09.03, BAI09.01, BAI09.02-03, DSS04.07, DSS05.04-05,
DSS06.06
(b) GDPR Article 25, 32
(c) HIPAA 164.308(a)(1)(ii)(B)
(d) ISO 27001 A.5.17, A.8.3-5, A.8.18
(e) NIST SP 800-37 3.1, 3.3
(f) NIST SP 800-53 CM-8, PL-4
(g) NIST Cybersecurity Framework ID.AM, PR.PT, DE.DP-2, DE.CM-1-2, RS.RP-1
(h) PCI 1.1.2

Technology Resources Law Rule 003 – Asset Management
Page 4 of 5
4 !5

34 of 141

End.
Original effective date: [add effective date established by authorized entity] (Certified by LOC on )

Technology Resources Law Rule 003 – Asset Management
Page 5
5i of 5
5i

35 of 141

Summary Report for Asset Management Rule
Original effective date: Ten days after rule adoption.
Amendment effective date:

Name of Rule: Asset Management
Name of law being interpreted: Technology Resources Law
Rule Number: 3
Other Laws or Rules that may be affected: n/a
Brief Summary of the proposed rule: Establish a comprehensive framework for the effective
management, tracking, and security of IT assets within Oneida Nation.
Statement of Effect: Obtained after requesting from the Legislative Reference Office.
Financial Analysis: See Attached.

Note: In addition- the agency must send a written request to each entity which may be affected by the
rule- asking that they provide information about how the rule would financially affect them.
The agency must include each entity’s response in the financial analysis. If the agency does not receive a
response within 10 business days after the request is made, the financial analysis can note which entities
did not provide a response.

36 of 141

Financial Analysis for Asset Management

Start Up Costs

Type of Cost

N/A

Description/Comment

Dollar Amount
$0.00

Personnel

N/A

$0.00

Office

N/A

$0.00

Documentation Costs

N/A

$0.00

Estimate of time necessary for an individual Estimated 3 months to 9 months
or agency to comply with the rule after
implementation
Other, please explain
Total Annual Net Revenue

$0.00

37 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~

GODOOO

ONEIDA

Statement of Effect
Technology Resources Law Rule No. 3 – Asset Management
Summary
The Technology Resources Law Rule No. 3 – Asset Management establish a comprehensive
framework for the effective management, tracking, and security of Information Technology assets
within the organization.
Submitted by: Clorissa N. Leeman, Senior Staff Attorney, Legislative Reference Office
Date: March 5, 2026
Analysis by the Legislative Reference Office
The Administrative Rulemaking law provides authorized agencies the opportunity to promulgate
rules interpreting the provisions of any law enforced or administered by it; provided that, a rule
may not exceed the rulemaking authority granted under the law for which the rule is being
promulgated. [1 O.C. 106.4-1]. Rulemaking authority is defined as the delegation of authority to
authorized agencies found in the Nation’s laws, other than the Administrative Rulemaking law,
which allows authorized agencies to implement, interpret and/or enforce a law of the Nation. [1
O.C. 106.3-1(i)]. An authorized agency is defined as any board, committee, commission,
department, program or officer of the Nation that has been granted rulemaking authority.[1 O.C.
106.3-1(a)].
The Technology Resources law regulates the usage of technology resources and processed data
owned and operated by the Nation. [2 O.C. 215.1-1]. It is the policy of the Nation to provide its
community and employees access to the tools necessary to participate in a technological society.
[2 O.C. 215.1-2]. Allowing limited personal use of these tools helps enhance the quality of the
workplace and helps the Nation to retain highly qualified and skilled workers and officials, as well
as to develop the technological skills of the community. Id. Pursuant to this law, users are
permitted limited use of technology resources of the Nation for personal needs if the use does not
interfere with the authorized duties of the user or official business of the Nation. Id. The
Technology Resources law does not create a right to use technology resources of the Nation for
personal use. [2 O.C. 215.1-2(a)]. The Technology Resources law in no way limits use of
technology resources to fulfill authorized duties. [2 O.C. 215.9-1].

Page 1 of 2
A good mind. A good heart. A strong fire.

38 of 141

The Technology Resources law provides that the Digital Technology Services (“DTS”) is
delegated administrative rulemaking authority in accordance with the Administrative Rulemaking
law to promulgate rules to govern technology resources of the Nation. [2 O.C. 215.1-2(b)].
The purpose of the Technology Resources Law Rule No. 3 – Asset Management (“the Rule”) is to
establish a comprehensive framework for the effective management, tracking, and security of
Information Technology assets within the organization. [Rule 3.1-1]. The Rule addresses:
■

■

■

Asset Management [Rule 3.4];
Enforcement [Rule 3.5]; and
References [Rule 3.6].

Conclusion
There are no legal bars to adopting the Technology Resources Law Rule No. 3 – Asset
Management.

Page 2 of 2

A good mind. A good heart. A strong fire.

~
ONEIDA

39 of 141

Title 2. Employment
Tutt~e
IEmp~oymen'lt –
= Chapter
Clhlap'lterr 215
2~5

TfECHNOlOGY
!R!E§OUC!E§ LAW
lAW
TECHNOLOGY RESOUCES
Rule
Security Awarcence$$
Awareness Trannnng
Training
!Ru~ce #004 –
= §ceccurntty
4.1 Purpose and Authority
4.2 Adoption, Amendment and Repeal
4.3 Definitions
4.4 Requirements & Responsibilities
4.5 Enforcement
4.6 References

4.1 Purpose and Authority
4.1-1. Purpose. A robust security program necessitates that staff are trained in security policies,
procedures, and technical controls. Oneida Nation staff who manage digital information shall
possess the skills required for their roles. The aim of this Security Awareness and Training Rule
is to ensure that security awareness and training measures safeguard Information Resources,
maintaining their availability, confidentiality, and integrity.
4.1-2. Authority. The Technology Resources Law delegates rulemaking authority to the Digital
Technology Services Department pursuant to the Administrative Rulemaking law.
4.2. Adoption, Amendment and Repeal
4.2-1. This rule was adopted by the Oneida Business Committee in accordance with the
procedures of the Administrative Rulemaking law.
4.2-2. This rule may be amended or repealed by the Digital Technology Services Department
and/or the Oneida Business Committee pursuant to the procedures set out in the Administrative
Rulemaking law.
4.2-3. Should a provision of this rule or the application thereof to any person or circumstances be
held as invalid, such invalidity shall not affect other provisions of this rule which are considered
to have legal force without the invalid portions.
4.2-4. In the event of a conflict between a provision of this rule and a provision of another rule,
internal policy, procedure, or other regulation; the provisions of this rule shall control.
4.2-5. This rule supersedes all prior rules, regulations, internal policies or other requirements
relating to security awareness training as outlined in the Technology Resources Law.
4.3. Definitions
4.3-1. This section shall govern the definitions of words and phrases used within this rule. All
words not defined herein shall be used in their ordinary and everyday sense.
(a) “Department” means the DTS Digital Technology Services department which is
responsible for overseeing information security policies and procedures.
(b) Digital Security Office: The area designated to oversee the security of Digital
Information Resources, ensuring the security program is well-supported with
adequate resources and budget.
(c) Information Resources: Digital data and information systems that are used, managed,
and protected by the organization.

Technology Resources Law Rule 004– Security Awareness Training
Page 1TI of 4
4

40 of 141

(d) Security Awareness and Training Plan (Plan): A documented strategy outlining the
process for staff security training, education, and awareness to ensure they understand
their roles and responsibilities in protecting Information Resources.
(e) Information Security Management System (ISMS): A systematic approach to
managing sensitive company information so that it remains secure. It includes people,
processes, and IT systems by applying a risk management process.
(f) Social Engineering Attacks: Manipulative tactics used by attackers to trick
individuals into divulging confidential or personal information that may be used for
fraudulent purposes. Examples include phishing, phone scams, and impersonation
calls.
(g) BYOD (Bring Your Own Device): A Rule that defines the use of personal devices
(such as smartphones, tablets, and laptops) for work purposes, which introduces
specific security risks and responsibilities.
(h) Cloud Computing Security: Measures and protocols designed to protect data,
applications, and services hosted in the cloud from threats and vulnerabilities. This
includes addressing multi-tenant environments, nationality issues, and different cloud
delivery models.
(i) Skills Gap Analysis: An assessment process to identify the difference between the
skills required for a job and the actual skills possessed by employees. This helps in
developing targeted training programs to bridge the gap.
(j) Secure Authentication: Methods used to verify the identity of a user, ensuring that
only authorized individuals can access sensitive information. This includes
passwords, biometrics, and multi-factor authentication.
(k) Security Incidents: Events that indicate a possible breach of information security
policies or failure of safeguards, which may compromise the confidentiality, integrity,
or availability of information resources.
(l) DTS Department: The department responsible for preparing and distributing
information security manuals and ensuring staff are aware of security policies and
procedures.
4.4. Requirements and Responsibilities
4.4-1. Management Responsibilities
(a) Oneida Nation management shall prioritize effective security awareness and training.
(a) Management shall implement a robust security program with a strong awareness and
training component.
(b) The Digital Security Office shall be designated to oversee the security of Digital
Information Resources.
(c) The Digital Security Office shall ensure the security program is well-supported with
adequate resources and budget.
4.4-2. Digital Security Office Responsibilities
(b) Develop, implement, and maintain a Security Awareness and Training Plan (Plan).
(c) Ensure the Plan documents the process for staff security training, education, and
awareness.
(d) Ensure staff understand their roles and responsibilities in protecting Information
Resources.

Technology Resources Law Rule 004– Security Awareness Training
Page 2 of 4

41 of 141

(e) Maintain continuous and engaging communication relevant to the information
security management system (ISMS).
4.4-3. Training and Awareness:
(a) Provide regular training, reference materials, and reminders to staff.
(b) Training topics shall include:
(1) Oneida Nation’s responsibilities for protecting Information Resources.
(2) Risks to Information Resources.
(3) Identifying social engineering attacks (e.g., phishing, phone scams).
(4) Secure use of Information Resources.
(5) Information security policies, procedures, and best practices.
4.4-4. Training Requirements:
(a) New users shall attend an approved security awareness training class within 90 days
of being granted access to Information Resources.
(b) Staff shall receive role-specific training and verify their understanding and
compliance.
(c) Staff shall be trained to identify, report, and prevent security incidents.
(d) Staff shall understand the importance of secure authentication and proper handling of
sensitive information.
(e) Security policies, procedures, and manuals shall be readily available for staff
reference.
(f) Staff shall attend annual security awareness training, with attendance records
maintained.
(g) Staff shall sign an acknowledgment of understanding Oneida Nation’s security
policies and procedures.
4.4-5. Additional Training Components:
(a) The DTS Department shall prepare and distribute information security manuals.
(b) Cloud computing security awareness training shall address multi-tenant, nationality,
and cloud delivery models.
(c) Staff shall be aware of BYOD risks and responsibilities.
(d) Staff shall understand actions for standalone, lost, and misplaced equipment.
4.4-6. Digital Security Office Duties:
(a) Conduct a skills gap analysis to identify training needs and develop an education
roadmap.
(b) Maintain a communication process for new security programs and updates.
(c) Ensure staff responsible for implementing security safeguards receive formal training.
(d) Provide periodic security reminders to keep staff updated on threats and best
practices.
(e) Collect and incorporate training feedback into future sessions.
4.5. Enforcement:
(a) Any Staff member found to have violated this rule may be subject to disciplinary
action, up to and including termination.
4.6. References:

Technology Resources Law Rule 004– Security Awareness Training
Page 3 of 4

42 of 141

a) COBIT EDM01.03, APO02.08, APO07.12-13, APO12.02, APO12.07, APO13.07,
MEA02.11
b) GDPR Article 25, 32
c) HIPAA 164.308(a)(5)(i), 164.308(a)(5)(ii)(A), 164.308(a)(5)(ii)(D)
d) ISO 27001 7.3, A.5.23, A.6.3, A.8.7, A.8.16
e) NIST SP 800-37 3.3, 3.4, 3.5, 3.7
f) NIST SP 800-53 AT-2, AT-3, CP-3, IR-2, PM-13, SI-3, SI-4(24), SR-1
g) NIST Cybersecurity Framework ID.GV-1, PR.AT-1-5, DE.DP-1, RS.RP-1, RS.MI-2
h) PCI 6.2.2, 9.1.1, 12.10.4, A3.1.4
End.
Original effective date: [add effective date established by authorized entity] (Certified by LOC on )

Technology Resources Law Rule 004– Security Awareness Training
Page 4 of 4

43 of 141

Summary Report for Security Awareness Rule
Original effective date: Ten days after rule adoption.
Amendment effective date:

Name of Rule: Security Awareness Training
Name of law being interpreted: Technology Resources Law
Rule Number: 4
Other Laws or Rules that may be affected: n/a
Brief Summary of the proposed rule: A robust security program requires that staff are trained in
security policies, procedures, and technical controls. Oneida Nation staff who manage digital
information must possess the skills required for their roles.
Statement of Effect: Obtained after requesting from the Legislative Reference Office.
Financial Analysis: See Attached.

Note: In addition- the agency must send a written request to each entity which may be affected by the
rule- asking that they provide information about how the rule would financially affect them.
The agency must include each entity’s response in the financial analysis. If the agency does not receive a
response within 10 business days after the request is made, the financial analysis can note which entities
did not provide a response.

44 of 141

Financial Analysis for Security Awareness

Start Up Costs

Type of Cost

N/A

Description/Comment

Dollar Amount
$0.00

Personnel

N/A

$0.00

Office

N/A

$0.00

Documentation Costs

N/A

$0.00

Estimate of time necessary for an individual Estimated 3 months to 9 months
or agency to comply with the rule after
implementation
Other, please explain
Total Annual Net Revenue

$0.00

45 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~

GODOOO

ONEIDA

Statement of Effect
Technology Resources Law Rule No. 4 – Security Awareness Training
Summary
The Technology Resources Law Rule No. 4 – Security Awareness Training ensure that security
awareness and training measures safeguard Information Resources, maintaining their availability,
confidentiality, and integrity.
Submitted by: Clorissa N. Leeman, Senior Staff Attorney, Legislative Reference Office
Date: March 5, 2026
Analysis by the Legislative Reference Office
The Administrative Rulemaking law provides authorized agencies the opportunity to promulgate
rules interpreting the provisions of any law enforced or administered by it; provided that, a rule
may not exceed the rulemaking authority granted under the law for which the rule is being
promulgated. [1 O.C. 106.4-1]. Rulemaking authority is defined as the delegation of authority to
authorized agencies found in the Nation’s laws, other than the Administrative Rulemaking law,
which allows authorized agencies to implement, interpret and/or enforce a law of the Nation. [1
O.C. 106.3-1(i)]. An authorized agency is defined as any board, committee, commission,
department, program or officer of the Nation that has been granted rulemaking authority.[1 O.C.
106.3-1(a)].
The Technology Resources law regulates the usage of technology resources and processed data
owned and operated by the Nation. [2 O.C. 215.1-1]. It is the policy of the Nation to provide its
community and employees access to the tools necessary to participate in a technological society.
[2 O.C. 215.1-2]. Allowing limited personal use of these tools helps enhance the quality of the
workplace and helps the Nation to retain highly qualified and skilled workers and officials, as well
as to develop the technological skills of the community. Id. Pursuant to this law, users are
permitted limited use of technology resources of the Nation for personal needs if the use does not
interfere with the authorized duties of the user or official business of the Nation. Id. The
Technology Resources law does not create a right to use technology resources of the Nation for
personal use. [2 O.C. 215.1-2(a)]. The Technology Resources law in no way limits use of
technology resources to fulfill authorized duties. [2 O.C. 215.9-1].

Page 1 of 2
A good mind. A good heart. A strong fire.

46 of 141

The Technology Resources law provides that the Digital Technology Services (“DTS”) is
delegated administrative rulemaking authority in accordance with the Administrative Rulemaking
law to promulgate rules to govern technology resources of the Nation. [2 O.C. 215.1-2(b)].
The purpose of the Technology Resources Law Rule No. 4 – Security Awareness Training (“the
Rule”) is to ensure that security awareness and training measures safeguard Information
Resources, maintaining their availability, confidentiality, and integrity. [Rule 4.1-1]. The Rule
addresses:
Requirements and Responsibilities [Rule 4.4];
Enforcement [Rule 4.5]; and
References [Rule 4.6].
■

■

■

Conclusion
There are no legal bars to adopting the Technology Resources Law Rule No. 4 – Security
Awareness Training.

Page 2 of 2

A good mind. A good heart. A strong fire.

~
ONEIDA

47 of 141

Title 2.
Tn1t~e
2. Employment
!Emp~oymen1t – Chapter
CChap1terr 215
2~5
TECHNOLOGY RESOURCES
T!ECCHNOlOGY
!R!E§OU!RCC!E§ LAW
~W
Rule
Third Party
!RUJI~e #008
#008 – Thnrrd
IParrty Providers
IPrrovnderrs
=

=

8.1 Purpose and Authority
8.2 Adoption, Amendment and Repeal
8.3 Definitions
8.4 Digital Security Dept Responsibilities
8.5 Scope
8.6 Third Party Service Provider Reqs
8.7 Enforcement
8.8 References

8.1 Purpose and Authority
8.1-1. Purpose. Third party service providers are integral to supporting Oneida Nation’s
infrastructure and information services. In some cases, these providers may collect, store, and
maintain Sensitive Information. This rule establishes guidelines to limit and control third party
service providers to minimize risks such as revenue loss, liability, loss of trust, and
embarrassment to Oneida Nation, while ensuring the responsible use of company information
and resources.
8.1-2. Authority. The Technology Resources Law delegates rulemaking authority to the Digital
Security Department pursuant to the Administrative Rulemaking law.
8.2 Adoption, Amendment and Repeal
8.2-1. This rule was adopted by the Oneida Nation Business Committee in accordance with the
procedures of the Administrative Rulemaking law.
8.2-2. This rule may be amended or repealed by the Digital Security Department and/or the
Oneida Nation Business Committee pursuant to the procedures set out in the Administrative
Rulemaking law.
8.2-3. Should a provision of this rule or the application thereof to any person or circumstances be
held as invalid, such invalidity shall not affect other provisions of this rule which are considered
to have legal force without the invalid portions.
8.2-4. In the event of a conflict between a provision of this rule and a provision of another rule,
internal policy, procedure, or other regulation; the provisions of this rule shall control.
8.2-5. This rule supersedes all prior rules, regulations, internal policies or other requirements
relating to third party providers as outlined in the Technology Resources Law.
8.3 Definitions
8.3-1. This section shall govern the definitions of words and phrases used within this rule. All
words not defined herein shall be used in their ordinary and everyday sense.
(a) Third Party Service Provider: Any external entity contracted to collect, store, process,
manage, or dispose of Oneida Nation’s information.
(b) Sensitive Information: Confidential or proprietary data owned by Oneida Nation or its
customers.
(c) Information Resources: DTS systems, networks, applications, and data managed by
Oneida Nation.

Technology Resources Law Rule 008 – Third Party Providers
Page 1TI of 4
4

48 of 141

(d) Digital Security Office: The department or personnel responsible for overseeing DTS
operations and third party assessments.
(e) Cyber Security Risk Assessment (CSRA): A process of identifying, analyzing, and
prioritizing potential threats and vulnerabilities to an organization’s information systems,
data, and digital infrastructure to reduce the likelihood and impact of cyberattacks.
8.4 Digital Security Office Responsibilities
8.4-1. The Digital Security Office shall ensure:
(a) Maintain a list of all third party service providers and their services as they relate to
digital technology.
(b) Retain records of assessments and audits of third party service providers.
(c) Assign a DTS point of contact to ensure compliance with this rule.
(d) Monitor and enforce third party adherence to applicable Oneida Nation policies and
agreements.
(e) Cyber security risk assessments are conducted during the purchasing process and
repeated as necessary such as when the scope of products, services, or technology
changes.
8.5 Scope
8.5-1. This rule applies to all Oneida Nation Staff responsible for reviewing, purchasing,
installing, operating, or maintaining digital information resources, and to all third party service
providers handling Oneida Nation information.
8.5-2. Third party service providers with remote or on-site access to Oneida Nation systems shall
comply with this rule, regardless of location.
8.6 Third Party Service Provider Requirements
8.6-1. Due Diligence.
(a) Prior to engagement, Oneida Nation Staff shall conduct due diligence on third party
service providers, including background checks, business history, and experience with
similar engagements.
8.6.2. Rule Compliance.
(a) Service providers shall comply with all applicable Oneida Nation policies, including
but not limited to:
(1) Acceptable Use Rule
(2) Password Policy
(3) Vendor Remote Access Rule
8.6.3. Agreement Specifications.
(a) Agreements with service providers shall include:
(1) Confidentiality clauses protecting Oneida Nation and customer information.
(2) Controlled access to Information Resources.
(3) Methods for protecting Information Resources.
(4) Acceptable processes for return, destruction, or disposal of Oneida Nation
information at agreement end.
(5) Restriction of information use to the purpose of the agreement only.
(6) Prohibition on using or sharing Oneida Nation information for other purposes.

Technology Resources Law Rule 008 – Third Party Providers
Page 2 of 4

49 of 141

(7) Defined service levels (SLA) and change control processes.
(b) Service providers shall notify Oneida Nation within five (5) working days of a
security breach, with Oneida Nation reserving the right to terminate the agreement. If
customer information is involved, the provider shall cover remediation costs, including
customer notifications and one year of free credit monitoring.
8.6.4. Staff Management
(a) Service providers shall provide and update a list of staff working on Oneida Nation
services within 24 hours of changes.
(b) On-site provider staff shall obtain and display Oneida Nation identification badges,
returning them upon departure.
(c) Staff handling Sensitive Information shall be cleared and have access activated only
when needed, deactivated post-service.
8.6.5. Access Controls
(a) Remote access aacounts shall be enabled only during use and disabled when not
needed, with unique credentials per client.
(b) Access to Information Systems shall be monitored and comply with the Oneida
Nation Password policy.
(c) Major activities shall be logged in the Third Party Service Provider Log, including
personnel changes, password updates, and milestones.
8.6-6. Security and Incident Reporting.
(a) Service provider personnel shall report security incidents to Oneida Nation
immediately.
(b) Incident management responsibilities shall be outlined in the agreement if applicable.
(c) Health information handling requires online and print descriptions of security and
privacy safeguards.
8.6-7. Termination Procedures.
(a) Upon staff departure or agreement termination, Sensitive Information shall be
returned or destroyed within 24 hours, with written certification provided.
(b) All Oneida Nation badges, access cards, and equipment shall be surrendered
immediately, with exceptions documented by management.
8.6-8. Auditing and Ethical Use.
(a) Service providers shall comply with state and Oneida Nation auditing requirements.
(b) Agreements shall include security controls (e.g., encryption, access restrictions) to
prevent data breaches or misuse.
8.7 Enforcement
8.7-1. Any Oneida Nation Staff member violating this rule may face disciplinary action, up to
and including termination.
8.8. References
(a) COBIT APO09.05, APO10.05, APO12.02, APO13.07, BAI02.05-06, DSS01.05,
DSS05.07
(b) GDPR Article 25, 26, 28, 32
(c) HIPAA 164.308(a)(1)(ii)(A), 164.308(b)(4), 164.502(b)(1), ARRA 13404(b), ARRA
13405(b)

Technology Resources Law Rule 008 – Third Party Providers
Page 3 of 4

50 of 141

(d) ISO 27001 8.1, A.8.12, A.8.21, A.8.30
(e) NIST SP 800-37 3.3, 3.7
(f) NIST SP 800-53 CM-4, IR-4, PM-30, PS-7, RA-9, SA-4, SA-10-12, SA-15, SA-17, SR-1
(g) NIST Cybersecurity Framework ID.AM-4-6, ID.BE-4, ID.RA-4, ID.RM-1, ID.SC-3-4,
DE.CM-6
(h) PCI 12.5.2, A1.1.1, A2.1.2-3, PCI Software Security Framework

End.
Original effective date: [add effective date established by authorized entity] (Certified by LOC on )

Technology Resources Law Rule 008 – Third Party Providers
Page 4 of 4

51 of 141

Summary Report for Third Party Providers Rule
Original effective date: Ten days after rule adoption.
Amendment effective date:

Name of Rule: Third Party Providers
Name of law being interpreted: Technology Resources Law
Rule Number: 8
Other Laws or Rules that may be affected:
Brief Summary of the proposed rule: Establish guidelines to limit and control third party service
providers to minimize risks such as revenue loss, liability, loss of trust, and embarrassment to Oneida
Nation, while ensuring the responsible use of the Tribe’sinformation and resources.
Statement of Effect: Obtained after requesting from the Legislative Reference Office.
Financial Analysis: See Attached.

Note: In addition- the agency must send a written request to each entity which may be affected by the
rule- asking that they provide information about how the rule would financially affect them.
The agency must include each entity’s response in the financial analysis. If the agency does not receive a
response within 10 business days after the request is made, the financial analysis can note which entities
did not provide a response.

52 of 141

Financial Analysis for Third Party Providers

Start Up Costs

Type of Cost

N/A

Description/Comment

Dollar Amount
$0.00

Personnel

N/A

$0.00

Office

N/A

$0.00

Documentation Costs

N/A

$0.00

Estimate of time necessary for an individual Estimated 3 months to 9 months
or agency to comply with the rule after
implementation
Other, please explain
Total Annual Net Revenue

$0.00

53 of 141

Oneida Nation

Oneida Business Committee
Legislative Operating Committee
PO Box 365 • Oneida, WI 54155-0365

Oneida-nsn.gov

~

GODOOO

ONEIDA

Statement of Effect
Technology Resources Law Rule No. 8 – Third Party Providers
Summary
The Technology Resources Law Rule No. 8 – Third Party Providers establishes guidelines to limit
and control third party service providers to minimize risks such as revenue loss, liability, loss of
trust, and embarrassment to Oneida Nation, while ensuring the responsible use of company
information and resources.
Submitted by: Clorissa N. Leeman, Senior Staff Attorney, Legislative Reference Office
Date: March 5, 2026
Analysis by the Legislative Reference Office
The Administrative Rulemaking law provides authorized agencies the opportunity to promulgate
rules interpreting the provisions of any law enforced or administered by it; provided that, a rule
may not exceed the rulemaking authority granted under the law for which the rule is being
promulgated. [1 O.C. 106.4-1]. Rulemaking authority is defined as the delegation of authority to
authorized agencies found in the Nation’s laws, other than the Administrative Rulemaking law,
which allows authorized agencies to implement, interpret and/or enforce a law of the Nation. [1
O.C. 106.3-1(i)]. An authorized agency is defined as any board, committee, commission,
department, program or officer of the Nation that has been granted rulemaking authority.[1 O.C.
106.3-1(a)].
The Technology Resources law regulates the usage of technology resources and processed data
owned and operated by the Nation. [2 O.C. 215.1-1]. It is the policy of the Nation to provide its
community and employees access to the tools necessary to participate in a technological society.
[2 O.C. 215.1-2]. Allowing limited personal use of these tools helps enhance the quality of the
workplace and helps the Nation to retain highly qualified and skilled workers and officials, as well
as to develop the technological skills of the community. Id. Pursuant to this law, users are
permitted limited use of technology resources of the Nation for personal needs if the use does not
interfere with the authorized duties of the user or official business of the Nation. Id. The
Technology Resources law does not create a right to use technology resources of the Nation for
personal use. [2 O.C. 215.1-2(a)]. The Technology Resources law in no way limits use of
technology resources to fulfill authorized duties. [2 O.C. 215.9-1].

Page 1 of 2
A good mind. A good heart. A strong fire.

54 of 141

The Technology Resources law provides that the Digital Technology Services (“DTS”) is
delegated administrative rulemaking authority in accordance with the Administrative Rulemaking
law to promulgate rules to govern technology resources of the Nation. [2 O.C. 215.1-2(b)].
The purpose of the Technology Resources Law Rule No. 8 – Third Party Providers (“the Rule”) is
to establish guidelines to limit and control third party service providers to minimize risks such as
revenue loss, liability, loss of trust, and embarrassment to Oneida Nation, while ensuring the
responsible use of company information and resources. [Rule 8.1-1]. The Rule addresses:
Digital Security Department Responsibilities [Rule 8.4];
Scope [Rule 8.5];
Third Party Service Provider Requirements [Rule 8.6];
Enforcement [Rule 8.7]; and
References [Rule 8.8].
■

■

■

■

■

Conclusion
There are no legal bars to adopting the Technology Resources Law Rule No. 8 – Third Party
Providers.

Page 2 of 2

A good mind. A good heart. A strong fire.

~
ONEIDA

55 of 141

Title 2.
rut~\¥H8f, Land Management shall
provide the applicant with the first steps for seeking approval for an easement from the BIA to include:
(a) Survey. A survey is required to determine the correct legal description for the
easement. The applicant shall collect consent to survey forms signed by the landowners
of the servient property and shall contract to have a survey completed. The legal
description generated shall be confirmed in an Engineer's Affidavit or a Surveyor's
Affadavit and provided to Land Management.
(b) Appraisal. Upon receipt of the survey information, Land Management shall draft a
scope of work to be submitted to the Department of Interior AVSO for approval to order
the appraisal. When the scope of work is approved, Land Management shall order an
appraisal from an appraiser qualified to perform appraisals on federal land. When the
appraisal is received, Land Management shall forward the appraisal to the Department of
Interior AVSO for approval and forwarding to the BIA. When an approved appraisal is
received, Land Management wi ll provide the approved appraisal to the applicant.
3.9-2. BIA Easement Application. When Land Management has all survey and appraisal
documents, Land Management shall send the BIA Easement Application to the Applicant to be
returned with any applicable Consent to Grant Easement forms, which shows the affected land
owners have reached agreement as to the purpose of the easement, the amount of consideration,
and any bonding requirements that will apply, signed by the property owners of the servient
property.
3.9----3. Environmental and Cultural Reviews. When Land Management has received the
completed application and any signed Consent to Grant Easement forms, Land Management
shall route the application to the Nation's environmental and cultural reviewers for completion of
the environmental and cu ltural reviews respectively.
3.9-4. BIA Submillal. Once the Nation's environmental and cultural reviewers have submitted
their reports to Land Management, Land Management shall forward the comp lete easement
package to the BIA to complete the processing of the easement request. Upon decision from the
BIA, the signed easement or easement denial, will be returned to Land Management and the
affected property owners by the BIA; Land Management is not responsib le for easement
processing after the complete easement package is submitted to the BIA.
3,10,

Recording Easements

3. I0-1. Recordation. Land Management shal l ensure that all easements executed in accordance
with this Rule are recorded in Oneida Nation Register G..Q[Deeds and, if for tribal trust, that the
easement also appears on the federal trust title.
End.
Original effective dale: 02-26-2025

Real Property Rule // 3 - Easements
Page 7 of7

Formatted: Indent: Left: 0"

81 of 141

Title 6. Property and Land
Real Property - Chapter 601
Rule #3 - Easements
3. I Purpose and Authority
3.2 Adoption, Amendment and Repeal
3.3 Definitions
3.4 Scope and Application
3.5 Requests for Easements on Tribal Land
3.6 Oneida Land Commission Preliminary Review
3. 7 Land Commission Final Review
3.8 Easement Administration
3.9 Requests for Easements on Individual Trust Land
3. IO Recording Easements in ONROD

3.1
Purpose and Authority
3.1-1. Purpose. To provide procedures for granting easements over, under and across tribal
lands in order to best protect the interests of the Oneida Nation. In addition, because the Nation
is a self-governance Nation, this rule also addresses how Land Management facilitates the
processing of easements on individual trust land.
3.1-2. Authority. The Real Property Law delegates rulemaking authority to the Environmental,
Land, and Agriculture Division1 and Land Commission pursuant to the Administrative
Rulemaking law.
3.2
Adoption, Amendment and Repeal
3.2-1. This rule was adopted by the Land Commission in accordance with the procedures of the
Administrative Rulemaking law.
3.2-2. This rule may be amended or repealed by the Environment, Land, and Agriculture Division
and Land Commission pursuant to the procedures set out in the Administrative Rulemaking law.
3.2-3. Should a provision of this rule or the application thereof to any person or circumstances be
held as invalid, such invalidity shall not affect other provisions of this rule which are considered
to have legal force without the invalid portions.
3.2-4. In the event of a conflict between a provision of this rule and a provision of another rule,
internal policy, procedure, or other regulation; the provisions of this rule shall control.
3.2-5. This rule supersedes all prior rules, regulations, internal policies or other requirements
relating to easements.
3.3
Defmitions
3.3-1. This section shall govern the definitions of words and phrases used within this rule
provided that the definition section of the Real Property law shall also apply hereto. All
words not defined herein shall be used in their ordinary and everyday sense.
(a) Affidavit of Completion. Means a legal document certifying as to the completion of
1 The delegation of authority in the law was to Land Management and the Land Commission, however, since the

law was adopted, Land Management has been rolled into a larger division, the Environmental, Land, and
Agriculture Division, of which Land Management is now a department without separate management from the
Division.

Real Property Rule #3 - Easements
Page I of 7

82 of 141

construction as related to the easement that acknowledges any known deviations from
stated plans, permits or other approvals.
(b) Applicant. Means the third party requesting use of the Nation's land when requesting
an easement on tribal land and means the individual trust land owner when an individual
trust land owner is requesting BIA approval of an easement on their individual trust land.
(c) A VSO. Means the Appraisal and Valuation Services Office which is the federal
administration within the Department oflnterior charged with approving and conducting
appraisals on federal land to ensure federal land transactions meet applicable fair market
value consideration requirements.
(d) Appraisal. Means an expert assessment of the value of a requested easement based on
the terms of a proposed easement.
(e) BIA. Means the Bureau of Indian Affairs, which is the federal administration within
the Department of Interior charged with overseeing the government's trust
responsibilities to indigenous governments and their citizens.
(f) Easement Negotiation Summary Form. Means the form used to aid the Land
Commission in arriving at easement request decisions which, at a minimum, includes the
appraised value of the easement, the legal description and map produced as a result of
the survey, the offered consideration and the date Land Commission approved the
easement use along with an excerpt of said meeting minutes.
(g) Engineer's Affidavit. Means a legal document completed by a licensed engineer that
certifies a legal description provided in a survey document is accurate.
(h) Grantee. Means the recipient of an easement on tribal land in accordance with this
Rule.
(i) Internal Entity. Means an entity of the Nation operating under the direction of the
Oneida Business Committee and within the management structure of the Nation.
G) Organization. Means an body of people with a particular purpose, especially a
business, other local government or association.
(k) Servient Property. Means the parcel ofland that is subject to an easement that benefits
another parcel of land.
(1) Survey. Means a document that measures and records the boundaries, elevation levels
and angles of a parcel of land.
(m) Surveyor's Affidavit. Means a legal document completed by a licensed surveyor
that certifies a legal description provided in a survey document is accurate.

3.4
Scope and Application
3 .4-1. General Applicability. The requirements of this rule shall apply to all requests for
easements on tribal land and to all individual trust land owners' requests for BIA approval of
easements on individual trust land located within the Oneida Nation reservation except that this
rule shall not apply to:
(a) Service Line Agreements. The requirements of this rule shall not apply to utility
service line agreements to cross or access the Nation's property for the purpose of
connecting a landowner's property to the main utility line. Service line agreement
templates shall be reviewed and approved by the Oneida Law Office, for legal contract
review, and the Oneida Land Commission, for content approval, on an annual basis.
Land Management staff are authorized to execute service line agreements using approved
templates without seeking Oneida Law Office or Oneida Land Commission review and

Real Property Rule #3 - Easements
Page 2 of 7

83 of 141

approval of individual service line agreements provided that no revisions are made to the
template document; if any revisions are made to the template document, the Oneida Law
Office and Oneida Land Commission must provide their respective reviews and
approvals before Land Management may execute the agreement. Land Management shall
submit all service line agreements affecting tribal trust land to the BIA for filing in the
Land Title and Records Office.
(b) Internal Entity Easement Requests. Internal requests will not be granted official
easement documents provided that, if any internal entity easement request is approved by
Oneida Land Commission, the granted easement must be platted on a recorded survey
and registered in the Geographic Land Information System (GLIS), to the extent capable.

3.5
Applications for Easements on Tribal Land
3.5-1. Application Form. Applicants shall submit requests for easements using the Tribal Land
Easement Request Form available on Land Management's website, at a minimum the form shall:
(a) Notice the requestor that there is a twenty-dollar ($20) application fee for all
applications;
(b) Notice the requestor that there is a one-hundred-dollar ($100) processing fee for
easement applications received from individuals and a five hundred ($500) for
organizations that receive preliminary approval from the Land Commission pursuant to
section 3.6;
(c) Ask what requested use is and which parcels it affects;
(d) Ask the requested duration of the requested use;
(e) Ask the requested method of communication with applicant noting a preference for
email communication; and
(f) Ask whether there is a preliminary offer of consideration for the easement or a request
for waived consideration.
(g) Note that fees are waived for easements needed for development and/or title clean up driven by
the Nation.

3.5-2. Upon receipt of an easement application, Land Management shall:
(a) Send the request to the Land Assessment Team established in the LANDBAC Rule
for feedback. The team members shall have five (5) business days to submit feedback.
(b) Order a title report for the affected parcel.
(c) Upon the close of the feedback period, prepare a recommendation explaining whether
Land Management recommends Land Commission grant the easement for the requested
use and duration for the consideration presented, or requested to be waived.
(d) Submit Land Management's easement recommendation to the next available Oneida
Land Commission agenda along with all feedback from the Land Assessment Team.
(e) Provide the applicant with a copy of Land Management's recommendation and the
date the recommendation will be the Land Commission agenda date with notice that Land
Management will inform the applicant of the Oneida Land Commission's decision within
five (5) business days of the meeting date.

3.6
Land Commission's Preliminary Review
3.6-1. Land Commission Easement Decision. When Land Management's easement
recommendation is presented to Land Commission, the Land Commission shall:
(a) Approve or deny the recommendation with regard to the requested use;
(b) Approve or deny the recommendation with regard to the requested use duration;
and
Real Property Rule #3 - Easements
Page 3 of 7

84 of 141

(c) Approve or deny the recommendation with regard to the requestor's proposed
consideration. Specifically, if Land Commission wishes to waive the requirement for an
appraisal and accept the offered consideration, Land Commission must inform Land
Management at this meeting. If the use and duration are approved, then Land
Management shall proceed with processing the application and collect the processing fee.
3.6-2. Notice ofEasement Decision. Land Management shall notify the Applicant of the Land
Commission's decisions concerning the easement request within five (5) business days of the
Land Commission's meeting date.
(a) Notice ofEasement Decision Letter. Land Management shall draft Notice of
Easement Decision Letter for applicants that explains the decisions made by the
Oneida Land Commission.
(1) If the land commission approved proceeding, the letter shall also include:
(A) Notice the applicant that the Applicant is responsible for all survey
and appraisal costs and that survey and appraisal costs, regardless of
whether an easement is ultimately granted or not;
(i) Survey. A survey is required to determine the correct legal
description for the easement and that there are specific surveying
requirements applicable to trust land. The legal description
generated shall be confirmed in an Engineer's Affidavit or a
Surveyor's Affidavit submitted to Land Management. Land
Management shall advise whether a Land Use License is required
to allow the applicant to complete the survey.
(ii) Appraisal. Land Management shall notice the applicant that
Land Commission will not accept consideration offers for less than
the full appraised value plus fifteen percent (15%) for any
requested use that does not directly benefit the Oneida Nation
and/or its citizens. For fee land, the Applicant may use any
appraisal company to complete the appraisal, provided that, the
Nation may elect to procure a competing appraisal for the purpose
of price negotiation. The Nation orders appraisals on trust land.
Land Management shall draft a scope of work to be submitted to
the United States Department of Interior, Appraisal and Valuation
Services Office for approval. When the scope of work is approved,
Land Management shall order an appraisal from an appraiser
qualified to perform appraisals on federal land. When the appraisal
is received, Land Management shall forward the appraisal to the
Department of Interior AVSO for approval and forwarding to BIA.
(B) Land Management shall notice the applicant that Land Commission
will not accept consideration offers for less than the full appraised value
plus 15% for any requested use that does not directly benefit the Oneida
Nation and/or its citizens;
(C) Notice that a Land Use Permit will be required from the Oneida
Zoning Department and contact information for said department;
(D)Iftrust land, the BIA easement application documents;
(E) If the applicant is an organization and not an individual, notice that the
applicant must submit:
(i) Organizational documents and by-laws;
Real Property Rule #3 - Easements
Page 4 of 7

85 of 141

(ii) Evidence of Authority of Officers to Execute Papers form;
(F) Notice that an Affidavit of Completion is required to be submitted
when the work is complete.

3. 7
Land Commission Final Review
3. 7-1. Land Management Preparation for Land Commission. When the required documents are
returned to Land Management in accordance with the noticed requirements, then Land
Management shall:
(a) Draft Easement. If the easement is on trust land, send the applicant the BIA template
easement and inform the applicant that revisions may not be requested to the template. If
the easement is on fee land, then Land Management shall prepare the draft easement
using the Oneida Easement Template approved by the Oneida Land Commission.
(b) Consideration Confirmation. If Land Commission has not approved a waiver of
consideration, then Land Management shall ask the applicant to confirm their offered
consideration for the easement after having received the appraisal and shall remind
applicants that Land Commission will not accept consideration offers for less than the
full appraised value plus 15% for any requested use that does not directly benefit the
Oneida Nation and/or its citizens.
(c) Land Commission Submittal. When the Applicant returns the required information,
submit an Easement Negotiation Summary Form to Land Commission for their
consideration, except for easements on trust land where Land Commission has already
waived consideration. Easements on trust land where Land Commission has already
waived consideration do not need to go back to Land Commission and can be routed to
the BIA for their final review and approval with the minutes from the Oneida Land
Commission meeting approving the easement use, duration and waiver of consideration.
3.7-2. Land Commission Review of Trust Land Easements. If the easement is for use of tribal
trust land, then there are not revisions to consider to the easement document, so the only thing
for Land Commission to consider is the offered consideration. Land Commission shall decide if
it accepts the offered consideration or if it will counter with a different request for consideration.
(a) Consideration Agreement Not Reached. If the applicant and Land Commission do not
eventually reach an agreement as to consideration, then no easement shall be granted.
(b) Consideration Agreement Reached. If the applicant and Land Commission do reach
an agreement as to consideration, then Land Management shall forward the minutes from
Land Commission's meetings approving the easement use, duration and consideration to
the BIA for easement processing. When the BIA processing is complete, so long as there
is nothing preventing approval, then consideration will have to be paid to the Nation with
the Nation's confirmation of payment sent to the BIA before the BIA will return the
approved and executed easement document to the parties.
3. 7-3. Land Commission Review ofFee Land Easements. If the easement is for use of tribal fee
land, then Land Management shall ensure that the easement document is in final draft form and
consideration information from the applicant is presented to the Land Commission. Land
Commission shall make decisions as to the minimum consideration the Land Commission will
accept and whether Land Commission will require any revisions to the easement document.
(a) Agreement Not Reached. If the applicant and Land Commission do not eventually
reach an agreement as to consideration and easement documents, then no easement shall
be granted.

Real Property Rule #3 - Easements
Page 5 of 7

86 of 141

(b) Agreement Reached. If the applicant and Land Commission do reach an agreement as
to consideration and easement documents, then Land Management shall complete the
easement documents pursuant to Land Commission's direction and circulate for
signature. Land Management shall provide the applicant with the signed easement
documents only after receiving payment of the agreed upon consideration.
3.7-4. Authority to Sign Easement Documents. The Environmental, Land, and Agriculture
Division Director and/or his or her designee is hereby authorized to sign easement documents
approved in accordance with this Rule on behalf of the Oneida Land Commission.

3.8.
Easement Administration
3.8-1. Land Data Sheet. All executed easements shall be forwarded to the Land Management
Deputy Director and/or his or her designee for the information to be entered into the affected
parcel's Land Data Sheet. Any party with an agreement affecting the same parcel shall be
noticed of the executed easement affecting the parcel by the Deputy Director, provided that
where a parcel has both internal and external end users (i.e. a parcel assigned to Comprehensive
Housing Division to be used for residential offerings by the Nation and thereafter assigned to an
Oneida citizen in a residential lease) the Deputy Director shall notice the internal user and it will
be the internal user's responsibility to notice their users.
3.8-2. Easement Corrections. In the event there is any error in an easement the erroneous
easement must be extinguished and a new easement entered in accordance with the processes in
this Rule, provided that the old easement may be extinguished within the new easement.
3.8-3. Affidavit of Completion. Upon receipt of the Affidavit of Completion, Land Management
shall schedule an inspection of the affected parcel and shall document the parcel's condition at
the time the work is complete.
(a) If there were bonding requirements and Land Management reports the parcel is in
acceptable condition, Land Management shall return funds held as bond in accordance
with the easement documents.
(b) If there were bonding requirements and Land Management reports the parcel is not in
acceptable condition, Land Management shall afford the grantee an opportunity to make
the necessary repairs to return the parcel to acceptable condition. If the grantee does not
make the repairs within the timeframe allotted, Land Management may deduct the
replacement cost of repairs from the funds held for bonding and shall return the
remainder of the bonding deposit to the grantee. To the extent the repair cost of the
damages exceeds the amount of bond held, the Nation may pursue the remainder of
damages using any available means of debt collection wherein the grantee shall pay
attorneys fees and other collection costs as incurred.
3.8-4. Easement Close-Out. When an easement term is complete, Land Management shall
ensure the easement has been removed from title and shall inspect and record the condition of the
property at easement expiration. If the property was not left in acceptable condition, Land
Management shall consult the Oneida Law Office for potential enforcement of contractual terms
that may have survived expiration of the easement.
3.9.
Requests for Easements on Individual Trust Land
3.9-1. Individual Trust Land Easement Requests. If the Nation receives a request for an easement on
individual trust land, the Nation shall provide the request to the individual trust land owners. Land
owners consent will be requested upon negotiated value. Land Management w i 11 c o m p i 1 e
information to be submitted to Bureau of Indian Affairs for their
d i s c r e t i o n a r y a p p r o v a 1.
Land Management shall provide the applicant with the first
Real Property Rule #3 - Easements
Page 6 of 7

87 of 141

steps for seeking approval for an easement from the BIA to include:
(a) Survey. A survey is required to determine the correct legal description for the
easement. The applicant shall collect consent to survey forms signed by the landowners
of the servient property and shall contract to have a survey completed. The legal
description generated shall be confirmed in an Engineer's Affidavit or a Surveyor's
Affidavit and provided to Land Management.
(b) Appraisal. Upon receipt of the survey information, Land Management shall draft a
scope of work to be submitted to the Department of Interior AVSO for approval to order
the appraisal. When the scope of work is approved, Land Management shall order an
appraisal from an appraiser qualified to perform appraisals on federal land. When the
appra

[Text truncated at 120,000 characters. The full text is on the page linked above.]

---

Source: Frix Law Library, https://www.frixlaw.com/law-library/documents/tribal%3Aoneida_nation%3A9a7271f98d7dc899. Public record. Not legal advice.
