Loading chat...

CA AB2135

Bill

Status

Passed

9/29/2022

Primary Sponsor

Jacqui Irwin

Click for details

Origin

State Assembly

2021-2022 Session

AI Summary

  • Requires state agencies not already subject to information security oversight to adopt and implement policies based on National Institute of Standards and Technology (NIST) Special Publication 800-53 Revision 5 and Federal Information Processing Standards (FIPS) 199 and 200.

  • Mandates state agencies perform comprehensive independent security assessments every two years, with costs funded by the agency being assessed; agencies may contract with the Military Department or qualified vendors for assessments.

  • Requires state agencies to certify annually by February 1 to the President pro Tempore of the Senate and Speaker of the Assembly that they comply with all adopted information security policies, including a plan of action and milestones.

  • Protects certification information and security assessment records from public disclosure, allowing sharing only with Legislature members and employees at the discretion of legislative leadership.

  • Authorizes the Military Department to conduct independent security assessments of local educational agencies at their request, with results disclosed only to the requesting agency and California Cybersecurity Integration Center.

Legislative Description

Information security.

Last Action

Chaptered by Secretary of State - Chapter 773, Statutes of 2022.

9/29/2022

Committee Referrals

Appropriations6/22/2022
Judiciary6/15/2022
Governmental Organization6/1/2022
Rules5/26/2022
Appropriations4/27/2022
Accountability and Administrative Review4/20/2022
Privacy and Consumer Protection2/24/2022

Full Bill Text

No bill text available