Loading chat...

CA AB869

Bill

Status

Engrossed

6/2/2025

Primary Sponsor

Jacqui Irwin

Click for details

Origin

State Assembly

2025-2026 Regular Session

AI Summary

  • Requires all California state agencies to implement Zero Trust architecture for all data, hardware, software, and systems, achieving "Advanced" maturity by June 1, 2026 and "Optimal" maturity by June 1, 2030 based on the CISA Maturity Model

  • Mandates prioritization of multifactor authentication for all system and data access, enterprise endpoint detection and response solutions, and robust logging practices for security investigations

  • Directs the Chief of the Office of Information Security to develop uniform technology policies and standards for Zero Trust implementation in the State Administrative Manual and Statewide Information Management Manual

  • Requires updated annual reporting on agencies' progress toward Zero Trust maturity, including completed steps, high-impact security activities not yet completed, and implementation schedules

  • Applies to University of California only if the Regents adopt these provisions by resolution

Legislative Description

State agencies: information security: Zero Trust architecture.

Last Action

In committee: Held under submission.

8/29/2025

Committee Referrals

Appropriations7/8/2025
Governmental Organization6/11/2025
Rules6/3/2025
Appropriations4/2/2025
Privacy and Consumer Protection3/10/2025

Full Bill Text

No bill text available