Loading chat...

HI SB1478

Bill

Status

Engrossed

3/7/2023

Primary Sponsor

Angus McKelvey

Click for details

Origin

Senate

2023 Regular Session

AI Summary

SB 1478 Summary

  • Establishes an offensive cybersecurity program within the Office of Enterprise Technology Services to analyze threats, evaluate intelligence, promote awareness, conduct penetration testing, and implement proactive security measures across state and county agencies.

  • Requires state and county agencies to report cybersecurity incidents affecting confidentiality, integrity, or availability of systems to the office expediently, including breaches, malware, denial of service attacks, ransom demands, identity theft, and incidents costing over $10,000 in remediation.

  • Mandates the chief information officer submit a report to the legislature no later than 20 days before each regular session listing all disclosed cybersecurity incidents, their status, and remediation efforts.

  • Requires the office to complete initial penetration testing on all agency information technology systems and assess vulnerabilities using the Common Vulnerability Scoring System by January 1, 2026, with agencies addressing vulnerabilities scoring above 3.9.

  • Appropriates unspecified amounts for fiscal years 2023-2024 and 2024-2025 for software, services, and full-time equivalent positions necessary to establish the program; effective January 1, 2050.

Legislative Description

Relating To Offensive Cybersecurity.

Appropriation ($)

Last Action

Passed Second Reading as amended in HD 1 and referred to the committee(s) on FIN with none voting aye with reservations; none voting no (0) and Representative(s) Kitagawa excused (1).

3/22/2023

Committee Referrals

Finance3/22/2023
Higher Education & Technology3/9/2023
Ways and Means2/15/2023
Labor and Technology1/30/2023

Full Bill Text

No bill text available