Loading chat...

HI SB1478

Bill

Status

Engrossed

3/7/2023

Primary Sponsor

Angus McKelvey

Click for details

Origin

Senate

2024 Regular Session

AI Summary

  • Establishes an offensive cybersecurity program within the office of enterprise technology services to analyze cybersecurity threats, evaluate intelligence, promote awareness, conduct penetration testing, and implement proactive security measures for state and county agencies.

  • Requires state and county agencies to disclose cybersecurity incidents affecting confidentiality, integrity, or availability of information systems expeditiously, including breaches, malware, denial of service attacks, ransom demands, identity theft, and incidents costing over $10,000 in remediation.

  • Mandates the office of enterprise technology services complete penetration testing on all state and county agency information technology systems by January 1, 2026, assess vulnerabilities using the common vulnerability scoring system, and work with agencies to address vulnerabilities scoring above 3.9.

  • Requires the chief information officer to submit a report to the legislature no later than twenty days prior to each regular session detailing disclosed cybersecurity incidents, their status, and any response or remediation actions taken.

  • Appropriates funds for fiscal years 2023-2024 and 2024-2025 to establish the offensive cybersecurity program with necessary software, services, and full-time equivalent positions; effective date June 30, 3000.

Legislative Description

Relating To Offensive Cybersecurity.

Appropriation ($)

Last Action

Carried over to 2024 Regular Session.

12/11/2023

Committee Referrals

Finance3/22/2023
Higher Education & Technology3/9/2023
Ways and Means2/15/2023
Labor and Technology1/30/2023

Full Bill Text

No bill text available