Loading chat...

IL HB5204

Bill

Status

Introduced

2/14/2020

Primary Sponsor

Keith Wheeler

Click for details

Origin

House of Representatives

101st General Assembly

AI Summary

  • Creates the Cybersecurity Compliance Act establishing an affirmative defense for covered entities that maintain written cybersecurity programs with administrative, technical, and physical safeguards conforming to industry-recognized frameworks.

  • Defines "covered entity" as any business accessing, maintaining, communicating, or processing personal or restricted information through systems in or outside Illinois.

  • Requires cybersecurity programs designed to protect information security and confidentiality, defend against anticipated threats, and prevent unauthorized access likely to cause identity theft or fraud.

  • Accepts compliance with six specified industry frameworks including NIST standards, FedRAMP, Center for Internet Security Controls, ISO/IEC 27000, and PCI data security standards, with one-year grace periods when frameworks are revised.

  • Provides no private right of action under the Act; covered entities must scale their programs based on entity size, complexity, activity scope, information sensitivity, available tools, and resources.

Legislative Description

CYBERSECURITY LEGAL DEFENSE

Last Action

Rule 19(b) / Re-referred to Rules Committee

6/23/2020

Committee Referrals

Rules6/23/2020
Commercial Law2/26/2020
Judiciary - Civil2/25/2020
Rules2/18/2020

Full Bill Text

No bill text available