Loading chat...

IL HB3030

Bill

Status

Introduced

2/18/2021

Primary Sponsor

Keith Wheeler

Click for details

Origin

House of Representatives

102nd General Assembly

AI Summary

  • Creates the Cybersecurity Compliance Act establishing an affirmative defense for businesses that implement written cybersecurity programs with administrative, technical, and physical safeguards conforming to industry-recognized frameworks.

  • Defines "covered entities" as any business accessing, maintaining, or processing personal information or restricted information, and establishes requirements for their cybersecurity programs based on entity size, complexity, information sensitivity, and available resources.

  • Recognizes multiple industry-standard cybersecurity frameworks including NIST standards, FedRAMP, Center for Internet Security Controls, ISO/IEC 27000 series, HIPAA, Gramm-Leach-Bliley Act, FISMA, and PCI data security standards as meeting compliance requirements.

  • Provides covered entities satisfying program requirements with an affirmative defense against tort claims alleging failure to implement reasonable information security controls resulted in data breaches involving personal or restricted information.

  • Requires covered entities to update their programs within one year when recognized frameworks are revised or amended; does not create a private right of action under the Act.

Legislative Description

CYBERSECURITY COMPLIANCE ACT

Last Action

Rule 19(a) / Re-referred to Rules Committee

3/27/2021

Committee Referrals

Rules3/27/2021
Judiciary - Civil3/16/2021
Rules2/19/2021

Full Bill Text

No bill text available