Loading chat...

NY A07331

Bill

Status

Introduced

5/17/2023

Primary Sponsor

Steven Otis

Click for details

Origin

Assembly

2023-2024 General Assembly

AI Summary

  • Requires every governmental entity to implement multifactor authentication whenever possible and feasible for local and remote network access to email accounts, cloud storage, web applications, networks, databases, and servers.

  • Defines multifactor authentication as using two or more types of identification credentials including knowledge-based (passwords/PINs), possession-based (security tokens/smartphones), and inherence-based credentials (fingerprints/facial recognition).

  • Prohibits governmental entities from requiring inherence-based credentials for network access and bans selling, monetizing, or sharing biometric data with law enforcement without a warrant.

  • Directs the Office of Technology to establish technical standards referencing National Institute of Standards and Technology, FedRAMP, FISMA, and DFARS guidelines, and allows waivers valid for no longer than two years.

  • Requires all governmental entity websites to encrypt all data exchanges between web servers and browsers unless equivalent security measures are provided.

Legislative Description

Requires governmental entities to, whenever possible and feasible, consider implementing multifactor authentication for local and remote network access; requires public websites to encrypt all exchanges and to comply with privacy standards.

Last Action

ordered to third reading rules cal.447

6/5/2024

Committee Referrals

Rules6/5/2024
Ways and Means5/21/2024
Science and Technology5/16/2024
Governmental Employees5/17/2023

Full Bill Text

No bill text available