Loading chat...
NY S01139
Bill
Status
6/11/2025
Primary Sponsor
Kristen Gonzalez
Click for details
AI Summary
-
Requires all New York governmental entities (state and local agencies, public authorities, SUNY, CUNY, counties, cities, towns, villages) to consider implementing multifactor authentication for network access to email, cloud storage, web applications, databases, and servers, excluding judiciary and legislatures
-
Defines multifactor authentication as requiring two or more credential types: knowledge-based (passwords/PINs), possession-based (security tokens, key fobs, smartphone apps), or biometric information (fingerprints, facial geometry, iris patterns, voice, gait)
-
Prohibits governmental entities from requiring biometric information for network access, and bans selling, monetizing, or sharing biometric data with law enforcement without a warrant
-
Mandates all government websites encrypt data exchanges between web servers and browsers, requiring HTTPS-level protection for all transfers
-
Authorizes the Office of Information Technology Services to establish technical standards using federal guidelines (NIST, FedRAMP, FISMA, DFARS), including accessibility provisions for individuals with disabilities, and allows two-year waivers for entities upon application
-
Takes effect one year after becoming law, with rulemaking authority effective immediately
Legislative Description
Requires governmental entities to, whenever possible and feasible, consider implementing multifactor authentication for local and remote network access; requires public websites to encrypt all exchanges and to comply with privacy standards.
Last Action
REPORTED AND COMMITTED TO FINANCE
2/25/2026