Arkansas 2023 Regular Session

Arkansas House Bill HB1555 Compare Versions

OldNewDifferences
11 Stricken language would be deleted from and underlined language would be added to present law.
2-Act 510 of the Regular Session
32 *ANS240* 03-14-2023 09:29:09 ANS240
43
54 State of Arkansas As Engrossed: H3/14/23 1
65 94th General Assembly A Bill 2
76 Regular Session, 2023 HOUSE BILL 1555 3
87 4
98 By: Representative S. Meeks 5
109 By: Senator J. English 6
1110 7
1211 For An Act To Be Entitled 8
1312 AN ACT TO AMEND THE REQUIREMENTS FOR MEE TINGS TO 9
1413 ADDRESS A CYBERSECUR ITY INCIDENT INVOLVI NG, OR A 10
1514 CYBERATTACK ON, A PU BLIC ENTITY; TO CLAR IFY THAT 11
1615 CERTAIN INTERNAL POL ICIES OR INTERNAL GU IDELINES 12
1716 CONCERNING A CYBERSE CURITY INCIDENT INVO LVING, OR A 13
1817 CYBERATTACK ON, A PUBLIC ENT ITY ARE NOT CONSIDER ED 14
1918 RULES; TO ALLOW THE JOINT COMMITTEE ON A DVANCED 15
2019 COMMUNICATIONS AND I NFORMATION TECHNOLOG Y TO MEET IN 16
2120 CLOSED MEETINGS ON M ATTERS CONCERNING A CYBERSECURITY 17
2221 INCIDENT INVOLVING, OR A CYBERATTACK ON, A PUBLIC 18
2322 ENTITY; AND FOR OTHER PURPOS ES. 19
2423 20
2524 21
2625 Subtitle 22
2726 TO REGULATE MEETINGS, INTERNAL POLICIES 23
2827 AND GUIDELINES, AND REPORTS TO ADDRESS A 24
2928 CYBERSECURITY INCIDENT INVOLVING, OR A 25
3029 CYBERATTACK ON, A PUBLIC ENTITY. 26
3130 27
3231 28
3332 BE IT ENACTED BY THE GENERAL ASSEMBLY OF THE STATE OF ARKANSAS: 29
3433 30
3534 SECTION 1. Arkansas Code § 10 -3-309(b)(1)(B), concerning the 31
3635 definition of "rule" used for review and approval of state agency rules, is 32
3736 amended to add an additional subdivision to read as follows: 33
3837 (v) An internal policy or the intern al guidelines of 34
3938 a state agency related to a cybersecurity incident involving, or a 35
4039 cyberattack on, a state agency. 36 As Engrossed: H3/14/23 HB1555
4140
4241 2 03-14-2023 09:29:09 ANS240
4342
4443
4544 1
4645 SECTION 2. Arkansas Code Title 10, Chapter 3, Subchapter 17, is 2
4746 amended to add an additional section to read as follows: 3
4847 10-3-1708. Joint Committee on Advanced Communications and Information 4
4948 Technology — Cybersecurity incidents and cyberattacks — Meetings in executive 5
5049 session — Definitions. 6
5150 (a) As used in this section: 7
5251 (1) "County" means any county of this state; 8
5352 (2) "Municipality" means: 9
5453 (A) A city of the first class; 10
5554 (B) A city of the second class; or 11
5655 (C) An incorporated town; 12
5756 (3) "Public entity" means: 13
5857 (A) A county; 14
5958 (B) A municipality; 15
6059 (C) A school district; or 16
6160 (D) The state; and 17
6261 (4) "School district" means a school district or open enrollment 18
6362 public charter school in this state. 19
6463 (b)(1) The meetings of the Joint Committee on Advanced Communications 20
6564 and Information Technology to review a cybersecurity incident involving, or a 21
6665 cyberattack on, a public entity are closed and are exempt from public 22
6766 observance under the Freedom of Information Act of 1967, § 25 -19-101 et seq. 23
6867 (2) Any member of the General Assembly may attend the closed 24
6968 hearing under subdivision (b)(1) of this section of the Joint Co mmittee on 25
7069 Advanced Communications and Information Technology. 26
7170 (3) An individual may attend a closed hearing under subdivision 27
7271 (b)(1) of this section at the invitation of either of the cochairs of the 28
7372 Joint Committee on Advanced Communications and Infor mation Technology. 29
7473 (4) The Joint Committee on Advanced Communications and 30
7574 Information Technology shall not disclose any information concerning an 31
7675 internal policy or the internal guidelines established to address a 32
7776 cybersecurity incident involving, or a cyberattack on, a public entity. 33
7877 (5) If the Joint Committee on Advanced Communications and 34
7978 Information Technology meets in a closed meeting under subdivision (b)(1) of 35
8079 this section, the Joint Committee on Advanced Communications and Information 36 As Engrossed: H3/14/23 HB1555
8180
8281 3 03-14-2023 09:29:09 ANS240
8382
8483
8584 Technology may discuss only a cybersecurity incident involving, or 1
8685 cyberattack on, a public entity or any cybersecurity policy. 2
8786 (c)(1) An internal policy or the internal guidelines that are 3
8887 established concerning a cybersecurity incident involving, or a cyberattack 4
8988 on, a public entity is: 5
9089 (A) Confidential; and 6
9190 (B) Exempt from the Freedom of Information Act of 1967, § 7
9291 25-19-101 et seq. 8
9392 (2) An internal policy or the internal guidelines of a public 9
9493 entity established to address a cybersecurity incident involving, or a 10
9594 cyberattack on, a public entity are not considered a rule under § 10 -3-309 or 11
9695 the Arkansas Administrative Procedure Act, § 25 -15-201 et seq. 12
9796 13
9897 SECTION 3. Arkansas Code § 25 -15-202(9)(B), concerning the definition 14
9998 of "rule" under the Arkansas Administrative Procedure Act, is amended to add 15
10099 an additional subdivision to read as follows: 16
101100 (viii) An internal policy or the internal guidelines 17
102101 of a state agency related to a cybersecurity incident involving, or a 18
103102 cyberattack on, a stat e agency. 19
104103 20
105104 /s/S. Meeks 21
106105 22
107106 23
108-APPROVED: 4/10/23 24
107+ 24
109108 25
110109 26
111110 27
112111 28
113112 29
114113 30
115114 31
116115 32
117116 33
118117 34
119118 35
120119 36