California 2017-2018 Regular Session

California Assembly Bill AB1306 Compare Versions

OldNewDifferences
1-Enrolled September 15, 2017 Passed IN Senate September 14, 2017 Passed IN Assembly September 14, 2017 Amended IN Senate September 08, 2017 Amended IN Senate September 01, 2017 Amended IN Senate July 18, 2017 Amended IN Assembly April 06, 2017 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION Assembly Bill No. 1306Introduced by Assembly Member ObernolteFebruary 17, 2017An act to add Section 8586.5 to the Government Code, relating to emergency services.LEGISLATIVE COUNSEL'S DIGESTAB 1306, Obernolte. California Cybersecurity Integration Center.Existing law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others. The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC. The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 8586.5 is added to the Government Code, to read:8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.
1+Amended IN Senate September 08, 2017 Amended IN Senate September 01, 2017 Amended IN Senate July 18, 2017 Amended IN Assembly April 06, 2017 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION Assembly Bill No. 1306Introduced by Assembly Member ObernolteFebruary 17, 2017An act to add Section 8586.5 to the Government Code, relating to emergency services.LEGISLATIVE COUNSEL'S DIGESTAB 1306, as amended, Obernolte. California Cybersecurity Integration Center.(1)ExistingExisting law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others. The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC. The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.(2)Existing law, the California Public Records Act, requires state and local agencies to make their records available for public inspection, unless an exemption from disclosure applies.This bill would prohibit the Cal-CSIC from sharing or disclosing information voluntarily obtained from private sector companies.(3)Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 8586.5 is added to the Government Code, to read:8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.(3)Release to the public any information that is voluntarily provided by private sector entities.SEC. 2.The Legislature finds and declares that Section 1 of this act, which adds Section 8586.5 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to promote voluntary information sharing by private sector entities, that may contain proprietary or sensitive information that is vital to the effective operation of the California Cybersecurity Integration Center, and to protect that information once it is received, it is necessary that public disclosure of the private sector information be prohibited.
22
3- Enrolled September 15, 2017 Passed IN Senate September 14, 2017 Passed IN Assembly September 14, 2017 Amended IN Senate September 08, 2017 Amended IN Senate September 01, 2017 Amended IN Senate July 18, 2017 Amended IN Assembly April 06, 2017 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION Assembly Bill No. 1306Introduced by Assembly Member ObernolteFebruary 17, 2017An act to add Section 8586.5 to the Government Code, relating to emergency services.LEGISLATIVE COUNSEL'S DIGESTAB 1306, Obernolte. California Cybersecurity Integration Center.Existing law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others. The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC. The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Amended IN Senate September 08, 2017 Amended IN Senate September 01, 2017 Amended IN Senate July 18, 2017 Amended IN Assembly April 06, 2017 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION Assembly Bill No. 1306Introduced by Assembly Member ObernolteFebruary 17, 2017An act to add Section 8586.5 to the Government Code, relating to emergency services.LEGISLATIVE COUNSEL'S DIGESTAB 1306, as amended, Obernolte. California Cybersecurity Integration Center.(1)ExistingExisting law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others. The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC. The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.(2)Existing law, the California Public Records Act, requires state and local agencies to make their records available for public inspection, unless an exemption from disclosure applies.This bill would prohibit the Cal-CSIC from sharing or disclosing information voluntarily obtained from private sector companies.(3)Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
44
5- Enrolled September 15, 2017 Passed IN Senate September 14, 2017 Passed IN Assembly September 14, 2017 Amended IN Senate September 08, 2017 Amended IN Senate September 01, 2017 Amended IN Senate July 18, 2017 Amended IN Assembly April 06, 2017
5+ Amended IN Senate September 08, 2017 Amended IN Senate September 01, 2017 Amended IN Senate July 18, 2017 Amended IN Assembly April 06, 2017
66
7-Enrolled September 15, 2017
8-Passed IN Senate September 14, 2017
9-Passed IN Assembly September 14, 2017
107 Amended IN Senate September 08, 2017
118 Amended IN Senate September 01, 2017
129 Amended IN Senate July 18, 2017
1310 Amended IN Assembly April 06, 2017
1411
1512 CALIFORNIA LEGISLATURE 20172018 REGULAR SESSION
1613
1714 Assembly Bill No. 1306
1815
1916 Introduced by Assembly Member ObernolteFebruary 17, 2017
2017
2118 Introduced by Assembly Member Obernolte
2219 February 17, 2017
2320
2421 An act to add Section 8586.5 to the Government Code, relating to emergency services.
2522
2623 LEGISLATIVE COUNSEL'S DIGEST
2724
2825 ## LEGISLATIVE COUNSEL'S DIGEST
2926
30-AB 1306, Obernolte. California Cybersecurity Integration Center.
27+AB 1306, as amended, Obernolte. California Cybersecurity Integration Center.
3128
32-Existing law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others. The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC. The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.
29+(1)ExistingExisting law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others. The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC. The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.(2)Existing law, the California Public Records Act, requires state and local agencies to make their records available for public inspection, unless an exemption from disclosure applies.This bill would prohibit the Cal-CSIC from sharing or disclosing information voluntarily obtained from private sector companies.(3)Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.
30+
31+(1)Existing
32+
33+
3334
3435 Existing law authorizes the Governor to make, amend, and rescind orders and regulations to implement the California Emergency Services Act. The act requires the Governor to coordinate the State Emergency Plan and those programs necessary for the mitigation of the effects of an emergency in this state. The act creates within the office of the Governor the Office of Emergency Services, which is responsible for the states emergency and disaster response services, as specified.
3536
3637 By Executive order in 2015, the Governor directed the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), with its primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state.
3738
3839 The Executive order, among other things, required that the Cal-CSIC be comprised of representatives from various entities, and that it develop a statewide cybersecurity strategy informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices.
3940
4041 This bill would establish in statute the Cal-CSIC within the Office of Emergency Services to develop a statewide cybersecurity strategy for California in coordination with the Cybersecurity Task Force. The bill would provide that Cal-CSIC would have the same primary mission as Cal-CSIC as created by Executive order. The bill would require Cal-CSIC to include, but not be limited to, representatives from the Office of Emergency Services, the Office of Information Security in the Department of Technology, the State Threat Assessment Center, the Department of the California Highway Patrol, the Military Department, the Office of the Attorney General, the California Health and Human Services Agency, and others.
4142
4243 The bill would incorporate language of the Executive order to, among other things, require Cal-CSIC to coordinate with the California State Threat Assessment System and the United States Department of Homeland Security, establish a cyber incident response team, and safeguard the privacy of individuals sensitive information. The bill would also direct all state departments and agencies to ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the Cal-CSIC.
4344
4445 The bill would authorize the Governor to suspend the operations of the Cal-CSIC if federal funding for its continued operation is unavailable. The bill would prohibit the Cal-CSIC from requiring private sector companies to share information but would permit voluntary sharing.
4546
47+(2)Existing law, the California Public Records Act, requires state and local agencies to make their records available for public inspection, unless an exemption from disclosure applies.
48+
49+
50+
51+This bill would prohibit the Cal-CSIC from sharing or disclosing information voluntarily obtained from private sector companies.
52+
53+
54+
55+(3)Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.
56+
57+
58+
59+This bill would make legislative findings to that effect.
60+
61+
62+
4663 ## Digest Key
4764
4865 ## Bill Text
4966
50-The people of the State of California do enact as follows:SECTION 1. Section 8586.5 is added to the Government Code, to read:8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.
67+The people of the State of California do enact as follows:SECTION 1. Section 8586.5 is added to the Government Code, to read:8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.(3)Release to the public any information that is voluntarily provided by private sector entities.SEC. 2.The Legislature finds and declares that Section 1 of this act, which adds Section 8586.5 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:In order to promote voluntary information sharing by private sector entities, that may contain proprietary or sensitive information that is vital to the effective operation of the California Cybersecurity Integration Center, and to protect that information once it is received, it is necessary that public disclosure of the private sector information be prohibited.
5168
5269 The people of the State of California do enact as follows:
5370
5471 ## The people of the State of California do enact as follows:
5572
56-SECTION 1. Section 8586.5 is added to the Government Code, to read:8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.
73+SECTION 1. Section 8586.5 is added to the Government Code, to read:8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.(3)Release to the public any information that is voluntarily provided by private sector entities.
5774
5875 SECTION 1. Section 8586.5 is added to the Government Code, to read:
5976
6077 ### SECTION 1.
6178
62-8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.
79+8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.(3)Release to the public any information that is voluntarily provided by private sector entities.
6380
64-8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.
81+8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.(3)Release to the public any information that is voluntarily provided by private sector entities.
6582
66-8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.
83+8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).(b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.(c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:(1) Governors Office of Emergency Services.(2) Department of Technology, Office of Information Security.(3) State Threat Assessment Center.(4) Department of the California Highway Patrol.(5) Military Department.(6) Office of the Attorney General.(7) California Health and Human Services Agency.(8) California Utilities Emergency Association.(9) California State University.(10) University of California.(11) California Community Colleges.(12) United States Department of Homeland Security.(13) United States Federal Bureau of Investigation.(14) United States Secret Service.(15) United States Coast Guard.(16) Other members as designated by the Director of the Governors Office of Emergency Services.(d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:(1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.(2) Assess risks to critical infrastructure and information technology networks.(3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.(4) Enable cross-sector coordination and sharing of recommended best practices and security measures.(5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.(g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.(h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.(i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.(j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:(1) Duplicate the efforts of other governmental agencies.(2) Require involuntary information sharing by private sector entities.(3)Release to the public any information that is voluntarily provided by private sector entities.
6784
6885
6986
7087 8586.5. (a) There is established within the Governors Office of Emergency Services the California Cybersecurity Integration Center, which shall develop a statewide cybersecurity strategy for California as set forth in subdivision (e).
7188
7289 (b) The primary mission of the California Cybersecurity Integration Center shall be to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.
7390
7491 (c) The California Governors Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations. The California Cybersecurity Integration Center shall be comprised of representatives from all of the following organizations:
7592
7693 (1) Governors Office of Emergency Services.
7794
7895 (2) Department of Technology, Office of Information Security.
7996
8097 (3) State Threat Assessment Center.
8198
8299 (4) Department of the California Highway Patrol.
83100
84101 (5) Military Department.
85102
86103 (6) Office of the Attorney General.
87104
88105 (7) California Health and Human Services Agency.
89106
90107 (8) California Utilities Emergency Association.
91108
92109 (9) California State University.
93110
94111 (10) University of California.
95112
96113 (11) California Community Colleges.
97114
98115 (12) United States Department of Homeland Security.
99116
100117 (13) United States Federal Bureau of Investigation.
101118
102119 (14) United States Secret Service.
103120
104121 (15) United States Coast Guard.
105122
106123 (16) Other members as designated by the Director of the Governors Office of Emergency Services.
107124
108125 (d) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall do all of the following:
109126
110127 (1) Provide warnings of cyber attacks to government agencies and nongovernmental partners and coordinate information sharing among these entities.
111128
112129 (2) Assess risks to critical infrastructure and information technology networks.
113130
114131 (3) Prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks.
115132
116133 (4) Enable cross-sector coordination and sharing of recommended best practices and security measures.
117134
118135 (5) Support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.
119136
120137 (e) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy is also intended to strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.
121138
122139 (f) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also provide assistance to law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and to agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented on the California Cybersecurity Integration Center.
123140
124141 (g) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals; safeguards sensitive information; preserves business confidentiality; and enables public officials to detect, investigate, respond to, and prevent cyber attacks that threaten public health and safety, economic stability, and national security.
125142
126143 (h) All state departments and agencies shall ensure compliance with existing information security and privacy policies, promote awareness of information security standards with their workforce, and assist the California Governors Office of Emergency Services and the California Cybersecurity Integration Center.
127144
128145 (i) The Governor may, by executive order, suspend the operations of the California Cybersecurity Integration Center if federal funds for its continued operation are not available. The suspension shall remain in effect only until federal funds for the operation of the California Cybersecurity Integration Center become available.
129146
130147 (j) In carrying out its mission, the California Cybersecurity Integration Center shall not do any of the following:
131148
132149 (1) Duplicate the efforts of other governmental agencies.
133150
134151 (2) Require involuntary information sharing by private sector entities.
152+
153+(3)Release to the public any information that is voluntarily provided by private sector entities.
154+
155+
156+
157+
158+
159+The Legislature finds and declares that Section 1 of this act, which adds Section 8586.5 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:
160+
161+
162+
163+In order to promote voluntary information sharing by private sector entities, that may contain proprietary or sensitive information that is vital to the effective operation of the California Cybersecurity Integration Center, and to protect that information once it is received, it is necessary that public disclosure of the private sector information be prohibited.