California 2017-2018 Regular Session

California Assembly Bill AB650

Introduced
2/14/17  
Introduced
2/14/17  
Refer
3/2/17  
Refer
3/2/17  
Failed
2/1/18  

Caption

Director of Technology: state baseline security controls.

Impact

The implementation of AB 650 would affect state law by providing a structured framework for state agencies to follow regarding information technology security. It prohibits individual agencies from establishing security controls that fall below the designated state baseline security controls. This regulatory oversight is likely to improve information security across state government, reduce risks related to data breaches, and promote efficiency in technology resource management.

Summary

Assembly Bill 650, introduced by Assembly Member Dahle, focuses on enhancing baseline security controls for state technology under the Department of Technology within the Government Operations Agency. The bill mandates that the Director of Technology creates, tailors, and reviews these security controls in accordance with emerging industry standards, particularly those set by the National Institute of Standards and Technology (NIST). This measure aims to ensure that state agencies comply with a uniform set of security protocols, thereby enhancing the state's cybersecurity posture.

Contention

While the bill is primarily aimed at strengthening security protocols, there may be concerns regarding the flexibility of state agencies to adapt these controls based on unique departmental needs. Critics could argue that a one-size-fits-all approach might not adequately address specific requirements of various state entities. The requirement for compliance with state baseline security controls could also introduce additional administrative burdens, particularly for smaller departments with limited resources.

Companion Bills

No companion bills found.

Previously Filed As

CA AB2777

Office of Information Security: Baseline Information Security Score.

CA SB74

Office of Wildfire Technology Research and Development.

CA SB398

Department of Technology: advanced technology: research.

CA AB609

Office of Wildfire Technology Research and Development: report on new technologies.

CA AB749

State agencies: information security: uniform standards.

CA SB1454

Bureau of Security and Investigative Services: sunset.

CA AB1667

Department of Technology: California Cybersecurity Awareness and Education Council.

CA AB2115

Controlled substances: clinics.

CA AB642

Law enforcement agencies: facial recognition technology.

CA SB313

Department of Technology: Office of Artificial Intelligence: state agency public interface: use of AI.

Similar Bills

CA AB475

Department of Technology.

CA AB754

Regional notification centers: GIS data: excavations.

CA AB2209

California Geographic Information Office.

FL H1511

Cybersecurity

PA HB883

In boards and offices, providing for information technology; establishing the Office of Information Technology and the Information Technology Fund; providing for administrative and procurement procedures and for the Joint Cybersecurity Oversight Committee; imposing duties on the Office of Information Technology; providing for administration of Pennsylvania Statewide Radio Network; and imposing penalties.

MS HB1491

Cloud Center of Excellence; establish for phased-in cloud computing and storage by state agencies and governing authorities.

PA HB1219

In boards and offices, providing for information technology; establishing the Office of Information Technology and the Information Technology Fund; providing for administrative and procurement procedures and for the Joint Cybersecurity Oversight Committee; imposing duties on the Office of Information Technology; providing for administration of Pennsylvania Statewide Radio Network; and imposing penalties.

PA SB284

In boards and offices, providing for information technology; establishing the Office of Information Technology and the Information Technology Fund; providing for administrative and procurement procedures and for the Joint Cybersecurity Oversight Committee; imposing duties on the Office of Information Technology; providing for administration of Pennsylvania Statewide Radio Network; and imposing penalties.