California 2021-2022 Regular Session

California Assembly Bill AB953 Compare Versions

OldNewDifferences
1-Amended IN Assembly March 17, 2021 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Assembly Bill No. 953Introduced by Assembly Member KileyFebruary 17, 2021An act to add Section 11093.8 to the Government Code, relating to state government. An act to add Section 711.5 to the Fish and Game Code, relating to environmental quality.LEGISLATIVE COUNSEL'S DIGESTAB 953, as amended, Kiley. Information security: state entities. California Environmental Quality Act: Department of Fish and Wildlife: review of environmental documents: revenue and cost tracking and accounting.The California Environmental Quality Act (CEQA) requires a lead agency, as defined, to prepare, or cause to be prepared, and certify the completion of an environmental impact report on a project that it proposes to carry out or approve that may have a significant effect on the environment or to adopt a negative declaration if it finds that the project will not have that effect. CEQA also requires a lead agency to prepare a mitigated negative declaration for a project that may have a significant effect on the environment if revisions in the project would avoid or mitigate that effect and there is no substantial evidence that the project, as revised, would have a significant effect on the environment. CEQA requires the lead agency to consult with a public agency that is a responsible agency or a trustee agency during the environmental review process.Existing law authorizes the Department of Fish and Wildlife to impose and collect a filing fee to defray the costs of managing and protecting fish and wildlife trust resources, including, but not limited to, consulting with other public agencies, reviewing environmental documents, recommending mitigation measures, developing monitoring requirements for purposes of CEQA, and other activities protecting those trust resources identified in the review pursuant to CEQA.This bill would require the department to separately track and account for all revenues collected under the above filing fee provision and all costs incurred in its role as a responsible agency or trustee agency under CEQA.Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office. This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YESNO Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 711.5 is added to the Fish and Game Code, to read:711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.SECTION 1.Section 11093.8 is added to the Government Code, to read:11093.8.Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a)Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b)Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c)Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIII B of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIII B of the California Constitution.
1+CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Assembly Bill No. 953Introduced by Assembly Member KileyFebruary 17, 2021 An act to add Section 11093.8 to the Government Code, relating to state government. LEGISLATIVE COUNSEL'S DIGESTAB 953, as introduced, Kiley. Information security: state entities.Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office. This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 11093.8 is added to the Government Code, to read:11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
22
3- Amended IN Assembly March 17, 2021 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Assembly Bill No. 953Introduced by Assembly Member KileyFebruary 17, 2021An act to add Section 11093.8 to the Government Code, relating to state government. An act to add Section 711.5 to the Fish and Game Code, relating to environmental quality.LEGISLATIVE COUNSEL'S DIGESTAB 953, as amended, Kiley. Information security: state entities. California Environmental Quality Act: Department of Fish and Wildlife: review of environmental documents: revenue and cost tracking and accounting.The California Environmental Quality Act (CEQA) requires a lead agency, as defined, to prepare, or cause to be prepared, and certify the completion of an environmental impact report on a project that it proposes to carry out or approve that may have a significant effect on the environment or to adopt a negative declaration if it finds that the project will not have that effect. CEQA also requires a lead agency to prepare a mitigated negative declaration for a project that may have a significant effect on the environment if revisions in the project would avoid or mitigate that effect and there is no substantial evidence that the project, as revised, would have a significant effect on the environment. CEQA requires the lead agency to consult with a public agency that is a responsible agency or a trustee agency during the environmental review process.Existing law authorizes the Department of Fish and Wildlife to impose and collect a filing fee to defray the costs of managing and protecting fish and wildlife trust resources, including, but not limited to, consulting with other public agencies, reviewing environmental documents, recommending mitigation measures, developing monitoring requirements for purposes of CEQA, and other activities protecting those trust resources identified in the review pursuant to CEQA.This bill would require the department to separately track and account for all revenues collected under the above filing fee provision and all costs incurred in its role as a responsible agency or trustee agency under CEQA.Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office. This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YESNO
3+ CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Assembly Bill No. 953Introduced by Assembly Member KileyFebruary 17, 2021 An act to add Section 11093.8 to the Government Code, relating to state government. LEGISLATIVE COUNSEL'S DIGESTAB 953, as introduced, Kiley. Information security: state entities.Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office. This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: YES
44
5- Amended IN Assembly March 17, 2021
65
7-Amended IN Assembly March 17, 2021
6+
7+
88
99 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION
1010
1111 Assembly Bill
1212
1313 No. 953
1414
1515 Introduced by Assembly Member KileyFebruary 17, 2021
1616
1717 Introduced by Assembly Member Kiley
1818 February 17, 2021
1919
20-An act to add Section 11093.8 to the Government Code, relating to state government. An act to add Section 711.5 to the Fish and Game Code, relating to environmental quality.
20+ An act to add Section 11093.8 to the Government Code, relating to state government.
2121
2222 LEGISLATIVE COUNSEL'S DIGEST
2323
2424 ## LEGISLATIVE COUNSEL'S DIGEST
2525
26-AB 953, as amended, Kiley. Information security: state entities. California Environmental Quality Act: Department of Fish and Wildlife: review of environmental documents: revenue and cost tracking and accounting.
26+AB 953, as introduced, Kiley. Information security: state entities.
2727
28-The California Environmental Quality Act (CEQA) requires a lead agency, as defined, to prepare, or cause to be prepared, and certify the completion of an environmental impact report on a project that it proposes to carry out or approve that may have a significant effect on the environment or to adopt a negative declaration if it finds that the project will not have that effect. CEQA also requires a lead agency to prepare a mitigated negative declaration for a project that may have a significant effect on the environment if revisions in the project would avoid or mitigate that effect and there is no substantial evidence that the project, as revised, would have a significant effect on the environment. CEQA requires the lead agency to consult with a public agency that is a responsible agency or a trustee agency during the environmental review process.Existing law authorizes the Department of Fish and Wildlife to impose and collect a filing fee to defray the costs of managing and protecting fish and wildlife trust resources, including, but not limited to, consulting with other public agencies, reviewing environmental documents, recommending mitigation measures, developing monitoring requirements for purposes of CEQA, and other activities protecting those trust resources identified in the review pursuant to CEQA.This bill would require the department to separately track and account for all revenues collected under the above filing fee provision and all costs incurred in its role as a responsible agency or trustee agency under CEQA.Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office. This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.
29-
30-The California Environmental Quality Act (CEQA) requires a lead agency, as defined, to prepare, or cause to be prepared, and certify the completion of an environmental impact report on a project that it proposes to carry out or approve that may have a significant effect on the environment or to adopt a negative declaration if it finds that the project will not have that effect. CEQA also requires a lead agency to prepare a mitigated negative declaration for a project that may have a significant effect on the environment if revisions in the project would avoid or mitigate that effect and there is no substantial evidence that the project, as revised, would have a significant effect on the environment. CEQA requires the lead agency to consult with a public agency that is a responsible agency or a trustee agency during the environmental review process.
31-
32-Existing law authorizes the Department of Fish and Wildlife to impose and collect a filing fee to defray the costs of managing and protecting fish and wildlife trust resources, including, but not limited to, consulting with other public agencies, reviewing environmental documents, recommending mitigation measures, developing monitoring requirements for purposes of CEQA, and other activities protecting those trust resources identified in the review pursuant to CEQA.
33-
34-This bill would require the department to separately track and account for all revenues collected under the above filing fee provision and all costs incurred in its role as a responsible agency or trustee agency under CEQA.
28+Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office. This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.This bill would make legislative findings to that effect.The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.This bill would provide that no reimbursement is required by this act for a specified reason.
3529
3630 Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires an entity within the executive branch that is under the direct authority of the Governor to comply with the information security and privacy policies, standards, and procedures issued by the office.
3731
38-
39-
4032 This bill would require state agencies not covered by the provisions described above to adopt and implement comparable information security and privacy policies, standards, and procedures, perform a security assessment at least every 3 years to determine compliance with the entirety of the adopted information security standards, and confidentially submit certification of compliance with the adopted standards, and, if applicable, corrective actions plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
41-
42-
4333
4434 Because the required certification would be made under penalty of perjury, the bill would expand the crime of perjury and impose a state-mandated local program.
4535
46-
47-
4836 Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.
49-
50-
5137
5238 This bill would make legislative findings to that effect.
5339
54-
55-
5640 The California Constitution requires the state to reimburse local agencies and school districts for certain costs mandated by the state. Statutory provisions establish procedures for making that reimbursement.
5741
58-
59-
6042 This bill would provide that no reimbursement is required by this act for a specified reason.
61-
62-
6343
6444 ## Digest Key
6545
6646 ## Bill Text
6747
68-The people of the State of California do enact as follows:SECTION 1. Section 711.5 is added to the Fish and Game Code, to read:711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.SECTION 1.Section 11093.8 is added to the Government Code, to read:11093.8.Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a)Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b)Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c)Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIII B of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIII B of the California Constitution.
48+The people of the State of California do enact as follows:SECTION 1. Section 11093.8 is added to the Government Code, to read:11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
6949
7050 The people of the State of California do enact as follows:
7151
7252 ## The people of the State of California do enact as follows:
7353
74-SECTION 1. Section 711.5 is added to the Fish and Game Code, to read:711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.
54+SECTION 1. Section 11093.8 is added to the Government Code, to read:11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
7555
76-SECTION 1. Section 711.5 is added to the Fish and Game Code, to read:
56+SECTION 1. Section 11093.8 is added to the Government Code, to read:
7757
7858 ### SECTION 1.
7959
80-711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.
60+11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
8161
82-711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.
62+11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
8363
84-711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.
64+11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
8565
8666
8767
88-711.5. (a) The department shall track and account for all revenues collected under Section 711.4 for the review of environmental documents in the departments capacity as a responsible agency or trustee agency under the California Environmental Quality Act (Division 13 (commencing with Section 21000) of the Public Resources Code).
89-
90-(b) The department shall track and account for all costs incurred in its role of a responsible agency or trustee agency under the California Environmental Quality Act.
91-
92-(c) The tracking and accounting of the revenues and costs required under this section shall be separate from all other revenues and costs of the department.
93-
94-
95-
96-
97-
98-Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:
68+11093.8. Every state agency, as defined in Section 11000, that is not included in the definition of state entities contained in subdivision (e) of Section 11546.1 shall do all of the following:(a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).(b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).(c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
9969
10070 (a) Adopt and implement information security and privacy policies, standards, and procedures that are comparable to those established by the Chief of the Office of Information Security pursuant to Chapter 5.7 (commencing with Section 11549).
10171
102-
103-
10472 (b) Perform, or cause to be performed, an information security assessment at least every three years to determine compliance with the entirety of the information security standards adopted pursuant to subdivision (a).
105-
106-
10773
10874 (c) Confidentially submit certification of compliance with the standards adopted pursuant to subdivision (a), and, if applicable, corrective action plans to address outstanding deficiencies, to the Assembly Privacy and Consumer Protection Committee.
10975
76+SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.
11077
78+SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.
11179
80+SEC. 2. The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:
11281
113-
114-
115-
116- The Legislature finds and declares that Section 1 of this act, which adds Section 11093.8 to the Government Code, imposes a limitation on the publics right of access to the meetings of public bodies or the writings of public officials and agencies within the meaning of Section 3 of Article I of the California Constitution. Pursuant to that constitutional provision, the Legislature makes the following findings to demonstrate the interest protected by this limitation and the need for protecting that interest:
117-
118-
82+### SEC. 2.
11983
12084 The state has a interest in protecting its information technology systems from intrusion, thus, information regarding the specific vulnerabilities of those systems must be protected.
12185
86+SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
12287
88+SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
12389
90+SEC. 3. No reimbursement is required by this act pursuant to Section 6 of Article XIIIB of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIIIB of the California Constitution.
12491
125-
126- No reimbursement is required by this act pursuant to Section 6 of Article XIII B of the California Constitution because the only costs that may be incurred by a local agency or school district will be incurred because this act creates a new crime or infraction, eliminates a crime or infraction, or changes the penalty for a crime or infraction, within the meaning of Section 17556 of the Government Code, or changes the definition of a crime within the meaning of Section 6 of Article XIII B of the California Constitution.
92+### SEC. 3.