California 2021-2022 Regular Session

California Senate Bill SB1001 Compare Versions

OldNewDifferences
1-Enrolled September 09, 2022 Passed IN Senate August 31, 2022 Passed IN Assembly August 31, 2022 Amended IN Assembly August 22, 2022 Amended IN Assembly August 15, 2022 Amended IN Senate March 16, 2022 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Senate Bill No. 1001Introduced by Senator MinFebruary 14, 2022An act to add and repeal Section 8586.6 of the Government Code, relating to consumer protection.LEGISLATIVE COUNSEL'S DIGESTSB 1001, Min. California Cybersecurity Integration Center: consumer protection: credit reporting.Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.This bill would require the center, by December 31, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 8586.6 is added to the Government Code, to read:8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
1+Amended IN Assembly August 22, 2022 Amended IN Assembly August 15, 2022 Amended IN Senate March 16, 2022 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Senate Bill No. 1001Introduced by Senator MinFebruary 14, 2022An act to add and repeal Section 8586.6 of the Government Code, relating to consumer protection.LEGISLATIVE COUNSEL'S DIGESTSB 1001, as amended, Min. California Cybersecurity Integration Center: consumer protection: credit reporting.Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.This bill would require the center, by December 31, 2023, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. Section 8586.6 is added to the Government Code, to read:8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
22
3- Enrolled September 09, 2022 Passed IN Senate August 31, 2022 Passed IN Assembly August 31, 2022 Amended IN Assembly August 22, 2022 Amended IN Assembly August 15, 2022 Amended IN Senate March 16, 2022 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Senate Bill No. 1001Introduced by Senator MinFebruary 14, 2022An act to add and repeal Section 8586.6 of the Government Code, relating to consumer protection.LEGISLATIVE COUNSEL'S DIGESTSB 1001, Min. California Cybersecurity Integration Center: consumer protection: credit reporting.Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.This bill would require the center, by December 31, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Amended IN Assembly August 22, 2022 Amended IN Assembly August 15, 2022 Amended IN Senate March 16, 2022 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION Senate Bill No. 1001Introduced by Senator MinFebruary 14, 2022An act to add and repeal Section 8586.6 of the Government Code, relating to consumer protection.LEGISLATIVE COUNSEL'S DIGESTSB 1001, as amended, Min. California Cybersecurity Integration Center: consumer protection: credit reporting.Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.This bill would require the center, by December 31, 2023, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
44
5- Enrolled September 09, 2022 Passed IN Senate August 31, 2022 Passed IN Assembly August 31, 2022 Amended IN Assembly August 22, 2022 Amended IN Assembly August 15, 2022 Amended IN Senate March 16, 2022
5+ Amended IN Assembly August 22, 2022 Amended IN Assembly August 15, 2022 Amended IN Senate March 16, 2022
66
7-Enrolled September 09, 2022
8-Passed IN Senate August 31, 2022
9-Passed IN Assembly August 31, 2022
107 Amended IN Assembly August 22, 2022
118 Amended IN Assembly August 15, 2022
129 Amended IN Senate March 16, 2022
1310
1411 CALIFORNIA LEGISLATURE 20212022 REGULAR SESSION
1512
1613 Senate Bill
1714
1815 No. 1001
1916
2017 Introduced by Senator MinFebruary 14, 2022
2118
2219 Introduced by Senator Min
2320 February 14, 2022
2421
2522 An act to add and repeal Section 8586.6 of the Government Code, relating to consumer protection.
2623
2724 LEGISLATIVE COUNSEL'S DIGEST
2825
2926 ## LEGISLATIVE COUNSEL'S DIGEST
3027
31-SB 1001, Min. California Cybersecurity Integration Center: consumer protection: credit reporting.
28+SB 1001, as amended, Min. California Cybersecurity Integration Center: consumer protection: credit reporting.
3229
33-Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.This bill would require the center, by December 31, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.
30+Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.This bill would require the center, by December 31, 2023, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.
3431
3532 Existing law establishes the California Cybersecurity Integration Center within the Office of Emergency Services, the primary mission of which is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or computer networks in the state. Existing law requires the center to serve as the central organizing hub of state governments cybersecurity activities and to coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, and nongovernmental organizations.
3633
37-This bill would require the center, by December 31, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.
34+This bill would require the center, by December 31, 2023, 2024, to submit to the Legislature, as specified, a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud, including requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed, and specified tactics related to using alternatives to social security numbers as authenticators.
3835
3936 ## Digest Key
4037
4138 ## Bill Text
4239
43-The people of the State of California do enact as follows:SECTION 1. Section 8586.6 is added to the Government Code, to read:8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
40+The people of the State of California do enact as follows:SECTION 1. Section 8586.6 is added to the Government Code, to read:8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
4441
4542 The people of the State of California do enact as follows:
4643
4744 ## The people of the State of California do enact as follows:
4845
49-SECTION 1. Section 8586.6 is added to the Government Code, to read:8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
46+SECTION 1. Section 8586.6 is added to the Government Code, to read:8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
5047
5148 SECTION 1. Section 8586.6 is added to the Government Code, to read:
5249
5350 ### SECTION 1.
5451
55-8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
52+8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
5653
57-8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
54+8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
5855
59-8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
56+8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:(1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.(2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.(3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.(b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.(2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.
6057
6158
6259
63-8586.6. (a) On or before December 31, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:
60+8586.6. (a) On or before December 31, 2023, 2024, the California Cybersecurity Integration Center shall submit to the Legislature a report on the feasibility of, and the potential benefits, risks, and costs of, requiring credit reporting bureaus and lenders to implement new information security tactics that protect consumers from financial fraud. The report shall include, but not be limited to, an assessment of the feasibility of, and the potential benefits, risks, and costs of, utilizing all of the following tactics:
6461
6562 (1) Requiring credit reporting bureaus or lenders to use multifactor authentication each time a new line of credit is opened or a credit report is accessed.
6663
6764 (2) Utilization of statewide alternatives to social security numbers as authenticators in determining an individuals identity.
6865
6966 (3) Requiring credit reporting bureaus or lenders to accept alternatives to social security numbers as authenticators in determining an individuals identity.
7067
7168 (b) (1) A report to be submitted pursuant to subdivision (a) shall be submitted in compliance with Section 9795.
7269
7370 (2) Pursuant to Section 10231.5, this section is repealed on January 1, 2027.