California 2023-2024 Regular Session

California Assembly Bill AB1023 Compare Versions

OldNewDifferences
1-Assembly Bill No. 1023 CHAPTER 555 An act to amend Section 8586.5 of the Government Code, relating to school security. [ Approved by Governor October 08, 2023. Filed with Secretary of State October 08, 2023. ] LEGISLATIVE COUNSEL'S DIGESTAB 1023, Papan. California Cybersecurity Integration Center: school cybersecurity.Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), to be composed of representatives from the specified organizations, with a primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.This bill would require Cal-CSIC to include representatives from the State Department of Education.Existing law requires Cal-CSIC to serve as the central organizing hub of the state governments cybersecurity activities and coordinate information sharing with, and share cyber threat information received from, specified public and private entities. Existing law also requires a school district, county office of education, or charter school to report any cyberattack, as defined, impacting more than 500 pupils or personnel to Cal-CSIC.This bill would explicitly include school districts, county offices of education, and charter schools among the specified entities with which Cal-CSIC coordinates information sharing, including cyber threat information.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. (a) The Legislature finds and declares all of the following:(1) School districts, county offices of education, and charter schools are increasingly facing a broad range of cyberthreats and ransomware attacks. For many local educational agencies, it is not a matter of if they will be subject to a cybersecurity attack on their school information system, but when will one occur.(2) Cyberattacks can render local educational agencies unable to conduct the day-to-day business of educating pupils. Successful attacks on local educational agencies have resulted in financial and learning loss, along with the exposure of private pupil data.(3) There are over 1,000 local educational agencies in California, collecting and maintaining data related to almost 6,000,000 pupils, their families, and school employees. Much of the data local educational agencies collect and maintain is sensitive and protected by federal and state law. Although local educational agencies take proactive steps to protect this data, they remain vulnerable to cyberattacks.(4) Currently, the California Cybersecurity Integration Center (Cal-CSIC) serves as the central organizing hub of the state governments cybersecurity preparedness and response activities and coordinates cyber intelligence and information sharing.(5) Due to the vast amount and great sensitivity of pupil data collected and maintained by local educational agencies, they need guidance and information to allow them to better prepare for the inevitable next cyberattack.(b) It is, therefore, the intent of the Legislature for Cal-CSIC to provide guidance on issues of cybersecurity and preparedness to school districts, county offices of education, and charter schools.SEC. 2. Section 8586.5 of the Government Code is amended to read:8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
1+Enrolled September 08, 2023 Passed IN Senate September 06, 2023 Passed IN Assembly May 18, 2023 Amended IN Assembly March 23, 2023 CALIFORNIA LEGISLATURE 20232024 REGULAR SESSION Assembly Bill No. 1023Introduced by Assembly Member PapanFebruary 15, 2023 An act to amend Section 8586.5 of the Government Code, relating to school security. LEGISLATIVE COUNSEL'S DIGESTAB 1023, Papan. California Cybersecurity Integration Center: school cybersecurity.Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), to be composed of representatives from the specified organizations, with a primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.This bill would require Cal-CSIC to include representatives from the State Department of Education.Existing law requires Cal-CSIC to serve as the central organizing hub of the state governments cybersecurity activities and coordinate information sharing with, and share cyber threat information received from, specified public and private entities. Existing law also requires a school district, county office of education, or charter school to report any cyberattack, as defined, impacting more than 500 pupils or personnel to Cal-CSIC.This bill would explicitly include school districts, county offices of education, and charter schools among the specified entities with which Cal-CSIC coordinates information sharing, including cyber threat information.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO Bill TextThe people of the State of California do enact as follows:SECTION 1. (a) The Legislature finds and declares all of the following:(1) School districts, county offices of education, and charter schools are increasingly facing a broad range of cyberthreats and ransomware attacks. For many local educational agencies, it is not a matter of if they will be subject to a cybersecurity attack on their school information system, but when will one occur.(2) Cyberattacks can render local educational agencies unable to conduct the day-to-day business of educating pupils. Successful attacks on local educational agencies have resulted in financial and learning loss, along with the exposure of private pupil data.(3) There are over 1,000 local educational agencies in California, collecting and maintaining data related to almost 6,000,000 pupils, their families, and school employees. Much of the data local educational agencies collect and maintain is sensitive and protected by federal and state law. Although local educational agencies take proactive steps to protect this data, they remain vulnerable to cyberattacks.(4) Currently, the California Cybersecurity Integration Center (Cal-CSIC) serves as the central organizing hub of the state governments cybersecurity preparedness and response activities and coordinates cyber intelligence and information sharing.(5) Due to the vast amount and great sensitivity of pupil data collected and maintained by local educational agencies, they need guidance and information to allow them to better prepare for the inevitable next cyberattack.(b) It is, therefore, the intent of the Legislature for Cal-CSIC to provide guidance on issues of cybersecurity and preparedness to school districts, county offices of education, and charter schools.SEC. 2. Section 8586.5 of the Government Code is amended to read:8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
22
3- Assembly Bill No. 1023 CHAPTER 555 An act to amend Section 8586.5 of the Government Code, relating to school security. [ Approved by Governor October 08, 2023. Filed with Secretary of State October 08, 2023. ] LEGISLATIVE COUNSEL'S DIGESTAB 1023, Papan. California Cybersecurity Integration Center: school cybersecurity.Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), to be composed of representatives from the specified organizations, with a primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.This bill would require Cal-CSIC to include representatives from the State Department of Education.Existing law requires Cal-CSIC to serve as the central organizing hub of the state governments cybersecurity activities and coordinate information sharing with, and share cyber threat information received from, specified public and private entities. Existing law also requires a school district, county office of education, or charter school to report any cyberattack, as defined, impacting more than 500 pupils or personnel to Cal-CSIC.This bill would explicitly include school districts, county offices of education, and charter schools among the specified entities with which Cal-CSIC coordinates information sharing, including cyber threat information.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
3+ Enrolled September 08, 2023 Passed IN Senate September 06, 2023 Passed IN Assembly May 18, 2023 Amended IN Assembly March 23, 2023 CALIFORNIA LEGISLATURE 20232024 REGULAR SESSION Assembly Bill No. 1023Introduced by Assembly Member PapanFebruary 15, 2023 An act to amend Section 8586.5 of the Government Code, relating to school security. LEGISLATIVE COUNSEL'S DIGESTAB 1023, Papan. California Cybersecurity Integration Center: school cybersecurity.Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), to be composed of representatives from the specified organizations, with a primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.This bill would require Cal-CSIC to include representatives from the State Department of Education.Existing law requires Cal-CSIC to serve as the central organizing hub of the state governments cybersecurity activities and coordinate information sharing with, and share cyber threat information received from, specified public and private entities. Existing law also requires a school district, county office of education, or charter school to report any cyberattack, as defined, impacting more than 500 pupils or personnel to Cal-CSIC.This bill would explicitly include school districts, county offices of education, and charter schools among the specified entities with which Cal-CSIC coordinates information sharing, including cyber threat information.Digest Key Vote: MAJORITY Appropriation: NO Fiscal Committee: YES Local Program: NO
44
5- Assembly Bill No. 1023 CHAPTER 555
5+ Enrolled September 08, 2023 Passed IN Senate September 06, 2023 Passed IN Assembly May 18, 2023 Amended IN Assembly March 23, 2023
66
7- Assembly Bill No. 1023
7+Enrolled September 08, 2023
8+Passed IN Senate September 06, 2023
9+Passed IN Assembly May 18, 2023
10+Amended IN Assembly March 23, 2023
811
9- CHAPTER 555
12+ CALIFORNIA LEGISLATURE 20232024 REGULAR SESSION
13+
14+ Assembly Bill
15+
16+No. 1023
17+
18+Introduced by Assembly Member PapanFebruary 15, 2023
19+
20+Introduced by Assembly Member Papan
21+February 15, 2023
1022
1123 An act to amend Section 8586.5 of the Government Code, relating to school security.
12-
13- [ Approved by Governor October 08, 2023. Filed with Secretary of State October 08, 2023. ]
1424
1525 LEGISLATIVE COUNSEL'S DIGEST
1626
1727 ## LEGISLATIVE COUNSEL'S DIGEST
1828
1929 AB 1023, Papan. California Cybersecurity Integration Center: school cybersecurity.
2030
2131 Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), to be composed of representatives from the specified organizations, with a primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.This bill would require Cal-CSIC to include representatives from the State Department of Education.Existing law requires Cal-CSIC to serve as the central organizing hub of the state governments cybersecurity activities and coordinate information sharing with, and share cyber threat information received from, specified public and private entities. Existing law also requires a school district, county office of education, or charter school to report any cyberattack, as defined, impacting more than 500 pupils or personnel to Cal-CSIC.This bill would explicitly include school districts, county offices of education, and charter schools among the specified entities with which Cal-CSIC coordinates information sharing, including cyber threat information.
2232
2333 Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center (Cal-CSIC), to be composed of representatives from the specified organizations, with a primary mission to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in our state.
2434
2535 This bill would require Cal-CSIC to include representatives from the State Department of Education.
2636
2737 Existing law requires Cal-CSIC to serve as the central organizing hub of the state governments cybersecurity activities and coordinate information sharing with, and share cyber threat information received from, specified public and private entities. Existing law also requires a school district, county office of education, or charter school to report any cyberattack, as defined, impacting more than 500 pupils or personnel to Cal-CSIC.
2838
2939 This bill would explicitly include school districts, county offices of education, and charter schools among the specified entities with which Cal-CSIC coordinates information sharing, including cyber threat information.
3040
3141 ## Digest Key
3242
3343 ## Bill Text
3444
3545 The people of the State of California do enact as follows:SECTION 1. (a) The Legislature finds and declares all of the following:(1) School districts, county offices of education, and charter schools are increasingly facing a broad range of cyberthreats and ransomware attacks. For many local educational agencies, it is not a matter of if they will be subject to a cybersecurity attack on their school information system, but when will one occur.(2) Cyberattacks can render local educational agencies unable to conduct the day-to-day business of educating pupils. Successful attacks on local educational agencies have resulted in financial and learning loss, along with the exposure of private pupil data.(3) There are over 1,000 local educational agencies in California, collecting and maintaining data related to almost 6,000,000 pupils, their families, and school employees. Much of the data local educational agencies collect and maintain is sensitive and protected by federal and state law. Although local educational agencies take proactive steps to protect this data, they remain vulnerable to cyberattacks.(4) Currently, the California Cybersecurity Integration Center (Cal-CSIC) serves as the central organizing hub of the state governments cybersecurity preparedness and response activities and coordinates cyber intelligence and information sharing.(5) Due to the vast amount and great sensitivity of pupil data collected and maintained by local educational agencies, they need guidance and information to allow them to better prepare for the inevitable next cyberattack.(b) It is, therefore, the intent of the Legislature for Cal-CSIC to provide guidance on issues of cybersecurity and preparedness to school districts, county offices of education, and charter schools.SEC. 2. Section 8586.5 of the Government Code is amended to read:8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
3646
3747 The people of the State of California do enact as follows:
3848
3949 ## The people of the State of California do enact as follows:
4050
4151 SECTION 1. (a) The Legislature finds and declares all of the following:(1) School districts, county offices of education, and charter schools are increasingly facing a broad range of cyberthreats and ransomware attacks. For many local educational agencies, it is not a matter of if they will be subject to a cybersecurity attack on their school information system, but when will one occur.(2) Cyberattacks can render local educational agencies unable to conduct the day-to-day business of educating pupils. Successful attacks on local educational agencies have resulted in financial and learning loss, along with the exposure of private pupil data.(3) There are over 1,000 local educational agencies in California, collecting and maintaining data related to almost 6,000,000 pupils, their families, and school employees. Much of the data local educational agencies collect and maintain is sensitive and protected by federal and state law. Although local educational agencies take proactive steps to protect this data, they remain vulnerable to cyberattacks.(4) Currently, the California Cybersecurity Integration Center (Cal-CSIC) serves as the central organizing hub of the state governments cybersecurity preparedness and response activities and coordinates cyber intelligence and information sharing.(5) Due to the vast amount and great sensitivity of pupil data collected and maintained by local educational agencies, they need guidance and information to allow them to better prepare for the inevitable next cyberattack.(b) It is, therefore, the intent of the Legislature for Cal-CSIC to provide guidance on issues of cybersecurity and preparedness to school districts, county offices of education, and charter schools.
4252
4353 SECTION 1. (a) The Legislature finds and declares all of the following:(1) School districts, county offices of education, and charter schools are increasingly facing a broad range of cyberthreats and ransomware attacks. For many local educational agencies, it is not a matter of if they will be subject to a cybersecurity attack on their school information system, but when will one occur.(2) Cyberattacks can render local educational agencies unable to conduct the day-to-day business of educating pupils. Successful attacks on local educational agencies have resulted in financial and learning loss, along with the exposure of private pupil data.(3) There are over 1,000 local educational agencies in California, collecting and maintaining data related to almost 6,000,000 pupils, their families, and school employees. Much of the data local educational agencies collect and maintain is sensitive and protected by federal and state law. Although local educational agencies take proactive steps to protect this data, they remain vulnerable to cyberattacks.(4) Currently, the California Cybersecurity Integration Center (Cal-CSIC) serves as the central organizing hub of the state governments cybersecurity preparedness and response activities and coordinates cyber intelligence and information sharing.(5) Due to the vast amount and great sensitivity of pupil data collected and maintained by local educational agencies, they need guidance and information to allow them to better prepare for the inevitable next cyberattack.(b) It is, therefore, the intent of the Legislature for Cal-CSIC to provide guidance on issues of cybersecurity and preparedness to school districts, county offices of education, and charter schools.
4454
4555 SECTION 1. (a) The Legislature finds and declares all of the following:
4656
4757 ### SECTION 1.
4858
4959 (1) School districts, county offices of education, and charter schools are increasingly facing a broad range of cyberthreats and ransomware attacks. For many local educational agencies, it is not a matter of if they will be subject to a cybersecurity attack on their school information system, but when will one occur.
5060
5161 (2) Cyberattacks can render local educational agencies unable to conduct the day-to-day business of educating pupils. Successful attacks on local educational agencies have resulted in financial and learning loss, along with the exposure of private pupil data.
5262
5363 (3) There are over 1,000 local educational agencies in California, collecting and maintaining data related to almost 6,000,000 pupils, their families, and school employees. Much of the data local educational agencies collect and maintain is sensitive and protected by federal and state law. Although local educational agencies take proactive steps to protect this data, they remain vulnerable to cyberattacks.
5464
5565 (4) Currently, the California Cybersecurity Integration Center (Cal-CSIC) serves as the central organizing hub of the state governments cybersecurity preparedness and response activities and coordinates cyber intelligence and information sharing.
5666
5767 (5) Due to the vast amount and great sensitivity of pupil data collected and maintained by local educational agencies, they need guidance and information to allow them to better prepare for the inevitable next cyberattack.
5868
5969 (b) It is, therefore, the intent of the Legislature for Cal-CSIC to provide guidance on issues of cybersecurity and preparedness to school districts, county offices of education, and charter schools.
6070
6171 SEC. 2. Section 8586.5 of the Government Code is amended to read:8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
6272
6373 SEC. 2. Section 8586.5 of the Government Code is amended to read:
6474
6575 ### SEC. 2.
6676
6777 8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
6878
6979 8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
7080
7181 8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:(1) The Office of Emergency Services.(2) The Office of Information Security.(3) The State Threat Assessment Center.(4) The Department of the California Highway Patrol.(5) The Military Department.(6) The Office of the Attorney General.(7) The California Health and Human Services Agency.(8) The California Utilities Emergency Association.(9) The California State University.(10) The University of California.(11) The California Community Colleges.(12) The State Department of Education.(13) The United States Department of Homeland Security.(14) The United States Federal Bureau of Investigation.(15) The United States Secret Service.(16) The United States Coast Guard.(17) Other members as designated by the Director of Emergency Services.(b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.(c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.(d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.(e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.(f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:(A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.(B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.(C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.(D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.(2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.
7282
7383
7484
7585 8586.5. (a) The Office of Emergency Services shall establish and lead the California Cybersecurity Integration Center. The California Cybersecurity Integration Centers primary mission is to reduce the likelihood and severity of cyber incidents that could damage Californias economy, its critical infrastructure, or public and private sector computer networks in the state. The California Cybersecurity Integration Center shall serve as the central organizing hub of state governments cybersecurity activities and coordinate information sharing with local, state, and federal agencies, tribal governments, utilities and other service providers, academic institutions, including school districts, county offices of education, and charter schools, and nongovernmental organizations. The California Cybersecurity Integration Center shall be composed of representatives from the following organizations:
7686
7787 (1) The Office of Emergency Services.
7888
7989 (2) The Office of Information Security.
8090
8191 (3) The State Threat Assessment Center.
8292
8393 (4) The Department of the California Highway Patrol.
8494
8595 (5) The Military Department.
8696
8797 (6) The Office of the Attorney General.
8898
8999 (7) The California Health and Human Services Agency.
90100
91101 (8) The California Utilities Emergency Association.
92102
93103 (9) The California State University.
94104
95105 (10) The University of California.
96106
97107 (11) The California Community Colleges.
98108
99109 (12) The State Department of Education.
100110
101111 (13) The United States Department of Homeland Security.
102112
103113 (14) The United States Federal Bureau of Investigation.
104114
105115 (15) The United States Secret Service.
106116
107117 (16) The United States Coast Guard.
108118
109119 (17) Other members as designated by the Director of Emergency Services.
110120
111121 (b) The California Cybersecurity Integration Center shall operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security National Cybersecurity and Communications Integration Center, including sharing cyber threat information that is received from utilities, academic institutions, including school districts, county offices of education, and charter schools, private companies, and other appropriate sources. The California Cybersecurity Integration Center shall provide warnings of cyberattacks to government agencies and nongovernmental partners, coordinate information sharing among these entities, assess risks to critical infrastructure and information technology networks, prioritize cyber threats and support public and private sector partners in protecting their vulnerable infrastructure and information technology networks, enable cross-sector coordination and sharing of recommended best practices and security measures, and support cybersecurity assessments, audits, and accountability programs that are required by state law to protect the information technology networks of Californias agencies and departments.
112122
113123 (c) The California Cybersecurity Integration Center shall develop a statewide cybersecurity strategy, informed by recommendations from the California Task Force on Cybersecurity and in accordance with state and federal requirements, standards, and best practices. The cybersecurity strategy shall be developed to improve how cyber threats are identified, understood, and shared in order to reduce threats to California government, businesses, and consumers. The strategy shall also strengthen cyber emergency preparedness and response, standardize implementation of data protection measures, enhance digital forensics and cyber investigative capabilities, deepen expertise among Californias workforce of cybersecurity professionals, and expand cybersecurity awareness and public education.
114124
115125 (d) The California Cybersecurity Integration Center shall establish a Cyber Incident Response Team to serve as Californias primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state. This team shall also assist law enforcement agencies with primary jurisdiction for cyber-related criminal investigations and agencies responsible for advancing information security within state government. This team shall be comprised of personnel from agencies, departments, and organizations represented in the California Cybersecurity Integration Center.
116126
117127 (e) Information sharing by the California Cybersecurity Integration Center shall be conducted in a manner that protects the privacy and civil liberties of individuals, safeguards sensitive information, preserves business confidentiality, and enables public officials to detect, investigate, respond to, and prevent cyberattacks that threaten public health and safety, economic stability, and national security.
118128
119129 (f) (1) Notwithstanding Section 10231.5, the California Cybersecurity Integration Center shall create four reports that describe all expenditures made by the state within a single fiscal year pursuant to the federal State and Local Cybersecurity Improvement Act (Subtitle B of Title VI of the Infrastructure Investment and Jobs Act (Public Law 117-58), as specified in Section 665g of Title 6 of the United States Code). The reports shall be delivered to the Legislature according to the following:
120130
121131 (A) The first report for the 202122 fiscal year shall be delivered no later than December 31, 2023.
122132
123133 (B) The second report for the 202223 fiscal year shall be delivered no later than December 31, 2024.
124134
125135 (C) The third report for the 202324 fiscal year shall be delivered no later than December 31, 2025.
126136
127137 (D) The fourth report for the 202425 fiscal year shall be delivered no later than December 31, 2026.
128138
129139 (2) Reports to be submitted pursuant to this subdivision shall be submitted in compliance with Section 9795.