Iowa 2023-2024 Regular Session

Iowa House Bill HSB15

Introduced
1/12/23  
Introduced
1/12/23  

Caption

A bill for an act creating a cybersecurity unit within the office of the chief information officer.

Impact

The bill significantly impacts state management of cybersecurity, by formalizing a structure for incident reporting and response. Under HSB15, state agencies and political subdivisions are required to report any qualified cybersecurity incidents to the unit within ten days of discovery. This establishes a clear protocol for addressing cybersecurity threats and ensuring that information about incidents is shared across various governmental levels effectively. Not only does this enhance the response capacity of the state, but it also enables better preparedness among local entities and businesses operating within Iowa.

Summary

House Study Bill 15 (HSB15) introduces a dedicated cybersecurity unit within the office of the chief information officer for the state of Iowa. This unit is tasked with monitoring, managing, coordinating, and reporting cybersecurity incidents that occur within the state or its political subdivisions. As cybersecurity threats continue to rise, this bill aims to streamline the state's response to such incidents by providing a centralized unit for oversight and accountability. The legislation also includes provisions for annual reporting on the nature and frequency of cybersecurity incidents, as well as recommendations for improving cybersecurity standards across the state.

Contention

While the bill aims to enhance state cybersecurity efforts, it may raise concerns regarding data privacy and the potential bureaucratic challenges of reporting incidents to a centralized unit. Critics could argue that while monitoring is necessary, the strict reporting timeline and criteria might burden smaller agencies or local governments that may not have the resources to comply swiftly. Furthermore, there may be discussions on the adequacy of the measures put forth in the reports and whether they ensure comprehensive protection and preparedness against advanced cybersecurity threats.

Companion Bills

No companion bills found.

Previously Filed As

IA SB12

Revises provisions relating to the Office of the Chief Information Officer within the Office of the Governor. (BDR 19-280)

IA SSB1161

A bill for an act relating to conflicts between federal funding and the office of the chief information officer.(See SF 388.)

IA SB291

House Substitute for SB 291 by Committee on Legislative Modernization - Transferring all cybsersecurity services under the chief information technology officer of each branch of government, creating chief information security officers within the judicial and legislative branches, requiring a chief information security officer to be appointed by the attorney general, Kansas bureau of investigation, secretary of state, state treasurer and insurance commissioner and requiring the chief information security officers to implement certain minimum cybersecurity standards, requiring the information technology executive council to develop a plan to integrate executive branch information technology services under the executive chief information technology officer, making and concerning appropriations for the fiscal years ending June 30, 2025, and June 30, 2026, for the office of information technology, Kansas information security office and the adjutant general, authorizing certain transfers and imposing certain limitations and restrictions and directing or authorizing certain disbursements and procedures for all state agencies and requiring legislative review of state agencies not in compliance with this act.

IA HB2271

Removing the expiration of provisions relating to moving cybersecurity services under the chief information technology officer of each branch of government.

IA SB254

Cybersecurity Act & Office Changes

IA SF388

A bill for an act relating to conflicts between federal funding and the office of the chief information officer. (Formerly SSB 1161.) Vetoed 6-1-23.

IA HB2842

Transferring all information technology services under the chief information technology officer of each branch of government, creating chief information security officers within the judicial and legislative branches, requiring a chief information security officer to be appointed by the attorney general, secretary of state, state treasurer and insurance commissioner and requiring the chief information security officers to implement certain minimum cybersecurity standards, making and concerning appropriations for the fiscal years ending June 30, 2025, and June 30, 2026, for the office of information technology, Kansas information security office and the adjutant general, authorizing certain transfers and imposing certain limitations and restrictions, and directing or authorizing certain disbursements and procedures for all state agencies and requiring legislative review of state agencies not in compliance with this act.

IA HB2270

Authorizing the chief information security officer to receive audit reports and updating statutes related to services provided by the chief information technology officer.

IA HB8

Relating to cybersecurity for state agency information resources.

IA SB7

Creates the office of Chief Data Officer

Similar Bills

CA SB265

Cybersecurity preparedness: critical infrastructure sectors.

CA SB892

Cybersecurity preparedness: food and agriculture sector and water and wastewater systems sector.

CA AB1242

Information security.

CA AB405

Public postsecondary education: community college districts: baccalaureate degree cybersecurity pilot program.

CA AB276

Local educational agencies: charter schools.

IA HF698

A bill for an act establishing the cybersecurity simulation training center at the Iowa state university of science and technology, and including contingent effective date provisions.(Formerly HF 139, HSB 14.)

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

CA AB569

California State University: Cybersecurity Regional Alliances and Multistakeholder Partnerships Pilot Program.