1 | 1 | | 104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026 HB3576 Introduced , by Rep. Dagmara Avelar SYNOPSIS AS INTRODUCED: 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101220 ILCS 5/4-102 new Amends the Public Utilities Act. Provides that, within 120 days after the effective date of the amendatory provisions, each water purveyor shall develop a cybersecurity program that defines and implements organizational accountabilities and responsibilities for cyber risk management activities, and establishes policies, plans, processes, and procedures for identifying and mitigating cyber risk to its public community water system. Provides that, within certain time periods after the effective date of the amendatory provisions, a water purveyor shall create a cybersecurity incident reporting process; obtain a cybersecurity insurance policy that meets certain standards; reasonably conform to the most recent version of one or more of specified industry-recognized cybersecurity frameworks; submit a compliance report; submit an incident report; and submit an annual status report. Sets forth provisions concerning violations of the amendatory provisions and rulemaking abilities of the Department of Natural Resources and the Illinois Commerce Commission. Makes other changes. LRB104 08875 AAS 18930 b A BILL FOR 104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026 HB3576 Introduced , by Rep. Dagmara Avelar SYNOPSIS AS INTRODUCED: 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101220 ILCS 5/4-102 new 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101 220 ILCS 5/4-102 new Amends the Public Utilities Act. Provides that, within 120 days after the effective date of the amendatory provisions, each water purveyor shall develop a cybersecurity program that defines and implements organizational accountabilities and responsibilities for cyber risk management activities, and establishes policies, plans, processes, and procedures for identifying and mitigating cyber risk to its public community water system. Provides that, within certain time periods after the effective date of the amendatory provisions, a water purveyor shall create a cybersecurity incident reporting process; obtain a cybersecurity insurance policy that meets certain standards; reasonably conform to the most recent version of one or more of specified industry-recognized cybersecurity frameworks; submit a compliance report; submit an incident report; and submit an annual status report. Sets forth provisions concerning violations of the amendatory provisions and rulemaking abilities of the Department of Natural Resources and the Illinois Commerce Commission. Makes other changes. LRB104 08875 AAS 18930 b LRB104 08875 AAS 18930 b A BILL FOR |
---|
2 | 2 | | 104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026 HB3576 Introduced , by Rep. Dagmara Avelar SYNOPSIS AS INTRODUCED: |
---|
3 | 3 | | 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101220 ILCS 5/4-102 new 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101 220 ILCS 5/4-102 new |
---|
4 | 4 | | 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101 |
---|
5 | 5 | | 220 ILCS 5/4-102 new |
---|
6 | 6 | | Amends the Public Utilities Act. Provides that, within 120 days after the effective date of the amendatory provisions, each water purveyor shall develop a cybersecurity program that defines and implements organizational accountabilities and responsibilities for cyber risk management activities, and establishes policies, plans, processes, and procedures for identifying and mitigating cyber risk to its public community water system. Provides that, within certain time periods after the effective date of the amendatory provisions, a water purveyor shall create a cybersecurity incident reporting process; obtain a cybersecurity insurance policy that meets certain standards; reasonably conform to the most recent version of one or more of specified industry-recognized cybersecurity frameworks; submit a compliance report; submit an incident report; and submit an annual status report. Sets forth provisions concerning violations of the amendatory provisions and rulemaking abilities of the Department of Natural Resources and the Illinois Commerce Commission. Makes other changes. |
---|
7 | 7 | | LRB104 08875 AAS 18930 b LRB104 08875 AAS 18930 b |
---|
8 | 8 | | LRB104 08875 AAS 18930 b |
---|
9 | 9 | | A BILL FOR |
---|
10 | 10 | | HB3576LRB104 08875 AAS 18930 b HB3576 LRB104 08875 AAS 18930 b |
---|
11 | 11 | | HB3576 LRB104 08875 AAS 18930 b |
---|
12 | 12 | | 1 AN ACT concerning regulation. |
---|
13 | 13 | | 2 Be it enacted by the People of the State of Illinois, |
---|
14 | 14 | | 3 represented in the General Assembly: |
---|
15 | 15 | | 4 Section 5. The Public Utilities Act is amended by changing |
---|
16 | 16 | | 5 Section 4-101 and by adding Section 4-102 as follows: |
---|
17 | 17 | | 6 (220 ILCS 5/4-101) (from Ch. 111 2/3, par. 4-101) |
---|
18 | 18 | | 7 Sec. 4-101. The Commerce Commission shall have general |
---|
19 | 19 | | 8 supervision of all public utilities, except as otherwise |
---|
20 | 20 | | 9 provided in this Act, shall inquire into the management of the |
---|
21 | 21 | | 10 business thereof and shall keep itself informed as to the |
---|
22 | 22 | | 11 manner and method in which the business is conducted. It shall |
---|
23 | 23 | | 12 examine those public utilities and keep informed as to their |
---|
24 | 24 | | 13 general condition, their franchises, capitalization, rates and |
---|
25 | 25 | | 14 other charges, and the manner in which their plants, equipment |
---|
26 | 26 | | 15 and other property owned, leased, controlled or operated are |
---|
27 | 27 | | 16 managed, conducted and operated, not only with respect to the |
---|
28 | 28 | | 17 adequacy, security and accommodation afforded by their service |
---|
29 | 29 | | 18 but also with respect to their compliance with this Act and any |
---|
30 | 30 | | 19 other law, with the orders of the Commission and with the |
---|
31 | 31 | | 20 charter and franchise requirements. |
---|
32 | 32 | | 21 Whenever the Commission is authorized or required by law |
---|
33 | 33 | | 22 to consider some aspect of criminal history record information |
---|
34 | 34 | | 23 for the purpose of carrying out its statutory powers and |
---|
35 | 35 | | |
---|
36 | 36 | | |
---|
37 | 37 | | |
---|
38 | 38 | | 104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026 HB3576 Introduced , by Rep. Dagmara Avelar SYNOPSIS AS INTRODUCED: |
---|
39 | 39 | | 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101220 ILCS 5/4-102 new 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101 220 ILCS 5/4-102 new |
---|
40 | 40 | | 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101 |
---|
41 | 41 | | 220 ILCS 5/4-102 new |
---|
42 | 42 | | Amends the Public Utilities Act. Provides that, within 120 days after the effective date of the amendatory provisions, each water purveyor shall develop a cybersecurity program that defines and implements organizational accountabilities and responsibilities for cyber risk management activities, and establishes policies, plans, processes, and procedures for identifying and mitigating cyber risk to its public community water system. Provides that, within certain time periods after the effective date of the amendatory provisions, a water purveyor shall create a cybersecurity incident reporting process; obtain a cybersecurity insurance policy that meets certain standards; reasonably conform to the most recent version of one or more of specified industry-recognized cybersecurity frameworks; submit a compliance report; submit an incident report; and submit an annual status report. Sets forth provisions concerning violations of the amendatory provisions and rulemaking abilities of the Department of Natural Resources and the Illinois Commerce Commission. Makes other changes. |
---|
43 | 43 | | LRB104 08875 AAS 18930 b LRB104 08875 AAS 18930 b |
---|
44 | 44 | | LRB104 08875 AAS 18930 b |
---|
45 | 45 | | A BILL FOR |
---|
46 | 46 | | |
---|
47 | 47 | | |
---|
48 | 48 | | |
---|
49 | 49 | | |
---|
50 | 50 | | |
---|
51 | 51 | | 220 ILCS 5/4-101 from Ch. 111 2/3, par. 4-101 |
---|
52 | 52 | | 220 ILCS 5/4-102 new |
---|
53 | 53 | | |
---|
54 | 54 | | |
---|
55 | 55 | | |
---|
56 | 56 | | LRB104 08875 AAS 18930 b |
---|
57 | 57 | | |
---|
58 | 58 | | |
---|
59 | 59 | | |
---|
60 | 60 | | |
---|
61 | 61 | | |
---|
62 | 62 | | |
---|
63 | 63 | | |
---|
64 | 64 | | |
---|
65 | 65 | | |
---|
66 | 66 | | HB3576 LRB104 08875 AAS 18930 b |
---|
67 | 67 | | |
---|
68 | 68 | | |
---|
69 | 69 | | HB3576- 2 -LRB104 08875 AAS 18930 b HB3576 - 2 - LRB104 08875 AAS 18930 b |
---|
70 | 70 | | HB3576 - 2 - LRB104 08875 AAS 18930 b |
---|
71 | 71 | | 1 responsibilities, then, upon request and payment of fees in |
---|
72 | 72 | | 2 conformance with the requirements of Section 2605-400 of the |
---|
73 | 73 | | 3 Illinois State Police Law, the Illinois State Police is |
---|
74 | 74 | | 4 authorized to furnish, pursuant to positive identification, |
---|
75 | 75 | | 5 such information contained in State files as is necessary to |
---|
76 | 76 | | 6 fulfill the request. |
---|
77 | 77 | | 7 The Commission shall require all public utilities to |
---|
78 | 78 | | 8 establish a security policy that includes on-site safeguards |
---|
79 | 79 | | 9 to restrict physical or electronic access to critical |
---|
80 | 80 | | 10 infrastructure and computerized control and data systems. The |
---|
81 | 81 | | 11 Commission shall maintain a record of and each regulated |
---|
82 | 82 | | 12 entity shall provide to the Commission an annual affidavit |
---|
83 | 83 | | 13 signed by a representative of the regulated entity that |
---|
84 | 84 | | 14 states: |
---|
85 | 85 | | 15 (1) that the entity has a security policy in place; |
---|
86 | 86 | | 16 (2) that the entity has conducted at least one |
---|
87 | 87 | | 17 practice exercise based on the security policy within the |
---|
88 | 88 | | 18 12 months immediately preceding the date of the affidavit; |
---|
89 | 89 | | 19 and |
---|
90 | 90 | | 20 (3) with respect to any entity that is an electric |
---|
91 | 91 | | 21 public utility, that the entity follows, at a minimum, the |
---|
92 | 92 | | 22 most current security standards set forth by the North |
---|
93 | 93 | | 23 American Electric Reliability Council. |
---|
94 | 94 | | 24 A water public utility's security policy shall also meet |
---|
95 | 95 | | 25 the requirements set forth in Section 4-102. |
---|
96 | 96 | | 26 (Source: P.A. 102-538, eff. 8-20-21.) |
---|
97 | 97 | | |
---|
98 | 98 | | |
---|
99 | 99 | | |
---|
100 | 100 | | |
---|
101 | 101 | | |
---|
102 | 102 | | HB3576 - 2 - LRB104 08875 AAS 18930 b |
---|
103 | 103 | | |
---|
104 | 104 | | |
---|
105 | 105 | | HB3576- 3 -LRB104 08875 AAS 18930 b HB3576 - 3 - LRB104 08875 AAS 18930 b |
---|
106 | 106 | | HB3576 - 3 - LRB104 08875 AAS 18930 b |
---|
107 | 107 | | 1 (220 ILCS 5/4-102 new) |
---|
108 | 108 | | 2 Sec. 4-102. Cybersecurity policy for water purveyors. |
---|
109 | 109 | | 3 (a) As used in this Section: |
---|
110 | 110 | | 4 "Cybersecurity incident" means an event occurring on or |
---|
111 | 111 | | 5 conducted through a computer network that jeopardizes the |
---|
112 | 112 | | 6 integrity, confidentiality, or availability of computers, |
---|
113 | 113 | | 7 information systems, communications systems, networks, |
---|
114 | 114 | | 8 physical or virtual infrastructure controlled by computers or |
---|
115 | 115 | | 9 information systems, or information residing on such computers |
---|
116 | 116 | | 10 or information systems. |
---|
117 | 117 | | 11 "Cybersecurity insurance policy" means an insurance policy |
---|
118 | 118 | | 12 designed to mitigate losses from cybersecurity incidents, |
---|
119 | 119 | | 13 including, but not limited to, data breaches, business |
---|
120 | 120 | | 14 interruption, and network damage. |
---|
121 | 121 | | 15 "Department" means the Department of Natural Resources. |
---|
122 | 122 | | 16 "Industrial control system" means an information system |
---|
123 | 123 | | 17 used to control industrial processes such as manufacturing, |
---|
124 | 124 | | 18 product handling, production, or distribution. |
---|
125 | 125 | | 19 "Industrial control system" includes supervisory control |
---|
126 | 126 | | 20 and data acquisition systems used to control geographically |
---|
127 | 127 | | 21 dispersed assets, and distributed control systems and smaller |
---|
128 | 128 | | 22 control systems using programmable logic controllers to |
---|
129 | 129 | | 23 control localized processes. |
---|
130 | 130 | | 24 "Information resource" means information and related |
---|
131 | 131 | | 25 resources, such as personnel, equipment, funds, and |
---|
132 | 132 | | |
---|
133 | 133 | | |
---|
134 | 134 | | |
---|
135 | 135 | | |
---|
136 | 136 | | |
---|
137 | 137 | | HB3576 - 3 - LRB104 08875 AAS 18930 b |
---|
138 | 138 | | |
---|
139 | 139 | | |
---|
140 | 140 | | HB3576- 4 -LRB104 08875 AAS 18930 b HB3576 - 4 - LRB104 08875 AAS 18930 b |
---|
141 | 141 | | HB3576 - 4 - LRB104 08875 AAS 18930 b |
---|
142 | 142 | | 1 information technology. |
---|
143 | 143 | | 2 "Information system" means a discrete set of information |
---|
144 | 144 | | 3 resources organized for the collection, processing, |
---|
145 | 145 | | 4 maintenance, use, sharing, dissemination, or disposition of |
---|
146 | 146 | | 5 information. |
---|
147 | 147 | | 6 "Public community water system" means a public water |
---|
148 | 148 | | 7 system which serves at least 15 service connections used by |
---|
149 | 149 | | 8 year-round residents or regularly serves at least 25 |
---|
150 | 150 | | 9 year-round residents. |
---|
151 | 151 | | 10 "Public water system" means a system for the provision to |
---|
152 | 152 | | 11 the public of water for human consumption through pipes or |
---|
153 | 153 | | 12 other constructed conveyances, if such system has at least 15 |
---|
154 | 154 | | 13 service connections or regularly serves an average of at least |
---|
155 | 155 | | 14 25 individuals daily at least 60 days out of the year. "Public |
---|
156 | 156 | | 15 water system" includes (i) any collection, treatment, storage |
---|
157 | 157 | | 16 and distribution facilities under control of the operator of |
---|
158 | 158 | | 17 such system and used primarily in connection with such system, |
---|
159 | 159 | | 18 and (ii) any collection or pre-treatment storage facilities |
---|
160 | 160 | | 19 not under such control which are used primarily in connection |
---|
161 | 161 | | 20 with such system. |
---|
162 | 162 | | 21 "Water purveyor" means any person that owns a public |
---|
163 | 163 | | 22 community water system with more than 500 service connections. |
---|
164 | 164 | | 23 (b) Within 120 days after the effective date of this |
---|
165 | 165 | | 24 amendatory Act of the 104th General Assembly, each water |
---|
166 | 166 | | 25 purveyor shall develop a cybersecurity program that defines |
---|
167 | 167 | | 26 and implements organizational accountabilities and |
---|
168 | 168 | | |
---|
169 | 169 | | |
---|
170 | 170 | | |
---|
171 | 171 | | |
---|
172 | 172 | | |
---|
173 | 173 | | HB3576 - 4 - LRB104 08875 AAS 18930 b |
---|
174 | 174 | | |
---|
175 | 175 | | |
---|
176 | 176 | | HB3576- 5 -LRB104 08875 AAS 18930 b HB3576 - 5 - LRB104 08875 AAS 18930 b |
---|
177 | 177 | | HB3576 - 5 - LRB104 08875 AAS 18930 b |
---|
178 | 178 | | 1 responsibilities for cyber risk management activities, and |
---|
179 | 179 | | 2 establishes policies, plans, processes, and procedures for |
---|
180 | 180 | | 3 identifying and mitigating cyber risk to the water purveyor's |
---|
181 | 181 | | 4 public community water system. As part of the cybersecurity |
---|
182 | 182 | | 5 program, a water purveyor shall do the following: |
---|
183 | 183 | | 6 (1) identify the individual directly responsible for |
---|
184 | 184 | | 7 ensuring that the policies, plans, processes, and |
---|
185 | 185 | | 8 procedures established pursuant to this Section are |
---|
186 | 186 | | 9 executed in a timely manner; |
---|
187 | 187 | | 10 (2) conduct risk assessments and implement appropriate |
---|
188 | 188 | | 11 controls to mitigate identified risks to the public |
---|
189 | 189 | | 12 community water system; |
---|
190 | 190 | | 13 (3) maintain situational awareness of cyber threats |
---|
191 | 191 | | 14 and vulnerabilities to the public community water system; |
---|
192 | 192 | | 15 and |
---|
193 | 193 | | 16 (4) create and exercise incident response and recovery |
---|
194 | 194 | | 17 plans. |
---|
195 | 195 | | 18 A water purveyor shall submit a copy of the cybersecurity |
---|
196 | 196 | | 19 program developed pursuant to this subsection (b) to the |
---|
197 | 197 | | 20 Commission in a form and manner as determined by the |
---|
198 | 198 | | 21 Commission. |
---|
199 | 199 | | 22 (c) Within 60 days after developing the cybersecurity |
---|
200 | 200 | | 23 program required pursuant to subsection (b) of this Section, |
---|
201 | 201 | | 24 each water purveyor shall create a cybersecurity incident |
---|
202 | 202 | | 25 reporting process. |
---|
203 | 203 | | 26 (d) No later than 180 days after the effective date of this |
---|
204 | 204 | | |
---|
205 | 205 | | |
---|
206 | 206 | | |
---|
207 | 207 | | |
---|
208 | 208 | | |
---|
209 | 209 | | HB3576 - 5 - LRB104 08875 AAS 18930 b |
---|
210 | 210 | | |
---|
211 | 211 | | |
---|
212 | 212 | | HB3576- 6 -LRB104 08875 AAS 18930 b HB3576 - 6 - LRB104 08875 AAS 18930 b |
---|
213 | 213 | | HB3576 - 6 - LRB104 08875 AAS 18930 b |
---|
214 | 214 | | 1 amendatory Act of the 104th General Assembly, each water |
---|
215 | 215 | | 2 purveyor shall obtain a cybersecurity insurance policy that |
---|
216 | 216 | | 3 meets any applicable standards adopted by the Commission. |
---|
217 | 217 | | 4 (e) No later than 180 days after the effective date of this |
---|
218 | 218 | | 5 amendatory Act of the 104th General Assembly, each water |
---|
219 | 219 | | 6 purveyor shall update its cybersecurity program developed |
---|
220 | 220 | | 7 pursuant to this Section to apply to all of the public |
---|
221 | 221 | | 8 community water system's industrial control systems and to |
---|
222 | 222 | | 9 reasonably conform to the most recent version of one or more of |
---|
223 | 223 | | 10 the following industry-recognized cybersecurity frameworks: |
---|
224 | 224 | | 11 (1) the Framework for Improving Critical |
---|
225 | 225 | | 12 Infrastructure Cybersecurity developed by the National |
---|
226 | 226 | | 13 Institute of Standards and Technology; |
---|
227 | 227 | | 14 (2) the Center for Internet Security Critical Security |
---|
228 | 228 | | 15 Controls for Effective Cyber Defense; or |
---|
229 | 229 | | 16 (3) the International Organization for Standardization |
---|
230 | 230 | | 17 and International Electrotechnical Commission 27000 family |
---|
231 | 231 | | 18 of standards for an information security management |
---|
232 | 232 | | 19 system. |
---|
233 | 233 | | 20 Whenever a final revision to one or more of the frameworks |
---|
234 | 234 | | 21 listed in this subsection (e) is published, a water purveyor |
---|
235 | 235 | | 22 whose cybersecurity program conformed to that framework shall |
---|
236 | 236 | | 23 revise its cybersecurity program to reasonably conform to the |
---|
237 | 237 | | 24 revised framework, and submit a copy of the revised |
---|
238 | 238 | | 25 cybersecurity program to the Commission, no later than 180 |
---|
239 | 239 | | 26 days after publication of the revised framework. |
---|
240 | 240 | | |
---|
241 | 241 | | |
---|
242 | 242 | | |
---|
243 | 243 | | |
---|
244 | 244 | | |
---|
245 | 245 | | HB3576 - 6 - LRB104 08875 AAS 18930 b |
---|
246 | 246 | | |
---|
247 | 247 | | |
---|
248 | 248 | | HB3576- 7 -LRB104 08875 AAS 18930 b HB3576 - 7 - LRB104 08875 AAS 18930 b |
---|
249 | 249 | | HB3576 - 7 - LRB104 08875 AAS 18930 b |
---|
250 | 250 | | 1 (f) No later than one year after the effective date of this |
---|
251 | 251 | | 2 amendatory Act of the 104th General Assembly, and each year |
---|
252 | 252 | | 3 thereafter, each water purveyor shall submit to the Department |
---|
253 | 253 | | 4 and the Commission a certification demonstrating that the |
---|
254 | 254 | | 5 water purveyor is in compliance with the requirements of this |
---|
255 | 255 | | 6 Section. The certification shall be made in a form and manner |
---|
256 | 256 | | 7 as determined by the Department, in consultation with the |
---|
257 | 257 | | 8 Commission. The certification shall be signed by a senior |
---|
258 | 258 | | 9 executive responsible for security of the regulated entity. |
---|
259 | 259 | | 10 (g) The Commission shall cause to be audited any public |
---|
260 | 260 | | 11 community water system that fails to submit a cybersecurity |
---|
261 | 261 | | 12 program, a revision, or a certification pursuant to this |
---|
262 | 262 | | 13 Section. Any audit shall be conducted by a qualified and |
---|
263 | 263 | | 14 independent cybersecurity company, at the water purveyor's |
---|
264 | 264 | | 15 expense. Following the audit, the water purveyor shall submit |
---|
265 | 265 | | 16 the audit and any corrective action plans derived from the |
---|
266 | 266 | | 17 audit to the Commission. |
---|
267 | 267 | | 18 (h) A water purveyor shall, upon the request of the |
---|
268 | 268 | | 19 Department or the Commission, provide proof of compliance with |
---|
269 | 269 | | 20 the requirements of this Section, in a form and manner as |
---|
270 | 270 | | 21 determined by the Department or by the Commission. |
---|
271 | 271 | | 22 (i) On and after 90 days after the effective date of this |
---|
272 | 272 | | 23 amendatory Act of the 104th General Assembly, a water purveyor |
---|
273 | 273 | | 24 shall inform the Commission, in a written or oral report, |
---|
274 | 274 | | 25 within 48 hours or as soon as practicable after the discovery |
---|
275 | 275 | | 26 or occurrence of any notable, unusual, or significant |
---|
276 | 276 | | |
---|
277 | 277 | | |
---|
278 | 278 | | |
---|
279 | 279 | | |
---|
280 | 280 | | |
---|
281 | 281 | | HB3576 - 7 - LRB104 08875 AAS 18930 b |
---|
282 | 282 | | |
---|
283 | 283 | | |
---|
284 | 284 | | HB3576- 8 -LRB104 08875 AAS 18930 b HB3576 - 8 - LRB104 08875 AAS 18930 b |
---|
285 | 285 | | HB3576 - 8 - LRB104 08875 AAS 18930 b |
---|
286 | 286 | | 1 cybersecurity incident or any cybersecurity incident that must |
---|
287 | 287 | | 2 be reported to another regulatory agency, including the |
---|
288 | 288 | | 3 following: |
---|
289 | 289 | | 4 (1) any cybersecurity incident that results in the |
---|
290 | 290 | | 5 compromise of the confidentiality, integrity, |
---|
291 | 291 | | 6 availability, or privacy of the water purveyor's utility |
---|
292 | 292 | | 7 billing, communications, data management, or business |
---|
293 | 293 | | 8 information systems, or the information on such systems; |
---|
294 | 294 | | 9 and |
---|
295 | 295 | | 10 (2) any cybersecurity incident against the water |
---|
296 | 296 | | 11 purveyor's industrial control systems, including |
---|
297 | 297 | | 12 monitoring, operations, and centralized control systems, |
---|
298 | 298 | | 13 that adversely impacts, disables, or manipulates |
---|
299 | 299 | | 14 infrastructure, resulting in loss of service, |
---|
300 | 300 | | 15 contamination of finished water, or damage to |
---|
301 | 301 | | 16 infrastructure. |
---|
302 | 302 | | 17 (j) No later than 30 days after receiving a report of a |
---|
303 | 303 | | 18 cybersecurity incident from a water purveyor pursuant to |
---|
304 | 304 | | 19 subsection (i), the Commission shall cause to be audited the |
---|
305 | 305 | | 20 water purveyor's cybersecurity program and any actions the |
---|
306 | 306 | | 21 water purveyor took in response to the cybersecurity incident. |
---|
307 | 307 | | 22 The audit shall identify cyber threats and vulnerabilities to |
---|
308 | 308 | | 23 the public community water system, weaknesses in the public |
---|
309 | 309 | | 24 community water system's cybersecurity program, and strategies |
---|
310 | 310 | | 25 to address those weaknesses so as to protect the public |
---|
311 | 311 | | 26 community water system from the threat of future cybersecurity |
---|
312 | 312 | | |
---|
313 | 313 | | |
---|
314 | 314 | | |
---|
315 | 315 | | |
---|
316 | 316 | | |
---|
317 | 317 | | HB3576 - 8 - LRB104 08875 AAS 18930 b |
---|
318 | 318 | | |
---|
319 | 319 | | |
---|
320 | 320 | | HB3576- 9 -LRB104 08875 AAS 18930 b HB3576 - 9 - LRB104 08875 AAS 18930 b |
---|
321 | 321 | | HB3576 - 9 - LRB104 08875 AAS 18930 b |
---|
322 | 322 | | 1 incidents. Any audit shall be conducted by a qualified and |
---|
323 | 323 | | 2 independent cybersecurity company at the water purveyor's |
---|
324 | 324 | | 3 expense. After the completion of the audit, the water purveyor |
---|
325 | 325 | | 4 shall submit the audit and any corrective action plans derived |
---|
326 | 326 | | 5 from the audit to the Commission. |
---|
327 | 327 | | 6 (k) By July 31 of each year, a water purveyor shall provide |
---|
328 | 328 | | 7 to the Commission a report that identifies the following: |
---|
329 | 329 | | 8 (1) an overview of the water purveyor's approach to |
---|
330 | 330 | | 9 cybersecurity awareness and protection; |
---|
331 | 331 | | 10 (2) a description of cybersecurity awareness training |
---|
332 | 332 | | 11 efforts for the water purveyor's staff members, |
---|
333 | 333 | | 12 specialized cybersecurity training for cybersecurity |
---|
334 | 334 | | 13 personnel, and participation by the water purveyor's |
---|
335 | 335 | | 14 cybersecurity staff in emergency preparedness exercises in |
---|
336 | 336 | | 15 the previous calendar year; |
---|
337 | 337 | | 16 (3) an organizational diagram of the water purveyor's |
---|
338 | 338 | | 17 cybersecurity organization, including positions and |
---|
339 | 339 | | 18 contact information for primary and secondary |
---|
340 | 340 | | 19 cybersecurity emergency contacts; |
---|
341 | 341 | | 20 (4) a description of the water purveyor's internal and |
---|
342 | 342 | | 21 external communications plan regarding unauthorized |
---|
343 | 343 | | 22 actions that result in interruption, degradation of |
---|
344 | 344 | | 23 service, financial harm, or breach of sensitive business |
---|
345 | 345 | | 24 or customer data, including the water purveyor's plan for |
---|
346 | 346 | | 25 notifying the Commission and customers; |
---|
347 | 347 | | 26 (5) a redacted summary of any unauthorized actions |
---|
348 | 348 | | |
---|
349 | 349 | | |
---|
350 | 350 | | |
---|
351 | 351 | | |
---|
352 | 352 | | |
---|
353 | 353 | | HB3576 - 9 - LRB104 08875 AAS 18930 b |
---|
354 | 354 | | |
---|
355 | 355 | | |
---|
356 | 356 | | HB3576- 10 -LRB104 08875 AAS 18930 b HB3576 - 10 - LRB104 08875 AAS 18930 b |
---|
357 | 357 | | HB3576 - 10 - LRB104 08875 AAS 18930 b |
---|
358 | 358 | | 1 that resulted in material interruption, financial harm, or |
---|
359 | 359 | | 2 breach of sensitive business or customer data, including |
---|
360 | 360 | | 3 the parties that were notified of the unauthorized action |
---|
361 | 361 | | 4 and any remedial actions undertaken; |
---|
362 | 362 | | 5 (6) key performance indicators and other metrics |
---|
363 | 363 | | 6 related to physical security and cybersecurity; |
---|
364 | 364 | | 7 (7) any notable cybersecurity information not included |
---|
365 | 365 | | 8 in paragraphs (1) through (6); and |
---|
366 | 366 | | 9 (8) any other information as directed by the |
---|
367 | 367 | | 10 Commission. |
---|
368 | 368 | | 11 (l) The Department or the Commission shall create a |
---|
369 | 369 | | 12 centralized portal allowing for electronic submittal of the |
---|
370 | 370 | | 13 report required under this Section. The lack of a centralized |
---|
371 | 371 | | 14 portal pursuant to this subsection (l) shall not negate the |
---|
372 | 372 | | 15 requirement for a water purveyor to submit a report. |
---|
373 | 373 | | 16 (m) Any person who violates the provisions of this |
---|
374 | 374 | | 17 Section, or any rule or regulation adopted pursuant thereto, |
---|
375 | 375 | | 18 shall be subject to the penalties and other remedies set forth |
---|
376 | 376 | | 19 in Sections 4-202 and Section 4-203. No later than 18 months |
---|
377 | 377 | | 20 after the effective date of this amendatory Act of the 104th |
---|
378 | 378 | | 21 General Assembly, the Department shall adopt a schedule of |
---|
379 | 379 | | 22 civil administrative penalties for specific violations of this |
---|
380 | 380 | | 23 Section. |
---|
381 | 381 | | 24 (n) Reports and other submissions made under this Section |
---|
382 | 382 | | 25 shall not be open to public inspection unless otherwise |
---|
383 | 383 | | 26 ordered by the Commission. Regulated entities shall not report |
---|
384 | 384 | | |
---|
385 | 385 | | |
---|
386 | 386 | | |
---|
387 | 387 | | |
---|
388 | 388 | | |
---|
389 | 389 | | HB3576 - 10 - LRB104 08875 AAS 18930 b |
---|
390 | 390 | | |
---|
391 | 391 | | |
---|
392 | 392 | | HB3576- 11 -LRB104 08875 AAS 18930 b HB3576 - 11 - LRB104 08875 AAS 18930 b |
---|
393 | 393 | | HB3576 - 11 - LRB104 08875 AAS 18930 b |
---|
394 | 394 | | |
---|
395 | 395 | | |
---|
396 | 396 | | |
---|
397 | 397 | | |
---|
398 | 398 | | |
---|
399 | 399 | | HB3576 - 11 - LRB104 08875 AAS 18930 b |
---|