Illinois 2025-2026 Regular Session

Illinois Senate Bill SB1542 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 104TH GENERAL ASSEMBLY State of Illinois 2025 and 2026 SB1542 Introduced 2/4/2025, by Sen. Ram Villivalam SYNOPSIS AS INTRODUCED: 20 ILCS 1370/1-520 ILCS 1370/1-1020 ILCS 1370/1-1520 ILCS 1370/1-2520 ILCS 1370/1-75 rep.20 ILCS 1375/5-520 ILCS 1375/5-1520 ILCS 1375/5-2520 ILCS 1375/5-35 new Amends the Department of Innovation and Technology Act. Repeals the definition of "client agency" and makes changes in the definitions of "dedicated unit", "State agency", and "transferring agency". Replaces references to "transferring agency" with references to "transferred agency". Makes changes in provisions concerning the powers and duties of the Department of Innovation and Technology, including changes in the scope of services provided by the Department and in the classes of persons to whom those services are to be provided. Authorizes the Department to charge fees for service to all State agencies under the jurisdiction of the Governor (rather than only client agencies). Repeals from the Department of Innovation and Technology Act and adds to the Illinois Information Security Improvement Act a provision requiring the principal executive officer of specified units of local government to designate a local official or employee as the primary point of contact for local cybersecurity issues. Requires the name and contact information for the specified individual to be provided to the Statewide Chief Information Security Officer. Further amends the Illinois Information Security Improvement Act. Makes changes concerning the duties of the Office of the Statewide Chief Information Security Officer and the Secretary of Innovation and Technology. Changes the definition of "State agency". LRB104 09812 BDA 19879 b A BILL FOR 104TH GENERAL ASSEMBLY State of Illinois 2025 and 2026 SB1542 Introduced 2/4/2025, by Sen. Ram Villivalam SYNOPSIS AS INTRODUCED: 20 ILCS 1370/1-520 ILCS 1370/1-1020 ILCS 1370/1-1520 ILCS 1370/1-2520 ILCS 1370/1-75 rep.20 ILCS 1375/5-520 ILCS 1375/5-1520 ILCS 1375/5-2520 ILCS 1375/5-35 new 20 ILCS 1370/1-5 20 ILCS 1370/1-10 20 ILCS 1370/1-15 20 ILCS 1370/1-25 20 ILCS 1370/1-75 rep. 20 ILCS 1375/5-5 20 ILCS 1375/5-15 20 ILCS 1375/5-25 20 ILCS 1375/5-35 new Amends the Department of Innovation and Technology Act. Repeals the definition of "client agency" and makes changes in the definitions of "dedicated unit", "State agency", and "transferring agency". Replaces references to "transferring agency" with references to "transferred agency". Makes changes in provisions concerning the powers and duties of the Department of Innovation and Technology, including changes in the scope of services provided by the Department and in the classes of persons to whom those services are to be provided. Authorizes the Department to charge fees for service to all State agencies under the jurisdiction of the Governor (rather than only client agencies). Repeals from the Department of Innovation and Technology Act and adds to the Illinois Information Security Improvement Act a provision requiring the principal executive officer of specified units of local government to designate a local official or employee as the primary point of contact for local cybersecurity issues. Requires the name and contact information for the specified individual to be provided to the Statewide Chief Information Security Officer. Further amends the Illinois Information Security Improvement Act. Makes changes concerning the duties of the Office of the Statewide Chief Information Security Officer and the Secretary of Innovation and Technology. Changes the definition of "State agency". LRB104 09812 BDA 19879 b LRB104 09812 BDA 19879 b A BILL FOR
22 104TH GENERAL ASSEMBLY State of Illinois 2025 and 2026 SB1542 Introduced 2/4/2025, by Sen. Ram Villivalam SYNOPSIS AS INTRODUCED:
33 20 ILCS 1370/1-520 ILCS 1370/1-1020 ILCS 1370/1-1520 ILCS 1370/1-2520 ILCS 1370/1-75 rep.20 ILCS 1375/5-520 ILCS 1375/5-1520 ILCS 1375/5-2520 ILCS 1375/5-35 new 20 ILCS 1370/1-5 20 ILCS 1370/1-10 20 ILCS 1370/1-15 20 ILCS 1370/1-25 20 ILCS 1370/1-75 rep. 20 ILCS 1375/5-5 20 ILCS 1375/5-15 20 ILCS 1375/5-25 20 ILCS 1375/5-35 new
44 20 ILCS 1370/1-5
55 20 ILCS 1370/1-10
66 20 ILCS 1370/1-15
77 20 ILCS 1370/1-25
88 20 ILCS 1370/1-75 rep.
99 20 ILCS 1375/5-5
1010 20 ILCS 1375/5-15
1111 20 ILCS 1375/5-25
1212 20 ILCS 1375/5-35 new
1313 Amends the Department of Innovation and Technology Act. Repeals the definition of "client agency" and makes changes in the definitions of "dedicated unit", "State agency", and "transferring agency". Replaces references to "transferring agency" with references to "transferred agency". Makes changes in provisions concerning the powers and duties of the Department of Innovation and Technology, including changes in the scope of services provided by the Department and in the classes of persons to whom those services are to be provided. Authorizes the Department to charge fees for service to all State agencies under the jurisdiction of the Governor (rather than only client agencies). Repeals from the Department of Innovation and Technology Act and adds to the Illinois Information Security Improvement Act a provision requiring the principal executive officer of specified units of local government to designate a local official or employee as the primary point of contact for local cybersecurity issues. Requires the name and contact information for the specified individual to be provided to the Statewide Chief Information Security Officer. Further amends the Illinois Information Security Improvement Act. Makes changes concerning the duties of the Office of the Statewide Chief Information Security Officer and the Secretary of Innovation and Technology. Changes the definition of "State agency".
1414 LRB104 09812 BDA 19879 b LRB104 09812 BDA 19879 b
1515 LRB104 09812 BDA 19879 b
1616 A BILL FOR
1717 SB1542LRB104 09812 BDA 19879 b SB1542 LRB104 09812 BDA 19879 b
1818 SB1542 LRB104 09812 BDA 19879 b
1919 1 AN ACT concerning State government.
2020 2 Be it enacted by the People of the State of Illinois,
2121 3 represented in the General Assembly:
2222 4 Section 5. The Department of Innovation and Technology Act
2323 5 is amended by changing Sections 1-5, 1-10, 1-15, and 1-25 as
2424 6 follows:
2525 7 (20 ILCS 1370/1-5)
2626 8 Sec. 1-5. Definitions. In this Act:
2727 9 "Client agency" means each transferring agency, or its
2828 10 successor, and any other public agency to which the Department
2929 11 provides service to the extent specified in an interagency
3030 12 agreement with the public agency.
3131 13 "Dedicated unit" means the dedicated bureau, division,
3232 14 office, or other unit within a transferred transferring agency
3333 15 that is responsible for the information technology functions
3434 16 of the transferred transferring agency.
3535 17 "Department" means the Department of Innovation and
3636 18 Technology.
3737 19 "Information technology" means technology,
3838 20 infrastructure, equipment, systems, software, networks, and
3939 21 processes used to create, send, receive, and store electronic
4040 22 or digital information, including, without limitation,
4141 23 computer systems and telecommunication services and systems.
4242
4343
4444
4545 104TH GENERAL ASSEMBLY State of Illinois 2025 and 2026 SB1542 Introduced 2/4/2025, by Sen. Ram Villivalam SYNOPSIS AS INTRODUCED:
4646 20 ILCS 1370/1-520 ILCS 1370/1-1020 ILCS 1370/1-1520 ILCS 1370/1-2520 ILCS 1370/1-75 rep.20 ILCS 1375/5-520 ILCS 1375/5-1520 ILCS 1375/5-2520 ILCS 1375/5-35 new 20 ILCS 1370/1-5 20 ILCS 1370/1-10 20 ILCS 1370/1-15 20 ILCS 1370/1-25 20 ILCS 1370/1-75 rep. 20 ILCS 1375/5-5 20 ILCS 1375/5-15 20 ILCS 1375/5-25 20 ILCS 1375/5-35 new
4747 20 ILCS 1370/1-5
4848 20 ILCS 1370/1-10
4949 20 ILCS 1370/1-15
5050 20 ILCS 1370/1-25
5151 20 ILCS 1370/1-75 rep.
5252 20 ILCS 1375/5-5
5353 20 ILCS 1375/5-15
5454 20 ILCS 1375/5-25
5555 20 ILCS 1375/5-35 new
5656 Amends the Department of Innovation and Technology Act. Repeals the definition of "client agency" and makes changes in the definitions of "dedicated unit", "State agency", and "transferring agency". Replaces references to "transferring agency" with references to "transferred agency". Makes changes in provisions concerning the powers and duties of the Department of Innovation and Technology, including changes in the scope of services provided by the Department and in the classes of persons to whom those services are to be provided. Authorizes the Department to charge fees for service to all State agencies under the jurisdiction of the Governor (rather than only client agencies). Repeals from the Department of Innovation and Technology Act and adds to the Illinois Information Security Improvement Act a provision requiring the principal executive officer of specified units of local government to designate a local official or employee as the primary point of contact for local cybersecurity issues. Requires the name and contact information for the specified individual to be provided to the Statewide Chief Information Security Officer. Further amends the Illinois Information Security Improvement Act. Makes changes concerning the duties of the Office of the Statewide Chief Information Security Officer and the Secretary of Innovation and Technology. Changes the definition of "State agency".
5757 LRB104 09812 BDA 19879 b LRB104 09812 BDA 19879 b
5858 LRB104 09812 BDA 19879 b
5959 A BILL FOR
6060
6161
6262
6363
6464
6565 20 ILCS 1370/1-5
6666 20 ILCS 1370/1-10
6767 20 ILCS 1370/1-15
6868 20 ILCS 1370/1-25
6969 20 ILCS 1370/1-75 rep.
7070 20 ILCS 1375/5-5
7171 20 ILCS 1375/5-15
7272 20 ILCS 1375/5-25
7373 20 ILCS 1375/5-35 new
7474
7575
7676
7777 LRB104 09812 BDA 19879 b
7878
7979
8080
8181
8282
8383
8484
8585
8686
8787 SB1542 LRB104 09812 BDA 19879 b
8888
8989
9090 SB1542- 2 -LRB104 09812 BDA 19879 b SB1542 - 2 - LRB104 09812 BDA 19879 b
9191 SB1542 - 2 - LRB104 09812 BDA 19879 b
9292 1 "Information technology" shall be construed broadly to
9393 2 incorporate future technologies that change or supplant those
9494 3 in effect as of the effective date of this Act.
9595 4 "Information technology functions" means the development,
9696 5 procurement, installation, retention, maintenance, operation,
9797 6 possession, storage, and related functions of all information
9898 7 technology.
9999 8 "Secretary" means the Secretary of Innovation and
100100 9 Technology.
101101 10 "State agency" means each State agency, department, board,
102102 11 and commission under the jurisdiction of the Governor to which
103103 12 the Department provides services.
104104 13 "Transferred Transferring agency" means the Department on
105105 14 Aging; the Departments of Agriculture, Central Management
106106 15 Services, Children and Family Services, Commerce and Economic
107107 16 Opportunity, Corrections, Employment Security, Financial and
108108 17 Professional Regulation, Healthcare and Family Services, Human
109109 18 Rights, Human Services, Insurance, Juvenile Justice, Labor,
110110 19 Lottery, Military Affairs, Natural Resources, Public Health,
111111 20 Revenue, Transportation, and Veterans' Affairs; the Illinois
112112 21 State Police; the Capital Development Board; the Deaf and Hard
113113 22 of Hearing Commission; the Environmental Protection Agency;
114114 23 the Governor's Office of Management and Budget; the
115115 24 Guardianship and Advocacy Commission; the Abraham Lincoln
116116 25 Presidential Library and Museum; the Illinois Arts Council;
117117 26 the Illinois Council on Developmental Disabilities; the
118118
119119
120120
121121
122122
123123 SB1542 - 2 - LRB104 09812 BDA 19879 b
124124
125125
126126 SB1542- 3 -LRB104 09812 BDA 19879 b SB1542 - 3 - LRB104 09812 BDA 19879 b
127127 SB1542 - 3 - LRB104 09812 BDA 19879 b
128128 1 Illinois Emergency Management Agency; the Illinois Gaming
129129 2 Board; the Illinois Liquor Control Commission; the Office of
130130 3 the State Fire Marshal; the Prisoner Review Board; and the
131131 4 Department of Early Childhood.
132132 5 (Source: P.A. 102-376, eff. 1-1-22; 102-538, eff. 8-20-21;
133133 6 102-813, eff. 5-13-22; 102-870, eff. 1-1-23; 103-588, eff.
134134 7 6-5-24.)
135135 8 (20 ILCS 1370/1-10)
136136 9 Sec. 1-10. Transfer of functions. On and after March 25,
137137 10 2016 (the effective date of Executive Order 2016-001):
138138 11 (a) (Blank).
139139 12 (b) (Blank).
140140 13 (c) The personnel of each transferred transferring agency
141141 14 designated by the Governor are transferred to the Department.
142142 15 The status and rights of the employees and the State of
143143 16 Illinois or its transferred transferring agencies under the
144144 17 Personnel Code, the Illinois Public Labor Relations Act, and
145145 18 applicable collective bargaining agreements or under any
146146 19 pension, retirement, or annuity plan shall not be affected by
147147 20 this Act. Under the direction of the Governor, the Secretary,
148148 21 in consultation with the transferred transferring agencies and
149149 22 labor organizations representing the affected employees, shall
150150 23 identify each position and employee who is engaged in the
151151 24 performance of functions transferred to the Department, or
152152 25 engaged in the administration of a law the administration of
153153
154154
155155
156156
157157
158158 SB1542 - 3 - LRB104 09812 BDA 19879 b
159159
160160
161161 SB1542- 4 -LRB104 09812 BDA 19879 b SB1542 - 4 - LRB104 09812 BDA 19879 b
162162 SB1542 - 4 - LRB104 09812 BDA 19879 b
163163 1 which is transferred to the Department, to be transferred to
164164 2 the Department. An employee engaged primarily in providing
165165 3 administrative support for information technology functions
166166 4 may be considered engaged in the performance of functions
167167 5 transferred to the Department.
168168 6 (d) All books, records, papers, documents, property (real
169169 7 and personal), contracts, causes of action, and pending
170170 8 business pertaining to the powers, duties, rights, and
171171 9 responsibilities relating to dedicated units and information
172172 10 technology functions transferred under this Act to the
173173 11 Department, including, but not limited to, material in
174174 12 electronic or magnetic format and necessary computer hardware
175175 13 and software, shall be transferred to the Department.
176176 14 (e) All unexpended appropriations and balances and other
177177 15 funds available for use relating to dedicated units and
178178 16 information technology functions transferred under this Act
179179 17 shall be transferred for use by the Department at the
180180 18 direction of the Governor. Unexpended balances so transferred
181181 19 shall be expended only for the purpose for which the
182182 20 appropriations were originally made.
183183 21 (f) The powers, duties, rights, and responsibilities
184184 22 relating to dedicated units and information technology
185185 23 functions transferred by this Act shall be vested in and shall
186186 24 be exercised by the Department.
187187 25 (g) Whenever reports or notices are now required to be
188188 26 made or given or papers or documents furnished or served by any
189189
190190
191191
192192
193193
194194 SB1542 - 4 - LRB104 09812 BDA 19879 b
195195
196196
197197 SB1542- 5 -LRB104 09812 BDA 19879 b SB1542 - 5 - LRB104 09812 BDA 19879 b
198198 SB1542 - 5 - LRB104 09812 BDA 19879 b
199199 1 person to or upon each dedicated unit in connection with any of
200200 2 the powers, duties, rights, and responsibilities relating to
201201 3 information technology functions transferred by this Act, the
202202 4 same shall be made, given, furnished, or served in the same
203203 5 manner to or upon the Department.
204204 6 (h) This Act does not affect any act done, ratified, or
205205 7 canceled or any right occurring or established or any action
206206 8 or proceeding had or commenced in an administrative, civil, or
207207 9 criminal cause by each dedicated unit relating to information
208208 10 technology functions before the transfer of responsibilities
209209 11 under this Act; such actions or proceedings may be prosecuted
210210 12 and continued by the Department.
211211 13 (i) (Blank).
212212 14 (j) (Blank).
213213 15 (Source: P.A. 102-376, eff. 1-1-22.)
214214 16 (20 ILCS 1370/1-15)
215215 17 Sec. 1-15. Powers and duties.
216216 18 (a) The head officer of the Department is the Secretary,
217217 19 who shall be the chief information officer for the State and
218218 20 the steward of State data with respect to those transferred
219219 21 agencies under the jurisdiction of the Governor. The Secretary
220220 22 shall be appointed by the Governor, with the advice and
221221 23 consent of the Senate. The Department may employ or retain
222222 24 other persons to assist in the discharge of its functions,
223223 25 subject to the Personnel Code.
224224
225225
226226
227227
228228
229229 SB1542 - 5 - LRB104 09812 BDA 19879 b
230230
231231
232232 SB1542- 6 -LRB104 09812 BDA 19879 b SB1542 - 6 - LRB104 09812 BDA 19879 b
233233 SB1542 - 6 - LRB104 09812 BDA 19879 b
234234 1 (b) The Department shall promote best-in-class innovation
235235 2 and technology to transferred client agencies to foster
236236 3 collaboration among client agencies, empower client agencies
237237 4 to provide better service to residents of Illinois, and
238238 5 maximize the value of taxpayer resources. The Department shall
239239 6 be responsible for information technology functions on behalf
240240 7 of transferred client agencies.
241241 8 (c) When requested and when in the best interest of the
242242 9 State, the The Department may shall provide for and assist
243243 10 with coordinate information technology for non-transferred
244244 11 State agencies, and, when requested and when in the best
245245 12 interests of the State, for State constitutional offices,
246246 13 units of federal or local governments, and public and
247247 14 not-for-profit institutions of primary, secondary, and higher
248248 15 education, or other parties not associated with State
249249 16 government. The Department shall establish charges for
250250 17 information technology for State agencies, and, when
251251 18 requested, for State constitutional offices, units of federal
252252 19 or local government, and public and not-for-profit
253253 20 institutions of primary, secondary, or higher education and
254254 21 for use by other parties not associated with State government
255255 22 for any services requested or provided. Entities charged for
256256 23 these services shall make payment to the Department. The
257257 24 Department may instruct all State agencies to report their
258258 25 usage of information technology regularly to the Department in
259259 26 the manner the Secretary may prescribe.
260260
261261
262262
263263
264264
265265 SB1542 - 6 - LRB104 09812 BDA 19879 b
266266
267267
268268 SB1542- 7 -LRB104 09812 BDA 19879 b SB1542 - 7 - LRB104 09812 BDA 19879 b
269269 SB1542 - 7 - LRB104 09812 BDA 19879 b
270270 1 (d) The Department shall establish principles develop and
271271 2 implement standards for the protection of , policies, and
272272 3 procedures to protect the security and interoperability of
273273 4 State data with respect to State those agencies under the
274274 5 jurisdiction of the Governor, including in particular data
275275 6 that are confidential, sensitive, or protected from disclosure
276276 7 by privacy or other laws, while recognizing and balancing the
277277 8 need for collaboration and public transparency.
278278 9 (e) The Department shall be responsible for providing the
279279 10 Governor with timely, comprehensive, and meaningful
280280 11 information pertinent to the formulation and execution of
281281 12 fiscal policy. In performing this responsibility, the
282282 13 Department shall have the power to do the following:
283283 14 (1) Control the procurement, retention, installation,
284284 15 maintenance, and operation, as specified by the
285285 16 Department, of information technology equipment used by
286286 17 State client agencies in such a manner as to achieve
287287 18 maximum economy and provide appropriate assistance in the
288288 19 development of information suitable for management
289289 20 analysis.
290290 21 (2) Establish principles and standards for the
291291 22 implementation of information technology-related
292292 23 reporting by State client agencies and priorities for
293293 24 completion of research by those agencies in accordance
294294 25 with the requirements for management analysis specified by
295295 26 the Department. State agencies shall work with the
296296
297297
298298
299299
300300
301301 SB1542 - 7 - LRB104 09812 BDA 19879 b
302302
303303
304304 SB1542- 8 -LRB104 09812 BDA 19879 b SB1542 - 8 - LRB104 09812 BDA 19879 b
305305 SB1542 - 8 - LRB104 09812 BDA 19879 b
306306 1 Department to follow the principles and standards
307307 2 developed by the Department.
308308 3 (3) Establish charges for information technology and
309309 4 related services requested by transferred client agencies
310310 5 and rendered by the Department. The Department is likewise
311311 6 empowered to establish prices or charges for all
312312 7 information technology reports purchased by State agencies
313313 8 and governmental entities individuals not connected with
314314 9 State government using the Department's services.
315315 10 (4) Instruct all State client agencies to report
316316 11 regularly to the Department, in the manner the Department
317317 12 may prescribe, their usage of information technology, the
318318 13 cost incurred, the information produced, and the
319319 14 procedures followed in obtaining the information. All
320320 15 State client agencies shall request from the Department
321321 16 assistance and consultation in securing any necessary
322322 17 information technology to support their requirements.
323323 18 (5) Examine the accounts and information
324324 19 technology-related data of any organization, body, or
325325 20 agency receiving appropriations from the General Assembly,
326326 21 except for a State constitutional office, the Office of
327327 22 the Executive Inspector General, or any office of the
328328 23 legislative or judicial branches of State government. For
329329 24 a State constitutional office, the Office of the Executive
330330 25 Inspector General, or any office of the legislative or
331331 26 judicial branches of State government, the Department
332332
333333
334334
335335
336336
337337 SB1542 - 8 - LRB104 09812 BDA 19879 b
338338
339339
340340 SB1542- 9 -LRB104 09812 BDA 19879 b SB1542 - 9 - LRB104 09812 BDA 19879 b
341341 SB1542 - 9 - LRB104 09812 BDA 19879 b
342342 1 shall have the power to examine the accounts and
343343 2 information technology-related data of the State
344344 3 constitutional office, the Office of the Executive
345345 4 Inspector General, or any office of the legislative or
346346 5 judicial branches of State government when requested by
347347 6 those offices.
348348 7 (6) Install and operate a modern information
349349 8 technology system for State agencies using equipment
350350 9 adequate to satisfy the requirements for analysis and
351351 10 review as specified by the Department. Expenditures for
352352 11 information technology and related services rendered shall
353353 12 be reimbursed by the recipients. The reimbursement shall
354354 13 be determined by the Department as amounts sufficient to
355355 14 reimburse the Technology Management Revolving Fund for
356356 15 expenditures incurred in rendering the services.
357357 16 (f) In addition to the other powers and duties listed in
358358 17 subsection (e), the Department shall analyze the present and
359359 18 future aims, needs, and requirements of information
360360 19 technology, research, and planning for State agencies in order
361361 20 to provide for the formulation of overall policy relative to
362362 21 the use of information technology and related equipment by the
363363 22 State of Illinois. In making this analysis, the Department
364364 23 shall formulate a master plan for information technology,
365365 24 using information technology most advantageously, and advising
366366 25 whether information technology should be leased or purchased
367367 26 by the State. The Department shall prepare and submit interim
368368
369369
370370
371371
372372
373373 SB1542 - 9 - LRB104 09812 BDA 19879 b
374374
375375
376376 SB1542- 10 -LRB104 09812 BDA 19879 b SB1542 - 10 - LRB104 09812 BDA 19879 b
377377 SB1542 - 10 - LRB104 09812 BDA 19879 b
378378 1 reports of meaningful developments and proposals for
379379 2 legislation to the Governor on or before January 30 each year.
380380 3 The Department shall engage in a continuing analysis and
381381 4 evaluation of the master plan so developed, and it shall be the
382382 5 responsibility of the Department to recommend from time to
383383 6 time any needed amendments and modifications of any master
384384 7 plan enacted by the General Assembly.
385385 8 (g) The Department may make information technology and the
386386 9 use of information technology available to units of local
387387 10 government, elected State officials, State educational
388388 11 institutions, the judicial branch, the legislative branch, and
389389 12 all other governmental units of the State requesting them. The
390390 13 Department shall establish prices and charges for the
391391 14 information technology so furnished and for the use of the
392392 15 information technology. The prices and charges shall be
393393 16 sufficient to reimburse the cost of furnishing the services
394394 17 and use of information technology.
395395 18 (h) The Department may establish principles and standards
396396 19 to provide consistency in the operation and use of information
397397 20 technology by State agencies. State agencies shall work with
398398 21 the Department to follow the principles and standards
399399 22 developed by the Department.
400400 23 (i) The Department may adopt rules under the Illinois
401401 24 Administrative Procedure Act necessary to carry out its
402402 25 responsibilities under this Act.
403403 26 (Source: P.A. 102-376, eff. 1-1-22.)
404404
405405
406406
407407
408408
409409 SB1542 - 10 - LRB104 09812 BDA 19879 b
410410
411411
412412 SB1542- 11 -LRB104 09812 BDA 19879 b SB1542 - 11 - LRB104 09812 BDA 19879 b
413413 SB1542 - 11 - LRB104 09812 BDA 19879 b
414414 1 (20 ILCS 1370/1-25)
415415 2 Sec. 1-25. Charges for services; non-State funding. The
416416 3 Department may establish charges for services rendered by the
417417 4 Department to State client agencies from funds provided
418418 5 directly to the State client agency by appropriation or
419419 6 otherwise. In establishing charges, the Department shall
420420 7 consult with State client agencies to make charges transparent
421421 8 and clear and seek to minimize or avoid charges for costs for
422422 9 which the Department has other funding sources available.
423423 10 State Client agencies shall continue to apply for and
424424 11 otherwise seek federal funds and other capital and operational
425425 12 resources for technology for which the agencies are eligible
426426 13 and, subject to compliance with applicable laws, regulations,
427427 14 and grant terms, make those funds available for use by the
428428 15 Department.
429429 16 (Source: P.A. 102-870, eff. 1-1-23.)
430430 17 (20 ILCS 1370/1-75 rep.)
431431 18 Section 10. The Department of Innovation and Technology
432432 19 Act is amended by repealing Section 1-75.
433433 20 Section 15. The Illinois Information Security Improvement
434434 21 Act is amended by changing Sections 5-5, 5-15, and 5-25 and by
435435 22 adding Section 5-35 as follows:
436436
437437
438438
439439
440440
441441 SB1542 - 11 - LRB104 09812 BDA 19879 b
442442
443443
444444 SB1542- 12 -LRB104 09812 BDA 19879 b SB1542 - 12 - LRB104 09812 BDA 19879 b
445445 SB1542 - 12 - LRB104 09812 BDA 19879 b
446446 1 (20 ILCS 1375/5-5)
447447 2 Sec. 5-5. Definitions. As used in this Act:
448448 3 "Critical information system" means any information system
449449 4 (including any telecommunications system) used or operated by
450450 5 a State agency or by a contractor of a State agency or other
451451 6 organization or entity on behalf of a State agency: that
452452 7 contains health insurance information, medical information, or
453453 8 personal information as defined in the Personal Information
454454 9 Protection Act; where the unauthorized disclosure,
455455 10 modification, destruction of information in the information
456456 11 system could be expected to have a serious, severe, or
457457 12 catastrophic adverse effect on State agency operations,
458458 13 assets, or individuals; or where the disruption of access to
459459 14 or use of the information or information system could be
460460 15 expected to have a serious, severe, or catastrophic adverse
461461 16 effect on State operations, assets, or individuals.
462462 17 "Department" means the Department of Innovation and
463463 18 Technology.
464464 19 "Information security" means protecting information and
465465 20 information systems from unauthorized access, use, disclosure,
466466 21 disruption, modification, or destruction in order to provide:
467467 22 integrity, which means guarding against improper information
468468 23 modification or destruction, and includes ensuring information
469469 24 non-repudiation and authenticity; confidentiality, which means
470470 25 preserving authorized restrictions on access and disclosure,
471471 26 including means for protecting personal privacy and
472472
473473
474474
475475
476476
477477 SB1542 - 12 - LRB104 09812 BDA 19879 b
478478
479479
480480 SB1542- 13 -LRB104 09812 BDA 19879 b SB1542 - 13 - LRB104 09812 BDA 19879 b
481481 SB1542 - 13 - LRB104 09812 BDA 19879 b
482482 1 proprietary information; and availability, which means
483483 2 ensuring timely and reliable access to and use of information.
484484 3 "Incident" means an occurrence that: actually or
485485 4 imminently jeopardizes, without lawful authority, the
486486 5 confidentiality, integrity, or availability of information or
487487 6 an information system; or constitutes a violation or imminent
488488 7 threat of violation of law, security policies, security
489489 8 procedures, or acceptable use policies or standard security
490490 9 practices.
491491 10 "Information system" means a discrete set of information
492492 11 resources organized for the collection, processing,
493493 12 maintenance, use, sharing, dissemination, or disposition of
494494 13 information created or maintained by or for the State of
495495 14 Illinois.
496496 15 "Office" means the Office of the Statewide Chief
497497 16 Information Security Officer.
498498 17 "Secretary" means the Secretary of Innovation and
499499 18 Technology.
500500 19 "Security controls" means the management, operational, and
501501 20 technical controls (including safeguards and countermeasures)
502502 21 for an information system that protect the confidentiality,
503503 22 integrity, and availability of the system and its information.
504504 23 "State agency" means any State agency, department, board,
505505 24 and commission under the jurisdiction of the Governor to which
506506 25 the Department provides services.
507507 26 (Source: P.A. 100-611, eff. 7-20-18.)
508508
509509
510510
511511
512512
513513 SB1542 - 13 - LRB104 09812 BDA 19879 b
514514
515515
516516 SB1542- 14 -LRB104 09812 BDA 19879 b SB1542 - 14 - LRB104 09812 BDA 19879 b
517517 SB1542 - 14 - LRB104 09812 BDA 19879 b
518518 1 (20 ILCS 1375/5-15)
519519 2 Sec. 5-15. Office of the Statewide Chief Information
520520 3 Security Officer.
521521 4 (a) The Office of the Statewide Chief Information Security
522522 5 Officer is established within the Department of Innovation and
523523 6 Technology. The Office is directly subordinate to the
524524 7 Secretary of Innovation and Technology.
525525 8 (b) The Office shall:
526526 9 (1) serve as the strategic planning, facilitation, and
527527 10 coordination office for information technology security in
528528 11 this State and as the lead and central coordinating entity
529529 12 to guide and oversee the information security functions of
530530 13 State agencies;
531531 14 (2) provide information security services to support
532532 15 the secure delivery of State agency services that utilize
533533 16 information systems and to assist State agencies with
534534 17 fulfilling their responsibilities under this Act;
535535 18 (3) conduct information and cybersecurity strategic,
536536 19 operational, and resource planning and facilitating an
537537 20 effective enterprise information security architecture
538538 21 capable of protecting the State;
539539 22 (4) identify information security risks to each State
540540 23 agency, to third-party providers, and to key supply chain
541541 24 partners, including an assessment of the extent to which
542542 25 information resources or processes are vulnerable to
543543
544544
545545
546546
547547
548548 SB1542 - 14 - LRB104 09812 BDA 19879 b
549549
550550
551551 SB1542- 15 -LRB104 09812 BDA 19879 b SB1542 - 15 - LRB104 09812 BDA 19879 b
552552 SB1542 - 15 - LRB104 09812 BDA 19879 b
553553 1 unauthorized access or harm, including the extent to which
554554 2 the State agency's or contractor's electronically stored
555555 3 information is vulnerable to unauthorized access, use,
556556 4 disclosure, disruption, modification, or destruction, and
557557 5 recommend risk mitigation strategies, methods, and
558558 6 procedures to reduce those risks. These assessments shall
559559 7 also include, but not be limited to, assessments of
560560 8 information systems, computers, printers, software,
561561 9 computer networks, interfaces to computer systems, mobile
562562 10 and peripheral device sensors, and other devices or
563563 11 systems which access the State's network, computer
564564 12 software, and information processing or operational
565565 13 procedures of the State agency or of a contractor of the
566566 14 State agency.
567567 15 (5) manage the response to information security and
568568 16 information security incidents involving State agency
569569 17 State of Illinois information systems and ensure the
570570 18 completeness of information system security plans for
571571 19 critical information systems;
572572 20 (6) conduct pre-deployment information security
573573 21 assessments for critical information systems and submit
574574 22 findings and recommendations to the Secretary and State
575575 23 agency heads;
576576 24 (7) develop and conduct targeted operational
577577 25 evaluations, including threat and vulnerability
578578 26 assessments on State agency information systems;
579579
580580
581581
582582
583583
584584 SB1542 - 15 - LRB104 09812 BDA 19879 b
585585
586586
587587 SB1542- 16 -LRB104 09812 BDA 19879 b SB1542 - 16 - LRB104 09812 BDA 19879 b
588588 SB1542 - 16 - LRB104 09812 BDA 19879 b
589589 1 (8) monitor and report compliance of each State
590590 2 agency's compliance agency with State information security
591591 3 policies, standards, and procedures;
592592 4 (9) coordinate statewide information security
593593 5 awareness and training programs; and
594594 6 (10) develop and execute other strategies as necessary
595595 7 to protect State agency's this State's information
596596 8 technology infrastructure and the data stored on or
597597 9 transmitted by such infrastructure.
598598 10 (c) The Office may temporarily suspend operation of an
599599 11 information system or information technology infrastructure
600600 12 that is owned, leased, outsourced, or shared by one or more
601601 13 State agencies in order to isolate the source of, or stop the
602602 14 spread of, an information security breach or other similar
603603 15 information security incident. State agencies shall comply
604604 16 with directives to temporarily discontinue or suspend
605605 17 operations of information systems or information technology
606606 18 infrastructure.
607607 19 (Source: P.A. 100-611, eff. 7-20-18.)
608608 20 (20 ILCS 1375/5-25)
609609 21 Sec. 5-25. Responsibilities.
610610 22 (a) The Secretary shall:
611611 23 (1) appoint a Statewide Chief Information Security
612612 24 Officer pursuant to Section 5-20;
613613 25 (2) provide the Office with the staffing and resources
614614
615615
616616
617617
618618
619619 SB1542 - 16 - LRB104 09812 BDA 19879 b
620620
621621
622622 SB1542- 17 -LRB104 09812 BDA 19879 b SB1542 - 17 - LRB104 09812 BDA 19879 b
623623 SB1542 - 17 - LRB104 09812 BDA 19879 b
624624 1 deemed necessary by the Secretary to fulfill the
625625 2 responsibilities of the Office;
626626 3 (3) oversee statewide information security policies
627627 4 and practices for State agencies, including:
628628 5 (A) directing and overseeing the development,
629629 6 implementation, and communication of statewide
630630 7 information security policies, standards, and
631631 8 guidelines;
632632 9 (B) overseeing the education of State agency
633633 10 personnel regarding the requirement to identify and
634634 11 provide information security protections commensurate
635635 12 with the risk and magnitude of the harm resulting from
636636 13 the unauthorized access, use, disclosure, disruption,
637637 14 modification, or destruction of information in a
638638 15 critical information system;
639639 16 (C) overseeing the development and implementation
640640 17 of a statewide information security risk management
641641 18 program;
642642 19 (D) overseeing State agency compliance with the
643643 20 requirements of this Section;
644644 21 (E) coordinating Information Security policies and
645645 22 practices with related information and personnel
646646 23 resources management policies and procedures; and
647647 24 (F) providing an effective and efficient process
648648 25 to assist State agencies with complying with the
649649 26 requirements of this Act; and
650650
651651
652652
653653
654654
655655 SB1542 - 17 - LRB104 09812 BDA 19879 b
656656
657657
658658 SB1542- 18 -LRB104 09812 BDA 19879 b SB1542 - 18 - LRB104 09812 BDA 19879 b
659659 SB1542 - 18 - LRB104 09812 BDA 19879 b
660660 1 (4) subject to appropriation, establish a
661661 2 cybersecurity liaison program to advise and assist units
662662 3 of local government in identifying cyber threats,
663663 4 performing risk assessments, sharing best practices, and
664664 5 responding to cyber incidents.
665665 6 (b) The Statewide Chief Information Security Officer
666666 7 shall:
667667 8 (1) serve as the head of the Office and ensure the
668668 9 execution of the responsibilities of the Office as set
669669 10 forth in subsection (c) of Section 5-15, the Statewide
670670 11 Chief Information Security Officer shall also oversee
671671 12 State agency personnel with significant responsibilities
672672 13 for information security and ensure a competent workforce
673673 14 that keeps pace with the changing information security
674674 15 environment;
675675 16 (2) develop and recommend information security
676676 17 policies, standards, procedures, and guidelines to the
677677 18 Secretary for statewide adoption and monitor compliance
678678 19 with these policies, standards, guidelines, and procedures
679679 20 through periodic testing;
680680 21 (3) develop and maintain risk-based, cost-effective
681681 22 information security programs and control techniques to
682682 23 address all applicable security and compliance
683683 24 requirements throughout the life cycle of State agency
684684 25 information systems;
685685 26 (4) establish the procedures, processes, and
686686
687687
688688
689689
690690
691691 SB1542 - 18 - LRB104 09812 BDA 19879 b
692692
693693
694694 SB1542- 19 -LRB104 09812 BDA 19879 b SB1542 - 19 - LRB104 09812 BDA 19879 b
695695 SB1542 - 19 - LRB104 09812 BDA 19879 b
696696 1 technologies for State agencies to rapidly and effectively
697697 2 identify threats, risks, and vulnerabilities to State
698698 3 information systems, and ensure the prioritization of the
699699 4 remediation of vulnerabilities that pose risk to the
700700 5 State;
701701 6 (5) develop and implement capabilities and procedures
702702 7 for detecting, reporting, and responding to information
703703 8 security incidents;
704704 9 (6) establish and direct a statewide information
705705 10 security risk management program to identify information
706706 11 security risks in State agencies and deploy risk
707707 12 mitigation strategies, processes, and procedures;
708708 13 (7) establish the State's capability to sufficiently
709709 14 protect the security of data through effective information
710710 15 system security planning, secure system development,
711711 16 acquisition, and deployment, the application of protective
712712 17 technologies and information system certification,
713713 18 accreditation, and assessments;
714714 19 (8) ensure that State agency personnel, including
715715 20 contractors, are appropriately screened and receive
716716 21 information security awareness training;
717717 22 (9) convene meetings with State agency heads and other
718718 23 State officials to help ensure:
719719 24 (A) the ongoing communication of risk and risk
720720 25 reduction strategies,
721721 26 (B) effective implementation of information
722722
723723
724724
725725
726726
727727 SB1542 - 19 - LRB104 09812 BDA 19879 b
728728
729729
730730 SB1542- 20 -LRB104 09812 BDA 19879 b SB1542 - 20 - LRB104 09812 BDA 19879 b
731731 SB1542 - 20 - LRB104 09812 BDA 19879 b
732732 1 security policies and practices, and
733733 2 (C) the incorporation of and compliance with
734734 3 information security policies, standards, and
735735 4 guidelines into the policies and procedures of the
736736 5 State agencies;
737737 6 (10) provide operational and technical assistance to
738738 7 State agencies in implementing policies, principles,
739739 8 standards, and guidelines on information security,
740740 9 including implementation of standards promulgated under
741741 10 subparagraph (A) of paragraph (3) of subsection (a) of
742742 11 this Section, and provide assistance and effective and
743743 12 efficient means for State agencies to comply with the
744744 13 State agency requirements under this Act;
745745 14 (11) in coordination and consultation with the
746746 15 Secretary and the Governor's Office of Management and
747747 16 Budget, review State agency budget requests related to
748748 17 Information Security systems and provide recommendations
749749 18 to the Governor's Office of Management and Budget;
750750 19 (12) ensure the preparation and maintenance of plans
751751 20 and procedures to provide cyber resilience and continuity
752752 21 of operations for critical information systems that
753753 22 support the operations of the State; and
754754 23 (13) take such other actions as the Secretary may
755755 24 direct.
756756 25 (Source: P.A. 101-81, eff. 7-12-19; 102-753, eff. 1-1-23.)
757757
758758
759759
760760
761761
762762 SB1542 - 20 - LRB104 09812 BDA 19879 b
763763
764764
765765 SB1542- 21 -LRB104 09812 BDA 19879 b SB1542 - 21 - LRB104 09812 BDA 19879 b
766766 SB1542 - 21 - LRB104 09812 BDA 19879 b
767767
768768
769769
770770
771771
772772 SB1542 - 21 - LRB104 09812 BDA 19879 b