Kansas 2023-2024 Regular Session

Kansas House Bill HB2077 Compare Versions

The same version is selected twice. Please select two different versions to compare.
OldNewDifferences
11 Session of 2023
22 HOUSE BILL No. 2077
33 By Joint Committee on Information Technology
44 1-18
55 AN ACT concerning information technology; relating to information
66 technology projects and reporting requirements; information
77 technology security training and cybersecurity reports; requiring certain
88 information to be provided to the joint committee on information
99 technology; amending K.S.A. 46-2102, 75-7201, 75-7205, 75-7206,
1010 75-7208, 75-7209, 75-7210, 75-7211, 75-7237, 75-7239, 75-7240 and
1111 75-7242 and repealing the existing sections.
1212 Be it enacted by the Legislature of the State of Kansas:
1313 Section 1. K.S.A. 46-2102 is hereby amended to read as follows: 46-
1414 2102. In addition to other powers and duties authorized or prescribed by
1515 law or by the legislative coordinating council, the joint committee on
1616 information technology shall:
1717 (a) Study the use by state agencies and institutions of computers,
1818 telecommunications and other information technologies;
1919 (b) review new governmental computer hardware and software
2020 acquisition, information storage, transmission, processing and
2121 telecommunications technologies proposed by state agencies and
2222 institutions, and the implementation plans therefor, including all
2323 information technology project budget estimates and three-year strategic
2424 information technology plans that are submitted to the joint committee
2525 pursuant to K.S.A. 2000 Supp. 75-7210, and amendments thereto;
2626 (c) advise and consult on all state agency information technology
2727 projects, as defined in K.S.A. 75-7201, and amendments thereto, that pose
2828 a significant business risk as determined by the information technology
2929 executive council's policies and in accordance with K.S.A. 75-7209, and
3030 amendments thereto;
3131 (d) make recommendations on all such implementation plans, budget
3232 estimates, requests for proposals for information technology projects and
3333 three-year plans to the ways and means committee of the senate and the
3434 committee on appropriations of the house of representatives;
3535 (d)(e) study the progress and results of all newly implemented
3636 governmental computer hardware and software, information storage,
3737 transmission, processing and telecommunications technologies of state
3838 agencies and institutions including all information technology projects for
3939 state agencies which have been authorized or for which appropriations
4040 1
4141 2
4242 3
4343 4
4444 5
4545 6
4646 7
4747 8
4848 9
4949 10
5050 11
5151 12
5252 13
5353 14
5454 15
5555 16
5656 17
5757 18
5858 19
5959 20
6060 21
6161 22
6262 23
6363 24
6464 25
6565 26
6666 27
6767 28
6868 29
6969 30
7070 31
7171 32
7272 33
7373 34
7474 35
7575 36 HB 2077 2
7676 have been approved by the legislature; and
7777 (e)(f) make an annual report to the legislative coordinating council as
7878 provided in K.S.A. 46-1207, and amendments thereto, and such special
7979 reports to committees of the house of representatives and senate as are
8080 deemed appropriate by the joint committee.
8181 Sec. 2. K.S.A. 75-7201 is hereby amended to read as follows: 75-
8282 7201. As used in K.S.A. 75-7201 through 75-7212, and amendments
8383 thereto:
8484 (a) "Business risk" means the overall level of risk determined by a
8585 business risk assessment that includes, but is not limited to, cost,
8686 information security and other elements as determined by the information
8787 technology executive council's policies.
8888 (b) "Cumulative cost" means the total expenditures, from all sources,
8989 for any information technology project by one or more state agencies to
9090 meet project objectives from project start to project completion or the date
9191 and time the project is terminated if it is not completed.
9292 (b)(c) "Executive agency" means any state agency in the executive
9393 branch of government.
9494 (c)(d) "Information technology project" means a project for a major
9595 computer, telecommunications or other information technology
9696 improvement with an estimated cumulative cost of $250,000 or more and
9797 includes any such project that has proposed expenditures for: (1) New or
9898 replacement equipment or software; (2) upgrade improvements to existing
9999 equipment and any computer systems, programs or software upgrades
100100 therefor; or (3) data or consulting or other professional services for such a
101101 project an information technology effort by a state agency of defined and
102102 limited duration that implements, effects a change in or presents a risk to
103103 processes, services, security, systems, records, data, human resources or
104104 architecture.
105105 (d)(e) "Information technology project change or overrun" means any
106106 of the following any change in:
107107 (1) Any change in Planned expenditures for an information
108108 technology project that would result in the total authorized cost of the
109109 project being increased above the currently authorized cost of such project
110110 by more than either $1,000,000 or 10% of such currently authorized cost
111111 of such project, whichever is lower or an established threshold within the
112112 information technology executive council's policies;
113113 (2) any change in the scope or project timeline of an information
114114 technology project, as such scope or timeline was presented to and
115115 reviewed by the joint committee or the chief information technology
116116 officer to whom the project was submitted pursuant to K.S.A. 75-7209,
117117 and amendments thereto, that is a change of more than 10% or a change
118118 that is significant as determined by the information technology executive
119119 1
120120 2
121121 3
122122 4
123123 5
124124 6
125125 7
126126 8
127127 9
128128 10
129129 11
130130 12
131131 13
132132 14
133133 15
134134 16
135135 17
136136 18
137137 19
138138 20
139139 21
140140 22
141141 23
142142 24
143143 25
144144 26
145145 27
146146 28
147147 29
148148 30
149149 31
150150 32
151151 33
152152 34
153153 35
154154 36
155155 37
156156 38
157157 39
158158 40
159159 41
160160 42
161161 43 HB 2077 3
162162 council's policies; or
163163 (3) any change in the proposed use of any new or replacement
164164 information technology equipment or in the use of any existing
165165 information technology equipment that has been significantly upgraded.
166166 (e)(f) "Joint committee" means the joint committee on information
167167 technology.
168168 (f)(g) "Judicial agency" means any state agency in the judicial branch
169169 of government.
170170 (g)(h) "Legislative agency" means any state agency in the legislative
171171 branch of government.
172172 (h)(i) "Project" means a planned series of events or activities that is
173173 intended to accomplish a specified outcome in a specified time period,
174174 under consistent management direction within a state agency or shared
175175 among two or more state agencies, and that has an identifiable budget for
176176 anticipated expenses.
177177 (i)(j) "Project completion" means the date and time when the head of
178178 a state agency having primary responsibility for an information technology
179179 project certifies that the improvement being produced or altered under the
180180 project is ready for operational use.
181181 (j)(k) "Project start" means the date and time when a state agency
182182 begins a formal study of a business process or technology concept to
183183 assess the needs of the state agency, determines project feasibility or
184184 prepares an information technology project budget estimate under K.S.A.
185185 75-7209, and amendments thereto.
186186 (k)(l) "State agency" means any state office or officer, department,
187187 board, commission, institution or bureau, or any agency, division or unit
188188 thereof.
189189 Sec. 3. K.S.A. 75-7205 is hereby amended to read as follows: 75-
190190 7205. (a) There is hereby established within and as a part of the office of
191191 information technology services the position of executive chief
192192 information technology officer. The executive chief information
193193 technology officer shall be in the unclassified service under the Kansas
194194 civil service act, shall be appointed by the governor, and shall receive
195195 compensation in an amount fixed by the governor. The executive chief
196196 information technology officer shall maintain a presence in any cabinet
197197 established by the governor and shall report to the governor.
198198 (b) The executive chief information technology officer shall:
199199 (1) Review and consult with each executive agency regarding
200200 information technology plans, deviations from the state information
201201 technology architecture, information technology project estimates and
202202 information technology project changes and overruns submitted by such
203203 agency pursuant to K.S.A. 75-7209, and amendments thereto, to determine
204204 whether the agency has complied with:
205205 1
206206 2
207207 3
208208 4
209209 5
210210 6
211211 7
212212 8
213213 9
214214 10
215215 11
216216 12
217217 13
218218 14
219219 15
220220 16
221221 17
222222 18
223223 19
224224 20
225225 21
226226 22
227227 23
228228 24
229229 25
230230 26
231231 27
232232 28
233233 29
234234 30
235235 31
236236 32
237237 33
238238 34
239239 35
240240 36
241241 37
242242 38
243243 39
244244 40
245245 41
246246 42
247247 43 HB 2077 4
248248 (A) The information technology resource policies and procedures and
249249 project management methodologies adopted by the information technology
250250 executive council;
251251 (B) the information technology architecture adopted by the
252252 information technology executive council;
253253 (C) the standards for data management adopted by the information
254254 technology executive council; and
255255 (D) the strategic information technology management plan adopted
256256 by the information technology executive council;
257257 (2) report to the chief information technology architect all deviations
258258 from the state information architecture that are reported to the executive
259259 information technology officer by executive agencies;
260260 (3) submit recommendations to the division of the budget as to the
261261 technical and management merit of information technology project
262262 estimates projects and information technology project changes and
263263 overruns submitted by executive agencies that are reportable pursuant to
264264 K.S.A. 75-7209, and amendments thereto, based on the determinations
265265 made pursuant to subsection (b)(1);
266266 (4) monitor executive agencies' compliance with:
267267 (A) The information technology resource policies and procedures and
268268 project management methodologies adopted by the information technology
269269 executive council;
270270 (B) the information technology architecture adopted by the
271271 information technology executive council;
272272 (C) the standards for data management adopted by the information
273273 technology executive council; and
274274 (D) the strategic information technology management plan adopted
275275 by the information technology executive council;
276276 (5) coordinate implementation of new information technology among
277277 executive agencies and with the judicial and legislative chief information
278278 technology officers;
279279 (6) designate the ownership of information resource processes and the
280280 lead agency for implementation of new technologies and networks shared
281281 by multiple agencies within the executive branch of state government; and
282282 (7) perform such other functions and duties as provided by law or as
283283 directed by the governor.
284284 Sec. 4. K.S.A. 75-7206 is hereby amended to read as follows: 75-
285285 7206. (a) There is hereby established within and as a part of the office of
286286 the state judicial administrator the position of judicial chief information
287287 technology officer. The judicial chief information technology officer shall
288288 be appointed by the judicial administrator, subject to approval of the chief
289289 justice, and shall receive compensation determined by the judicial
290290 administrator, subject to approval of the chief justice.
291291 1
292292 2
293293 3
294294 4
295295 5
296296 6
297297 7
298298 8
299299 9
300300 10
301301 11
302302 12
303303 13
304304 14
305305 15
306306 16
307307 17
308308 18
309309 19
310310 20
311311 21
312312 22
313313 23
314314 24
315315 25
316316 26
317317 27
318318 28
319319 29
320320 30
321321 31
322322 32
323323 33
324324 34
325325 35
326326 36
327327 37
328328 38
329329 39
330330 40
331331 41
332332 42
333333 43 HB 2077 5
334334 (b) The judicial chief information technology officer shall:
335335 (1) Review and consult with each judicial agency regarding
336336 information technology plans, deviations from the state information
337337 technology architecture, information technology project estimates and
338338 information technology project changes and overruns submitted by such
339339 agency pursuant to K.S.A. 75-7209, and amendments thereto, to determine
340340 whether the agency has complied with:
341341 (A) The information technology resource policies and procedures and
342342 project management methodologies adopted by the information technology
343343 executive council;
344344 (B) the information technology architecture adopted by the
345345 information technology executive council;
346346 (C) the standards for data management adopted by the information
347347 technology executive council; and
348348 (D) the strategic information technology management plan adopted
349349 by the information technology executive council;
350350 (2) report to the chief information technology architect all deviations
351351 from the state information architecture that are reported to the judicial
352352 information technology officer by judicial agencies;
353353 (3) submit recommendations to the judicial administrator as to the
354354 technical and management merit of information technology project
355355 estimates projects and information technology project changes and
356356 overruns submitted by judicial agencies that are reportable pursuant to
357357 K.S.A. 75-7209, and amendments thereto, based on the determinations
358358 pursuant to subsection (b)(1);
359359 (4) monitor judicial agencies' compliance with:
360360 (A) The information technology resource policies and procedures and
361361 project management methodologies adopted by the information technology
362362 executive council;
363363 (B) the information technology architecture adopted by the
364364 information technology executive council;
365365 (C) the standards for data management adopted by the information
366366 technology executive council; and
367367 (D) the strategic information technology management plan adopted
368368 by the information technology executive council;
369369 (5) coordinate implementation of new information technology among
370370 judicial agencies and with the executive and legislative chief information
371371 technology officers;
372372 (6) designate the ownership of information resource processes and the
373373 lead agency for implementation of new technologies and networks shared
374374 by multiple agencies within the judicial branch of state government; and
375375 (7) perform such other functions and duties as provided by law or as
376376 directed by the judicial administrator.
377377 1
378378 2
379379 3
380380 4
381381 5
382382 6
383383 7
384384 8
385385 9
386386 10
387387 11
388388 12
389389 13
390390 14
391391 15
392392 16
393393 17
394394 18
395395 19
396396 20
397397 21
398398 22
399399 23
400400 24
401401 25
402402 26
403403 27
404404 28
405405 29
406406 30
407407 31
408408 32
409409 33
410410 34
411411 35
412412 36
413413 37
414414 38
415415 39
416416 40
417417 41
418418 42
419419 43 HB 2077 6
420420 Sec. 5. K.S.A. 75-7208 is hereby amended to read as follows: 75-
421421 7208. The legislative chief information technology officer shall:
422422 (a) Review and consult with each legislative agency regarding
423423 information technology plans, deviations from the state information
424424 technology architecture, information technology project estimates and
425425 information technology project changes and overruns submitted by such
426426 agency pursuant to K.S.A. 75-7209, and amendments thereto, to determine
427427 whether the agency has complied with the:
428428 (1)The  Information technology resource policies and procedures and
429429 project management methodologies adopted by the information technology
430430 executive council;
431431 (2)the  information technology architecture adopted by the
432432 information technology executive council;
433433 (3)the  standards for data management adopted by the information
434434 technology executive council; and
435435 (4)the  strategic information technology management plan adopted by
436436 the information technology executive council;
437437 (b) report to the chief information technology architect all deviations
438438 from the state information architecture that are reported to the legislative
439439 information technology officer by legislative agencies;
440440 (c) submit recommendations to the legislative coordinating council as
441441 to the technical and management merit of information technology project
442442 estimates projects and information technology project changes and
443443 overruns submitted by legislative agencies that are reportable pursuant to
444444 K.S.A. 75-7209, and amendments thereto, based on the determinations
445445 pursuant to subsection (a);
446446 (d) monitor legislative agencies' compliance with the:
447447 (1) The Information technology resource policies and procedures and
448448 project management methodologies adopted by the information technology
449449 executive council;
450450 (2) the information technology architecture adopted by the
451451 information technology executive council;
452452 (3) the standards for data management adopted by the information
453453 technology executive council; and
454454 (4) the strategic information technology management plan adopted by
455455 the information technology executive council;
456456 (e) coordinate implementation of new information technology among
457457 legislative agencies and with the executive and judicial chief information
458458 technology officers;
459459 (f) designate the ownership of information resource processes and the
460460 lead agency for implementation of new technologies and networks shared
461461 by multiple agencies within the legislative branch of state government;
462462 (g) serve as staff of the joint committee; and
463463 1
464464 2
465465 3
466466 4
467467 5
468468 6
469469 7
470470 8
471471 9
472472 10
473473 11
474474 12
475475 13
476476 14
477477 15
478478 16
479479 17
480480 18
481481 19
482482 20
483483 21
484484 22
485485 23
486486 24
487487 25
488488 26
489489 27
490490 28
491491 29
492492 30
493493 31
494494 32
495495 33
496496 34
497497 35
498498 36
499499 37
500500 38
501501 39
502502 40
503503 41
504504 42
505505 43 HB 2077 7
506506 (h) perform such other functions and duties as provided by law or as
507507 directed by the legislative coordinating council or the joint committee.
508508 Sec. 6. K.S.A. 75-7209 is hereby amended to read as follows: 75-
509509 7209. (a) (1) Whenever an agency proposes an information technology
510510 project, such agency shall prepare and submit information technology
511511 project documentation to the chief information technology officer of the
512512 branch of state government of which the agency is a part of a project
513513 budget estimate therefor, and for each amendment or revision thereof, in
514514 accordance with this section. Each information technology project budget
515515 estimate shall be in such form as required by the director of the budget, in
516516 consultation with the chief information technology architect, and by this
517517 section. In each case, the agency shall prepare and include as a part of such
518518 project budget estimate a plan consisting of a written program statement
519519 describing the project. The program statement shall:
520520 (1) Include a detailed description of and justification for the project,
521521 including: (A) An analysis of the programs, activities and other needs and
522522 intended uses for the additional or improved information technology; (B) a
523523 statement of project scope including identification of the organizations and
524524 individuals to be affected by the project and a definition of the
525525 functionality to result from the project; and (C) an analysis of the
526526 alternative means by which such information technology needs and uses
527527 could be satisfied;
528528 (2) describe the tasks and schedule for the project and for each phase
529529 of the project, if the project is to be completed in more than one phase;
530530 (3) include a financial plan showing: (A) The proposed source of
531531 funding and categorized expenditures for each phase of the project; and
532532 (B) cost estimates for any needs analyses or other investigations,
533533 consulting or other professional services, computer programs, data,
534534 equipment, buildings or major repairs or improvements to buildings and
535535 other items or services necessary for the project; and
536536 (4) include a cost-benefit statement based on an analysis of
537537 qualitative as well as financial benefits. Such information technology
538538 project documentation shall:
539539 (A) Include a financial plan showing the proposed source of funding
540540 and categorized expenditures for each phase of the project and cost
541541 estimates for any needs analyses or other investigations, consulting or
542542 other professional services, computer programs, data, equipment,
543543 buildings or major repairs or improvements to buildings and other items
544544 or services necessary for the project; and
545545 (B) be consistent with:
546546 (i) Information technology resource policies and procedures and
547547 project management methodologies for all state agencies;
548548 (ii) an information technology architecture, including
549549 1
550550 2
551551 3
552552 4
553553 5
554554 6
555555 7
556556 8
557557 9
558558 10
559559 11
560560 12
561561 13
562562 14
563563 15
564564 16
565565 17
566566 18
567567 19
568568 20
569569 21
570570 22
571571 23
572572 24
573573 25
574574 26
575575 27
576576 28
577577 29
578578 30
579579 31
580580 32
581581 33
582582 34
583583 35
584584 36
585585 37
586586 38
587587 39
588588 40
589589 41
590590 42
591591 43 HB 2077 8
592592 telecommunications systems, networks and equipment, that covers all state
593593 agencies;
594594 (iii) standards for data management for all state agencies; and
595595 (iv) a strategic information technology management plan for the
596596 state.
597597 (2) Any information technology project with significant business risk,
598598 as determined pursuant to the information technology executive council's
599599 policies, shall be presented to the joint committee on information
600600 technology by such branch chief information technology officer.
601601 (b) (1) Before one or more state agencies proposing an information
602602 technology project begin implementation of the project, the project plan,
603603 including the architecture and the cost-benefit analysis, shall be approved
604604 by the head of each state agency proposing the project and by the chief
605605 information technology officer of each branch of state government of
606606 which the agency or agencies are a part. Approval of those projects that
607607 involve telecommunications services shall also be subject to the provisions
608608 of K.S.A. 75-4709, 75-4710 and 75-4712, and amendments thereto.
609609 (2) All specifications for bids or proposals related to an approved
610610 information technology project of one or more state agencies shall be
611611 reviewed by the chief information technology officer of each branch of
612612 state government of which the agency or agencies are a part Prior to the
613613 release of any request for proposal for an information technology project
614614 with significant business risk:
615615 (A) Specifications for bids or proposals for such project shall be
616616 submitted to the chief information technology officer of the branch of state
617617 government of which the agency or agencies are a part. Information
618618 technology projects requiring chief information technology officer
619619 approval shall also require the chief information technology officer's
620620 written approval on specifications for bids or proposals; and
621621 (B) (i) The chief information technology officer of the appropriate
622622 branch over the state agency or agencies that are involved in such project
623623 shall submit the project, the project plan, including the architecture, and
624624 the cost-benefit analysis to the joint committee on information technology
625625 to advise and consult on the project. Such chief information technology
626626 officer shall submit such information to each member of the joint
627627 committee and to the director of the legislative research department. Each
628628 such project plan summary shall include a notice specifying the date the
629629 summary was mailed or emailed. After receiving any such project plan
630630 summary, each member shall review the information and may submit
631631 questions, requests for additional information or request a presentation
632632 and review of the proposed project at a meeting of the joint committee. If
633633 two or more members of the joint committee contact the director of the
634634 legislative research department within seven business days of the date
635635 1
636636 2
637637 3
638638 4
639639 5
640640 6
641641 7
642642 8
643643 9
644644 10
645645 11
646646 12
647647 13
648648 14
649649 15
650650 16
651651 17
652652 18
653653 19
654654 20
655655 21
656656 22
657657 23
658658 24
659659 25
660660 26
661661 27
662662 28
663663 29
664664 30
665665 31
666666 32
667667 33
668668 34
669669 35
670670 36
671671 37
672672 38
673673 39
674674 40
675675 41
676676 42
677677 43 HB 2077 9
678678 specified in the summary description and request that the joint committee
679679 schedule a meeting for such presentation and review, then the director of
680680 the legislative research department shall notify the chief information
681681 technology officer of the appropriate branch, the head of such agency and
682682 the chairperson of the joint committee that a meeting has been requested
683683 for such presentation and review on the next business day following the
684684 members' contact with the director of the legislative research department.
685685 Upon receiving such notification, the chairperson shall call a meeting of
686686 the joint committee as soon as practicable for the purpose of such
687687 presentation and review and shall furnish the chief information technology
688688 officer of the appropriate branch and the head of such agency with notice
689689 of the time, date and place of the meeting. Except as provided in
690690 subsection (b)(1)(B)(ii), the state agency shall not authorize or approve
691691 the release of any request for proposal or other bid event for an
692692 information technology project without having first advised and consulted
693693 with the joint committee at a meeting.
694694 (ii) The state agency or agencies shall be deemed to have advised
695695 and consulted with the joint committee about such proposed release of any
696696 request for proposal or other bid event for an information technology
697697 project and may authorize or approve such proposed release of any
698698 request for proposal or other bid event for an information technology
699699 project if:
700700 (a) Fewer than two members of the joint committee contact the
701701 director of the legislative research department within seven business days
702702 of the date the project plan summary was mailed and request a committee
703703 meeting for a presentation and review of any such proposed request for
704704 proposal or other bid event for an information technology project; or
705705 (b) a committee meeting is requested by at least two members of the
706706 joint committee pursuant to this paragraph, but such meeting does not
707707 occur within two calendar weeks of the chairperson receiving the
708708 notification from the director of the legislative research department of a
709709 request for such meeting.
710710 (3)(2) (A) Agencies are prohibited from contracting with a vendor to
711711 implement the project if that vendor prepared or assisted in the preparation
712712 of the program statement required under subsection (a), the project
713713 planning documents required under subsection (b)(1), or any other project
714714 plans prepared prior to the project being approved by the chief information
715715 technology officer as required under subsection (b)(1) by this section.
716716 (B) Information technology projects with an estimated cumulative
717717 cost of less than $5,000,000 are exempted from the provisions of
718718 subparagraph (A).
719719 (C) The provisions of subparagraph (A) may be waived with prior
720720 written permission from the chief information technology officer.
721721 1
722722 2
723723 3
724724 4
725725 5
726726 6
727727 7
728728 8
729729 9
730730 10
731731 11
732732 12
733733 13
734734 14
735735 15
736736 16
737737 17
738738 18
739739 19
740740 20
741741 21
742742 22
743743 23
744744 24
745745 25
746746 26
747747 27
748748 28
749749 29
750750 30
751751 31
752752 32
753753 33
754754 34
755755 35
756756 36
757757 37
758758 38
759759 39
760760 40
761761 41
762762 42
763763 43 HB 2077 10
764764 (c) Annually at the time specified by the chief information technology
765765 officer of the branch of state government of which the agency is a part,
766766 each agency shall submit to such officer:
767767 (1) A copy of a three-year strategic information technology plan that
768768 sets forth the agency's current and future information technology needs
769769 and utilization plans for the next three ensuing fiscal years, in such form
770770 and containing such additional information as prescribed by the chief
771771 information technology officer; and
772772 (2) any deviations from the state information technology architecture
773773 adopted by the information technology executive council.
774774 (d) The provisions of this section shall not apply to the information
775775 network of Kansas (INK).
776776 Sec. 7. K.S.A. 75-7210 is hereby amended to read as follows: 75-
777777 7210. (a) Not later than October November 1 of each year, the executive,
778778 judicial and legislative chief information technology officers shall submit
779779 to the joint committee and to the legislative research department all
780780 information technology project budget estimates and amendments and
781781 revisions thereto, all three-year plans and all deviations from the state
782782 information technology architecture submitted to such officers pursuant to
783783 K.S.A. 75-7209, and amendments thereto. The legislative chief
784784 information technology officer joint committee shall review all such
785785 estimates and amendments and revisions thereto, plans and deviations and
786786 shall make recommendations to the joint committee house standing
787787 committee on appropriations and the senate standing committee on ways
788788 and means regarding the merit thereof and appropriations therefor.
789789 (b) The executive and judicial chief information technology officers
790790 shall report to the legislative chief information technology officer, at times
791791 agreed upon by the three officers:
792792 (1) Progress regarding implementation of information technology
793793 projects of state agencies within the executive and judicial branches of
794794 state government; and
795795 (2) all proposed expenditures for such projects, including all revisions
796796 to such proposed expenditures, for the current fiscal year and for ensuing
797797 fiscal years.
798798 Sec. 8. K.S.A. 75-7211 is hereby amended to read as follows: 75-
799799 7211. (a) The legislative chief information technology officer, under the
800800 direction of the joint committee, shall monitor state agency execution of
801801 reported information technology projects and, at times agreed upon by.
802802 The joint committee shall require the three chief information technology
803803 officers, shall to report progress regarding the implementation of such
804804 projects and all proposed expenditures therefor, including all revisions to
805805 such proposed expenditures for the current fiscal year and for ensuing
806806 fiscal years.
807807 1
808808 2
809809 3
810810 4
811811 5
812812 6
813813 7
814814 8
815815 9
816816 10
817817 11
818818 12
819819 13
820820 14
821821 15
822822 16
823823 17
824824 18
825825 19
826826 20
827827 21
828828 22
829829 23
830830 24
831831 25
832832 26
833833 27
834834 28
835835 29
836836 30
837837 31
838838 32
839839 33
840840 34
841841 35
842842 36
843843 37
844844 38
845845 39
846846 40
847847 41
848848 42
849849 43 HB 2077 11
850850 (b) For information technology projects, the joint committee may:
851851 (1) Require the head of a any state agency with primary responsibility
852852 for an information technology project may authorize or approve, without
853853 prior consultation with the joint committee, any change in planned
854854 expenditures for an information technology project that would result in the
855855 total cost of the project being increased above the currently authorized cost
856856 of such project but that increases the total cost of such project by less than
857857 the lower of either $1,000,000 or 10% of the currently authorized cost, and
858858 any change in planned expenditures for an information technology project
859859 involving a cost reduction, other than a change in the proposed use of any
860860 new or replacement information technology equipment or in the use of any
861861 existing information technology equipment that has been significantly
862862 upgraded to advise and consult on the status and progress of such
863863 information technology project, including revisions to expenditures for the
864864 current fiscal year and ensuing fiscal years; and
865865 (2) report on the status and progress of such information technology
866866 projects to the senate standing committee on ways and means, the house of
867867 representatives standing committee on appropriations and the legislative
868868 budget committee.
869869 (c) Prior to authorizing or approving any information technology
870870 project change or overrun, the head of a state agency with primary
871871 responsibility for an such information technology project shall not
872872 authorize or approve, without first advising and consulting with the joint
873873 committee any information technology project change or overrun report
874874 all such information technology project changes or overruns to the joint
875875 committee through the chief information technology officer of the branch
876876 of state government of which the agency is a part pursuant to the
877877 information technology executive council's policy. The joint committee
878878 shall report all such changes and overruns to the senate standing
879879 committee on ways and means and, the house of representatives standing
880880 committee on appropriations and the legislative budget committee.
881881 Sec. 9. K.S.A. 75-7237 is hereby amended to read as follows: 75-
882882 7237. As used in K.S.A. 75-7236 through 75-7243, and amendments
883883 thereto:
884884 (a) "Act" means the Kansas cybersecurity act.
885885 (b) "Breach" or "breach of security" means unauthorized access of
886886 data in electronic form containing personal information. Good faith access
887887 of personal information by an employee or agent of an executive branch
888888 agency does not constitute a breach of security, provided that the
889889 information is not used for a purpose unrelated to the business or subject to
890890 further unauthorized use.
891891 (c) "CISO" means the executive branch chief information security
892892 officer.
893893 1
894894 2
895895 3
896896 4
897897 5
898898 6
899899 7
900900 8
901901 9
902902 10
903903 11
904904 12
905905 13
906906 14
907907 15
908908 16
909909 17
910910 18
911911 19
912912 20
913913 21
914914 22
915915 23
916916 24
917917 25
918918 26
919919 27
920920 28
921921 29
922922 30
923923 31
924924 32
925925 33
926926 34
927927 35
928928 36
929929 37
930930 38
931931 39
932932 40
933933 41
934934 42
935935 43 HB 2077 12
936936 (d) "Cybersecurity" is the body of information technologies,
937937 processes and practices designed to protect networks, computers, programs
938938 and data from attack, damage or unauthorized access.
939939 (e) "Cybersecurity positions" do not include information technology
940940 positions within executive branch agencies.
941941 (f) "Data in electronic form" means any data stored electronically or
942942 digitally on any computer system or other database and includes
943943 recordable tapes and other mass storage devices.
944944 (g) "Executive branch agency" means any agency in the executive
945945 branch of the state of Kansas, but does not include elected office agencies,
946946 the adjutant general's department, the Kansas public employees retirement
947947 system, regents' institutions, or the board of regents.
948948 (h) "KISO" means the Kansas information security office.
949949 (i) (1) "Personal information" means:
950950 (A) An individual's first name or first initial and last name, in
951951 combination with at least one of the following data elements for that
952952 individual:
953953 (i) Social security number;
954954 (ii) driver's license or identification card number, passport number,
955955 military identification number or other similar number issued on a
956956 government document used to verify identity;
957957 (iii) financial account number or credit or debit card number, in
958958 combination with any security code, access code or password that is
959959 necessary to permit access to an individual's financial account;
960960 (iv) any information regarding an individual's medical history, mental
961961 or physical condition or medical treatment or diagnosis by a healthcare
962962 professional; or
963963 (v) an individual's health insurance policy number or subscriber
964964 identification number and any unique identifier used by a health insurer to
965965 identify the individual; or
966966 (B) a user name or email address, in combination with a password or
967967 security question and answer that would permit access to an online
968968 account.
969969 (2) "Personal information" does not include information:
970970 (A) About an individual that has been made publicly available by a
971971 federal agency, state agency or municipality; or
972972 (B) that is encrypted, secured or modified by any other method or
973973 technology that removes elements that personally identify an individual or
974974 that otherwise renders the information unusable.
975975 (j) "State agency" means the same as defined in K.S.A. 75-7201, and
976976 amendments thereto.
977977 Sec. 10. K.S.A. 75-7239 is hereby amended to read as follows: 75-
978978 7239. (a) There is hereby established within and as a part of the office of
979979 1
980980 2
981981 3
982982 4
983983 5
984984 6
985985 7
986986 8
987987 9
988988 10
989989 11
990990 12
991991 13
992992 14
993993 15
994994 16
995995 17
996996 18
997997 19
998998 20
999999 21
10001000 22
10011001 23
10021002 24
10031003 25
10041004 26
10051005 27
10061006 28
10071007 29
10081008 30
10091009 31
10101010 32
10111011 33
10121012 34
10131013 35
10141014 36
10151015 37
10161016 38
10171017 39
10181018 40
10191019 41
10201020 42
10211021 43 HB 2077 13
10221022 information technology services the Kansas information security office.
10231023 The Kansas information security office shall be administered by the CISO
10241024 and be staffed appropriately to effect the provisions of the Kansas
10251025 cybersecurity act.
10261026 (b) For the purpose of preparing the governor's budget report and
10271027 related legislative measures submitted to the legislature, the Kansas
10281028 information security office, established in this section, shall be considered
10291029 a separate state agency and shall be titled for such purpose as the "Kansas
10301030 information security office." The budget estimates and requests of such
10311031 office shall be presented as from a state agency separate from the
10321032 department of administration office of information technology services,
10331033 and such separation shall be maintained in the budget documents and
10341034 reports prepared by the director of the budget and the governor, or either of
10351035 them, including all related legislative reports and measures submitted to
10361036 the legislature.
10371037 (c) Under direction of the CISO, the KISO shall:
10381038 (1) Administer the Kansas cybersecurity act;
10391039 (2) assist the executive branch in developing, implementing and
10401040 monitoring strategic and comprehensive information security risk-
10411041 management programs;
10421042 (3) facilitate executive branch information security governance,
10431043 including the consistent application of information security programs,
10441044 plans and procedures;
10451045 (4) using standards adopted by the information technology executive
10461046 council, create and manage a unified and flexible control framework to
10471047 integrate and normalize requirements resulting from applicable state and
10481048 federal laws, and rules and regulations;
10491049 (5) facilitate a metrics, logging and reporting framework to measure
10501050 the efficiency and effectiveness of state information security programs;
10511051 (6) provide the executive branch strategic risk guidance for
10521052 information technology projects, including the evaluation and
10531053 recommendation of technical controls;
10541054 (7) assist in the development of executive branch agency
10551055 cybersecurity programs that are in to ensure compliance with applicable
10561056 state and federal laws and rules and regulations and standards adopted by
10571057 the information technology executive council;
10581058 (8) coordinate the use of external resources involved in information
10591059 security programs, including, but not limited to, interviewing and
10601060 negotiating contracts and fees;
10611061 (9) liaise with external agencies, such as law enforcement and other
10621062 advisory bodies as necessary, to ensure a strong security posture;
10631063 (10) assist in the development of plans and procedures to manage and
10641064 recover business-critical services in the event of a cyberattack or other
10651065 1
10661066 2
10671067 3
10681068 4
10691069 5
10701070 6
10711071 7
10721072 8
10731073 9
10741074 10
10751075 11
10761076 12
10771077 13
10781078 14
10791079 15
10801080 16
10811081 17
10821082 18
10831083 19
10841084 20
10851085 21
10861086 22
10871087 23
10881088 24
10891089 25
10901090 26
10911091 27
10921092 28
10931093 29
10941094 30
10951095 31
10961096 32
10971097 33
10981098 34
10991099 35
11001100 36
11011101 37
11021102 38
11031103 39
11041104 40
11051105 41
11061106 42
11071107 43 HB 2077 14
11081108 disaster;
11091109 (11) assist executive branch agencies to create a framework for roles
11101110 and responsibilities relating to information ownership, classification,
11111111 accountability and protection;
11121112 (12) ensure a cybersecurity training program is provided to executive
11131113 branch agencies at no cost to the agencies awareness training program is
11141114 made available to all branches of state government; and
11151115 (13) provide cybersecurity threat briefings to the information
11161116 technology executive council;
11171117 (14) provide an annual status report of executive branch cybersecurity
11181118 programs of executive branch agencies to the joint committee on
11191119 information technology and the house committee on government,
11201120 technology and security; and
11211121 (15) perform such other functions and duties as provided by law and
11221122 as directed by the CISO.
11231123 Sec. 11. K.S.A. 75-7240 is hereby amended to read as follows: 75-
11241124 7240. (a) The executive branch agency heads shall:
11251125 (a)(1) Be solely responsible for security of all data and information
11261126 technology resources under such agency's purview, irrespective of the
11271127 location of the data or resources. Locations of data may include:
11281128 (1)(A) Agency sites;
11291129 (2)(B) agency real property;
11301130 (3)(C) infrastructure in state data centers;
11311131 (4)(D) third-party locations; and
11321132 (5)(E) in transit between locations;
11331133 (b)(2) ensure that an agency-wide information security program is in
11341134 place;
11351135 (c)(3) designate an information security officer to administer the
11361136 agency's information security program that reports directly to executive
11371137 leadership;
11381138 (d)(4) participate in CISO-sponsored statewide cybersecurity program
11391139 initiatives and services;
11401140 (e)(5) implement policies and standards to ensure that all the agency's
11411141 data and information technology resources are maintained in compliance
11421142 with applicable state and federal laws and rules and regulations;
11431143 (f)(6) implement appropriate cost-effective safeguards to reduce,
11441144 eliminate or recover from identified threats to data and information
11451145 technology resources;
11461146 (g)(7) include all appropriate cybersecurity requirements in the
11471147 agency's request for proposal specifications for procuring data and
11481148 information technology systems and services;
11491149 (h) (1)(8) (A) submit a cybersecurity assessment self-assessment
11501150 report to the CISO by October 16 of each even-numbered year, including
11511151 1
11521152 2
11531153 3
11541154 4
11551155 5
11561156 6
11571157 7
11581158 8
11591159 9
11601160 10
11611161 11
11621162 12
11631163 13
11641164 14
11651165 15
11661166 16
11671167 17
11681168 18
11691169 19
11701170 20
11711171 21
11721172 22
11731173 23
11741174 24
11751175 25
11761176 26
11771177 27
11781178 28
11791179 29
11801180 30
11811181 31
11821182 32
11831183 33
11841184 34
11851185 35
11861186 36
11871187 37
11881188 38
11891189 39
11901190 40
11911191 41
11921192 42
11931193 43 HB 2077 15
11941194 an executive summary of the findings, that assesses the extent to which a
11951195 computer, a computer program, a computer network, a computer system, a
11961196 printer, an interface to a computer system, including mobile and peripheral
11971197 devices, computer software, or the data processing of the agency or of a
11981198 contractor of the agency is vulnerable to unauthorized access or harm,
11991199 including the extent to which the agency's or contractor's electronically
12001200 stored information is vulnerable to alteration, damage, erasure or
12011201 inappropriate use;
12021202 (2)(B) ensure that the agency conducts annual internal assessments of
12031203 its security program. Internal assessment results shall be considered
12041204 confidential and shall not be subject to discovery by or release to any
12051205 person or agency, outside of the KISO or CISO, without authorization
12061206 from the executive branch agency director or head. This provision
12071207 regarding confidentiality shall expire on July 1, 2023, unless the
12081208 legislature reviews and reenacts such provision pursuant to K.S.A. 45-229,
12091209 and amendments thereto, prior to July 1, 2023; and
12101210 (3)(C) prepare or have prepared a summary financial summary
12111211 identifying cybersecurity expenditures addressing the findings of the
12121212 cybersecurity assessment self-assessment report required in paragraph (1)
12131213 (8)(A), excluding information that might put the data or information
12141214 resources of the agency or its contractors at risk and submit such report to
12151215 the house of representatives committee on government, technology and
12161216 security or its successor committee appropriations and the senate
12171217 committee on ways and means;
12181218 (i) participate in annual agency leadership training to ensure
12191219 understanding of: (1) The information and information systems that
12201220 support the operations and assets of the agency; (2) The potential impact of
12211221 common types of cyberattacks and data breaches on the agency's
12221222 operations and assets; (3) how cyberattacks and data breaches on the
12231223 agency's operations and assets could impact the operations and assets of
12241224 other governmental entities on the state enterprise network; (4) how
12251225 cyberattacks and data breaches occur; (5) steps to be undertaken by the
12261226 executive director or agency head and agency employees to protect their
12271227 information and information systems; and (6) the annual reporting
12281228 requirements required of the executive director or agency head; and
12291229 (j)(9) ensure that if an agency owns, licenses or maintains
12301230 computerized data that includes personal information, confidential
12311231 information or information, the disclosure of which is regulated by law,
12321232 such agency shall, in the event of a breach or suspected breach of system
12331233 security or an unauthorized exposure of that information:
12341234 (1)(A) Comply with the notification requirements set out in K.S.A.
12351235 2022 Supp. 50-7a01 et seq., and amendments thereto, and applicable
12361236 federal laws and rules and regulations, to the same extent as a person who
12371237 1
12381238 2
12391239 3
12401240 4
12411241 5
12421242 6
12431243 7
12441244 8
12451245 9
12461246 10
12471247 11
12481248 12
12491249 13
12501250 14
12511251 15
12521252 16
12531253 17
12541254 18
12551255 19
12561256 20
12571257 21
12581258 22
12591259 23
12601260 24
12611261 25
12621262 26
12631263 27
12641264 28
12651265 29
12661266 30
12671267 31
12681268 32
12691269 33
12701270 34
12711271 35
12721272 36
12731273 37
12741274 38
12751275 39
12761276 40
12771277 41
12781278 42
12791279 43 HB 2077 16
12801280 conducts business in this state; and
12811281 (2)(B) not later than 48 hours after the discovery of the breach,
12821282 suspected breach or unauthorized exposure, notify: (A)(i) The CISO; and
12831283 (B)(ii) if the breach, suspected breach or unauthorized exposure involves
12841284 election data, the secretary of state.
12851285 (b) The director or head of each state agency shall:
12861286 (1) Participate in annual agency leadership training to ensure
12871287 understanding of:
12881288 (A) The potential impact of common types of cyberattacks and data
12891289 breaches on the agency's operations and assets;
12901290 (B) how cyberattacks and data breaches on the agency's operations
12911291 and assets may impact the operations and assets of other governmental
12921292 entities on the state enterprise network;
12931293 (C) how cyberattacks and data breaches occur; and
12941294 (D) steps to be undertaken by the executive director or agency head
12951295 and agency employees to protect their information and information
12961296 systems;
12971297 (2) ensure that all information technology login credentials are
12981298 disabled the same day that any employee ends their employment with the
12991299 state; and
13001300 (3) require that all employees with access to information technology
13011301 receive a minimum of one hour of information technology security training
13021302 per year.
13031303 (c) (1) The CISO, with input from the joint committee on information
13041304 technology and the joint committee on Kansas security, shall develop a
13051305 self-assessment report template for use under subsection (a)(8)(A). The
13061306 most recent version of such template shall be made available to state
13071307 agencies prior to July 1 of each even-numbered year. The CISO shall
13081308 aggregate data from the self-assessments received under subsection (a)(8)
13091309 (A) and provide a summary of such data to the joint committee on
13101310 information technology and the joint committee on Kansas security.
13111311 (2) Self-assessment reports made to the CISO pursuant to subsection
13121312 (a)(8)(A) shall be confidential and shall not be subject to the provisions of
13131313 the Kansas open records act, K.S.A. 45-215 et seq., and amendments
13141314 thereto. The provisions of this paragraph shall expire on July 1, 2028,
13151315 unless the legislature reviews and reenacts this provision pursuant to
13161316 K.S.A. 45-229, and amendments thereto, prior to July 1, 2028.
13171317 Sec. 12. K.S.A. 75-7242 is hereby amended to read as follows: 75-
13181318 7242. Information collected to effectuate this act shall be considered
13191319 confidential by the executive branch agency and KISO all state and local
13201320 governmental organizations unless all data elements or information that
13211321 specifically identifies a target, vulnerability or weakness that would place
13221322 the organization at risk have been redacted, including: (a) System
13231323 1
13241324 2
13251325 3
13261326 4
13271327 5
13281328 6
13291329 7
13301330 8
13311331 9
13321332 10
13331333 11
13341334 12
13351335 13
13361336 14
13371337 15
13381338 16
13391339 17
13401340 18
13411341 19
13421342 20
13431343 21
13441344 22
13451345 23
13461346 24
13471347 25
13481348 26
13491349 27
13501350 28
13511351 29
13521352 30
13531353 31
13541354 32
13551355 33
13561356 34
13571357 35
13581358 36
13591359 37
13601360 38
13611361 39
13621362 40
13631363 41
13641364 42
13651365 43 HB 2077 17
13661366 information logs; (b) vulnerability reports; (c) risk assessment reports; (d)
13671367 system security plans; (e) detailed system design plans; (f) network or
13681368 system diagrams; and (g) audit reports. The provisions of this section shall
13691369 expire on July 1, 2023, unless the legislature reviews and reenacts this
13701370 provision pursuant to K.S.A. 45-229, and amendments thereto, prior to
13711371 July 1, 2023.
13721372 Sec. 13. K.S.A. 46-2102, 75-7201, 75-7205, 75-7206, 75-7208, 75-
13731373 7209, 75-7210, 75-7211, 75-7237, 75-7239, 75-7240 and 75-7242 are
13741374 hereby repealed.
13751375 Sec. 14. This act shall take effect and be in force from and after its
13761376 publication in the statute book.
13771377 1
13781378 2
13791379 3
13801380 4
13811381 5
13821382 6
13831383 7
13841384 8
13851385 9
13861386 10
13871387 11