ENROLLED 2020 Regular Session HOUSE BILL NO. 633 BY REPRESENTATIVE FREIBERG 1 AN ACT 2 To enact R.S. 42:1267, relative to cybersecurity training; to provide for the development of 3 the training; to require all public servants to receive training; to require certain 4 contractors to receive training; and to provide for related matters. 5 Be it enacted by the Legislature of Louisiana: 6 Section 1. R.S. 42:1267 is hereby enacted to read as follows: 7 ยง1267. Required training; cybersecurity 8 A.(1) The Department of State Civil Service shall institute, develop, conduct, 9 and otherwise provide for training programs designed to keep state agencies safe 10 from cyberattack. The programs shall be designed to focus on forming information 11 security habits and procedures that protect information resources and teach best 12 practices for detecting, assessing, reporting, and addressing information security 13 threats. The department may make the training available as an online course. The 14 office of technology services shall provide assistance to the Department of State 15 Civil Service in the development of the training program. The cost of instituting, 16 developing, conducting, and otherwise providing cybersecurity awareness training 17 shall be paid in the manner established by R.S. 42:1262. 18 (2) The Department of State Civil Service shall make the education and 19 training on cybersecurity developed pursuant to Paragraph (1) of this Subsection 20 available to agencies within political subdivisions of the state at as minimal cost as 21 possible to assist those agencies in compliance with the provisions of this Section. 22 B.(1) Each state and local agency shall identify employees or elected 23 officials who have access to the agency's information technology assets and require 24 those employees and elected officials to complete cybersecurity training. Each new Page 1 of 2 CODING: Words in struck through type are deletions from existing law; words underscored are additions. HB NO. 633 ENROLLED 1 state and local agency official or employee with access to the agency's information 2 technology assets shall complete this training within the first thirty days of initial 3 service or employment with the agency. 4 (2) The agency head shall verify and report to the Department of State Civil 5 Service on the completion of cybersecurity training by agency employees. The 6 agency head shall periodically require an internal review to ensure compliance. 7 (3)(a) An agency shall require any contractor who has access to state or local 8 government information technology assets to complete cybersecurity training during 9 the term of the contract and during any renewal period. 10 (b) Completion of cybersecurity shall be included in the terms of a contract 11 awarded by a state or local government agency to a contractor who has access to its 12 information technology assets. 13 (c) The person who oversees contract management for the agency shall 14 report each such contractor's completion to the agency head and periodically review 15 agency contracts to ensure compliance. 16 (d) The agency head shall verify and report to the Department of State Civil 17 Service on the completion of cybersecurity training by each such contractor. 18 Section 2. This Act shall become effective upon signature by the governor or, if not 19 signed by the governor, upon expiration of the time for bills to become law without signature 20 by the governor, as provided by Article III, Section 18 of the Constitution of Louisiana. If 21 vetoed by the governor and subsequently approved by the legislature, this Act shall become 22 effective on the day following such approval. SPEAKER OF THE HOUSE OF REPRESENTATIVES PRESIDENT OF THE SENATE GOVERNOR OF THE STATE OF LOUISIANA APPROVED: Page 2 of 2 CODING: Words in struck through type are deletions from existing law; words underscored are additions.