Louisiana 2020 Regular Session

Louisiana Senate Bill SB273

Introduced
2/27/20  
Introduced
2/27/20  
Refer
2/27/20  
Refer
2/27/20  
Refer
3/9/20  
Refer
3/9/20  
Report Pass
5/7/20  
Report Pass
5/7/20  
Engrossed
5/15/20  
Engrossed
5/15/20  
Report Pass
5/18/20  
Report Pass
5/18/20  
Enrolled
5/29/20  
Chaptered
6/9/20  
Chaptered
6/9/20  
Passed
6/9/20  

Caption

Provides for registration with secretary of state by managed service providers servicing public bodies. (See Act) (EN +$48,000 GF EX See Note)

Impact

The law imposes a requirement for MSPs and MSSPs to report any cyber incidents or ransomware payments to the Louisiana Fusion Center within specific timeframes. This aligns with efforts to improve the state's cybersecurity framework by ensuring swift reporting and response to incidents that compromise the security of public bodies. Additionally, the bill introduces exceptions to public records laws regarding the details of certain cyber incidents, which could enhance the confidentiality of sensitive information but raises concerns about transparency.

Summary

Senate Bill 273 (SB273) introduces regulations for managed service providers (MSPs) and managed security service providers (MSSPs) that offer services to public bodies in Louisiana. The bill mandates a formal registration process with the Secretary of State for any provider managing a public body’s information technology systems. One of the primary goals of the bill is to ensure that public bodies can access reliable information about their service providers and enhance the security of their operations, particularly regarding cybersecurity threats and incidents.

Sentiment

The sentiment surrounding SB273 appears to be generally supportive among legislators, especially those invested in cybersecurity and information technology governance. The bill has received unanimous support in voting, reflecting a collective agreement on the necessity of establishing stronger controls over cybersecurity for public organizations. However, there are potential concerns among advocates for transparency about the exceptions made regarding public records, which could limit public oversight.

Contention

One point of contention noted during discussions relates to the implications of restricting public access to information about cyber incidents and the financial transactions related to ransomware. Stakeholders and advocacy groups express concern that while protecting sensitive data is crucial, it should not come at the expense of public accountability. Overall, SB273 is a significant step towards formalizing cybersecurity measures for public bodies, balancing the need for security with the imperatives of public trust.

Companion Bills

No companion bills found.

Similar Bills

LA HCR84

Directs the La. State Law Institute to reorganize and recodify the Miscellaneous Health Provisions chapter of Title 40 of the La. Revised Statutes

LA HCR196

Urges and requests a study of the means by which the La. State Board of Nursing may obtain access to investigative records

LA HCR173

Requests that the Bd. of Regents and the State Bd. of Elementary and Secondary Education, with the Taylor Foundation, La. Office of Student Financial Assistance, public postsecondary education management boards, and certain others, study certain issues relative to TOPS

LA HCR104

Requests the Louisiana Workforce Commission and the Louisiana Department of Veterans Affairs to study employment practices and professional licensing requirements to benefit veterans in the workforce

LA SB212

Provides for the membership of the Prescription Monitoring Program Advisory Council. (8/15/10)

LA SB31

Provides for the repeal of certain inactive or obsolete healthcare laws. (8/1/22)

LA HB874

Makes supplemental appropriations for Fiscal Year 2017-2018

LA SCR65

Creates a task force to study meaningful oversight of the professional healthcare licensing boards statutorily created within the Department of Health and Hospitals.