Oklahoma 2022 Regular Session

Oklahoma Senate Bill SB75

Introduced
2/1/21  
Refer
2/2/21  
Report Pass
2/4/21  
Engrossed
3/8/21  
Refer
3/22/21  
Report Pass
3/24/21  
Enrolled
4/12/21  

Caption

Public finance; providing exception from security risk assessments for certain state agency division. Effective date.

Impact

If enacted, SB75 would require state agencies to perform annual security risk assessments and audits, utilizing a selection of pre-approved firms to ensure compliance with the latest cybersecurity frameworks. The Information Services Division would oversee this process, helping agencies to identify and rectify security weaknesses. Additionally, agencies not consolidating under the Information Technology Consolidation and Coordination Act would face specific obligations around reporting and compliance timelines, aiming to create a more secure technological environment for state operations.

Summary

Senate Bill 75, introduced by Simpson and Townley, aims to amend the state's public finance statute concerning security risk assessments. The bill seeks to establish a standardized process for state agencies when conducting security risk evaluations for their information technology systems. By introducing these updates, the bill endeavors to align state practices with international standards, specifically those set forth by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The intent is to improve security protocols within state agencies to proactively address information technology vulnerabilities.

Sentiment

The overarching sentiment surrounding SB75 appears to be supportive, as it seeks to enhance cybersecurity measures for state agencies, which is often a priority for public safety and operational efficiency. Legislators from both parties have expressed the importance of fortifying state technology systems against cyber threats. However, there could be concerns regarding the implications of increased bureaucratic oversight and the potential for additional costs associated with meeting the new requirements.

Contention

Notable points of contention may arise regarding the practicality and funding of the mandated security audits. Some critics might argue that the imposed requirements could create unexpected financial burdens for smaller agencies or hinder their operational flexibility. Moreover, while the bill exempts certain agencies from these assessments, discussions may emerge about the adequacy of existing protections within those entities. Balancing the need for robust cybersecurity without overzealously restricting the operational capabilities of state agencies is likely to be a focal point in discussions.

Companion Bills

No companion bills found.

Previously Filed As

OK HB1784

Public finance; creating the Information Services Agency; making Information Services Division a separate and distinct agency; modifying references to Division; effective date.

OK HB1784

Public finance; creating the Information Services Agency; making Information Services Division a separate and distinct agency; modifying references to Division; effective date.

OK SB570

Public finance; state agency information systems; making certain provisions inapplicable to the Oklahoma Military Department. Effective date. Emergency.

OK HB3067

Public finance; state agency information technology systems; Oklahoma State Bureau of Investigation; exemption; effective date; emergency.

OK HB3298

Public finance; requiring Human Capital Management Division investigate certain state agencies; effective date.

OK HB2331

Public finance; Office of Management and Enterprise Services; Oklahoma Military Department; effective date; emergency.

OK SB179

Information technology; directing state agencies to manage information technology services. Effective date. Emergency.

OK SB1361

State government; granting certain agencies certain exemption; granting powers and duties. Effective date.

OK HB3274

Schools; allowing the statewide system of student assessments to include certain retest and career-readiness and armed services assessments; providing certain exemption; effective date; emergency.

OK SB100

Schools; requiring districts to undergo certain risk and vulnerability assessment by certain date. Effective date. Emergency.

Similar Bills

No similar bills found.