Hawaii 2024 Regular Session

Hawaii Senate Bill SB1478

Introduced
1/25/23  
Refer
1/30/23  
Introduced
1/25/23  
Report Pass
2/15/23  
Refer
1/30/23  
Report Pass
2/15/23  
Report Pass
3/3/23  
Refer
2/15/23  
Engrossed
3/7/23  
Report Pass
3/3/23  
Refer
3/9/23  
Engrossed
3/7/23  
Report Pass
3/22/23  
Refer
3/9/23  
Report Pass
3/22/23  

Caption

Relating To Offensive Cybersecurity.

Impact

The implementation of SB1478 is poised to strengthen the overall cybersecurity framework of state government operations. Agencies will be required to adopt proactive measures such as conducting penetration tests and utilizing a common vulnerability scoring system to prioritize the remediation of identified vulnerabilities. This systematic approach aims to improve the safeguarding of confidential data across state-managed systems, ultimately helping to ensure the integrity and availability of essential state services and information.

Summary

SB1478 introduces an offensive cybersecurity program intended to enhance the security posture of state and county agencies in Hawaii. By establishing this program, the bill mandates that the chief information officer of the office of enterprise technology services conduct regular security audits and penetration testing to analyze and mitigate cybersecurity threats. Moreover, it emphasizes the requirement for agencies to report any suspected cybersecurity incidents without delay, clearly outlining the types of incidents that must be reported.

Sentiment

General sentiment surrounding SB1478 appears to be supportive of bolstering cybersecurity measures to protect sensitive government data. Stakeholders recognize the significance of addressing insidious cyber threats, especially as reliance on digital systems increases. However, concerns about the feasibility of the program, particularly regarding budget allocation and the effective execution of the mandated tasks, have been raised. Advocates argue that stronger cybersecurity awareness and practices are crucial, while detractors point to potential resource constraints.

Contention

Points of contention within discussions around SB1478 include the adequacy of funding for the offensive cybersecurity program, as the bill calls for appropriations for software, services, and personnel necessary for its execution. Additionally, there are worries about the extent of the chief information officer's authority, specifically in managing cybersecurity incidents and conducting audits without infringing on existing responsibilities of state agencies. The long-term effectiveness and actual funding to sustain this initiative remain central issues in ongoing legislative dialogues.

Companion Bills

HI SB1478

Carry Over Relating To Offensive Cybersecurity.

Previously Filed As

HI SB1478

Relating To Offensive Cybersecurity.

Similar Bills

HI SB1478

Relating To Offensive Cybersecurity.

MS HB1380

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

FL H1555

Cybersecurity

FL H1293

Cybersecurity

FL H1511

Cybersecurity

CA AB749

State agencies: information security: uniform standards.

CA AB869

State agencies: information security: Zero Trust architecture.

HI HB1493

Relating To The First Responders Technology Campus And Cybersecurity Data Center.