Massachusetts 2023-2024 Regular Session

Massachusetts Senate Bill S32 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 1 of 1
22 SENATE DOCKET, NO. 2404 FILED ON: 1/20/2023
33 SENATE . . . . . . . . . . . . . . No. 32
44 The Commonwealth of Massachusetts
55 _________________
66 PRESENTED BY:
77 Barry R. Finegold
88 _________________
99 To the Honorable Senate and House of Representatives of the Commonwealth of Massachusetts in General
1010 Court assembled:
1111 The undersigned legislators and/or citizens respectfully petition for the adoption of the accompanying bill:
1212 An Act relative to cyber incident response.
1313 _______________
1414 PETITION OF:
1515 NAME:DISTRICT/ADDRESS :Barry R. FinegoldSecond Essex and Middlesex 1 of 9
1616 SENATE DOCKET, NO. 2404 FILED ON: 1/20/2023
1717 SENATE . . . . . . . . . . . . . . No. 32
1818 By Mr. Finegold, a petition (accompanied by bill, Senate, No. 32) of Barry R. Finegold for
1919 legislation relative to cyber incident response. Advanced Information Technology, the Internet
2020 and Cybersecurity.
2121 The Commonwealth of Massachusetts
2222 _______________
2323 In the One Hundred and Ninety-Third General Court
2424 (2023-2024)
2525 _______________
2626 An Act relative to cyber incident response.
2727 Be it enacted by the Senate and House of Representatives in General Court assembled, and by the authority
2828 of the same, as follows:
2929 1 SECTION 1. Chapter 7D of the General Laws, as appearing in the 2022 Official Edition,
3030 2is hereby amended by inserting after section 11 the following new sections:-
3131 3 Section 12. State-Level Incident Reporting and Response
3232 4 (a) As used in this section and section 13, the following words shall have the following
3333 5meanings, unless the context clearly requires otherwise:
3434 6 “Breach of security” shall have the same meaning as defined in section 1 of chapter 93H.
3535 7 “Critical infrastructure”, the systems and assets, either physical or virtual, within the
3636 8commonwealth that are so vital to the commonwealth or the United States that the incapacitation
3737 9or destruction of such a system or asset would have a debilitating impact on physical security,
3838 10economic security, public health or safety or any combination thereof; provided, however, that 2 of 9
3939 11“critical infrastructure” shall include, but not be limited to, election systems, transportation
4040 12infrastructure, water, gas and electric utilities.
4141 13 “Cybersecurity incident”, an incident that: (i) risks or could risk the confidentiality,
4242 14integrity or availability of information systems; (ii) consists of unauthorized access to, or
4343 15malicious software present on, systems or assets that are so vital that the incapacity or
4444 16destruction of such systems or assets would have a debilitating impact on cybersecurity, physical
4545 17security, economic security, public health or public safety; and (iii) results or could result in a
4646 18significant loss of data, system availability or control of systems; provided, however, that a
4747 19“cybersecurity incident” shall include, but not be limited to, a breach of security, imminent threat
4848 20of a breach of security or other cyber attack intended to compromise the use of an electronic
4949 21system.
5050 22 “Cybersecurity threat”, an action on or through an information system that may result in
5151 23an unauthorized effort to adversely impact the security, availability, confidentiality or integrity of
5252 24an information system or information that is stored on, processed by or transiting an information
5353 25system; provided, however, that a “cybersecurity threat” does not include any action that solely
5454 26involves a violation of a consumer terms-of-service agreement or consumer licensing agreement.
5555 27 “Response team”, the Massachusetts Cyber Incident Response Team established pursuant
5656 28to this section.
5757 29 (b) There shall be established a Massachusetts Cyber Incident Response Team, the
5858 30mission of which is to enhance this commonwealth’s ability to prepare for, respond to, mitigate
5959 31against and recover from significant cybersecurity incidents. 3 of 9
6060 32 (c) The response team shall consist of: (i) the secretary of the executive office of
6161 33technology services and security or their designee, who shall serve as chair of the response team;
6262 34(ii) a representative of the commonwealth security operations center as designated by the director
6363 35of security operations; (iii) the secretary of the executive office of public safety and security or
6464 36their designee; (iv) a representative of the state police cyber crime unit; (v) a representative of
6565 37the commonwealth fusion center; (vi) the adjutant general of the Massachusetts National Guard
6666 38or their designee; and (vii) the director of the Massachusetts emergency management agency or
6767 39their designee.
6868 40 (d) The response team shall review cybersecurity threat information and vulnerabilities,
6969 41make informed recommendations and establish appropriate policies to manage the risk of
7070 42cybersecurity incidents for all state agencies served by the executive office of technology
7171 43services and security; provided, however, that such recommendations, policies and directives
7272 44shall be informed by information and best practices obtained through the established information
7373 45sharing network of local, state, federal and industry partners in which response team members
7474 46regularly participate.
7575 47 (e) The response team shall develop and maintain an updated cybersecurity incident
7676 48response plan for the commonwealth and submit such plan annually for review, not later than
7777 49November 1, to the governor and the joint committee on advanced information technology, the
7878 50internet and cybersecurity. Said plan, which shall not be a public record pursuant to section 66,
7979 51shall include, but not be limited to:
8080 52 (i) ongoing and anticipated cybersecurity incidents or cybersecurity threats; 4 of 9
8181 53 (ii) a risk analysis identifying the vulnerabilities of critical infrastructure and detailing
8282 54risk-informed recommendations to address such vulnerabilities;
8383 55 (iii) recommendations regarding the deployment of state agency resources and security
8484 56professionals in rapidly responding to such cybersecurity incidents or cybersecurity threats; and
8585 57 (iv) recommendations regarding best practices to minimize the impact of significant
8686 58cybersecurity threats to agencies.
8787 59 (f) In the event of a cybersecurity incident that threatens or results in a material
8888 60impairment of the infrastructure or services of a state agency, the secretary of the executive
8989 61office of technology services and security shall, with the approval of the governor, serve as the
9090 62director of the response team; provided, however, that the secretary of the executive office of
9191 63technology services and security may direct the response team to collaborate with other state
9292 64agencies and entities that are not members of the response team as appropriate to respond to a
9393 65cybersecurity incident.
9494 66 (g) State agencies shall comply with all protocols and procedures established by the
9595 67response team and all related policies, standards and administrative directives issued by the
9696 68executive office of technology services and security pursuant to subsection (b) of section 3 of
9797 69this chapter. The chief information officer or equivalent responsible officer for any state agency
9898 70served by the executive office of technology services and security shall, as soon as practicable,
9999 71report any known cybersecurity incident to the commonwealth security operations center, in a
100100 72form to be prescribed by the executive office of technology services and security. The
101101 73commonwealth security operations center shall notify the response team of all reported security
102102 74threats or incidents as soon as practicable, but no later than 24 hours after receiving a report. 5 of 9
103103 75 (h) The commonwealth fusion center and the commonwealth security operations center
104104 76shall routinely exchange information related to cybersecurity threats and cybersecurity incidents
105105 77that have been reported to or discovered by their respective state agencies or reported to the
106106 78response team.
107107 79 (i) The executive office of technology services and security and the response team shall
108108 80consult with the Massachusetts Cyber Center and assist said center with efforts to foster
109109 81cybersecurity resiliency through communications, collaboration and outreach to state agencies,
110110 82municipalities, educational institutions and industry partners.
111111 83 (j) Notwithstanding anything in this section to the contrary, other agencies not served by
112112 84the executive office of technology services may report cybersecurity threats or cybersecurity
113113 85incidents to the commonwealth security operations center in a form to be prescribed by the
114114 86executive office of technology services and security.
115115 87 (k) All employees of the executive agencies of the commonwealth shall be required to
116116 88annually complete a security awareness training program approved by the executive office of
117117 89technology services and security and administered by the human resources division.
118118 90 (l) The secretary of the executive office of technology services and security shall
119119 91promulgate regulations or directives to carry out the purposes of this section.
120120 92 Section 13. Municipal and Critical Infrastructure Cyber Incident Reporting Requirements
121121 93 (a) As used in this section, the following words shall have the following meanings unless
122122 94the context clearly requires otherwise: 6 of 9
123123 95 “Covered entity”, any (i) agency, office, department, board, commission, bureau, division
124124 96or authority of a municipality or any political subdivision thereof; or (ii) an entity that owns or
125125 97operates critical infrastructure.
126126 98 “Secretary”, the secretary of the executive office of public safety and security.
127127 99 (b) A covered entity shall provide notice, as soon as practicable and without unreasonable
128128 100delay when such covered entity knows or has reason to know of a cybersecurity incident to the
129129 101commonwealth fusion center in a form to be prescribed by the secretary in consultation with the
130130 102response team; provided, however, that such notice shall include, but not be limited to:
131131 103 (i) a timeline of events as best known by the covered entity and the type of cybersecurity
132132 104incident known or suspected;
133133 105 (ii) how the cybersecurity incident was initially detected or discovered;
134134 106 (iii) a list of the specific assets that have been affected or are suspected to be affected;
135135 107 (iv) copies of any electronic communications that are suspected of being malicious, if
136136 108applicable;
137137 109 (v) copies of any malware, threat actor tool or malicious links suspected of causing the
138138 110cybersecurity incident, if applicable;
139139 111 (vi) any digital logs such as firewall, active directory and event logs, if available;
140140 112 (vii) forensic images of random access memory or virtualized random access memory
141141 113from affected systems, if available; 7 of 9
142142 114 (viii) contact information for the covered entity and any third-party entity engaging in
143143 115cybersecurity incident response that is involved; and
144144 116 (ix) any other information as required by the commonwealth fusion center or secretary.
145145 117 (c) Upon receipt of said notice, the representative of the commonwealth fusion center to
146146 118the response team or their designee shall:
147147 119 (i) create and maintain a record of the cybersecurity incident, including all information
148148 120provided by the covered entity in the notice under subsection (b);
149149 121 (ii) provide a copy of said record to the response team to be included in the response
150150 122team’s annual cyber incident response plan required by subsection (e) of section 12; provided,
151151 123however, that such copy shall not include any information identifiable to the covered entity that
152152 124is not expressly necessary for the preparation of the response team’s report unless the covered
153153 125entity has provided affirmative consent to share such information; and
154154 126 (iii) if the covered entity is a municipality or municipal agency under clause (i) of the
155155 127definition of covered entity in this section, provide notice of the cybersecurity incident to the
156156 128appropriate local law enforcement agency, including the contact information of the covered
157157 129entity; provided, however, that this notification shall not be construed to fulfill any of the
158158 130covered entity’s reporting obligations under this chapter.
159159 131 (d) Upon receipt of the notice required by subsection (b), the commonwealth fusion
160160 132center may: 8 of 9
161161 133 (i) coordinate with the response team to identify or communicate recommended response
162162 134measures as appropriate; provided, however, that such recommended response measures shall
163163 135not include the payment of a ransom;
164164 136 (ii) assist the covered entity with implementing recommended response measures as
165165 137appropriate, alone or in conjunction with: (1) any agency or entity represented in the response
166166 138team; (2) any local law enforcement agency; or (3) the Massachusetts Cyber Center; and
167167 139 (iii) provide, at the discretion of the secretary, information about other entities that are
168168 140capable of providing mitigation and remediation support following a cybersecurity incident or in
169169 141response to a cybersecurity threat.
170170 142 (e) Nothing in this section shall be construed to:
171171 143 (i) fulfill any regulatory data breach reporting requirements pursuant to chapter 93H; or
172172 144 (ii) absolve any duty under applicable federal law to report a cybersecurity threat or
173173 145cybersecurity incident to the cybersecurity and infrastructure security agency.
174174 146 (f) This section shall not apply to a covered entity pursuant to clause (ii) of the definition
175175 147of a covered entity that reports the cybersecurity incident to the cybersecurity and infrastructure
176176 148security agency pursuant to the federal Cyber Incident Reporting for Critical Infrastructure Act
177177 149of 2022 and its implementing regulations.
178178 150 (g) The secretary, alone or in conjunction with the secretary of the executive office of
179179 151technology services and security, shall promulgate regulations for the purposes of carrying out
180180 152this section. 9 of 9
181181 153 SECTION 2. Section 12 of chapter 7D of the General Laws, as inserted by section 1 of
182182 154this act, shall take effect upon the passage of this act.
183183 155 SECTION 3. Section 13 of chapter 7D of the General Laws, as inserted by section 1 of
184184 156this act, shall take effect 12 months after the passage of this act.