EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW. [Brackets] indicate matter deleted from existing law. Underlining indicates amendments to bill. Strike out indicates matter stricken from the bill by amendment or deleted from the law by amendment. *hb1205* HOUSE BILL 1205 S2, P1, S1 2lr1777 CF SB 811 By: Delegates P. Young, Kerr, Feldmark, Bartlett, Kelly, Kipke, and McIntosh McIntosh, Bagnall, Bhandari, Carr, Chisholm, Cullison, Hill, Johnson, Kaiser, Landis, R. Lewis, Morgan, Pena –Melnyk, Pendergrass, Reilly, Rosenberg, Saab, Sample–Hughes, Szeliga, and K. Young Introduced and read first time: February 11, 2022 Assigned to: Health and Government Operations and Appropriations Committee Report: Favorable with amendments House action: Adopted Read second time: March 13, 2022 CHAPTER ______ AN ACT concerning 1 State Government – Information Technology and Cybersecurity –Related 2 Infrastructure 3 (Modernize Maryland Act of 2022) 4 FOR the purpose of authorizing the Maryland Stadium Authority to issue bonds and, in 5 consultation with the Department of Information Technology, finance projects 6 related to information technology and cybersecurity–related State government 7 infrastructure; establishing an Information Technology and Cybersecurity 8 Infrastructure establishing the Local Cybersecurity Support Fund as a special, 9 nonlapsing fund; requiring interest earnings of the Fund to be credited to the Fund; 10 establishing certain eligibility requirements to receive assistance from the Fund; 11 altering the duties of the Secretary of Information Technology; establishing a 12 Statewide Reporting Framework and Oversight Commission in the Department of 13 Information Technology; requiring the Department to hire an independent 14 contractor contractors to develop a framework for investments in technology and 15 annually periodically assess the cybersecurity and information technology systems 16 in each unit certain units of State government; specifying the use of proceeds from 17 certain bonds; exempting certain procurements by the Department from oversight 18 by the Board of Public Works; establishing that the Department is a primary 19 procurement unit and authorizing the Department to engage in or control certain 20 procurements; authorizing a certain independent contractor to issue a certain 21 change order applying certain change order requirements to State procurement 22 2 HOUSE BILL 1205 contracts for certain equipment, services, and upgrades; and generally relating to 1 the development, financing, and procurement of information technology and 2 cybersecurity–related State government infrastructure projects. 3 BY repealing and reenacting, with amendments, 4 Article – Economic Development 5 Section 10–628(a) 6 Annotated Code of Maryland 7 (2018 Replacement Volume and 2021 Supplement) 8 BY adding to 9 Article – Economic Development 10 Section 10–628(d), 10–650.1, and 10–657.5 11 Annotated Code of Maryland 12 (2018 Replacement Volume and 2021 Supplement) 13 BY repealing and reenacting, with amendments, 14 Article – State Finance and Procurement 15 Section 3A–303(a)(7) and (8), 6–226(a)(2)(ii)144. and 145., 11–101(m), 12–101, 16 12–107(b)(2)(i)9. through 11. 12–107(b)(2)(i)8., (3)(vi), and (4)(v), and 17 15–112(a)(1)(i) 18 Annotated Code of Maryland 19 (2021 Replacement Volume) 20 BY adding to 21 Article – State Finance and Procurement 22 Section 3A–303(a)(9), 3A–315 through 3A–317, 6–226(a)(2)(ii)146., 12–107(b)(5), and 23 and 12–107(b)(5) 15–112(b)(4) 24 Annotated Code of Maryland 25 (2021 Replacement Volume) 26 BY repealing and reenacting, without amendments, 27 Article – State Finance and Procurement 28 Section 6–226(a)(2)(i), 11–101(a), and 15–112(b)(3) 11–101(a), and 12–107(b)(2)(i)9. 29 Annotated Code of Maryland 30 (2021 Replacement Volume) 31 BY repealing 32 Article – State Finance and Procurement 33 Section 12–107(b)(2)(i)10. and 11. 34 Annotated Code of Maryland 35 (2021 Replacement Volume) 36 SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 37 That the Laws of Maryland read as follows: 38 Article – Economic Development 39 HOUSE BILL 1205 3 10–628. 1 (a) Except as provided in subsections (b) [and], (c), AND (D) of this section and 2 subject to the prior approval of the Board of Public Works, the Authority may issue bonds 3 at any time for any corporate purpose of the Authority, including the establishment of 4 reserves and the payment of interest. 5 (D) UNLESS AUTHORIZED BY THE GENERAL ASSEMBLY, THE BOARD OF 6 PUBLIC WORKS MAY NOT APPROVE AN ISSUANCE BY THE AUTHORITY OF BONDS , 7 WHETHER TAXABLE OR T AX EXEMPT, THAT CONSTITUTE TAX SUPPORTED DEBT OR 8 NONTAX SUPPORTED DEB T IF, AFTER ISSUANCE , THERE WOULD BE OUTST ANDING 9 AND UNPAID $1,500,000,000 FACE AMOUNTS OF THE BONDS FOR THE PURPOS E OF 10 FINANCING RESEARCH I NTO, ACQUISITION OF , INSTALLATION OF , MAINTENANCE 11 OF, AND RELATED EXPENSES FOR UPGRADES TO INFO RMATION TECHNOLOGY AN D 12 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 13 10–650.1. 14 (A) THE AUTHORITY AND THE DEPARTMENT OF INFORMATION 15 TECHNOLOGY SHALL COMP LY WITH THIS SECTION TO FINANCE PROJECTS TO 16 RESEARCH, ACQUIRE, INSTALL, MAINTAIN, AND UPGRAD E INFORMATION 17 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 18 INFRASTRUCTURE . 19 (B) THE AUTHORITY SHALL TRANS FER TO THE DEPARTMENT OF 20 INFORMATION TECHNOLOGY THE PROCEE DS OF BONDS ISSUED U NDER THIS 21 SUBTITLE FOR FINANCI NG INFORMATION TECHN OLOGY AND 22 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS . 23 (C) AT LEAST 90 DAYS BEFORE PROVIDIN G THE WRITTEN NOTICE TO THE 24 FISCAL COMMITTEES OF THE GENERAL ASSEMBLY REQUIRED UND ER SUBSECTION 25 (D) OF THIS SECTION, THE AUTHORITY SHALL CONSU LT WITH THE DEPARTMENT OF 26 INFORMATION TECHNOLOGY TO DETERMI NE THE AMOUNT OF FUN DS NEEDED FOR 27 INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 28 INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS. 29 (D) AT LEAST 45 DAYS BEFORE SEEKING APPROVAL OF THE BOARD OF 30 PUBLIC WORKS FOR EACH BOND I SSUE RELATED TO INFO RMATION TECHNOLOGY 31 AND CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE , THE 32 AUTHORITY SHALL PROVI DE TO THE FISCAL COM MITTEES OF THE GENERAL 33 ASSEMBLY, IN ACCORDANCE WITH § 2–1257 OF THE STATE GOVERNMENT ARTICLE, 34 WRITTEN NOTICE OF : 35 4 HOUSE BILL 1205 (1) THE AGGREGATE AMOUNT OF FUNDS NEEDED FOR INFORMATION 1 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 2 INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS; 3 (2) THE ANTICIPATED TOTA L DEBT SERVICE FOR THE PROP OSED 4 BOND ISSUE; AND 5 (3) THE ANTICIPATED TOTA L DEBT SERVICE WHEN COMBINED WITH 6 THE DEBT SERVICE FOR ALL PRIOR OUTSTANDIN G BOND ISSUES FOR IN FORMATION 7 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 8 INFRASTRUCTURE PROJE CTS. 9 (E) BEFORE EACH ISSUANCE OF BONDS TO FINANCE INFORMATION 10 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 11 INFRASTRUCTURE PROJE CTS, THE AUTHORITY SHALL OBTAI N THE APPROVAL OF 12 THE BOARD OF PUBLIC WORKS OF THE AGGREGAT E AMOUNT OF THE PROP OSED 13 BOND ISSUE. 14 (F) FOR FISCAL YEAR 2024 AND EACH FISCAL YEAR THEREAFTER , UNTIL 15 THE BONDS THAT HAVE BEEN ISSUED TO FINAN CE INFORMATION TECHN OLOGY AND 16 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ARE 17 NO LONGER OUTSTANDIN G AND UNPAID , THE GOVERNOR SHALL INCLUDE IN THE 18 ANNUAL BUDGET BILL A N APPROPRIATION TO T HE INFORMATION TECHNOLOGY 19 AND CYBERSECURITY INFRASTRUCTURE FUND IN AN AMOUNT SUF FICIENT TO 20 COVER THE PROJECTED DEBT SERVICE REQUIRE MENTS FOR THE UPCOMI NG FISCAL 21 YEAR. 22 10–657.5. 23 (A) IN THIS SECTION , “FUND” MEANS THE INFORMATION TECHNOLOGY 24 AND CYBERSECURITY INFRASTRUCTURE FUND. 25 (B) THERE IS AN INFORMATION TECHNOLOGY AND CYBERSECURITY 26 INFRASTRUCTURE FUND. 27 (C) (1) THE FUND IS A SPECIAL , NONLAPSING FUND THAT IS NOT 28 SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE AND 29 THAT SHALL BE AVAILA BLE IN PERPETUITY TO IMPLEMENT THIS SUBTI TLE 30 RELATED TO UPGRADES TO INFORMATION TECHN OLOGY AND 31 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 32 (2) THE AUTHORITY SHALL : 33 HOUSE BILL 1205 5 (I) USE THE FUND AS A REVOLVING FUND FOR CARRYING OUT 1 THE PROVISIONS OF TH IS SUBTITLE RELATED TO UPGRADES TO INFOR MATION 2 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 3 INFRASTRUCTURE ; AND 4 (II) PAY ANY AND ALL EXPE NSES FROM THE FUND THAT ARE 5 INCURRED BY THE AUTHORITY OR THE DEPARTMENT OF INFORMATION 6 TECHNOLOGY RELATED TO UPGRADES TO INFORMAT ION TECHNOLOGY AND 7 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 8 (D) THE FUND CONSISTS OF : 9 (1) FUNDS APPROPRIATED F OR DEPOSIT TO THE FUND; 10 (2) PROCEEDS FR OM THE SALE OF BONDS RELATED TO UPGRADES TO 11 INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 12 INFRASTRUCTURE PROJE CTS; 13 (3) REVENUES COLLECTED O R RECEIVED FROM ANY SOURCE UNDER 14 THIS SUBTITLE RELATE D TO UPGRADES TO INF ORMATION TECHNOLOGY AND 15 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ; 16 (4) INTEREST EARNINGS ; AND 17 (5) ANY ADDITIONAL MONEY MADE AVAILABLE FROM ANY PUBLIC OR 18 PRIVATE SOURCE FOR T HE PURPOSES ESTABLIS HED FOR THE FUND. 19 (E) (1) THE STATE TREASURER SHALL INVEST THE MONEY OF THE FUND 20 IN THE SAME MANNER A S OTHER STATE FUNDS. 21 (2) ANY INVESTMENT EARNIN GS SHALL BE CREDITED TO THE FUND. 22 (3) NO PART OF THE FUND MAY REVERT OR BE CREDITED TO THE 23 GENERAL FUND OF THE STATE OR ANY SPECIAL FUND OF THE STATE. 24 Article – State Finance and Procurement 25 3A–303. 26 (a) The Secretary is responsible for carrying out the following duties: 27 (7) advising and consulting with the Legislative and Judicial branches of 28 State government regarding a cybersecurity strategy; [and] 29 6 HOUSE BILL 1205 (8) in consultation with the Attorney General, developing guidance on 1 consistent cybersecurity strategies for counties, municipal corporations, school systems, 2 and all other political subdivisions of the State; AND 3 (9) UPGRADING INFORMATIO N TECHNOLOG Y AND 4 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 5 3A–315. 6 (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS 7 INDICATED. 8 (2) “CITIZEN ADVOCACY GROU P” MEANS AN ORGANIZATIO N WHOSE 9 MISSION IS TO PROVID E SUPPORT FOR INFORM ATION TECHNOLOGY AND 10 CYBERSECURITY POLICI ES. 11 (3) “COMMISSION” MEANS THE STATEWIDE REPORTING 12 FRAMEWORK AND OVERSIGHT COMMISSION. 13 (4) “CRITICAL SYSTEM ” MEANS AN INFORMATION TECHN OLOGY OR 14 CYBERSECURITY SYSTEM THAT IS SEVERELY OUT DATED, AS DETERMINED BY THE 15 DEPARTMENT . 16 (B) THERE IS A STATEWIDE REPORTING FRAMEWORK AND OVERSIGHT 17 COMMISSION IN THE DEPARTMENT . 18 (C) THE PURPOSE OF THE COMMISSION IS TO: 19 (1) ENSURE THE CONFIDENTIALIT Y, INTEGRITY, AND AVAILABILITY 20 OF INFORMATION HELD BY THE STATE CONCERNING STATE RESIDENTS ; AND 21 (2) DETERMINE THE APPROP RIATE INFORMATION TE CHNOLOGY AND 22 CYBERSECURITY INVEST MENTS AND UPGRADES . 23 (D) THE COMMISSION CONSISTS O F THE FOLLOWING MEMBERS : 24 (1) THE SECRETARY; 25 (2) THE STATE CHIEF INFORMATION SECURITY OFFICER; 26 (3) THE STATE TREASURER; 27 (4) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 28 INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY ; 29 HOUSE BILL 1205 7 (5) (3) THREE CHIEF INFORMATION SECURITY OFFICERS 1 REPRESENTING DIFFERE NT UNITS OF STATE GOVERNMENT , APPOINTED BY THE 2 GOVERNOR; 3 (6) (4) FOUR INFORMATION TEC HNOLOGY EXPERTS IN T HE 4 PRIVATE SECTOR , APPOINTED BY THE GOVERNOR; 5 (7) (5) ONE REPRESENTATIVE F ROM THE MARYLAND CHAMBER OF 6 COMMERCE WITH KNOWLEDGE OF CY BERSECURITY ISSUES ; 7 (8) (6) TWO REPRESENTATIVES FROM CITIZEN ADVOCAC Y GROUPS 8 IN THE STATE, APPOINTED BY THE GOVERNOR; 9 (9) (7) ONE CHIEF INFORMATION SECURITY OFFICER FRO M THE 10 PRIVATE SECTOR WHO H AS COMPLETED INFORMA TION TECHNOLOGY AND 11 CYBERSECURITY UPGRAD ES FOR A BUSINESS WI TH OVER 100 INFORMATION 12 TECHNOLOGY SYSTEMS , APPOINTED BY THE GOVERNOR; AND 13 (10) (8) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE 14 EDUCATION SECTOR WHO HAS COMPLETED IN FORMATION TECHNOLOGY AND 15 CYBERSECURITY UPGRAD ES FOR AN EDUCATIONA L INSTITUTION WITH O VER 100 16 INFORMATION TECHNOLO GY SYSTEMS, APPOINTED BY THE GOVERNOR. 17 (E) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 18 INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY SHALL S ERVE AS ADVISORY , 19 NONVOTING MEMBERS OF THE COMMISSION. 20 (E) (F) THE COMMISSION SHALL : 21 (1) DEVELOP A STRATEGIC ROADMAP WITH A TIMEL INE AND BUDGET 22 THAT WILL: 23 (I) REQUIRE THE UPDATES AND INVESTMENTS OF C RITICAL 24 INFORMATION TECHNOLO GY AND CYBERSECURITY SYSTEMS TO BE COMPLE TED ON 25 OR BEFORE DECEMBER 31, 2025; AND 26 (II) REQUIRE ALL UPDATES AND INVESTMENTS OF 27 INFORMATION TECHNOLO GY AND CYBERSECURITY TO BE MADE ON OR BEFORE 28 DECEMBER 31, 2030; 29 (2) MAKE PERIODIC RECOMM ENDATIONS ON INVESTM ENTS IN STATE 30 INFORMATION TECHNOLO GY STRUCTURES BASED ON THE ASSESSMENTS 31 COMPLETED IN ACCORDA NCE WITH THE FRAMEWO RK DEVELOPED IN § 3A–316 OF 32 THIS SUBTITLE; AND 33 8 HOUSE BILL 1205 (3) REVIEW AND PROV IDE RECOMMENDATIONS ON THE 1 DEPARTMENT ’S BASIC SECURITY STA NDARDS FOR USE OF TH E NETWORK 2 ESTABLISHED UNDER § 3A–404(B) OF THIS TITLE; AND 3 (3) (4) EACH YEAR, IN ACCORDANCE WITH § 2–1257 OF THE STATE 4 GOVERNMENT ARTICLE, REPORT ITS FINDINGS AND RECOMMENDAT IONS TO THE 5 SENATE BUDGET AND TAXATION COMMITTEE, THE HOUSE APPROPRIATIONS 6 COMMITTEE, THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE, 7 AND THE JOINT COMMITTEE ON CYBERSECURITY , INFORMATION TECHNOLOGY , 8 AND BIOTECHNOLOGY . 9 (G) THE REPORT SUBMITTED UNDER SUBSECTION (F)(4) OF THIS SECTION 10 MAY NOT CONTAIN INFO RMATION ABOUT THE SE CURITY OF AN INFORMA TION 11 SYSTEM. 12 3A–316. 13 (A) THIS SECTION DOES NOT APPLY TO: 14 (1) THE MARYLAND PORT ADMINISTRATION ; 15 (2) THE UNIVERSITY SYSTEM OF MARYLAND; 16 (3) ST. MARY’S COLLEGE OF MARYLAND; 17 (4) MORGAN STATE UNIVERSITY; 18 (5) THE MARYLAND STADIUM AUTHORITY; 19 (6) BALTIMORE CITY COMMUNITY COLLEGE; OR 20 (7) THE STATE BOARD OF ELECTIONS. 21 (A) (B) (1) THE DEPARTMENT SHALL HIRE AN INDEPENDENT 22 CONTRACTOR CONTRACTORS TO: 23 (I) DEVELOP A FRAMEWORK FOR INVESTMENTS IN 24 TECHNOLOGY ; AND 25 (II) AT LEAST ONCE EVERY 3 YEARS, IN ACCORDANCE WITH T HE 26 FRAMEWORK , ANNUALLY ASSESS THE CYBERSECU RITY AND INFORMATION 27 TECHNOLOGY SYSTEMS I N EACH UNIT OF STATE GOVERNMENT . 28 (2) THE FRAMEWORK SHALL I NCLUDE THE FOLLOWING CRITERIA: 29 HOUSE BILL 1205 9 (I) SECURITY RISKS TO TH E SYSTEM; 1 (II) SYSTEM PERFORMANCE ; 2 (III) THE SYSTEM ’S DEPENDENCE ON OTHE R INFORMATION 3 TECHNOLOGY OR CYBERS ECURITY SYSTEMS AND DATA; 4 (IV) THE SYSTEM ’S ABILITY TO CREATE AN EFFICIENT AND 5 SEAMLESS EXPERIENCE FOR USERS; 6 (V) THE SYSTEM ’S EFFECTIVENESS IN A CHIEVING UNIT 7 OBJECTIVES; 8 (VI) THE SYSTEM’S EFFECTIVENESS IN M EETING THE NEEDS OF 9 CITIZENS AND CUSTOME RS; 10 (VII) THE COSTS TO MAINTAI N AND OPERATE THE SYSTEM ; 11 (VIII) THE SPEED OF GOVERNM ENT RESPONSE TIME ; 12 (IX) THE EFFECTIVENESS OF THE SYSTEM IN REGARD TO THE 13 UNIT’S OBJECTIVES; 14 (X) IMPROVEMENTS TO THE UNIT’S RELATIVE AUDIT FIN DINGS 15 ATTRIBUTABLE TO THE SYSTEM; AND 16 (XI) AN ASSESSMENT OF THE SYSTEM USING THE NATIONAL 17 INSTITUTE OF STANDARDS AND TECHNOLOGY CYBERSECURITY FRAMEWORK . 18 (B) (C) EACH UNIT SHALL PROMP TLY PROVIDE THE CONTRACTOR A 19 CONTRACTOR EMPLOYED UNDER SUBSECTION (B) OF THIS SECTION WITH THE 20 INFORMATION NECESSAR Y TO PERFORM THE ASSESSMENTS . 21 (C) (D) (1) EACH YEAR, THE EVERY 3 YEARS, A CONTRACTOR SHALL 22 PROVIDE THE RESULTS OF THE ASSESSMENTS T O: 23 (I) THE STATEWIDE REPORTING FRAMEWORK AND 24 OVERSIGHT COMMISSION ESTABLISHE D UNDER § 3A–315 OF THIS SUBTITLE; AND 25 (II) IN ACCORDANCE WITH § 2–1257 OF THE STATE 26 GOVERNMENT ARTICLE, THE SENATE BUDGET AND TAXATION COMMITTEE AND 27 THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE. 28 10 HOUSE BILL 1205 (2) THE REPORT SUBMITTED UNDER PARAGRAPH (1)(II) OF THIS 1 SUBSECTION MAY NOT C ONTAIN INFORMATION ABOUT THE SECURITY O F AN 2 INFORMATION SYSTEM . 3 (D) (E) THE DEPARTMENT MAY USE FUNDS AVAILABLE FROM THE 4 ISSUANCE OF BONDS IN ACCORDANCE WITH § 10–650.1 OF THE ECONOMIC 5 DEVELOPMENT ARTICLE TO PAY FOR TH E INDEPENDENT CONTRA CTOR REQUIRED 6 UNDER MULTIPLE CONTR ACTORS AT A TIME TO MEET THE REQUIREMENT S OF THIS 7 SECTION. 8 3A–317. 9 (A) THE DEPARTMENT SHALL CONS ULT WITH THE MARYLAND STADIUM 10 AUTHORITY REGARDING T HE ISSUANCE OF BONDS FOR UPGRADES TO 11 INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 12 INFRASTRUCTURE IN ACCO RDANCE WITH § 10–650.1 OF THE ECONOMIC 13 DEVELOPMENT ARTICLE. 14 (B) THE DEPARTMENT MAY USE TH E PROCEEDS FROM BOND S ISSUED FOR 15 UPGRADES TO INFORMAT ION TECHNOLOGY AND C YBERSECURITY –RELATED STATE 16 GOVERNMENT INFRASTRU CTURE UNDER § 10–650.1 OF THE ECONOMIC 17 DEVELOPMENT ARTICLE ONLY FOR PROJ ECTS THAT RELATE TO RESEARCH INTO , 18 ACQUISITION OF , INSTALLATION OF , MAINTENANCE OF , AND RELATED EXPENSES 19 FOR UPGRADES TO INFO RMATION TECHNOLOGY A ND CYBERSECURITY –RELATED 20 STATE GOVERNMENT INFR ASTRUCTURE . 21 (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS 22 INDICATED. 23 (2) “FUND” MEANS THE LOCAL CYBERSECURITY SUPPORT FUND. 24 (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, 25 LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. 26 (B) (1) THERE IS A LOCAL CYBERSECURITY SUPPORT FUND. 27 (2) THE PURPOSE OF THE FUND IS TO: 28 (I) PROVIDE FINANCIAL AS SISTANCE TO LOCAL GO VERNMENTS 29 TO IMPROVE CYBERSECU RITY PREPAREDNESS , INCLUDING: 30 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 31 THE MOST UP–TO–DATE CYBERSECURITY PROTECTIO NS; 32 HOUSE BILL 1205 11 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 1 SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 2 PREPAREDNESS ; 3 3. RECRUITING AND HIRIN G INFORMATION 4 TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND 5 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 6 STAFF TRAINING ; AND 7 (II) ASSIST LOCAL GOVERNM ENTS APPLYING FOR FE DERAL 8 CYBERSECURITY PREPAR EDNESS GRANTS . 9 (3) THE SECRETARY SHALL ADMIN ISTER THE FUND. 10 (4) (I) THE FUND IS A SPECIAL, NONLAPSING FUND THAT IS NOT 11 SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE. 12 (II) THE STATE TREASURER SHALL HOLD THE FUND 13 SEPARATELY, AND THE COMPTROLLER SHALL ACC OUNT FOR THE FUND. 14 (5) THE FUND CONSISTS OF : 15 (I) MONEY APPROPRIATED I N THE STATE BUDG ET TO THE 16 FUND; 17 (II) INTEREST EARNINGS ; AND 18 (III) ANY OTHER MONEY FROM ANY OTHER SOURCE ACC EPTED 19 FOR THE BENEFIT OF T HE FUND. 20 (6) THE FUND MAY BE USED ONLY : 21 (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL 22 GOVERNMENTS TO IMPRO VE CYBERSECURITY PREPAREDNESS , INCLUDING: 23 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 24 THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 25 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 26 SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 27 PREPAREDNESS ; 28 12 HOUSE BILL 1205 3. RECRUITING AND HIRIN G INFORMATION 1 TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND 2 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 3 STAFF TRAINING ; 4 (II) TO ASSIST LOCAL GOVE RNMENTS APPLYING FOR FEDERAL 5 CYBERSECURITY PREPAR EDNESS GRANTS ; AND 6 (III) FOR ADMINISTRATIVE E XPENSES ASSOCIATED W ITH 7 PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH . 8 (7) (I) THE STATE TREASURER SHALL INVES T THE MONEY OF THE 9 FUND IN THE SAME MANN ER AS OTHER STATE MONEY MAY BE IN VESTED. 10 (II) ANY INTERE ST EARNINGS OF THE FUND SHALL BE 11 CREDITED TO THE FUND. 12 (8) EXPENDITURES FROM THE FUND MAY BE MADE ONLY IN 13 ACCORDANCE WITH THE STATE BUDGET . 14 (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL 15 GOVERNMENT SHALL UND ERGO A CYBERSECURITY PREPAREDNESS ASSESSMENT 16 PROVIDED BY THE DEPARTMENT AT A COST TO THE LOCAL GOVERNM ENT THAT 17 DOES NOT EXCEED THE COST TO THE DEPARTMENT OF PROVIDI NG THE 18 ASSESSMENT . 19 6–226. 20 (a) (2) (i) Notwithstanding any other provision of law, and unless 21 inconsistent with a federal law, grant agreement, or other federal requirement or with the 22 terms of a gift or settlement agreement, net interest on all State money allocated by the 23 State Treasurer under this section to special funds or accounts, and otherwise entitled to 24 receive interest earnings, as accounted for by the Comptroller, shall accrue to the General 25 Fund of the State. 26 (ii) The provisions of subparagraph (i) of this paragraph do not apply 27 to the following funds: 28 144. the Health Equity Resource Community Reserve Fund; 29 [and] 30 145. the Access to Counsel in Evictions Special Fund; AND 31 HOUSE BILL 1205 13 146. THE INFORMATION TECHNOLOGY AND LOCAL 1 CYBERSECURITY INFRASTRUCTURE SUPPORT FUND. 2 11–101. 3 (a) In this Division II the following words have the meanings indicated unless: 4 (1) the context clearly requires a different meaning; or 5 (2) a different definition is provided for a particular title or provision. 6 (m) “Primary procurement units” means: 7 (1) the State Treasurer; 8 (2) the Department of General Services; 9 (3) the Department of Transportation; 10 (4) the University System of Maryland; 11 (5) the Maryland Port Commission; 12 (6) the Morgan State University; [and] 13 (7) the St. Mary’s College of Maryland; AND 14 (8) THE DEPARTMENT OF INFORMATION TECHNOLOGY . 15 12–101. 16 (a) This section does not apply to: 17 (1) capital expenditures by the Department of Transportation or the 18 Maryland Transportation Authority, in connection with State roads, bridges, or highways, 19 as provided in § 12–202 of this title; OR 20 (2) PROCUREMENTS BY THE DEPARTMENT OF INFORMATION 21 TECHNOLOGY FOR THE PU RPOSE OF MODERNIZING CYBERSECURITY 22 INFRASTRUCTURE FOR T HE STATE VALUED BELOW $1,000,000. 23 (b) (1) The Board may control procurement by units. 24 (2) To implement the provisions of this Division II, the Board may: 25 (i) set policy; 26 14 HOUSE BILL 1205 (ii) adopt regulations, in accordance with Title 10, Subtitle 1 of the 1 State Government Article; and 2 (iii) establish internal operational procedures consistent with this 3 Division II. 4 (3) The Board shall ensure that the regulations of the primary 5 procurement units provide for procedures that are consistent with this Division II and Title 6 13, Subtitle 4 of the State Personnel and Pensions Article and, to the extent the 7 circumstances of a particular type of procurement or a particular unit do not require 8 otherwise, are substantially the same. 9 (4) The Board may delegate any of its authority that it determines to be 10 appropriate for delegation and may require prior Board approval for specified procurement 11 actions. 12 (5) Except as limited by the Maryland Constitution, the Board may 13 exercise any control authority conferred on a primary procurement unit by this Division II 14 and, to the extent that its action conflicts with the action of the primary procurement unit, 15 the action of the Board shall prevail. 16 (6) The Board shall develop and submit to the General Assembly, in 17 accordance with § 2–1257 of the State Government Article, an annual report on the 18 procurement system that includes information on actions necessary to improve effective 19 broad–based competition in procurement. 20 (C) ON OR BEFORE DECEMBER 1 EACH YEAR, THE DEPARTMENT OF 21 INFORMATION TECHNOLOGY SHALL SUBM IT A REPORT TO THE BOARD ON 22 PROCUREMENTS MADE UN DER SUBSECTION (A)(2) OF THIS SECTION THAT SHALL 23 INCLUDE FOR EACH PRO CUREMENT: 24 (1) THE PURPOSE OF THE P ROCUREMENT ; 25 (2) THE NAME OF THE CONT RACTOR; 26 (3) THE CONTRACT AMOUNT ; AND 27 (4) THE CONTRACT TERM . 28 12–107. 29 (b) Subject to the authority of the Board, jurisdiction over procurement is as 30 follows: 31 (2) the Department of General Services may: 32 HOUSE BILL 1205 15 (i) engage in or control procurement of: 1 8. construction and construction–related services for State 2 correctional facilities; AND 3 9. supplies, materials, and equipment in support of 4 construction and construction–related services for State correctional facilities in 5 accordance with this Division II and Title 2 and Title 10, Subtitle 1 of the Correctional 6 Services Article; AND 7 10. [information processing equipment and associated 8 services, as provided in Title 3A, Subtitle 3 of this article; and 9 11.] telecommunication equipment, systems, or services, as 10 provided in Title 3A, Subtitle 4 of this article; 11 (3) the Department of Transportation and the Maryland Transportation 12 Authority, without the approval of any of the other primary procurement units, may engage 13 in the procurement of: 14 (vi) services for aeronautics related activities, including information 15 processing services, but excluding banking and financial services under the authority of the 16 State Treasurer under item (1) of this subsection; [and] 17 (4) the Maryland Port Commission, without the approval of any of the 18 other primary procurement units, may engage in the procurement of: 19 (v) leases of real property for port related activities unless the lease 20 payments are from the General Fund of the State; AND 21 (5) THE DEPARTMENT OF INFORMATION TECHNOLOGY , WITHOUT 22 THE APPROVAL OF ANY OTHER PRIMARY PROCUR EMENT UNIT, MAY ENGAGE IN OR 23 CONTROL PROCUREMENT OF: 24 (I) INFORMATION PROCESSI NG EQUIPMENT AND ASS OCIATED 25 SERVICES, AS PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE; AND 26 (II) INFORMATION TECHNOLO GY SYSTEM AND 27 MODERNIZATION , AS PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE; 28 (III) TELECOMMUNICATION EQ UIPMENT, SYSTEMS, OR 29 SERVICES, AS PROVIDED IN TITLE 3A, SUBTITLE 4 OF THIS ARTICLE; AND 30 (IV) CYBERSECURITY UPGRAD ES AND MODERNIZATION , AS 31 PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE . 32 16 HOUSE BILL 1205 15–112. 1 (a) (1) (i) Except as provided in subparagraph (ii) of this paragraph, this 2 section applies to State procurement contracts for: 3 1. construction; 4 2. INFORMATION PROCESSI NG EQUIPMENT AND 5 ASSOCIATED SERVICES ; AND 6 3. IN ACCORDANCE WITH TITLE 3A, SUBTITLE 3 OF THIS 7 ARTICLE, INFORMATION TECHNOLO GY SYSTEM AND CYBERS ECURITY UPGRADES 8 AND MODERNIZATION . 9 (b) (3) (i) If a unit is to pay for a contract or a part of a contract using a 10 unit price methodology, a change order may not be required for work to continue and be 11 completed beyond the estimated quantities in the contract. 12 (ii) After work is completed, a unit shall: 13 1. determine the actual quantity used to complete the 14 contract; and 15 2. if necessary, issue a final adjustment change order to the 16 contractor. 17 (4) AN INDEPENDENT CONTRA CTOR WHO PERFORMS AN 18 ASSESSMENT UNDER § 3A–316 OF THIS ARTICLE MAY ISSUE A CHANGE ORDER ON 19 THE ORIGINAL ASSESSM ENT CONTRACT FOR ANY SUBSEQUENT CYBERSECU RITY 20 UPGRADES. 21 SECTION 2. AND BE IT FURTHER ENACTED, That this Act shall take effect July 22 1, 2022. 23 Approved: ________________________________________________________________________________ Governor. ________________________________________________________________________________ Speaker of the House of Delegates. ________________________________________________________________________________ President of the Senate.