EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW. [Brackets] indicate matter deleted from existing law. Underlining indicates amendments to bill. Strike out indicates matter stricken from the bill by amendment or deleted from the law by amendment. Italics indicate opposite chamber/conference committee amendments. *hb1205* HOUSE BILL 1205 S2, P1, S1 EMERGENCY BILL (2lr1777) ENROLLED BILL — Health and Government Operations and Appropriations/Budget and Taxation — Introduced by Delegates P. Young, Kerr, Feldmark, Bartlett, Kelly, Kipke, and McIntosh McIntosh, Bagnall, Bhandari, Carr, Chisholm, Cullison, Hill, Johnson, Kaiser, Landis, R. Lewis, Morgan, Pena–Melnyk, Pendergrass, Reilly, Rosenberg, Saab, Sample–Hughes, Szeliga, and K. Young Read and Examined by Proofreaders: _______________________________________________ Proofreader. _______________________________________________ Proofreader. Sealed with the Great Seal and presented to the Governor, for his approval this _______ day of _______________ at ________________________ o’clock, ________M. ______________________________________________ Speaker. CHAPTER ______ AN ACT concerning 1 State Government – Information Technology and Cybersecurity –Related 2 Infrastructure 3 (Modernize Maryland Act of 2022) 4 FOR the purpose of requiring a certain water or sewer system to, on or before a certain date, 5 assess its vulnerability to a cyber attack, develop a cybersecurity plan if appropriate, 6 and submit a certain report to the General Assembly; authorizing the Maryland Water 7 Quality Financing Administration to provide financial assistance to a public water 8 or wastewater system to assess system cybersecurity vulnerabilities and develop a 9 cybersecurity plan; authorizing the Maryland Stadium Authority to issue bonds and, 10 in consultation with the Department of Information Technology, finance projects 11 related to information technology and cybersecurity–related State government 12 2 HOUSE BILL 1205 infrastructure; establishing an Information Technology and C ybersecurity 1 Infrastructure establishing the Local Cybersecurity Support Fund as a special, 2 nonlapsing fund; requiring interest earnings of the Fund to be credited to the Fund; 3 establishing certain eligibility requirements to receive assistance from the Fund; 4 altering the duties of the Secretary of Information Technology; establishing a 5 Statewide Reporting Framework and an independent Modernize Maryland 6 Oversight Commission in the Department of Information Technology; requiring the 7 Department to hire an independent contractor contractors to develop a framework 8 for investments in technology and annually periodically assess the cybersecurity and 9 information technology systems in each unit certain units of State government; 10 specifying the use of proceeds from certain bonds; exempting certain procurements 11 by the Department of General Services from oversight by the Board of Public Works; 12 establishing that the Department is a primary procurement unit and authorizing the 13 Department to engage in or control certain procurements; authorizing a certain 14 independent contractor to issue a certain change order applying certain change order 15 requirements to State procurement contracts for certain equipment, services, and 16 upgrades; authorizing funds to be transferred by budget amendment from the 17 Dedicated Purpose Account in a certain fiscal year to implement this Act; and 18 generally relating to the development, financing, and procurement of information 19 technology and cybersecurity–related State government infrastructure projects. 20 BY repealing and reenacting, with amendments, 21 Article – Environment 22 Section 9–1604(c) 23 Annotated Code of Maryland 24 (2014 Replacement Volume and 2021 Supplement) 25 BY adding to 26 Article – Public Safety 27 Section 14–104.1 28 Annotated Code of Maryland 29 (2018 Replacement Volume and 2021 Supplement) 30 BY repealing and reenacting, with amendments, 31 Article – Economic Development 32 Section 10–628(a) 33 Annotated Code of Maryland 34 (2018 Replacement Volume and 2021 Supplement) 35 BY adding to 36 Article – Economic Development 37 Section 10–628(d), 10–650.1, and 10–657.5 38 Annotated Code of Maryland 39 (2018 Replacement Volume and 2021 Supplement) 40 BY repealing and reenacting, with amendments, 41 Article – State Finance and Procurement 42 HOUSE BILL 1205 3 Section 3A–101, 3A–303(a)(7) and (8), 6–226(a)(2)(ii)144. and 145., 11–101(m), 1 12–101, 12–107(b)(2)(i)9. through 11. 12–107(b)(2)(i)8., (3)(vi), and (4)(v), and 2 12–107(b)(3)(vi) and (4)(v), and 15–112(a)(1)(i) 3 Annotated Code of Maryland 4 (2021 Replacement Volume) 5 BY adding to 6 Article – State Finance and Procurement 7 Section 3A–303(a)(9) and (10), 3A–315 through 3A–317, 3A–316, 6–226(a)(2)(ii)146., 8 12–107(b)(5), and and 12–107(b)(5) 15–112(b)(4) 9 Annotated Code of Maryland 10 (2021 Replacement Volume) 11 BY repealing and reenacting, without amendments, 12 Article – State Finance and Procurement 13 Section 6–226(a)(2)(i), 11–101(a), and 15–112(b)(3) 11–101(a), and 12–107(b)(2)(i)9. 14 Annotated Code of Maryland 15 (2021 Replacement Volume) 16 BY repealing 17 Article – State Finance and Procurement 18 Section 12–107(b)(2)(i)10. and 11. 19 Annotated Code of Maryland 20 (2021 Replacement Volume) 21 SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 22 That the Laws of Maryland read as follows: 23 Article – Environment 24 9–1604. 25 (c) (1) This subsection applies to financial assistance provided by the 26 Administration under: 27 (i) The Water Quality Fund; 28 (ii) The Bay Restoration Fund; 29 (iii) The Biological Nutrient Removal Program; and 30 (iv) The Supplemental Assistance Program. 31 (2) The Administration shall ensure the fair and equitable distribution of 32 financial assistance among wastewater treatment facilities with a design capacity of less 33 than 500,000 gallons per day and wastewater treatment facilities with a design capacity of 34 500,000 gallons or more per day. 35 4 HOUSE BILL 1205 (3) A PUBLIC OR PRIVATE WA TER OR SEWER SYSTEM THAT SERVES 1 10,000 OR MORE USERS AND RE CEIVES FINANCIAL ASS ISTANCE FROM THE STATE 2 SHALL: 3 (I) ASSESS ITS VULNERABIL ITY TO A CYBER ATTAC K; AND 4 (II) IF APPROPRIATE , DEVELOP A CYBERSECUR ITY PLAN. 5 (4) THE ADMINISTRATION MAY PR OVIDE FINANCIAL ASSI STANCE TO 6 A PUBLIC WATER OR WA STEWATER SYSTEM TO A SSESS SYSTEM CYBERSE CURITY 7 VULNERABILITIES AND DEVELOP A CYBERSECUR ITY PLAN. 8 Article – Public Safety 9 14–104.1. 10 (A) (1) IN THIS SECTION THE FOLLOWING WORDS HAVE THE MEANINGS 11 INDICATED. 12 (2) “FUND” MEANS THE LOCAL CYBERSECURITY SUPPORT FUND. 13 (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, 14 LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. 15 (B) (1) THERE IS A LOCAL CYBERSECURITY SUPPORT FUND. 16 (2) THE PURPOSE OF THE FUND IS TO: 17 (I) PROVIDE FINANCIAL AS SISTANCE TO LOCAL GO VERNMENTS 18 TO IMPROVE CYBERSECU RITY PREPAREDNESS , INCLUDING: 19 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 20 THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 21 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 22 SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 23 PREPAREDNESS ; 24 3. RECRUITING AND HIRIN G INFORMATION 25 TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; 26 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 27 STAFF TRAINING ; 28 HOUSE BILL 1205 5 5. CONDUCTING CYBERSECU RITY VULNERABILITY 1 ASSESSMENTS ; 2 6. ADDRESSING HIGH –RISK CYBERSECURITY 3 VULNERABILITIES IDEN TIFIED BY VULNERABIL ITY ASSESSMENTS ; 4 7. IMPLEMENTING AND MAI NTAINING INTEGRATORS 5 AND OTHER SIMILAR IN TELLIGENCE SHARING INFRASTRUC TURE THAT ENABLE 6 CONNECTION WITH THE INFORMATION SHARING AND ANALYSIS CENTER IN THE 7 DEPARTMENT OF INFORMATION TECHNOLOGY ; AND 8 8. SUPPORTING THE SECUR ITY OF LOCAL WASTEWA TER 9 TREATMENT PLANTS , INCLUDING BICOUNTY , COUNTY, AND MUNICIPA L PLANTS, BY 10 ACQUIRING OR IMPLEME NTING CYBERSECURITY –RELATED UPGRADES TO THE 11 PLANTS; AND 12 (II) ASSIST LOCAL GOVERNM ENTS APPLYING FOR FE DERAL 13 CYBERSECURITY PREPAR EDNESS GRANTS . 14 (3) THE SECRETARY SHALL ADMIN ISTER THE FUND. 15 (4) (I) THE FUND IS A SPECIAL, NONLAPSING FUND THAT IS NOT 16 SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE. 17 (II) THE STATE TREASURER SHALL HOLD THE FUND 18 SEPARATELY, AND THE COMPTROLLER SHALL ACC OUNT FOR THE FUND. 19 (5) THE FUND CONSISTS OF : 20 (I) MONEY APPROPRIATED I N THE STATE BUDGET TO THE 21 FUND; 22 (II) INTEREST EARNINGS ; AND 23 (III) ANY OTHER MONEY FROM ANY OTHER SOURCE ACC EPTED 24 FOR THE BENEFIT OF T HE FUND. 25 (6) THE FUND MAY BE USED ONLY : 26 (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL 27 GOVERNMENTS TO IMPRO VE CYBERSECURITY PRE PAREDNESS, INCLUDING: 28 6 HOUSE BILL 1205 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 1 THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 2 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 3 SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 4 PREPAREDNESS ; 5 3. RECRUITING AND HIRIN G INFORMATION 6 TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; 7 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 8 STAFF TRAINING ; 9 5. CONDUCTING CYBERSECU RITY VULNE RABILITY 10 ASSESSMENTS ; 11 6. ADDRESSING HIGH –RISK CYBERSECURITY 12 VULNERABILITIES IDEN TIFIED BY VULNERABIL ITY ASSESSMENTS ; 13 7. IMPLEMENTING OR MAIN TAINING INTEGRATORS AND 14 OTHER SIMILAR INTELL IGENCE SHARING INFRA STRUCTURE THAT ENABL E 15 CONNECTION WITH THE INFORMATION SHARING AND ANALYSIS CENTER IN THE 16 DEPARTMENT OF INFORMATION TECHNOLOGY ; AND 17 8. SUPPORTING THE SECUR ITY OF LOCAL WASTEWA TER 18 TREATMENT PLANTS , INCLUDING BICOUNTY , COUNTY, AND MUNICIPAL PLANTS , BY 19 ACQUIRING OR IMPLEME NTING CYBERSECURITY –RELATED UPGRADES TO THE 20 PLANTS; 21 (II) TO ASSIST LOCAL GOVE RNMENTS APPLYING FOR FEDERAL 22 CYBERSECURITY PREPAR EDNESS GRANTS ; AND 23 (III) FOR ADMINISTRATIVE E XPENSES ASSOCIATED W ITH 24 PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH. 25 (7) (I) THE STATE TREASURER SHALL INVES T THE MONEY OF THE 26 FUND IN THE SAME MANN ER AS OTHER STATE MONEY MAY BE IN VESTED. 27 (II) ANY INTEREST EARNINGS OF THE FUND SHALL BE 28 CREDITED TO THE FUND. 29 (8) EXPENDITURES FROM THE FUND MAY BE MADE ON LY IN 30 ACCORDANCE WITH THE STATE BUDGET. 31 HOUSE BILL 1205 7 (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL 1 GOVERNMENT SHALL : 2 (1) PROVIDE PROOF TO THE DEPARTMENT OF INFORMATION 3 TECHNOLOGY THAT THE L OCAL GOVERNMENT COND UCTED A CYBERSECURIT Y 4 PREPAREDNESS AS SESSMENT IN THE PREV IOUS 12 MONTHS; OR 5 (2) WITHIN 12 MONTHS UNDERGO A CYB ERSECURITY PREPAREDN ESS 6 ASSESSMENT PROVIDED BY, IN ACCORDANCE WITH T HE PREFERENCE OF THE LOCAL 7 GOVERNMENT : 8 (I) THE DEPARTMENT OF INFORMATION TECHNOLOGY AT A 9 COST TO THE LOCAL G OVERNMENT THAT DOES NOT EXCEED THE COST TO THE 10 DEPARTMENT OF INFORMATION TECHNOLOGY OF PROVIDI NG THE ASSESSMENT ; OR 11 (II) A VENDOR AUTHORIZED BY THE DEPARTMENT OF 12 INFORMATION TECHNOLOGY TO COMPLET E CYBERSECURITY PREP AREDNESS 13 ASSESSMENTS . 14 Article – Economic Development 15 10–628. 16 (a) Except as provided in subsections (b) [and], (c), AND (D) of this section and 17 subject to the prior approval of the Board of Public Works, the Authority may issue bonds 18 at any time for any corporate purpose of the Authority, including the establishment of 19 reserves and the payment of interest. 20 (D) UNLESS AUTHORI ZED BY THE GENERAL ASSEMBLY, THE BOARD OF 21 PUBLIC WORKS MAY NOT APPROVE AN ISSUANCE BY THE AUTHORITY OF BONDS , 22 WHETHER TAXABLE OR T AX EXEMPT, THAT CONSTITUTE TAX SUPPORTED DEBT OR 23 NONTAX SUPPORTED DEB T IF, AFTER ISSUANCE , THERE WOULD BE OUTST ANDING 24 AND UNPAID $1,500,000,000 FACE AMOUNTS OF THE BONDS FOR THE PURPOS E OF 25 FINANCING RESEARCH I NTO, ACQUISITION OF , INSTALLATION OF , MAINTENANCE 26 OF, AND RELATED EXPENSES FOR UPGRADES TO INFO RMATION TECHNOLOGY A ND 27 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTU RE. 28 10–650.1. 29 (A) THE AUTHORITY AND THE DEPARTMENT OF INFORMATION 30 TECHNOLOGY SHALL COMP LY WITH THIS SECTION TO FINANCE PROJECTS TO 31 RESEARCH, ACQUIRE, INSTALL, MAINTAIN, AND UPGRADE INFORMAT ION 32 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 33 INFRASTRUCTURE. 34 8 HOUSE BILL 1205 (B) THE AUTHORITY SHALL TRANS FER TO THE DEPARTMENT OF 1 INFORMATION TECHNOLOGY THE PROCEE DS OF BONDS ISSUED U NDER THIS 2 SUBTITLE FOR FINANCI NG INFORMATION TECHN OLOGY AND 3 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS . 4 (C) AT LEAST 90 DAYS BEFORE PROVIDIN G THE WRITTEN NOTICE TO THE 5 FISCAL COMMITTEES OF THE GENERAL ASSEMBLY REQUIRED UND ER SUBSECTION 6 (D) OF THIS SECTION, THE AUTHORITY SHALL CONSU LT WITH THE DEPARTMENT OF 7 INFORMATION TECHNOLOGY TO DETERMI NE THE AMOUNT OF FUN DS NEEDED FOR 8 INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 9 INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS. 10 (D) AT LEAST 45 DAYS BEFORE SEEKING APPROVAL OF THE BOARD OF 11 PUBLIC WORKS FOR EACH BOND I SSUE RELATED TO INFO RMATION TECHNOLOGY 12 AND CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE , THE 13 AUTHORITY SHALL PROVI DE TO THE FISCAL COM MITTEES OF THE GENERAL 14 ASSEMBLY, IN ACCORDANCE WITH § 2–1257 OF THE STATE GOVERNMENT ARTICLE, 15 WRITTEN NOTICE OF : 16 (1) THE AGGREGATE AMOUNT OF FUNDS NEEDED FOR INFORMATION 17 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 18 INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS; 19 (2) THE ANTICIPATED TOTA L DEBT SERVICE FOR T HE PROPOSED 20 BOND ISSUE; AND 21 (3) THE ANTICIPATED TOTA L DEBT SERVICE WHEN CO MBINED WITH 22 THE DEBT SERVICE FOR ALL PRIOR OUTSTANDIN G BOND ISSUES FOR IN FORMATION 23 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 24 INFRASTRUCTURE PROJE CTS. 25 (E) BEFORE EACH ISSUANCE OF BONDS TO FINANCE INFORMATION 26 TECHNOLOGY AND CYBERSECURITY –RELATED STATE GOVERNMENT 27 INFRASTRUCTURE PROJE CTS, THE AUTHORITY SHALL OBTAI N THE APPROVAL OF 28 THE BOARD OF PUBLIC WORKS OF THE AGGREGAT E AMOUNT OF THE PROP OSED 29 BOND ISSUE. 30 (F) FOR FISCAL YEAR 2024 AND EACH FISCAL YEAR THEREAFTER , UNTIL 31 THE BONDS THAT HAVE BEEN ISSUED TO FINANCE IN FORMATION TECHNOLOGY AND 32 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ARE 33 NO LONGER OUTSTANDIN G AND UNPAID , THE GOVERNOR SHALL INCLUD E IN THE 34 ANNUAL BUDGET BILL A N APPROPRIATION TO T HE INFORMATION TECHNOLOGY 35 AND CYBERSECURITY INFRASTRUCTURE FUND IN AN AMOUNT SUF FICIENT TO 36 HOUSE BILL 1205 9 COVER THE PROJECTED DEBT SERVICE REQUIRE MENTS FOR THE UPCOMI NG FISCAL 1 YEAR. 2 10–657.5. 3 (A) IN THIS SECTION , “FUND” MEANS THE INFORMATION TECHNOLOGY 4 AND CYBERSECURITY INFRASTRUCTU RE FUND. 5 (B) THERE IS AN INFORMATION TECHNOLOGY AND CYBERSECURITY 6 INFRASTRUCTURE FUND. 7 (C) (1) THE FUND IS A SPECIAL , NONLAPSING FUND THAT IS NOT 8 SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE AND 9 THAT SHALL BE AVAILA BLE IN PERPETUITY TO IMPLEMENT THIS SU BTITLE 10 RELATED TO UPGRADES TO INFORMATION TECHN OLOGY AND 11 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 12 (2) THE AUTHORITY SHALL : 13 (I) USE THE FUND AS A REVOLVING F UND FOR CARRYING OUT 14 THE PROVISIONS OF TH IS SUBTITLE RELA TED TO UPGRADES TO I NFORMATION 15 TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 16 INFRASTRUCTURE ; AND 17 (II) PAY ANY AND ALL EXPE NSES FROM THE FUND THAT ARE 18 INCURRED BY THE AUTHORITY OR THE DEPARTMENT OF INFORMATION 19 TECHNOLOGY RELATED TO UPGRADES TO I NFORMATION TECHNOLOG Y AND 20 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 21 (D) THE FUND CONSISTS OF : 22 (1) FUNDS APPROPRIATED F OR DEPOSIT TO THE FUND; 23 (2) PROCEEDS FROM THE SA LE OF BONDS RELATED TO UPGRADES TO 24 INFORMATION TECHNOLO GY AND CYBERSE CURITY–RELATED STATE GOVERNMENT 25 INFRASTRUCTURE PROJE CTS; 26 (3) REVENUES COLLECTED O R RECEIVED FROM ANY SOURCE UNDER 27 THIS SUBTITLE RELATE D TO UPGRADES TO INF ORMATION TECHNOLOGY AND 28 CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ; 29 (4) INTEREST EARNINGS ; AND 30 10 HOUSE BILL 1205 (5) ANY ADDITIONAL MONEY MADE AVAILABLE FROM ANY PUBLIC OR 1 PRIVATE SOURCE FOR T HE PURPOSES ESTABLIS HED FOR THE FUND. 2 (E) (1) THE STATE TREASURER SHALL INVES T THE MONEY OF THE FUND 3 IN THE SAME MANNER A S OTHER STATE FUNDS. 4 (2) ANY INVESTMENT EARNIN GS SHALL BE CREDITED TO THE FUND. 5 (3) NO PART OF THE FUND MAY REVERT OR BE CREDITED TO THE 6 GENERAL FUND OF THE STATE OR ANY SPECIAL FUND OF THE STATE. 7 Article – State Finance and Procurement 8 3A–101. 9 (a) In this title the following words have the meanings indicated. 10 (b) “CLOUD COMPUTING SERVICE” MEANS A SERVICE THAT ENABLES 11 ON–DEMAND SELF –SERVICE NETWORK ACCE SS TO A SHARED POOL OF 12 CONFIGURABLE COMPUTE R RESOURCES , INCLUDING DATA STORA GE, ANALYTICS, 13 COMMERCE , STREAMING, E–MAIL, DOCUMENT SHARING , AND DOCUMENT EDITING . 14 (C) “Department” means the Department of Information Technology. 15 [(c)] (D) “Secretary” means the Secretary of Information Technology. 16 [(d)] (E) “Telecommunication” means the transmission of information, images, 17 pictures, voice, or data by radio, video, or other electronic or impulse means. 18 [(e)] (F) “Unit of State government” means an agency or unit of the Executive 19 Branch of State government. 20 3A–303. 21 (a) The Secretary is responsible for carrying out the following duties: 22 (7) advising and consulting with the Legislative and Judicial branches of 23 State government regarding a cybersecurity strategy; [and] 24 (8) in consultation with the Attorney General, developing guidance on 25 consistent cybersecurity strategies for counties, municipal corporations, school systems, 26 and all other political subdivisions of the State; AND 27 (9) UPGRADING INFORMATIO N TECHNOLOGY AND 28 CYBERSECURITY –RELATED STATE GOVERNMENT INFRASTRUCTURE ; AND 29 HOUSE BILL 1205 11 (10) ANNUALLY EVALUATING : 1 (I) THE FEASIBILITY OF U NITS OF STATE GOVERNMENT 2 PROVIDING PUBLIC SER VICES USING ARTIFICI AL INTELLIGENCE , MACHINE 3 LEARNING, COMMERCIAL CLOUD COM PUTING SERVICES , DEVICE–AS–A–SERVICE 4 PROCUREMENT MODELS , AND OTHER EMERGING T ECHNOLOGIES ; AND 5 (II) THE DEVELOPMENT OF D ATA ANALYTICS CAPABI LITIES TO 6 ENABLE DATA–DRIVEN POLICYMAKING BY UNITS OF STATE GOVERNMENT . 7 3A–315. 8 (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS 9 INDICATED. 10 (2) “CITIZEN ADVOCACY GROU P” MEANS AN ORGANIZATIO N WHOSE 11 MISSION IS TO PROVID E SUPPORT FOR INFORM ATION TECHNOLOGY AND 12 CYBERSECURITY POLICI ES. 13 (3) (2) “COMMISSION” MEANS THE STATEWIDE REPORTING 14 FRAMEWORK AND MODERNIZE MARYLAND OVERSIGHT COMMISSION. 15 (4) (3) “CRITICAL SYSTEM ” MEANS AN INFORMATION 16 TECHNOLOGY OR CYBERS ECURITY SYSTEM THAT IS SEVERELY OUTDATED , AS 17 DETERMINED BY THE DEPARTMENT . 18 (B) THERE IS A STATEWIDE REPORTING FRAMEWORK AND AN 19 INDEPENDENT MODERNIZE MARYLAND OVERSIGHT COMMISSION IN THE 20 DEPARTMENT . 21 (C) THE PURPOSE OF THE COMMISSION IS TO: 22 (1) ENSURE THE CONFIDENT IALITY, INTEGRITY, AND AVAILABILITY 23 OF INFORMATION HELD BY THE STATE CONCERNING STATE RESIDENTS ; AND 24 (2) DETERMINE ADVISE THE SECRETARY AND STATE CHIEF 25 INFORMATION SECURITY OFFICER ON: 26 (I) THE APPROPRIATE INFO RMATION TECHNOLOGY A ND 27 CYBERSECURITY INVEST MENTS AND UPGRADES ; 28 (II) THE FUNDING SOURCES FOR THE APPROPRIATE 29 INFORMATION TECHNOLO GY AND CYBERSECURITY UPGRADES; AND 30 12 HOUSE BILL 1205 (III) FUTURE MECHANISMS FO R THE PROCUREMENT OF 1 APPROPRIATE INFORMAT ION TECHNOLOGY AND C YBERSECURITY UPGRADE S, 2 INCLUDING WAYS TO IN CREASE THE EFFICIENC Y OF PROCUREMENTS MA DE FOR 3 INFORMATION TECHNOLO GY AND CYBERSECURITY UPGRADES. 4 (D) THE COMMISSION CONSISTS O F THE FOLLOWING MEMB ERS: 5 (1) THE SECRETARY; 6 (2) THE STATE CHIEF INFORMATION SECURITY OFFICER; 7 (3) THE STATE TREASURER; 8 (4) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 9 INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY ; 10 (5) (3) THREE CHIEF INFORMAT ION SECURITY OFFICERS 11 REPRESENTING DIFFERE NT UNITS OF STATE GOVERNMENT , APPOINTED BY THE 12 GOVERNOR; 13 (6) (4) FOUR ONE INFORMATION TECHNOLO GY EXPERTS IN 14 MODERNIZATION EXPERT WITH EXPERIENCE IN THE PRIVATE SECTOR , APPOINTED 15 BY THE GOVERNOR; 16 (7) (5) ONE REPRESENTATIVE F ROM THE MARYLAND CHAMBER OF 17 COMMERCE WITH KNOWLEDGE OF CY BERSECURITY ISSUES ; 18 (8) (6) TWO REPRESENTATIVES FROM CITIZEN ADVOCACY GRO UPS 19 IN THE STATE, APPOINTED BY THE GOVERNOR; INDIVIDUALS WHO ARE END USERS 20 OF STATE INFORMATION TEC HNOLOGY SYSTEMS , ONE APPOINTED BY THE 21 PRESIDENT OF THE SENATE AND ONE APPOIN TED BY THE SPEAKER OF THE HOUSE 22 APPOINTED BY THE GOVERNOR; 23 (9) (7) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE 24 PRIVATE SECTOR WHO H AS COMPLETED INFORMA TION TECHNOLOGY AND 25 CYBERSECURITY UPGRAD ES FOR A BUSINESS WI TH OVER 100 INFORMATION 26 TECHNOLOGY SYSTEMS , APPOINTED BY THE GOVERNOR; AND 27 (10) (8) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE 28 EDUCATION SECTOR WHO HAS COMPLETED INFORM ATION TECHNOLOGY AND 29 CYBERSECURITY UPGRA DES FOR AN EDUCATION AL INSTITUTION WITH OVER 100 30 INFORMATION TECHNOLO GY SYSTEMS, APPOINTED BY THE GOVERNOR. 31 HOUSE BILL 1205 13 (7) ONE REPRESENTATIVE F ROM THE CYBERSECURITY ASSOCIATION 1 OF MARYLAND; AND 2 (8) ONE INDIVIDUAL WHO I S EITHER AN INSTRUCT OR OR A 3 PROFESSIONAL IN THE ACADEMIC FIEL D OF CYBERSECURITY A T A COLLEGE OR 4 UNIVERSITY IN THE STATE, APPOINTED BY THE GOVERNOR. 5 (E) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 6 INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY SHALL S ERVE AS ADVISORY , 7 NONVOTING MEMBERS OF THE COMMISSION. 8 (E) (F) THE COMMISSION SHALL : 9 (1) DEVELOP ADVISE THE SECRETARY ON A STRATEGIC ROADMAP 10 WITH A TIMELINE AND BUDGET THAT WILL : 11 (I) REQUIRE THE UPDATES AND INVESTMENTS OF C RITICAL 12 INFORMATION TECHNOLO GY AND CYBERSECURITY SYSTEMS IDENTIFIED BY THE 13 COMMISSION IN THE FIR ST RECOMMENDATIONS R EPORTED UNDER PARAGR APH (2) 14 OF THIS SUBSECTION TO BE COMPLETED ON O R BEFORE DECEMBER 31, 2025; AND 15 (II) REQUIRE ALL UPDATES AND INVESTMENTS OF 16 INFORMATION TECHNOLO GY AND CYBERSECURITY TO BE MADE ON OR BEF ORE 17 DECEMBER 31, 2030; 18 (2) MAKE PERIODIC RECOMM ENDATIONS ON INVESTM ENTS IN STATE 19 INFORMATION TECHNOLO GY STRUCTURES BASED ON THE ASSESSMENTS 20 COMPLETED IN ACCORDANCE WITH THE FRAMEWORK DEVELOPED IN § 3A–316 OF 21 THIS SUBTITLE; AND 22 (3) REVIEW AND PROVIDE R ECOMMENDATIONS ON TH E 23 DEPARTMENT ’S BASIC SECURITY STA NDARDS FOR USE OF TH E NETWORK 24 ESTABLISHED UNDER § 3A–404(B) OF THIS TITLE; AND 25 (3) (4) EACH YEAR, IN ACCORDANCE WITH § 2–1257 OF THE STATE 26 GOVERNMENT ARTICLE, REPORT ITS FINDINGS AND RECOMMENDATIONS TO THE 27 SENATE BUDGET AND TAXATION COMMITTEE, THE SENATE EDUCATION, HEALTH, 28 AND ENVIRONMENTAL AFFAIRS COMMITTEE, THE HOUSE APPROPRIATIONS 29 COMMITTEE, THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE, 30 AND THE JOINT COMMITTEE ON CYBERSECURITY , INFORMATION TECHNOLOGY , 31 AND BIOTECHNOLOGY . 32 14 HOUSE BILL 1205 (G) THE REPORT SUBMITTED UNDER SUBSECTION (F)(4) OF THIS SECTION 1 MAY NOT CONTAIN INFO RMATION ABOUT THE SE CURITY OF AN INFORMATION 2 SYSTEM. 3 3A–316. 4 (A) THIS SECTION DOES NOT APPLY TO: 5 (1) THE MARYLAND PORT ADMINISTRATION ; 6 (2) THE UNIVERSITY SYSTEM OF MARYLAND; 7 (3) ST. MARY’S COLLEGE OF MARYLAND; 8 (4) MORGAN STATE UNIVERSITY; 9 (5) THE MARYLAND STADIUM AUTHORITY; 10 (6) BALTIMORE CITY COMMUNITY COLLEGE; OR 11 (7) THE STATE BOARD OF ELECTIONS.; 12 (8) THE OFFICE OF THE ATTORNEY GENERAL; 13 (9) THE COMPTROLLER ; OR 14 (10) THE STATE TREASURER. 15 (A) (B) (1) THE DEPARTMENT SHALL HIRE AN INDEPENDENT 16 CONTRACTOR CONTRACTORS TO: 17 (I) DEVELOP A FRAMEWORK FOR INVESTMENTS IN 18 TECHNOLOGY ; AND 19 (II) AT LEAST ONCE EVERY 3 2 YEARS, IN ACCORDANCE WITH 20 THE FRAMEWORK , ANNUALLY ASSESS THE CYBERSECU RITY AND INFORMATION 21 TECHNOLOGY SYSTEMS I N EACH UNIT OF STATE GOVERNMENT . 22 (2) THE FRAMEWORK SHALL I NCLUDE THE FOLLOWING CRITERIA: 23 (I) SECURITY RISKS TO TH E SYSTEM; 24 (II) SYSTEM PERFORMANCE ; 25 HOUSE BILL 1205 15 (III) THE SYSTEM ’S DEPENDENCE ON OTHE R INFORMATION 1 TECHNOLOGY OR CYBERS ECURITY SYSTEMS AND DATA; 2 (IV) THE SYSTEM ’S ABILITY TO CREATE AN EFFICIENT AND 3 SEAMLESS EXPERIENCE FOR USERS; 4 (V) THE SYSTEM ’S EFFECTIVENESS IN A CHIEVING UNIT 5 OBJECTIVES; 6 (VI) THE SYSTEM’S EFFECTIVENESS IN M EETING THE NEEDS OF 7 CITIZENS AND CUSTOME RS; 8 (VII) THE COSTS TO MAINTAI N AND OPERATE THE SY STEM; 9 (VIII) THE SPEED OF GOVERNM ENT RESPONSE TIME ; 10 (IX) THE EFFECTIVENESS OF THE SYSTEM IN REGARD TO THE 11 UNIT’S OBJECTIVES; 12 (X) IMPROVEMENTS TO THE UNIT’S RELATIVE AUDIT FIN DINGS 13 ATTRIBUTABLE TO THE SYSTEM; AND 14 (XI) AN ASSESSMENT OF THE SYSTEM USING THE NATIONAL 15 INSTITUTE OF STANDARDS AND TECHNOLOGY CYBERSECURITY FRAMEWORK . 16 (B) (C) EACH UNIT SHALL PROMP TLY PROVIDE THE CONTRACTOR A 17 CONTRACTOR EMPLOYED UNDER SUBSECTION (B) OF THIS SECTION WITH THE 18 INFORMATION NECESSAR Y TO PERFORM THE ASS ESSMENTS. 19 (C) (D) (1) EACH YEAR, THE EVERY 3 2 YEARS, A CONTRACTOR SHALL 20 PROVIDE THE RESULTS OF THE ASSESSMENTS T O: 21 (I) THE STATEWIDE REPORTING FRAMEWORK AND 22 OVERSIGHT MODERNIZE MARYLAND COMMISSION ESTABLISHE D UNDER § 3A–315 23 OF THIS SUBTITLE; AND 24 (II) IN ACCORDANCE WITH § 2–1257 OF THE STATE 25 GOVERNMENT ARTICLE, THE SENATE BUDGET AND TAXATION COMMITTEE, THE 26 SENATE EDUCATION, HEALTH, AND ENVIRONMENTAL AFFAIRS COMMITTEE, AND 27 THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE. 28 (2) THE REPORT SUBMITTED UNDER PARAGRAPH (1)(II) OF THIS 29 SUBSECTION MAY NOT C ONTAIN INFORMATION A BOUT THE SECURITY OF AN 30 INFORMATION SYSTEM . 31 16 HOUSE BILL 1205 (D) (E) THE DEPARTMENT MAY USE FUNDS AVAILABLE FROM THE 1 ISSUANCE OF BONDS IN ACCORDANCE WITH § 10–650.1 OF THE ECONOMIC 2 DEVELOPMENT ARTICLE TO PAY FOR TH E INDEPENDENT CONTRA CTOR REQUIRED 3 UNDER MULTIPLE CONTRACTORS AT A TIME TO MEET TH E REQUIREMENTS OF THIS 4 SECTION. 5 3A–317. 6 (A) THE DEPARTMENT SHALL CONS ULT WITH THE MARYLAND STADIUM 7 AUTHORITY REGARDING T HE ISSUANCE OF BONDS FOR UPGRADES TO 8 INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 9 INFRASTRUCTURE IN AC CORDANCE WITH § 10–650.1 OF THE ECONOMIC 10 DEVELOPMENT ARTICLE. 11 (B) THE DEPARTMENT MAY USE TH E PROCEEDS FROM BONDS ISSUED FOR 12 UPGRADES TO INFORMAT ION TECHNOLOGY AND C YBERSECURITY –RELATED STATE 13 GOVERNMENT INFRASTRU CTURE UNDER § 10–650.1 OF THE ECONOMIC 14 DEVELOPMENT ARTICLE ONLY FOR PROJ ECTS THAT RELATE TO RESEARCH INTO , 15 ACQUISITION OF , INSTALLATION OF , MAINTENANCE OF, AND RELATED EXPENSES 16 FOR UPGRADES TO INFO RMATION TECHNOLOGY A ND CYBERSECURITY –RELATED 17 STATE GOVERNMENT INFR ASTRUCTURE . 18 (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS 19 INDICATED. 20 (2) “FUND” MEANS THE LOCAL CYBERSECURITY SUPPORT FUND. 21 (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, 22 LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. 23 (B) (1) THERE IS A LOCAL CYBERSECURITY SUPPORT FUND. 24 (2) THE PURPOSE OF THE FUND IS TO: 25 (I) PROVIDE FINANCIAL AS SISTANCE TO LOCAL GO VERNMENTS 26 TO IMPROVE CYBERSECU RITY PREPAREDNESS , INCLUDING: 27 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 28 THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 29 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 30 SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 31 PREPAREDNESS ; 32 HOUSE BILL 1205 17 3. RECRUITING AND HIRIN G INFORMATION 1 TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND 2 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 3 STAFF TRAINING; AND 4 (II) ASSIST LOCAL GOVERNM ENTS APPLYING FOR FE DERAL 5 CYBERSECURITY PREPAR EDNESS GRANTS . 6 (3) THE SECRETARY SHALL ADMIN ISTER THE FUND. 7 (4) (I) THE FUND IS A SPECIAL, NONLAPSING FUND THAT IS NOT 8 SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE. 9 (II) THE STATE TREASURER SHALL HOLD THE FUND 10 SEPARATELY, AND THE COMPTROLLER SHALL ACC OUNT FOR THE FUND. 11 (5) THE FUND CONSISTS OF : 12 (I) MONEY APPROPRIATED I N THE STATE BUDGET TO THE 13 FUND; 14 (II) INTEREST EARNI NGS; AND 15 (III) ANY OTHER MONEY FROM ANY OTHER SOURCE ACC EPTED 16 FOR THE BENEFIT OF T HE FUND. 17 (6) THE FUND MAY BE USED ONLY : 18 (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL 19 GOVERNMENTS TO IMPRO VE CYBERSECURITY PRE PAREDNESS, INCLUDING: 20 1. UPDATING CURRENT DEVICES A ND NETWORKS WITH 21 THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 22 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 23 SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 24 PREPAREDNESS ; 25 3. RECRUITING AND HIRIN G INFORMATION 26 TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND 27 18 HOUSE BILL 1205 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 1 STAFF TRAINING ; 2 (II) TO ASSIST LOCAL GOVE RNMENTS APPLYING FOR FEDERAL 3 CYBERSECURITY PREPAR EDNESS GRANTS ; AND 4 (III) FOR ADMINISTRATIVE E XPENSES ASSOCIAT ED WITH 5 PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH . 6 (7) (I) THE STATE TREASURER SHALL INVES T THE MONEY OF THE 7 FUND IN THE SAME MANN ER AS OTHER STATE MONEY MAY BE IN VESTED. 8 (II) ANY INTEREST EARNINGS OF THE FUND SHALL BE 9 CREDITED TO THE FUND. 10 (8) EXPENDITURES FROM THE FUND MAY BE MADE ONLY IN 11 ACCORDANCE WITH THE STATE BUDGET . 12 (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL 13 GOVERNMENT SHALL UND ERGO A CYBERSECURITY PREPAREDNESS ASSESSM ENT 14 PROVIDED BY THE DEPARTMENT AT A COST TO THE LOCAL GOVERNM ENT THAT 15 DOES NOT EXCEED THE COST TO THE DEPARTMENT OF PROVIDI NG THE 16 ASSESSMENT . 17 6–226. 18 (a) (2) (i) Notwithstanding any other provision of law, and unless 19 inconsistent with a federal law, grant agreement, or other federal requirement or with the 20 terms of a gift or settlement agreement, net interest on all State money allocated by the 21 State Treasurer under this section to special funds or accounts, and otherwise entitled to 22 receive interest earnings, as accounted for by the Comptroller, shall accrue to the General 23 Fund of the State. 24 (ii) The provisions of subparagraph (i) of this paragraph do not apply 25 to the following funds: 26 144. the Health Equity Resource Community Reserve Fund; 27 [and] 28 145. the Access to Counsel in Evictions Special Fund; AND 29 146. THE INFORMATION TECHNOLOGY AND LOCAL 30 CYBERSECURITY INFRASTRUCTURE SUPPORT FUND. 31 11–101. 32 HOUSE BILL 1205 19 (a) In this Division II the following words have the meanings indicated unless: 1 (1) the context clearly requires a different meaning; or 2 (2) a different definition is provided for a particular title or provision. 3 (m) “Primary procurement units” means: 4 (1) the State Treasurer; 5 (2) the Department of General Services; 6 (3) the Department of Transportation; 7 (4) the University System of Maryland; 8 (5) the Maryland Port Commission; 9 (6) the Morgan State University; [and] 10 (7) the St. Mary’s College of Maryland; AND 11 (8) THE DEPARTMENT OF INFORMATION TECHNOLOGY . 12 12–101. 13 (a) This section does not apply to: 14 (1) capital expenditures by the Department of Transportation or the 15 Maryland Transportation Authority, in connection with State roads, bridges, or highways, 16 as provided in § 12–202 of this title; OR 17 (2) PROCUREMENTS BY THE DEPARTMENT OF INFORMATION 18 TECHNOLOGY GENERAL SERVICES FOR THE PURPOSE OF M ODERNIZING 19 CYBERSECURITY INFRAS TRUCTURE FOR THE STATE VALUED BELOW $1,000,000. 20 (b) (1) The Board may control procurement by units. 21 (2) To implement the provisions of this Division II, the Board may: 22 (i) set policy; 23 (ii) adopt regulations, in accordance with Title 10, Subtitle 1 of the 24 State Government Article; and 25 20 HOUSE BILL 1205 (iii) establish internal operational procedures consistent with this 1 Division II. 2 (3) The Board shall ensure that the regulations of the primary 3 procurement units provide for procedures that are consistent with this Division II and Title 4 13, Subtitle 4 of the State Personnel and Pensions Article and, to the extent the 5 circumstances of a particular type of procurement or a particular unit do not require 6 otherwise, are substantially the same. 7 (4) The Board may delegate any of its authority that it determines to be 8 appropriate for delegation and may require prior Board approval for specified procurement 9 actions. 10 (5) Except as limited by the Maryland Constitution, the Board may 11 exercise any control authority conferred on a primary procurement unit by this Division II 12 and, to the extent that its action conflicts with the action of the primary procurement unit, 13 the action of the Board shall prevail. 14 (6) The Board shall develop and submit to the General Assembly, in 15 accordance with § 2–1257 of the State Government Article, an annual report on the 16 procurement system that includes information on actions necessary to improve effective 17 broad–based competition in procurement. 18 (C) ON OR BEFORE DECEMBER 1 EACH YEAR, THE DEPARTMENT OF 19 INFORMATION TECHNOLOGY GENERAL SERVICES SHALL SUBMIT A REPOR T TO THE 20 BOARD ON PROCUREMENTS MADE UNDER S UBSECTION (A)(2) OF THIS SECTION 21 THAT SHALL INCLUDE F OR EACH PROCUREMENT : 22 (1) THE PURPOSE OF THE P ROCUREMENT ; 23 (2) THE NAME OF THE CONT RACTOR; 24 (3) THE CONTRACT AMOUNT ; AND 25 (4) THE METHOD OF PROCUR EMENT UTILIZED ; 26 (5) THE NUMBER OF BIDDER S WHO BID ON THE PROCU REMENT; AND 27 (4) (6) THE CONTRACT TERM . 28 12–107. 29 (b) Subject to the authority of the Board, jurisdiction over procurement is as 30 follows: 31 (2) the Department of General Services may: 32 HOUSE BILL 1205 21 (i) engage in or control procurement of: 1 8. construction and construction–related services for State 2 correctional facilities; AND 3 9. supplies, materials, and equipment in support of 4 construction and construction–related services for State correctional facilities in 5 accordance with this Division II and Title 2 and Title 10, Subtitle 1 of the Correctional 6 Services Article; AND 7 10. [information processing equipment and associated 8 services, as provided in Title 3A, Subtitle 3 of this article; and 9 11.] telecommunication equipment, systems, or services, as 10 provided in Title 3A, Subtitle 4 of this article; 11 (3) the Department of Transportation and the Maryland Transportation 12 Authority, without the approval of any of the other primary procurement units, may engage 13 in the procurement of: 14 (vi) services for aeronautics related activities, including information 15 processing services, but excluding banking and financial services under the authority of the 16 State Treasurer under item (1) of this subsection; [and] 17 (4) the Maryland Port Commission, without the approval of any of the 18 other primary procurement units, may engage in the procurement of: 19 (v) leases of real property for port related activities unless the lease 20 payments are from the General Fund of the State; AND 21 (5) THE DEPARTMENT OF INFORMATION TECHNOLOGY GENERAL 22 SERVICES, WITHOUT THE APPROVAL OF ANY OTHER PRIMARY PROCUREMENT UNIT , 23 MAY ENGAGE IN OR CON TROL PROCUREMENT OF : 24 (I) INFORMATION PROCESSI NG EQUIPMENT , CLOUD 25 COMPUTING EQUIPMENT , AND ASSOCIATED SERVI CES, AS PROVIDED IN TITLE 3A, 26 SUBTITLE 3 OF THIS ARTICLE; AND 27 (II) INFORMATION TECHNOLO GY SYSTEM AND 28 MODERNIZATION , AS PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE; 29 (III) TELECOMMUNICATION EQ UIPMENT, SYSTEMS, OR 30 SERVICES, AS PROVIDED IN TITLE 3A, SUBTITLE 4 OF THIS ARTICLE; AND 31 22 HOUSE BILL 1205 (IV) CYBERSECURITY UPGRAD ES AND MODERNIZATION , AS 1 PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE . 2 15–112. 3 (a) (1) (i) Except as provided in subparagraph (ii) of this paragraph, this 4 section applies to State procurement contracts for: 5 1. construction; 6 2. INFORMATION PROCESSI NG EQUIPMENT , CLOUD 7 COMPUTING EQUIPMENT SERVICES, AND ASSOCIATED SERVI CES; AND 8 3. IN ACCORDANCE WITH TITLE 3A, SUBTITLE 3 OF THIS 9 ARTICLE, INFORMATION TECHNOLOGY SYSTEM AN D CYBERSECURITY UPGR ADES 10 AND MODERNIZATION . 11 (b) (3) (i) If a unit is to pay for a contract or a part of a contract using a 12 unit price methodology, a change order may not be required for work to continue and be 13 completed beyond the estimated quantities in the contract. 14 (ii) After work is completed, a unit shall: 15 1. determine the actual quantity used to complete the 16 contract; and 17 2. if necessary, issue a final adjustment change order to the 18 contractor. 19 (4) AN INDEPEND ENT CONTRACTOR WHO P ERFORMS AN 20 ASSESSMENT UNDER § 3A–316 OF THIS ARTICLE MAY ISSUE A CHANGE ORDER ON 21 THE ORIGINAL ASSESSM ENT CONTRACT FOR ANY SUBSEQUENT CYBERSECU RITY 22 UPGRADES. 23 SECTION 2. AND BE IT FURTHER ENACTED, That this Act shall take effect July 24 1, 2022. 25 SECTION 2. AND BE IT FURTHER ENACTED, That for fiscal year 2023, funds 26 from the Dedicated Purpose Account may be transferred by budget amendment in 27 accordance with § 7–310 of the State Finance and Procurement Article to implement this 28 Act. 29 SECTION 3. AND BE IT FURTHER ENACTED, That for fiscal year 2024, the 30 Governor shall include in the annual budget bill an appropriation in an amount that is not 31 less than 20% of the aggregated amount appropriated for information technology and 32 HOUSE BILL 1205 23 cybersecurity resources in the annual budget bill for fiscal year 2023 for the Dedicated 1 Purpose Account for cybersecurity. 2 SECTION 4. AND BE IT FURTHER ENACTED, That: 3 (a) On or before December 1, 2023, a public or private water or sewer system that 4 serves 10,000 or more users and receives financial assistance from the State shall: 5 (1) assess its vulnerability to a cyber attack; 6 (2) if appropriate, develop a cybersecurity plan; and 7 (3) submit a report to the General Assembly, in accordance with § 2–1257 of 8 the State Government Article, on the findings of the assessment conducted under this 9 subsection and any recommendations for statutory changes needed for the system to 10 appropriately address its cybersecurity. 11 (b) The Maryland Water Quality Financing Administration may provide financial 12 assistance to a public water or wastewater system to assess system cybersecurity 13 vulnerabilities and develop a cybersecurity plan. 14 SECTION 4. 5. AND BE IT FURTHER ENACTED, That this Act is an emergency 15 measure, is necessary for the immediate preservation of the public health or safety, has been 16 passed by a yea and nay vote supported by three–fifths of all the members elected to each of 17 the two Houses of the General Assembly, and shall take effect from the date it is enacted. 18 Approved: ________________________________________________________________________________ Governor. ________________________________________________________________________________ Speaker of the House of Delegates. ________________________________________________________________________________ President of the Senate.