Old | New | Differences | |
---|---|---|---|
1 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
2 | 1 | ||
3 | - | – 1 – | |
4 | - | Chapter 243 | |
5 | - | (House Bill 1205) | |
6 | 2 | ||
7 | - | AN ACT concerning | |
3 | + | EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW. | |
4 | + | [Brackets] indicate matter deleted from existing law. | |
5 | + | Underlining indicates amendments to bill. | |
6 | + | Strike out indicates matter stricken from the bill by amendment or deleted from the law by | |
7 | + | amendment. | |
8 | + | Italics indicate opposite chamber/conference committee amendments. | |
9 | + | *hb1205* | |
8 | 10 | ||
9 | - | State Government – Information Technology and Cybersecurity –Related | |
10 | - | Infrastructure | |
11 | - | (Modernize Maryland Act of 2022) | |
11 | + | HOUSE BILL 1205 | |
12 | + | S2, P1, S1 EMERGENCY BILL (2lr1777) | |
13 | + | ENROLLED BILL | |
14 | + | — Health and Government Operations and Appropriations/Budget and Taxation — | |
15 | + | Introduced by Delegates P. Young, Kerr, Feldmark, Bartlett, Kelly, Kipke, and | |
16 | + | McIntosh McIntosh, Bagnall, Bhandari, Carr, Chisholm, Cullison, Hill, | |
17 | + | Johnson, Kaiser, Landis, R. Lewis, Morgan, Pena–Melnyk, Pendergrass, | |
18 | + | Reilly, Rosenberg, Saab, Sample–Hughes, Szeliga, and K. Young | |
12 | 19 | ||
13 | - | FOR the purpose of requiring a certain water or sewer system to, on or before a certain date, | |
14 | - | assess its vulnerability to a cyber attack, develop a cybersecurity plan if appropriate, | |
15 | - | and submit a certain report to the General Assembly; authorizing the Maryland Water | |
16 | - | Quality Financing Administration to provide financial assistance to a public water | |
17 | - | or wastewater system to assess system cybersecurity vulnerabilities and develop a | |
18 | - | cybersecurity plan; authorizing the Maryland Stadium Authority to issue bonds and, | |
19 | - | in consultation with the Department of Information Technology, finance projects | |
20 | - | related to information technology and cybersecurity–related State government | |
21 | - | infrastructure; establishing an Information Technology and Cybersecurity | |
22 | - | Infrastructure establishing the Local Cybersecurity Support Fund as a special, | |
23 | - | nonlapsing fund; requiring interest earnings of the Fund to be credited to the Fund; | |
24 | - | establishing certain eligibility requirements to receive assistance from the Fund; | |
25 | - | altering the duties of the Secretary of Information Technology; establishing a | |
26 | - | Statewide Reporting Framework and an independent Modernize Maryland | |
27 | - | Oversight Commission in the Department of Information Technology; requiring the | |
28 | - | Department to hire an independent contractor contractors to develop a framework | |
29 | - | for investments in technology and annually periodically assess the cybersecurity and | |
30 | - | information technology systems in each unit certain units of State government; | |
31 | - | specifying the use of proceeds from certain bonds; exempting certain procurements | |
32 | - | by the Department of General Services from oversight by the Board of Public Works; | |
33 | - | establishing that the Department is a primary procurement unit and authorizing the | |
34 | - | Department to engage in or control certain procurements; authorizing a certain | |
35 | - | independent contractor to issue a certain change order applying certain change order | |
36 | - | requirements to State procurement contracts for certain equipment, services, and | |
37 | - | upgrades; authorizing funds to be transferred by budget amendment from the | |
38 | - | Dedicated Purpose Account in a certain fiscal year to implement this Act; and | |
39 | - | generally relating to the development, financing, and procurement of information | |
40 | - | technology and cybersecurity–related State government infrastructure projects. | |
20 | + | Read and Examined by Proofreaders: | |
41 | 21 | ||
42 | - | BY repealing and reenacting, with amendments, | |
43 | - | Article – Environment | |
44 | - | Section 9–1604(c) | |
45 | - | Annotated Code of Maryland | |
46 | - | (2014 Replacement Volume and 2021 Supplement) | |
22 | + | _______________________________________________ | |
23 | + | Proofreader. | |
24 | + | _______________________________________________ | |
25 | + | Proofreader. | |
47 | 26 | ||
48 | - | BY adding to | |
49 | - | Article – Public Safety Ch. 243 2022 LAWS OF MARYLAND | |
27 | + | Sealed with the Great Seal and presented to the Governor, for his approval this | |
50 | 28 | ||
51 | - | – 2 – | |
52 | - | Section 14–104.1 | |
53 | - | Annotated Code of Maryland | |
54 | - | (2018 Replacement Volume and 2021 Supplement) | |
29 | + | _______ day of _______________ at ________________________ o’clock, ________M. | |
55 | 30 | ||
56 | - | BY repealing and reenacting, with amendments, | |
57 | - | Article – Economic Development | |
58 | - | Section 10–628(a) | |
59 | - | Annotated Code of Maryland | |
60 | - | (2018 Replacement Volume and 2021 Supplement) | |
31 | + | ______________________________________________ | |
32 | + | Speaker. | |
61 | 33 | ||
62 | - | BY adding to | |
63 | - | Article – Economic Development | |
64 | - | Section 10–628(d), 10–650.1, and 10–657.5 | |
65 | - | Annotated Code of Maryland | |
66 | - | (2018 Replacement Volume and 2021 Supplement) | |
34 | + | CHAPTER ______ | |
67 | 35 | ||
68 | - | BY repealing and reenacting, with amendments, | |
69 | - | Article – State Finance and Procurement | |
70 | - | Section 3A–101, 3A–303(a)(7) and (8), 6–226(a)(2)(ii)144. and 145., 11–101(m), | |
71 | - | 12–101, 12–107(b)(2)(i)9. through 11. 12–107(b)(2)(i)8., (3)(vi), and (4)(v), and | |
72 | - | 12–107(b)(3)(vi) and (4)(v), and 15–112(a)(1)(i) | |
73 | - | Annotated Code of Maryland | |
74 | - | (2021 Replacement Volume) | |
36 | + | AN ACT concerning 1 | |
75 | 37 | ||
76 | - | BY adding to | |
77 | - | Article – State Finance and Procurement | |
78 | - | Section 3A–303(a)(9) and (10), 3A–315 through 3A–317, 3A–316, 6–226(a)(2)(ii)146., | |
79 | - | 12–107(b)(5), and and 12–107(b)(5) 15–112(b)(4) | |
80 | - | Annotated Code of Maryland | |
81 | - | (2021 Replacement Volume) | |
38 | + | State Government – Information Technology and Cybersecurity –Related 2 | |
39 | + | Infrastructure 3 | |
40 | + | (Modernize Maryland Act of 2022) 4 | |
82 | 41 | ||
83 | - | BY repealing and reenacting, without amendments, | |
84 | - | Article – State Finance and Procurement | |
85 | - | Section 6–226(a)(2)(i), 11–101(a), and 15–112(b)(3) 11–101(a), and 12–107(b)(2)(i)9. | |
86 | - | Annotated Code of Maryland | |
87 | - | (2021 Replacement Volume) | |
42 | + | FOR the purpose of requiring a certain water or sewer system to, on or before a certain date, 5 | |
43 | + | assess its vulnerability to a cyber attack, develop a cybersecurity plan if appropriate, 6 | |
44 | + | and submit a certain report to the General Assembly; authorizing the Maryland Water 7 | |
45 | + | Quality Financing Administration to provide financial assistance to a public water 8 | |
46 | + | or wastewater system to assess system cybersecurity vulnerabilities and develop a 9 | |
47 | + | cybersecurity plan; authorizing the Maryland Stadium Authority to issue bonds and, 10 | |
48 | + | in consultation with the Department of Information Technology, finance projects 11 | |
49 | + | related to information technology and cybersecurity–related State government 12 2 HOUSE BILL 1205 | |
88 | 50 | ||
89 | - | BY repealing | |
90 | - | Article – State Finance and Procurement | |
91 | - | Section 12–107(b)(2)(i)10. and 11. | |
92 | - | Annotated Code of Maryland | |
93 | - | (2021 Replacement Volume) | |
94 | 51 | ||
95 | - | SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, | |
96 | - | That the Laws of Maryland read as follows: | |
97 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
52 | + | infrastructure; establishing an Information Technology and C ybersecurity 1 | |
53 | + | Infrastructure establishing the Local Cybersecurity Support Fund as a special, 2 | |
54 | + | nonlapsing fund; requiring interest earnings of the Fund to be credited to the Fund; 3 | |
55 | + | establishing certain eligibility requirements to receive assistance from the Fund; 4 | |
56 | + | altering the duties of the Secretary of Information Technology; establishing a 5 | |
57 | + | Statewide Reporting Framework and an independent Modernize Maryland 6 | |
58 | + | Oversight Commission in the Department of Information Technology; requiring the 7 | |
59 | + | Department to hire an independent contractor contractors to develop a framework 8 | |
60 | + | for investments in technology and annually periodically assess the cybersecurity and 9 | |
61 | + | information technology systems in each unit certain units of State government; 10 | |
62 | + | specifying the use of proceeds from certain bonds; exempting certain procurements 11 | |
63 | + | by the Department of General Services from oversight by the Board of Public Works; 12 | |
64 | + | establishing that the Department is a primary procurement unit and authorizing the 13 | |
65 | + | Department to engage in or control certain procurements; authorizing a certain 14 | |
66 | + | independent contractor to issue a certain change order applying certain change order 15 | |
67 | + | requirements to State procurement contracts for certain equipment, services, and 16 | |
68 | + | upgrades; authorizing funds to be transferred by budget amendment from the 17 | |
69 | + | Dedicated Purpose Account in a certain fiscal year to implement this Act; and 18 | |
70 | + | generally relating to the development, financing, and procurement of information 19 | |
71 | + | technology and cybersecurity–related State government infrastructure projects. 20 | |
98 | 72 | ||
99 | - | – 3 – | |
100 | - | Article – Environment | |
73 | + | BY repealing and reenacting, with amendments, 21 | |
74 | + | Article – Environment 22 | |
75 | + | Section 9–1604(c) 23 | |
76 | + | Annotated Code of Maryland 24 | |
77 | + | (2014 Replacement Volume and 2021 Supplement) 25 | |
101 | 78 | ||
102 | - | 9–1604. | |
79 | + | BY adding to 26 | |
80 | + | Article – Public Safety 27 | |
81 | + | Section 14–104.1 28 | |
82 | + | Annotated Code of Maryland 29 | |
83 | + | (2018 Replacement Volume and 2021 Supplement) 30 | |
103 | 84 | ||
104 | - | (c) (1) This subsection applies to financial assistance provided by the | |
105 | - | Administration under: | |
85 | + | BY repealing and reenacting, with amendments, 31 | |
86 | + | Article – Economic Development 32 | |
87 | + | Section 10–628(a) 33 | |
88 | + | Annotated Code of Maryland 34 | |
89 | + | (2018 Replacement Volume and 2021 Supplement) 35 | |
106 | 90 | ||
107 | - | (i) The Water Quality Fund; | |
91 | + | BY adding to 36 | |
92 | + | Article – Economic Development 37 | |
93 | + | Section 10–628(d), 10–650.1, and 10–657.5 38 | |
94 | + | Annotated Code of Maryland 39 | |
95 | + | (2018 Replacement Volume and 2021 Supplement) 40 | |
108 | 96 | ||
109 | - | (ii) The Bay Restoration Fund; | |
97 | + | BY repealing and reenacting, with amendments, 41 | |
98 | + | Article – State Finance and Procurement 42 HOUSE BILL 1205 3 | |
110 | 99 | ||
111 | - | (iii) The Biological Nutrient Removal Program; and | |
112 | 100 | ||
113 | - | (iv) The Supplemental Assistance Program. | |
101 | + | Section 3A–101, 3A–303(a)(7) and (8), 6–226(a)(2)(ii)144. and 145., 11–101(m), 1 | |
102 | + | 12–101, 12–107(b)(2)(i)9. through 11. 12–107(b)(2)(i)8., (3)(vi), and (4)(v), and 2 | |
103 | + | 12–107(b)(3)(vi) and (4)(v), and 15–112(a)(1)(i) 3 | |
104 | + | Annotated Code of Maryland 4 | |
105 | + | (2021 Replacement Volume) 5 | |
114 | 106 | ||
115 | - | (2) The Administration shall ensure the fair and equitable distribution of | |
116 | - | financial assistance among wastewater treatment facilities with a design capacity of less | |
117 | - | than 500,000 gallons per day and wastewater treatment facilities with a design capacity of | |
118 | - | 500,000 gallons or more per day. | |
107 | + | BY adding to 6 | |
108 | + | Article – State Finance and Procurement 7 | |
109 | + | Section 3A–303(a)(9) and (10), 3A–315 through 3A–317, 3A–316, 6–226(a)(2)(ii)146., 8 | |
110 | + | 12–107(b)(5), and and 12–107(b)(5) 15–112(b)(4) 9 | |
111 | + | Annotated Code of Maryland 10 | |
112 | + | (2021 Replacement Volume) 11 | |
119 | 113 | ||
120 | - | (3) A PUBLIC OR PRIVATE WA TER OR SEWER SYSTEM THAT SERVES | |
121 | - | 10,000 OR MORE USERS AND RE CEIVES FINANCIAL ASS ISTANCE FROM THE STATE | |
122 | - | SHALL: | |
114 | + | BY repealing and reenacting, without amendments, 12 | |
115 | + | Article – State Finance and Procurement 13 | |
116 | + | Section 6–226(a)(2)(i), 11–101(a), and 15–112(b)(3) 11–101(a), and 12–107(b)(2)(i)9. 14 | |
117 | + | Annotated Code of Maryland 15 | |
118 | + | (2021 Replacement Volume) 16 | |
123 | 119 | ||
124 | - | (I) ASSESS ITS VULNERABIL ITY TO A CYBER ATTAC K; AND | |
120 | + | BY repealing 17 | |
121 | + | Article – State Finance and Procurement 18 | |
122 | + | Section 12–107(b)(2)(i)10. and 11. 19 | |
123 | + | Annotated Code of Maryland 20 | |
124 | + | (2021 Replacement Volume) 21 | |
125 | 125 | ||
126 | - | (II) IF APPROPRIATE , DEVELOP A CYBERSECUR ITY PLAN. | |
126 | + | SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 22 | |
127 | + | That the Laws of Maryland read as follows: 23 | |
127 | 128 | ||
128 | - | (4) THE ADMINISTRATION MAY PR OVIDE FINANCIAL ASSI STANCE TO | |
129 | - | A PUBLIC WATER OR WA STEWATER SYSTEM TO A SSESS SYSTEM CYBERSE CURITY | |
130 | - | VULNERABILITIES AND DEVELOP A CYBERSECUR ITY PLAN. | |
129 | + | Article – Environment 24 | |
131 | 130 | ||
132 | - | ||
131 | + | 9–1604. 25 | |
133 | 132 | ||
134 | - | 14–104.1. | |
133 | + | (c) (1) This subsection applies to financial assistance provided by the 26 | |
134 | + | Administration under: 27 | |
135 | 135 | ||
136 | - | (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS | |
137 | - | INDICATED. | |
136 | + | (i) The Water Quality Fund; 28 | |
138 | 137 | ||
139 | - | ( | |
138 | + | (ii) The Bay Restoration Fund; 29 | |
140 | 139 | ||
141 | - | (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, | |
142 | - | LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. | |
140 | + | (iii) The Biological Nutrient Removal Program; and 30 | |
143 | 141 | ||
144 | - | ( | |
142 | + | (iv) The Supplemental Assistance Program. 31 | |
145 | 143 | ||
146 | - | – 4 – | |
144 | + | (2) The Administration shall ensure the fair and equitable distribution of 32 | |
145 | + | financial assistance among wastewater treatment facilities with a design capacity of less 33 | |
146 | + | than 500,000 gallons per day and wastewater treatment facilities with a design capacity of 34 | |
147 | + | 500,000 gallons or more per day. 35 4 HOUSE BILL 1205 | |
147 | 148 | ||
148 | - | (2) THE PURPOSE OF THE FUND IS TO: | |
149 | 149 | ||
150 | - | (I) PROVIDE FINANCIAL AS SISTANCE TO LOCAL GO VERNMENTS | |
151 | - | TO IMPROVE CYBERSECU RITY PREPAREDNESS , INCLUDING: | |
152 | 150 | ||
153 | - | 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH | |
154 | - | THE MOST UP–TO–DATE CYBERSE CURITY PROTECTIONS ; | |
151 | + | (3) A PUBLIC OR PRIVATE WA TER OR SEWER SYSTEM THAT SERVES 1 | |
152 | + | 10,000 OR MORE USERS AND RE CEIVES FINANCIAL ASS ISTANCE FROM THE STATE 2 | |
153 | + | SHALL: 3 | |
155 | 154 | ||
156 | - | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , | |
157 | - | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY | |
158 | - | PREPAREDNESS ; | |
155 | + | (I) ASSESS ITS VULNERABIL ITY TO A CYBER ATTAC K; AND 4 | |
159 | 156 | ||
160 | - | 3. RECRUITING AND HIRIN G INFORMATION | |
161 | - | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; | |
157 | + | (II) IF APPROPRIATE , DEVELOP A CYBERSECUR ITY PLAN. 5 | |
162 | 158 | ||
163 | - | 4. PAYING OUTSIDE VENDORS FOR CYBERSEC URITY | |
164 | - | STAFF TRAINING ; | |
159 | + | (4) THE ADMINISTRATION MAY PR OVIDE FINANCIAL ASSI STANCE TO 6 | |
160 | + | A PUBLIC WATER OR WA STEWATER SYSTEM TO A SSESS SYSTEM CYBERSE CURITY 7 | |
161 | + | VULNERABILITIES AND DEVELOP A CYBERSECUR ITY PLAN. 8 | |
165 | 162 | ||
166 | - | 5. CONDUCTING CYBERSECU RITY VULNERABILITY | |
167 | - | ASSESSMENTS ; | |
163 | + | Article – Public Safety 9 | |
168 | 164 | ||
169 | - | 6. ADDRESSING HIGH –RISK CYBERSECURITY | |
170 | - | VULNERABILITIES IDEN TIFIED BY VULNERABIL ITY ASSESSMENTS ; | |
165 | + | 14–104.1. 10 | |
171 | 166 | ||
172 | - | 7. IMPLEMENTING AND MAI NTAINING INTEGRATORS | |
173 | - | AND OTHER SIMILAR INTELL IGENCE SHARING INFRA STRUCTURE THAT ENABL E | |
174 | - | CONNECTION WITH THE INFORMATION SHARING AND ANALYSIS CENTER IN THE | |
175 | - | DEPARTMENT OF INFORMATION TECHNOLOGY ; AND | |
167 | + | (A) (1) IN THIS SECTION THE FOLLOWING WORDS HAVE THE MEANINGS 11 | |
168 | + | INDICATED. 12 | |
176 | 169 | ||
177 | - | 8. SUPPORTING THE SECUR ITY OF LOCAL WASTEWA TER | |
178 | - | TREATMENT PLANTS , INCLUDING BICOUNTY, COUNTY, AND MUNICIPAL PLANTS , BY | |
179 | - | ACQUIRING OR IMPLEME NTING CYBERSECURITY –RELATED UPGRADES TO THE | |
180 | - | PLANTS; AND | |
170 | + | (2) “FUND” MEANS THE LOCAL CYBERSECURITY SUPPORT FUND. 13 | |
181 | 171 | ||
182 | - | ( | |
183 | - | ||
172 | + | (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, 14 | |
173 | + | LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. 15 | |
184 | 174 | ||
185 | - | ( | |
175 | + | (B) (1) THERE IS A LOCAL CYBERSECURITY SUPPORT FUND. 16 | |
186 | 176 | ||
187 | - | (4) (I) THE FUND IS A SPECIAL, NONLAPSING FUND THAT IS NOT | |
188 | - | SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE. | |
189 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
177 | + | (2) THE PURPOSE OF THE FUND IS TO: 17 | |
190 | 178 | ||
191 | - | – 5 – | |
192 | - | (II) THE STATE TREASURER SHALL HOLD THE FUND | |
193 | - | SEPARATELY, AND THE COMPTROLLER SHALL ACC OUNT FOR THE FUND. | |
179 | + | (I) PROVIDE FINANCIAL AS SISTANCE TO LOCAL GO VERNMENTS 18 | |
180 | + | TO IMPROVE CYBERSECU RITY PREPAREDNESS , INCLUDING: 19 | |
194 | 181 | ||
195 | - | (5) THE FUND CONSISTS OF: | |
182 | + | 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 20 | |
183 | + | THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 21 | |
196 | 184 | ||
197 | - | (I) MONEY APPROPRIATED I N THE STATE BUDGET TO THE | |
198 | - | FUND; | |
185 | + | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 22 | |
186 | + | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 23 | |
187 | + | PREPAREDNESS ; 24 | |
199 | 188 | ||
200 | - | (II) INTEREST EARNINGS ; AND | |
189 | + | 3. RECRUITING AND HIRIN G INFORMATION 25 | |
190 | + | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; 26 | |
201 | 191 | ||
202 | - | | |
203 | - | ||
192 | + | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 27 | |
193 | + | STAFF TRAINING ; 28 HOUSE BILL 1205 5 | |
204 | 194 | ||
205 | - | (6) THE FUND MAY BE USED ONLY : | |
206 | 195 | ||
207 | - | (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL | |
208 | - | GOVERNMENTS TO IMPRO VE CYBERSECURITY PRE PAREDNESS, INCLUDING: | |
209 | 196 | ||
210 | - | 1 | |
211 | - | ||
197 | + | 5. CONDUCTING CYBERSECU RITY VULNERABILITY 1 | |
198 | + | ASSESSMENTS ; 2 | |
212 | 199 | ||
213 | - | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , | |
214 | - | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY | |
215 | - | PREPAREDNESS ; | |
200 | + | 6. ADDRESSING HIGH –RISK CYBERSECURITY 3 | |
201 | + | VULNERABILITIES IDEN TIFIED BY VULNERABIL ITY ASSESSMENTS ; 4 | |
216 | 202 | ||
217 | - | 3. RECRUITING AND HIRIN G INFORMATION | |
218 | - | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; | |
203 | + | 7. IMPLEMENTING AND MAI NTAINING INTEGRATORS 5 | |
204 | + | AND OTHER SIMILAR IN TELLIGENCE SHARING INFRASTRUC TURE THAT ENABLE 6 | |
205 | + | CONNECTION WITH THE INFORMATION SHARING AND ANALYSIS CENTER IN THE 7 | |
206 | + | DEPARTMENT OF INFORMATION TECHNOLOGY ; AND 8 | |
219 | 207 | ||
220 | - | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY | |
221 | - | STAFF TRAINING ; | |
208 | + | 8. SUPPORTING THE SECUR ITY OF LOCAL WASTEWA TER 9 | |
209 | + | TREATMENT PLANTS , INCLUDING BICOUNTY , COUNTY, AND MUNICIPA L PLANTS, BY 10 | |
210 | + | ACQUIRING OR IMPLEME NTING CYBERSECURITY –RELATED UPGRADES TO THE 11 | |
211 | + | PLANTS; AND 12 | |
222 | 212 | ||
223 | - | | |
224 | - | ||
213 | + | (II) ASSIST LOCAL GOVERNM ENTS APPLYING FOR FE DERAL 13 | |
214 | + | CYBERSECURITY PREPAR EDNESS GRANTS . 14 | |
225 | 215 | ||
226 | - | 6. ADDRESSING HIGH –RISK CYBERSECURITY | |
227 | - | VULNERABILITIES IDEN TIFIED BY VULNERABIL ITY ASSESSMENTS ; | |
216 | + | (3) THE SECRETARY SHALL ADMIN ISTER THE FUND. 15 | |
228 | 217 | ||
229 | - | 7. IMPLEMENTING OR MAIN TAINING INTEGRATORS AND | |
230 | - | OTHER SIMILAR INTELL IGENCE SHARING INFRA STRUCTURE THAT ENABL E | |
231 | - | CONNECTION WITH THE INFORMATION SHARING AND ANALYSIS CENTER IN THE | |
232 | - | DEPARTMENT OF INFORMATION TECHNOLOGY ; AND | |
218 | + | (4) (I) THE FUND IS A SPECIAL, NONLAPSING FUND THAT IS NOT 16 | |
219 | + | SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE. 17 | |
233 | 220 | ||
234 | - | | |
235 | - | ||
221 | + | (II) THE STATE TREASURER SHALL HOLD THE FUND 18 | |
222 | + | SEPARATELY, AND THE COMPTROLLER SHALL ACC OUNT FOR THE FUND. 19 | |
236 | 223 | ||
237 | - | – 6 – | |
238 | - | ACQUIRING OR IMPLEME NTING CYBERSECURITY –RELATED UPGRADES TO THE | |
239 | - | PLANTS; | |
224 | + | (5) THE FUND CONSISTS OF : 20 | |
240 | 225 | ||
241 | - | ( | |
242 | - | ||
226 | + | (I) MONEY APPROPRIATED I N THE STATE BUDGET TO THE 21 | |
227 | + | FUND; 22 | |
243 | 228 | ||
244 | - | (III) FOR ADMINISTRATIVE E XPENSES ASSOCIATED W ITH | |
245 | - | PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH. | |
229 | + | (II) INTEREST EARNINGS ; AND 23 | |
246 | 230 | ||
247 | - | ( | |
248 | - | ||
231 | + | (III) ANY OTHER MONEY FROM ANY OTHER SOURCE ACC EPTED 24 | |
232 | + | FOR THE BENEFIT OF T HE FUND. 25 | |
249 | 233 | ||
250 | - | (II) ANY INTEREST EARNINGS OF THE FUND SHALL BE | |
251 | - | CREDITED TO THE FUND. | |
234 | + | (6) THE FUND MAY BE USED ONLY : 26 | |
252 | 235 | ||
253 | - | (8) EXPENDITURES FROM THE FUND MAY BE MADE ON LY IN | |
254 | - | ACCORDANCE WITH THE STATE BUDGET. | |
236 | + | (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL 27 | |
237 | + | GOVERNMENTS TO IMPRO VE CYBERSECURITY PRE PAREDNESS, INCLUDING: 28 | |
238 | + | 6 HOUSE BILL 1205 | |
255 | 239 | ||
256 | - | (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL | |
257 | - | GOVERNMENT SHALL : | |
258 | 240 | ||
259 | - | (1) PROVIDE PROOF TO THE DEPARTMENT OF INFORMATION | |
260 | - | TECHNOLOGY THAT THE L OCAL GOVERNMENT COND UCTED A CYBERSECURIT Y | |
261 | - | PREPAREDNESS AS SESSMENT IN THE PREV IOUS 12 MONTHS; OR | |
241 | + | 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 1 | |
242 | + | THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 2 | |
262 | 243 | ||
263 | - | | |
264 | - | ||
265 | - | ||
244 | + | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 3 | |
245 | + | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 4 | |
246 | + | PREPAREDNESS ; 5 | |
266 | 247 | ||
267 | - | (I) THE DEPARTMENT OF INFORMATION TECHNOLOGY AT A | |
268 | - | COST TO THE LOCAL GOVERNMENT THAT DOES NOT EXCEED THE COST TO THE | |
269 | - | DEPARTMENT OF INFORMATION TECHNOLOGY OF PROVIDI NG THE ASSESSMENT ; OR | |
248 | + | 3. RECRUITING AND HIRIN G INFORMATION 6 | |
249 | + | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; 7 | |
270 | 250 | ||
271 | - | (II) A VENDOR AUTHORIZED BY THE DEPARTMENT OF | |
272 | - | INFORMATION TECHNOLOGY TO COMPLET E CYBERSECURITY PREP AREDNESS | |
273 | - | ASSESSMENTS . | |
251 | + | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 8 | |
252 | + | STAFF TRAINING ; 9 | |
274 | 253 | ||
275 | - | Article – Economic Development | |
254 | + | 5. CONDUCTING CYBERSECU RITY VULNE RABILITY 10 | |
255 | + | ASSESSMENTS ; 11 | |
276 | 256 | ||
277 | - | 10–628. | |
257 | + | 6. ADDRESSING HIGH –RISK CYBERSECURITY 12 | |
258 | + | VULNERABILITIES IDEN TIFIED BY VULNERABIL ITY ASSESSMENTS ; 13 | |
278 | 259 | ||
279 | - | (a) Except as provided in subsections (b) [and], (c), AND (D) of this section and | |
280 | - | subject to the prior approval of the Board of Public Works, the Authority may issue bonds LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
260 | + | 7. IMPLEMENTING OR MAIN TAINING INTEGRATORS AND 14 | |
261 | + | OTHER SIMILAR INTELL IGENCE SHARING INFRA STRUCTURE THAT ENABL E 15 | |
262 | + | CONNECTION WITH THE INFORMATION SHARING AND ANALYSIS CENTER IN THE 16 | |
263 | + | DEPARTMENT OF INFORMATION TECHNOLOGY ; AND 17 | |
281 | 264 | ||
282 | - | – 7 – | |
283 | - | at any time for any corporate purpose of the Authority, including the establishment of | |
284 | - | reserves and the payment of interest. | |
265 | + | 8. SUPPORTING THE SECUR ITY OF LOCAL WASTEWA TER 18 | |
266 | + | TREATMENT PLANTS , INCLUDING BICOUNTY , COUNTY, AND MUNICIPAL PLANTS , BY 19 | |
267 | + | ACQUIRING OR IMPLEME NTING CYBERSECURITY –RELATED UPGRADES TO THE 20 | |
268 | + | PLANTS; 21 | |
285 | 269 | ||
286 | - | (D) UNLESS AUTHORIZED BY THE GENERAL ASSEMBLY, THE BOARD OF | |
287 | - | PUBLIC WORKS MAY NOT APPROVE AN ISSUANCE BY THE AUTHORITY OF BONDS , | |
288 | - | WHETHER TAXABLE OR T AX EXEMPT, THAT CONSTITUTE TAX SUPPORTED DEBT OR | |
289 | - | NONTAX SUPPORTED DEB T IF, AFTER ISSUANCE , THERE WOULD BE OUTST ANDING | |
290 | - | AND UNPAID $1,500,000,000 FACE AMOUNTS OF THE BONDS FOR THE PURPOS E OF | |
291 | - | FINANCING RESEARCH I NTO, ACQUISITION OF , INSTALLATION OF , MAINTENANCE | |
292 | - | OF, AND RELATED EXPENSES FOR UPGRADES TO INFORMAT ION TECHNOLOGY AND | |
293 | - | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . | |
270 | + | (II) TO ASSIST LOCAL GOVE RNMENTS APPLYING FOR FEDERAL 22 | |
271 | + | CYBERSECURITY PREPAR EDNESS GRANTS ; AND 23 | |
294 | 272 | ||
295 | - | 10–650.1. | |
273 | + | (III) FOR ADMINISTRATIVE E XPENSES ASSOCIATED W ITH 24 | |
274 | + | PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH. 25 | |
296 | 275 | ||
297 | - | (A) THE AUTHORITY AND THE DEPARTMENT OF INFORMATION | |
298 | - | TECHNOLOGY SHALL COMP LY WITH THIS SECTION TO FINANCE PROJECTS TO | |
299 | - | RESEARCH, ACQUIRE, INSTALL, MAINTAIN, AND UPGRADE INFORMAT ION | |
300 | - | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT | |
301 | - | INFRASTRUCTURE . | |
276 | + | (7) (I) THE STATE TREASURER SHALL INVES T THE MONEY OF THE 26 | |
277 | + | FUND IN THE SAME MANN ER AS OTHER STATE MONEY MAY BE IN VESTED. 27 | |
302 | 278 | ||
303 | - | (B) THE AUTHORITY SHALL TRANS FER TO THE DEPARTMENT OF | |
304 | - | INFORMATION TECHNOLOGY THE PROCEE DS OF BONDS ISSUED U NDER THIS | |
305 | - | SUBTITLE FOR FINANCI NG INFORMATION TECHNOLOGY AND | |
306 | - | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS . | |
279 | + | (II) ANY INTEREST EARNINGS OF THE FUND SHALL BE 28 | |
280 | + | CREDITED TO THE FUND. 29 | |
307 | 281 | ||
308 | - | (C) AT LEAST 90 DAYS BEFORE PROVIDIN G THE WRITTEN NOTICE TO THE | |
309 | - | FISCAL COMMITTEES OF THE GENERAL ASSEMBLY REQUIRED UND ER SUBSECTION | |
310 | - | (D) OF THIS SECTION, THE AUTHORITY SHALL CONSULT WITH THE DEPARTMENT OF | |
311 | - | INFORMATION TECHNOLOGY TO DETERMI NE THE AMOUNT OF FUN DS NEEDED FOR | |
312 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT | |
313 | - | INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS. | |
282 | + | (8) EXPENDITURES FROM THE FUND MAY BE MADE ON LY IN 30 | |
283 | + | ACCORDANCE WITH THE STATE BUDGET. 31 | |
284 | + | HOUSE BILL 1205 7 | |
314 | 285 | ||
315 | - | (D) AT LEAST 45 DAYS BEFOR E SEEKING APPROVAL O F THE BOARD OF | |
316 | - | PUBLIC WORKS FOR EACH BOND I SSUE RELATED TO INFO RMATION TECHNOLOGY | |
317 | - | AND CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE , THE | |
318 | - | AUTHORITY SHALL PROVI DE TO THE FISCAL COM MITTEES OF THE GENERAL | |
319 | - | ASSEMBLY, IN ACCORDANCE WIT H § 2–1257 OF THE STATE GOVERNMENT ARTICLE, | |
320 | - | WRITTEN NOTICE OF : | |
321 | 286 | ||
322 | - | (1) THE AGGREGATE AMOUNT OF FUNDS NEEDED FOR INFORMATION | |
323 | - | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT | |
324 | - | INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS; | |
325 | - | Ch. 243 2022 LAWS OF MARYLAND | |
287 | + | (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL 1 | |
288 | + | GOVERNMENT SHALL : 2 | |
326 | 289 | ||
327 | - | ||
328 | - | ||
329 | - | ||
290 | + | (1) PROVIDE PROOF TO THE DEPARTMENT OF INFORMATION 3 | |
291 | + | TECHNOLOGY THAT THE L OCAL GOVERNMENT COND UCTED A CYBERSECURIT Y 4 | |
292 | + | PREPAREDNESS AS SESSMENT IN THE PREV IOUS 12 MONTHS; OR 5 | |
330 | 293 | ||
331 | - | (3) THE ANTICIPATED TOTA L DEBT SERVICE WHEN COMBINED WITH | |
332 | - | THE DEBT SERVICE FOR ALL PRIOR OUTSTANDIN G BOND ISSUES FOR IN FORMATION | |
333 | - | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT | |
334 | - | INFRASTRUCTURE PROJE CTS. | |
294 | + | (2) WITHIN 12 MONTHS UNDERGO A CYB ERSECURITY PREPAREDN ESS 6 | |
295 | + | ASSESSMENT PROVIDED BY, IN ACCORDANCE WITH T HE PREFERENCE OF THE LOCAL 7 | |
296 | + | GOVERNMENT : 8 | |
335 | 297 | ||
336 | - | (E) BEFORE EACH ISSUANCE OF BONDS TO FINANCE INFORMATION | |
337 | - | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT | |
338 | - | INFRASTRUCTURE PROJE CTS, THE AUTHORITY SHALL OBTAI N THE APPROVAL OF | |
339 | - | THE BOARD OF PUBLIC WORKS OF THE AGGREGAT E AMOUNT OF THE PROPOSED | |
340 | - | BOND ISSUE. | |
298 | + | (I) THE DEPARTMENT OF INFORMATION TECHNOLOGY AT A 9 | |
299 | + | COST TO THE LOCAL G OVERNMENT THAT DOES NOT EXCEED THE COST TO THE 10 | |
300 | + | DEPARTMENT OF INFORMATION TECHNOLOGY OF PROVIDI NG THE ASSESSMENT ; OR 11 | |
341 | 301 | ||
342 | - | (F) FOR FISCAL YEAR 2024 AND EACH FISCAL YEAR THEREAFTER , UNTIL | |
343 | - | THE BONDS THAT HAVE BEEN ISSUED TO FINAN CE INFORMATION TECHN OLOGY AND | |
344 | - | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ARE | |
345 | - | NO LONGER OUTSTANDIN G AND UNPAID, THE GOVERNOR SHALL INCLUD E IN THE | |
346 | - | ANNUAL BUDGET BILL A N APPROPRIATION TO T HE INFORMATION TECHNOLOGY | |
347 | - | AND CYBERSECURITY INFRASTRUCTURE FUND IN AN AMOUNT SUF FICIENT TO | |
348 | - | COVER THE PROJECTED DEBT SERVICE REQUIRE MENTS FOR THE UPCOMI NG FISCAL | |
349 | - | YEAR. | |
302 | + | (II) A VENDOR AUTHORIZED BY THE DEPARTMENT OF 12 | |
303 | + | INFORMATION TECHNOLOGY TO COMPLET E CYBERSECURITY PREP AREDNESS 13 | |
304 | + | ASSESSMENTS . 14 | |
350 | 305 | ||
351 | - | ||
306 | + | Article – Economic Development 15 | |
352 | 307 | ||
353 | - | (A) IN THIS SECTION , “FUND” MEANS THE INFORMATION TECHNOLOGY | |
354 | - | AND CYBERSECURITY INFRASTRUCTURE FUND. | |
308 | + | 10–628. 16 | |
355 | 309 | ||
356 | - | (B) THERE IS AN INFORMATION TECHNOLOGY AND CYBERSECURITY | |
357 | - | INFRASTRUCTURE FUND. | |
310 | + | (a) Except as provided in subsections (b) [and], (c), AND (D) of this section and 17 | |
311 | + | subject to the prior approval of the Board of Public Works, the Authority may issue bonds 18 | |
312 | + | at any time for any corporate purpose of the Authority, including the establishment of 19 | |
313 | + | reserves and the payment of interest. 20 | |
358 | 314 | ||
359 | - | (C) (1) THE FUND IS A SPECIAL , NONLAPSING FUND THAT IS NOT | |
360 | - | SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE AND | |
361 | - | THAT SHALL BE AVAILA BLE IN PERPETUITY TO IMPLEMENT THIS SUBTI TLE | |
362 | - | RELATED TO UPGRADES TO INFORMATION TECHN OLOGY AND | |
363 | - | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . | |
315 | + | (D) UNLESS AUTHORI ZED BY THE GENERAL ASSEMBLY, THE BOARD OF 21 | |
316 | + | PUBLIC WORKS MAY NOT APPROVE AN ISSUANCE BY THE AUTHORITY OF BONDS , 22 | |
317 | + | WHETHER TAXABLE OR T AX EXEMPT, THAT CONSTITUTE TAX SUPPORTED DEBT OR 23 | |
318 | + | NONTAX SUPPORTED DEB T IF, AFTER ISSUANCE , THERE WOULD BE OUTST ANDING 24 | |
319 | + | AND UNPAID $1,500,000,000 FACE AMOUNTS OF THE BONDS FOR THE PURPOS E OF 25 | |
320 | + | FINANCING RESEARCH I NTO, ACQUISITION OF , INSTALLATION OF , MAINTENANCE 26 | |
321 | + | OF, AND RELATED EXPENSES FOR UPGRADES TO INFO RMATION TECHNOLOGY A ND 27 | |
322 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTU RE. 28 | |
364 | 323 | ||
365 | - | ||
324 | + | 10–650.1. 29 | |
366 | 325 | ||
367 | - | (I) USE THE FUND AS A REVOLVING F UND FOR CARRYING OUT | |
368 | - | THE PROVISIONS OF TH IS SUBTITLE RELATED TO UPGRADES TO INFOR MATION | |
369 | - | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT | |
370 | - | INFRASTRUCTURE ; AND LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
326 | + | (A) THE AUTHORITY AND THE DEPARTMENT OF INFORMATION 30 | |
327 | + | TECHNOLOGY SHALL COMP LY WITH THIS SECTION TO FINANCE PROJECTS TO 31 | |
328 | + | RESEARCH, ACQUIRE, INSTALL, MAINTAIN, AND UPGRADE INFORMAT ION 32 | |
329 | + | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 33 | |
330 | + | INFRASTRUCTURE. 34 8 HOUSE BILL 1205 | |
371 | 331 | ||
372 | - | – 9 – | |
373 | 332 | ||
374 | - | (II) PAY ANY AND ALL EXPE NSES FROM THE FUND THAT ARE | |
375 | - | INCURRED BY THE AUTHORITY OR THE DEPARTMENT OF INFORMATION | |
376 | - | TECHNOLOGY RELATED TO UPGRADES TO INFORMAT ION TECHNOLOGY AND | |
377 | - | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . | |
378 | 333 | ||
379 | - | (D) THE FUND CONSISTS OF : | |
334 | + | (B) THE AUTHORITY SHALL TRANS FER TO THE DEPARTMENT OF 1 | |
335 | + | INFORMATION TECHNOLOGY THE PROCEE DS OF BONDS ISSUED U NDER THIS 2 | |
336 | + | SUBTITLE FOR FINANCI NG INFORMATION TECHN OLOGY AND 3 | |
337 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS . 4 | |
380 | 338 | ||
381 | - | (1) FUNDS APPROPRIATED F OR DEPOSIT TO THE FUND; | |
339 | + | (C) AT LEAST 90 DAYS BEFORE PROVIDIN G THE WRITTEN NOTICE TO THE 5 | |
340 | + | FISCAL COMMITTEES OF THE GENERAL ASSEMBLY REQUIRED UND ER SUBSECTION 6 | |
341 | + | (D) OF THIS SECTION, THE AUTHORITY SHALL CONSU LT WITH THE DEPARTMENT OF 7 | |
342 | + | INFORMATION TECHNOLOGY TO DETERMI NE THE AMOUNT OF FUN DS NEEDED FOR 8 | |
343 | + | INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 9 | |
344 | + | INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS. 10 | |
382 | 345 | ||
383 | - | (2) PROCEEDS FROM THE SA LE OF BONDS RELATED TO UPGRADES TO | |
384 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT | |
385 | - | INFRASTRUCTURE PROJE CTS; | |
346 | + | (D) AT LEAST 45 DAYS BEFORE SEEKING APPROVAL OF THE BOARD OF 11 | |
347 | + | PUBLIC WORKS FOR EACH BOND I SSUE RELATED TO INFO RMATION TECHNOLOGY 12 | |
348 | + | AND CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE , THE 13 | |
349 | + | AUTHORITY SHALL PROVI DE TO THE FISCAL COM MITTEES OF THE GENERAL 14 | |
350 | + | ASSEMBLY, IN ACCORDANCE WITH § 2–1257 OF THE STATE GOVERNMENT ARTICLE, 15 | |
351 | + | WRITTEN NOTICE OF : 16 | |
386 | 352 | ||
387 | - | ( | |
388 | - | ||
389 | - | ||
353 | + | (1) THE AGGREGATE AMOUNT OF FUNDS NEEDED FOR INFORMATION 17 | |
354 | + | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 18 | |
355 | + | INFRASTRUCTURE PROJE CTS TO BE FINANCED W ITH THE PROPOSED BON DS; 19 | |
390 | 356 | ||
391 | - | (4) INTEREST EARNINGS ; AND | |
357 | + | (2) THE ANTICIPATED TOTA L DEBT SERVICE FOR T HE PROPOSED 20 | |
358 | + | BOND ISSUE; AND 21 | |
392 | 359 | ||
393 | - | (5) ANY ADDITIONAL MONEY MADE AVAILABLE FROM ANY PUBLIC OR | |
394 | - | PRIVATE SOURCE FOR T HE PURPOSES ESTABLIS HED FOR THE FUND. | |
360 | + | (3) THE ANTICIPATED TOTA L DEBT SERVICE WHEN CO MBINED WITH 22 | |
361 | + | THE DEBT SERVICE FOR ALL PRIOR OUTSTANDIN G BOND ISSUES FOR IN FORMATION 23 | |
362 | + | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 24 | |
363 | + | INFRASTRUCTURE PROJE CTS. 25 | |
395 | 364 | ||
396 | - | (E) (1) THE STATE TREASURER SHALL INVES T THE MONEY OF THE FUND | |
397 | - | IN THE SAME MANNER A S OTHER STATE FUNDS. | |
365 | + | (E) BEFORE EACH ISSUANCE OF BONDS TO FINANCE INFORMATION 26 | |
366 | + | TECHNOLOGY AND CYBERSECURITY –RELATED STATE GOVERNMENT 27 | |
367 | + | INFRASTRUCTURE PROJE CTS, THE AUTHORITY SHALL OBTAI N THE APPROVAL OF 28 | |
368 | + | THE BOARD OF PUBLIC WORKS OF THE AGGREGAT E AMOUNT OF THE PROP OSED 29 | |
369 | + | BOND ISSUE. 30 | |
398 | 370 | ||
399 | - | (2) ANY INVESTMENT EARNIN GS SHALL BE CREDITED TO THE FUND. | |
371 | + | (F) FOR FISCAL YEAR 2024 AND EACH FISCAL YEAR THEREAFTER , UNTIL 31 | |
372 | + | THE BONDS THAT HAVE BEEN ISSUED TO FINANCE IN FORMATION TECHNOLOGY AND 32 | |
373 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ARE 33 | |
374 | + | NO LONGER OUTSTANDIN G AND UNPAID , THE GOVERNOR SHALL INCLUD E IN THE 34 | |
375 | + | ANNUAL BUDGET BILL A N APPROPRIATION TO T HE INFORMATION TECHNOLOGY 35 | |
376 | + | AND CYBERSECURITY INFRASTRUCTURE FUND IN AN AMOUNT SUF FICIENT TO 36 HOUSE BILL 1205 9 | |
400 | 377 | ||
401 | - | (3) NO PART OF THE FUND MAY REVERT OR BE CREDITED TO THE | |
402 | - | GENERAL FUND OF THE STATE OR ANY SPECIAL FUND OF THE STATE. | |
403 | 378 | ||
404 | - | Article – State Finance and Procurement | |
379 | + | COVER THE PROJECTED DEBT SERVICE REQUIRE MENTS FOR THE UPCOMI NG FISCAL 1 | |
380 | + | YEAR. 2 | |
405 | 381 | ||
406 | - | ||
382 | + | 10–657.5. 3 | |
407 | 383 | ||
408 | - | (a) In this title the following words have the meanings indicated. | |
384 | + | (A) IN THIS SECTION , “FUND” MEANS THE INFORMATION TECHNOLOGY 4 | |
385 | + | AND CYBERSECURITY INFRASTRUCTU RE FUND. 5 | |
409 | 386 | ||
410 | - | (b) “CLOUD COMPUTING SERVICE” MEANS A SERVICE THAT ENABLES | |
411 | - | ON–DEMAND SELF –SERVICE NETWORK ACCE SS TO A SHARED POOL OF | |
412 | - | CONFIGURABLE COMPUTE R RESOURCES , INCLUDING DATA STORA GE, ANALYTICS, | |
413 | - | COMMERCE , STREAMING, E–MAIL, DOCUMENT SHARING , AND DOCUMENT EDITING . | |
387 | + | (B) THERE IS AN INFORMATION TECHNOLOGY AND CYBERSECURITY 6 | |
388 | + | INFRASTRUCTURE FUND. 7 | |
414 | 389 | ||
415 | - | (C) “Department” means the Department of Information Technology. | |
416 | - | Ch. 243 2022 LAWS OF MARYLAND | |
390 | + | (C) (1) THE FUND IS A SPECIAL , NONLAPSING FUND THAT IS NOT 8 | |
391 | + | SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE AND 9 | |
392 | + | THAT SHALL BE AVAILA BLE IN PERPETUITY TO IMPLEMENT THIS SU BTITLE 10 | |
393 | + | RELATED TO UPGRADES TO INFORMATION TECHN OLOGY AND 11 | |
394 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 12 | |
417 | 395 | ||
418 | - | – 10 – | |
419 | - | [(c)] (D) “Secretary” means the Secretary of Information Technology. | |
396 | + | (2) THE AUTHORITY SHALL : 13 | |
420 | 397 | ||
421 | - | [(d)] (E) “Telecommunication” means the transmission of information, images, | |
422 | - | pictures, voice, or data by radio, video, or other electronic or impulse means. | |
398 | + | (I) USE THE FUND AS A REVOLVING F UND FOR CARRYING OUT 14 | |
399 | + | THE PROVISIONS OF TH IS SUBTITLE RELA TED TO UPGRADES TO I NFORMATION 15 | |
400 | + | TECHNOLOGY AND CYBER SECURITY–RELATED STATE GOVERNMENT 16 | |
401 | + | INFRASTRUCTURE ; AND 17 | |
423 | 402 | ||
424 | - | [(e)] (F) “Unit of State government” means an agency or unit of the Executive | |
425 | - | Branch of State government. | |
403 | + | (II) PAY ANY AND ALL EXPE NSES FROM THE FUND THAT ARE 18 | |
404 | + | INCURRED BY THE AUTHORITY OR THE DEPARTMENT OF INFORMATION 19 | |
405 | + | TECHNOLOGY RELATED TO UPGRADES TO I NFORMATION TECHNOLOG Y AND 20 | |
406 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE . 21 | |
426 | 407 | ||
427 | - | ||
408 | + | (D) THE FUND CONSISTS OF : 22 | |
428 | 409 | ||
429 | - | ( | |
410 | + | (1) FUNDS APPROPRIATED F OR DEPOSIT TO THE FUND; 23 | |
430 | 411 | ||
431 | - | (7) advising and consulting with the Legislative and Judicial branches of | |
432 | - | State government regarding a cybersecurity strategy; [and] | |
412 | + | (2) PROCEEDS FROM THE SA LE OF BONDS RELATED TO UPGRADES TO 24 | |
413 | + | INFORMATION TECHNOLO GY AND CYBERSE CURITY–RELATED STATE GOVERNMENT 25 | |
414 | + | INFRASTRUCTURE PROJE CTS; 26 | |
433 | 415 | ||
434 | - | ( | |
435 | - | ||
436 | - | ||
416 | + | (3) REVENUES COLLECTED O R RECEIVED FROM ANY SOURCE UNDER 27 | |
417 | + | THIS SUBTITLE RELATE D TO UPGRADES TO INF ORMATION TECHNOLOGY AND 28 | |
418 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFR ASTRUCTURE PROJECTS ; 29 | |
437 | 419 | ||
438 | - | ( | |
439 | - | ||
420 | + | (4) INTEREST EARNINGS ; AND 30 | |
421 | + | 10 HOUSE BILL 1205 | |
440 | 422 | ||
441 | - | (10) ANNUALLY EVALUATING : | |
442 | 423 | ||
443 | - | (I) THE FEASIBILITY OF U NITS OF STATE GOVERNMENT | |
444 | - | PROVIDING PUBLIC SER VICES USING ARTIFICI AL INTELLIGENCE , MACHINE | |
445 | - | LEARNING, COMMERCIAL CLOUD COM PUTING SERVICES , DEVICE–AS–A–SERVICE | |
446 | - | PROCUREMENT MODELS , AND OTHER EMERGING T ECHNOLOGIES ; AND | |
424 | + | (5) ANY ADDITIONAL MONEY MADE AVAILABLE FROM ANY PUBLIC OR 1 | |
425 | + | PRIVATE SOURCE FOR T HE PURPOSES ESTABLIS HED FOR THE FUND. 2 | |
447 | 426 | ||
448 | - | ( | |
449 | - | ||
427 | + | (E) (1) THE STATE TREASURER SHALL INVES T THE MONEY OF THE FUND 3 | |
428 | + | IN THE SAME MANNER A S OTHER STATE FUNDS. 4 | |
450 | 429 | ||
451 | - | ||
430 | + | (2) ANY INVESTMENT EARNIN GS SHALL BE CREDITED TO THE FUND. 5 | |
452 | 431 | ||
453 | - | ( | |
454 | - | ||
432 | + | (3) NO PART OF THE FUND MAY REVERT OR BE CREDITED TO THE 6 | |
433 | + | GENERAL FUND OF THE STATE OR ANY SPECIAL FUND OF THE STATE. 7 | |
455 | 434 | ||
456 | - | (2) “CITIZEN ADVOCACY GROU P” MEANS AN ORGANIZATIO N WHOSE | |
457 | - | MISSION IS TO PROVID E SUPPORT FOR INFORMATION TECHNOLO GY AND | |
458 | - | CYBERSECURITY POLICI ES. | |
435 | + | Article – State Finance and Procurement 8 | |
459 | 436 | ||
460 | - | (3) (2) “COMMISSION” MEANS THE STATEWIDE REPORTING | |
461 | - | FRAMEWORK AND MODERNIZE MARYLAND OVERSIGHT COMMISSION. | |
462 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
437 | + | 3A–101. 9 | |
463 | 438 | ||
464 | - | – 11 – | |
465 | - | (4) (3) “CRITICAL SYSTEM ” MEANS AN INFORMATION | |
466 | - | TECHNOLOGY OR CYBERS ECURITY SYSTEM THAT IS SEVERELY OUTDATED , AS | |
467 | - | DETERMINED BY THE DEPARTMENT . | |
439 | + | (a) In this title the following words have the meanings indicated. 10 | |
468 | 440 | ||
469 | - | (B) THERE IS A STATEWIDE REPORTING FRAMEWORK AND AN | |
470 | - | INDEPENDENT MODERNIZE MARYLAND OVERSIGHT COMMISSION IN THE | |
471 | - | DEPARTMENT . | |
441 | + | (b) “CLOUD COMPUTING SERVICE” MEANS A SERVICE THAT ENABLES 11 | |
442 | + | ON–DEMAND SELF –SERVICE NETWORK ACCE SS TO A SHARED POOL OF 12 | |
443 | + | CONFIGURABLE COMPUTE R RESOURCES , INCLUDING DATA STORA GE, ANALYTICS, 13 | |
444 | + | COMMERCE , STREAMING, E–MAIL, DOCUMENT SHARING , AND DOCUMENT EDITING . 14 | |
472 | 445 | ||
473 | - | (C) THE | |
446 | + | (C) “Department” means the Department of Information Technology. 15 | |
474 | 447 | ||
475 | - | (1) ENSURE THE CONFIDENT IALITY, INTEGRITY, AND AVAILABILITY | |
476 | - | OF INFORMATION HELD BY THE STATE CONCERNING STATE RESIDENTS ; AND | |
448 | + | [(c)] (D) “Secretary” means the Secretary of Information Technology. 16 | |
477 | 449 | ||
478 | - | ( | |
479 | - | ||
450 | + | [(d)] (E) “Telecommunication” means the transmission of information, images, 17 | |
451 | + | pictures, voice, or data by radio, video, or other electronic or impulse means. 18 | |
480 | 452 | ||
481 | - | ( | |
482 | - | ||
453 | + | [(e)] (F) “Unit of State government” means an agency or unit of the Executive 19 | |
454 | + | Branch of State government. 20 | |
483 | 455 | ||
484 | - | (II) THE FUNDING SOURCES FOR THE APPROPRIATE | |
485 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY UPGRADES; AND | |
456 | + | 3A–303. 21 | |
486 | 457 | ||
487 | - | (III) FUTURE MECHANISMS FO R THE PROCUREMENT OF | |
488 | - | APPROPRIATE INFORMAT ION TECHNOLOGY AND C YBERSECURITY UPGRADES, | |
489 | - | INCLUDING WAYS TO IN CREASE THE EFFICIENC Y OF PROCUREMENTS MA DE FOR | |
490 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY UPGRADES. | |
458 | + | (a) The Secretary is responsible for carrying out the following duties: 22 | |
491 | 459 | ||
492 | - | (D) THE COMMISSION CONSISTS O F THE FOLLOWING MEMB ERS: | |
460 | + | (7) advising and consulting with the Legislative and Judicial branches of 23 | |
461 | + | State government regarding a cybersecurity strategy; [and] 24 | |
493 | 462 | ||
494 | - | (1) THE SECRETARY; | |
463 | + | (8) in consultation with the Attorney General, developing guidance on 25 | |
464 | + | consistent cybersecurity strategies for counties, municipal corporations, school systems, 26 | |
465 | + | and all other political subdivisions of the State; AND 27 | |
495 | 466 | ||
496 | - | (2) THE STATE CHIEF INFORMATION SECURITY OFFICER; | |
467 | + | (9) UPGRADING INFORMATIO N TECHNOLOGY AND 28 | |
468 | + | CYBERSECURITY –RELATED STATE GOVERNMENT INFRASTRUCTURE ; AND 29 HOUSE BILL 1205 11 | |
497 | 469 | ||
498 | - | (3) THE STATE TREASURER; | |
499 | 470 | ||
500 | - | (4) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , | |
501 | - | INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY ; | |
502 | 471 | ||
503 | - | (5) (3) THREE CHIEF INFORMAT ION SECURITY OFFICER S | |
504 | - | REPRESENTING DIFFERE NT UNITS OF STATE GOVERNMENT , APPOINTED BY THE | |
505 | - | GOVERNOR; | |
506 | - | Ch. 243 2022 LAWS OF MARYLAND | |
472 | + | (10) ANNUALLY EVALUATING : 1 | |
507 | 473 | ||
508 | - | ||
509 | - | ||
510 | - | ||
511 | - | ||
474 | + | (I) THE FEASIBILITY OF U NITS OF STATE GOVERNMENT 2 | |
475 | + | PROVIDING PUBLIC SER VICES USING ARTIFICI AL INTELLIGENCE , MACHINE 3 | |
476 | + | LEARNING, COMMERCIAL CLOUD COM PUTING SERVICES , DEVICE–AS–A–SERVICE 4 | |
477 | + | PROCUREMENT MODELS , AND OTHER EMERGING T ECHNOLOGIES ; AND 5 | |
512 | 478 | ||
513 | - | ( | |
514 | - | ||
479 | + | (II) THE DEVELOPMENT OF D ATA ANALYTICS CAPABI LITIES TO 6 | |
480 | + | ENABLE DATA–DRIVEN POLICYMAKING BY UNITS OF STATE GOVERNMENT . 7 | |
515 | 481 | ||
516 | - | (8) (6) TWO REPRESENTATIVES FROM CITIZEN ADVOCACY GRO UPS | |
517 | - | IN THE STATE, APPOINTED BY THE GOVERNOR; INDIVIDUALS WHO ARE END USERS | |
518 | - | OF STATE INFORMATION TEC HNOLOGY SYSTEMS , ONE APPOINTED BY THE | |
519 | - | PRESIDENT OF THE SENATE AND ONE APPOIN TED BY THE SPEAKER OF THE HOUSE | |
520 | - | APPOINTED BY THE GOVERNOR; | |
482 | + | 3A–315. 8 | |
521 | 483 | ||
522 | - | (9) (7) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE | |
523 | - | PRIVATE SECTOR WHO H AS COMPLETED INFORMA TION TECHNOLOGY AND | |
524 | - | CYBERSECURITY UPGRAD ES FOR A BUSINESS WI TH OVER 100 INFORMATION | |
525 | - | TECHNOLOGY SYSTEMS , APPOINTED BY THE GOVERNOR; AND | |
484 | + | (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS 9 | |
485 | + | INDICATED. 10 | |
526 | 486 | ||
527 | - | (10) (8) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE | |
528 | - | EDUCATION SECTOR WHO HAS COMPLETED INFORM ATION TECHNOLOGY AND | |
529 | - | CYBERSECURITY UPGRAD ES FOR AN EDUCATIONA L INSTITUTION WITH O VER 100 | |
530 | - | INFORMATION TECHNOLO GY SYSTEMS, APPOINTED BY THE GOVERNOR. | |
487 | + | (2) “CITIZEN ADVOCACY GROU P” MEANS AN ORGANIZATIO N WHOSE 11 | |
488 | + | MISSION IS TO PROVID E SUPPORT FOR INFORM ATION TECHNOLOGY AND 12 | |
489 | + | CYBERSECURITY POLICI ES. 13 | |
531 | 490 | ||
532 | - | ( | |
533 | - | ||
491 | + | (3) (2) “COMMISSION” MEANS THE STATEWIDE REPORTING 14 | |
492 | + | FRAMEWORK AND MODERNIZE MARYLAND OVERSIGHT COMMISSION. 15 | |
534 | 493 | ||
535 | - | ( | |
536 | - | ||
537 | - | ||
494 | + | (4) (3) “CRITICAL SYSTEM ” MEANS AN INFORMATION 16 | |
495 | + | TECHNOLOGY OR CYBERS ECURITY SYSTEM THAT IS SEVERELY OUTDATED , AS 17 | |
496 | + | DETERMINED BY THE DEPARTMENT . 18 | |
538 | 497 | ||
539 | - | ( | |
540 | - | ||
541 | - | ||
498 | + | (B) THERE IS A STATEWIDE REPORTING FRAMEWORK AND AN 19 | |
499 | + | INDEPENDENT MODERNIZE MARYLAND OVERSIGHT COMMISSION IN THE 20 | |
500 | + | DEPARTMENT . 21 | |
542 | 501 | ||
543 | - | ( | |
502 | + | (C) THE PURPOSE OF THE COMMISSION IS TO: 22 | |
544 | 503 | ||
545 | - | (1) | |
546 | - | ||
504 | + | (1) ENSURE THE CONFIDENT IALITY, INTEGRITY, AND AVAILABILITY 23 | |
505 | + | OF INFORMATION HELD BY THE STATE CONCERNING STATE RESIDENTS ; AND 24 | |
547 | 506 | ||
548 | - | (I) REQUIRE THE UPDATES AND INVESTMENTS OF C RITICAL | |
549 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY SYSTEMS IDENTIFIED BY THE | |
550 | - | COMMISSION IN THE FIR ST RECOMMENDATIONS R EPORTED UNDER PARAGR APH (2) | |
551 | - | OF THIS SUBSECTION TO BE COMPLETED ON O R BEFORE DECEMBER 31, 2025; AND LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
507 | + | (2) DETERMINE ADVISE THE SECRETARY AND STATE CHIEF 25 | |
508 | + | INFORMATION SECURITY OFFICER ON: 26 | |
552 | 509 | ||
553 | - | – 13 – | |
510 | + | (I) THE APPROPRIATE INFO RMATION TECHNOLOGY A ND 27 | |
511 | + | CYBERSECURITY INVEST MENTS AND UPGRADES ; 28 | |
554 | 512 | ||
555 | - | (II) REQUIRE ALL UPDATES AND INVESTMENTS OF | |
556 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY TO BE MADE ON OR BEF ORE | |
557 | - | DECEMBER 31, 2030; | |
513 | + | (II) THE FUNDING SOURCES FOR THE APPROPRIATE 29 | |
514 | + | INFORMATION TECHNOLO GY AND CYBERSECURITY UPGRADES; AND 30 12 HOUSE BILL 1205 | |
558 | 515 | ||
559 | - | (2) MAKE PERIODIC RECOMM ENDATIONS ON INVESTM ENTS IN STATE | |
560 | - | INFORMATION TECHNOLO GY STRUCTURES BASED ON THE ASSESSMENTS | |
561 | - | COMPLETED IN ACCORDA NCE WITH THE FRAMEWO RK DEVELOPED IN § 3A–316 OF | |
562 | - | THIS SUBTITLE; AND | |
563 | 516 | ||
564 | - | (3) REVIEW AND PROVIDE R ECOMMENDATIONS ON TH E | |
565 | - | DEPARTMENT’S BASIC SECURITY STA NDARDS FOR USE OF TH E NETWORK | |
566 | - | ESTABLISHED UNDER § 3A–404(B) OF THIS TITLE; AND | |
567 | 517 | ||
568 | - | (3) (4) EACH YEAR, IN ACCORDANCE WITH § 2–1257 OF THE STATE | |
569 | - | GOVERNMENT ARTICLE, REPORT ITS FINDINGS AND RECOMMENDATIONS TO THE | |
570 | - | SENATE BUDGET AND TAXATION COMMITTEE, THE SENATE EDUCATION, HEALTH, | |
571 | - | AND ENVIRONMENTAL AFFAIRS COMMITTEE, THE HOUSE APPROPRIATIONS | |
572 | - | COMMITTEE, THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE, | |
573 | - | AND THE JOINT COMMITTEE ON CYBERSECURITY , INFORMATION TECHNOLOGY , | |
574 | - | AND BIOTECHNOLOGY . | |
518 | + | (III) FUTURE MECHANISMS FO R THE PROCUREMENT OF 1 | |
519 | + | APPROPRIATE INFORMAT ION TECHNOLOGY AND C YBERSECURITY UPGRADE S, 2 | |
520 | + | INCLUDING WAYS TO IN CREASE THE EFFICIENC Y OF PROCUREMENTS MA DE FOR 3 | |
521 | + | INFORMATION TECHNOLO GY AND CYBERSECURITY UPGRADES. 4 | |
575 | 522 | ||
576 | - | (G) THE REPORT SUBMITTED UNDER SUBSECTION (F)(4) OF THIS SECTION | |
577 | - | MAY NOT CONTAIN INFO RMATION ABOUT THE SE CURITY OF AN INFORMATION | |
578 | - | SYSTEM. | |
523 | + | (D) THE COMMISSION CONSISTS O F THE FOLLOWING MEMB ERS: 5 | |
579 | 524 | ||
580 | - | ||
525 | + | (1) THE SECRETARY; 6 | |
581 | 526 | ||
582 | - | ( | |
527 | + | (2) THE STATE CHIEF INFORMATION SECURITY OFFICER; 7 | |
583 | 528 | ||
584 | - | ( | |
529 | + | (3) THE STATE TREASURER; 8 | |
585 | 530 | ||
586 | - | (2) THE UNIVERSITY SYSTEM OF MARYLAND; | |
531 | + | (4) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 9 | |
532 | + | INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY ; 10 | |
587 | 533 | ||
588 | - | (3) ST. MARY’S COLLEGE OF MARYLAND; | |
534 | + | (5) (3) THREE CHIEF INFORMAT ION SECURITY OFFICERS 11 | |
535 | + | REPRESENTING DIFFERE NT UNITS OF STATE GOVERNMENT , APPOINTED BY THE 12 | |
536 | + | GOVERNOR; 13 | |
589 | 537 | ||
590 | - | (4) MORGAN STATE UNIVERSITY; | |
538 | + | (6) (4) FOUR ONE INFORMATION TECHNOLO GY EXPERTS IN 14 | |
539 | + | MODERNIZATION EXPERT WITH EXPERIENCE IN THE PRIVATE SECTOR , APPOINTED 15 | |
540 | + | BY THE GOVERNOR; 16 | |
591 | 541 | ||
592 | - | (5) THE MARYLAND STADIUM AUTHORITY; | |
542 | + | (7) (5) ONE REPRESENTATIVE F ROM THE MARYLAND CHAMBER OF 17 | |
543 | + | COMMERCE WITH KNOWLEDGE OF CY BERSECURITY ISSUES ; 18 | |
593 | 544 | ||
594 | - | (6) BALTIMORE CITY COMMUNITY COLLEGE; OR | |
545 | + | (8) (6) TWO REPRESENTATIVES FROM CITIZEN ADVOCACY GRO UPS 19 | |
546 | + | IN THE STATE, APPOINTED BY THE GOVERNOR; INDIVIDUALS WHO ARE END USERS 20 | |
547 | + | OF STATE INFORMATION TEC HNOLOGY SYSTEMS , ONE APPOINTED BY THE 21 | |
548 | + | PRESIDENT OF THE SENATE AND ONE APPOIN TED BY THE SPEAKER OF THE HOUSE 22 | |
549 | + | APPOINTED BY THE GOVERNOR; 23 | |
595 | 550 | ||
596 | - | (7) THE STATE BOARD OF ELECTIONS.; | |
597 | - | Ch. 243 2022 LAWS OF MARYLAND | |
551 | + | (9) (7) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE 24 | |
552 | + | PRIVATE SECTOR WHO H AS COMPLETED INFORMA TION TECHNOLOGY AND 25 | |
553 | + | CYBERSECURITY UPGRAD ES FOR A BUSINESS WI TH OVER 100 INFORMATION 26 | |
554 | + | TECHNOLOGY SYSTEMS , APPOINTED BY THE GOVERNOR; AND 27 | |
598 | 555 | ||
599 | - | – 14 – | |
600 | - | (8) THE OFFICE OF THE ATTORNEY GENERAL; | |
556 | + | (10) (8) ONE CHIEF INFORMATIO N SECURITY OFFICER F ROM THE 28 | |
557 | + | EDUCATION SECTOR WHO HAS COMPLETED INFORM ATION TECHNOLOGY AND 29 | |
558 | + | CYBERSECURITY UPGRA DES FOR AN EDUCATION AL INSTITUTION WITH OVER 100 30 | |
559 | + | INFORMATION TECHNOLO GY SYSTEMS, APPOINTED BY THE GOVERNOR. 31 | |
560 | + | HOUSE BILL 1205 13 | |
601 | 561 | ||
602 | - | (9) THE COMPTROLLER ; OR | |
603 | 562 | ||
604 | - | (10) THE STATE TREASURER. | |
563 | + | (7) ONE REPRESENTATIVE F ROM THE CYBERSECURITY ASSOCIATION 1 | |
564 | + | OF MARYLAND; AND 2 | |
605 | 565 | ||
606 | - | (A) (B) (1) THE DEPARTMENT SHALL HIRE AN INDEPENDENT | |
607 | - | CONTRACTOR CONTRACTORS TO: | |
566 | + | (8) ONE INDIVIDUAL WHO I S EITHER AN INSTRUCT OR OR A 3 | |
567 | + | PROFESSIONAL IN THE ACADEMIC FIEL D OF CYBERSECURITY A T A COLLEGE OR 4 | |
568 | + | UNIVERSITY IN THE STATE, APPOINTED BY THE GOVERNOR. 5 | |
608 | 569 | ||
609 | - | (I) DEVELOP A FRAMEWORK FOR INVESTMENTS IN | |
610 | - | TECHNOLOGY ; AND | |
570 | + | (E) THE COCHAIRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 6 | |
571 | + | INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY SHALL S ERVE AS ADVISORY , 7 | |
572 | + | NONVOTING MEMBERS OF THE COMMISSION. 8 | |
611 | 573 | ||
612 | - | (II) AT LEAST ONCE EVERY 3 2 YEARS, IN ACCORDANCE WITH | |
613 | - | THE FRAMEWORK , ANNUALLY ASSESS THE CYBERSECU RITY AND INFORMATION | |
614 | - | TECHNOLOGY SYSTEMS I N EACH UNIT OF STATE GOVERNMENT . | |
574 | + | (E) (F) THE COMMISSION SHALL : 9 | |
615 | 575 | ||
616 | - | (2) THE FRAMEWORK SHALL I NCLUDE THE FOLLOWING CRITERIA: | |
576 | + | (1) DEVELOP ADVISE THE SECRETARY ON A STRATEGIC ROADMAP 10 | |
577 | + | WITH A TIMELINE AND BUDGET THAT WILL : 11 | |
617 | 578 | ||
618 | - | (I) SECURITY RISKS TO TH E SYSTEM; | |
579 | + | (I) REQUIRE THE UPDATES AND INVESTMENTS OF C RITICAL 12 | |
580 | + | INFORMATION TECHNOLO GY AND CYBERSECURITY SYSTEMS IDENTIFIED BY THE 13 | |
581 | + | COMMISSION IN THE FIR ST RECOMMENDATIONS R EPORTED UNDER PARAGR APH (2) 14 | |
582 | + | OF THIS SUBSECTION TO BE COMPLETED ON O R BEFORE DECEMBER 31, 2025; AND 15 | |
619 | 583 | ||
620 | - | (II) SYSTEM PERFORMANCE ; | |
584 | + | (II) REQUIRE ALL UPDATES AND INVESTMENTS OF 16 | |
585 | + | INFORMATION TECHNOLO GY AND CYBERSECURITY TO BE MADE ON OR BEF ORE 17 | |
586 | + | DECEMBER 31, 2030; 18 | |
621 | 587 | ||
622 | - | (III) THE SYSTEM ’S DEPENDENCE ON OTHE R INFORMATION | |
623 | - | TECHNOLOGY OR CYBERS ECURITY SYSTEMS AND DATA; | |
588 | + | (2) MAKE PERIODIC RECOMM ENDATIONS ON INVESTM ENTS IN STATE 19 | |
589 | + | INFORMATION TECHNOLO GY STRUCTURES BASED ON THE ASSESSMENTS 20 | |
590 | + | COMPLETED IN ACCORDANCE WITH THE FRAMEWORK DEVELOPED IN § 3A–316 OF 21 | |
591 | + | THIS SUBTITLE; AND 22 | |
624 | 592 | ||
625 | - | (IV) THE SYSTEM ’S ABILITY TO CREATE AN EFFICIENT AND | |
626 | - | SEAMLESS EXPERIENCE FOR USERS; | |
593 | + | (3) REVIEW AND PROVIDE R ECOMMENDATIONS ON TH E 23 | |
594 | + | DEPARTMENT ’S BASIC SECURITY STA NDARDS FOR USE OF TH E NETWORK 24 | |
595 | + | ESTABLISHED UNDER § 3A–404(B) OF THIS TITLE; AND 25 | |
627 | 596 | ||
628 | - | (V) THE SYSTEM ’S EFFECTIVENESS IN A CHIEVING UNIT | |
629 | - | OBJECTIVES; | |
597 | + | (3) (4) EACH YEAR, IN ACCORDANCE WITH § 2–1257 OF THE STATE 26 | |
598 | + | GOVERNMENT ARTICLE, REPORT ITS FINDINGS AND RECOMMENDATIONS TO THE 27 | |
599 | + | SENATE BUDGET AND TAXATION COMMITTEE, THE SENATE EDUCATION, HEALTH, 28 | |
600 | + | AND ENVIRONMENTAL AFFAIRS COMMITTEE, THE HOUSE APPROPRIATIONS 29 | |
601 | + | COMMITTEE, THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE, 30 | |
602 | + | AND THE JOINT COMMITTEE ON CYBERSECURITY , INFORMATION TECHNOLOGY , 31 | |
603 | + | AND BIOTECHNOLOGY . 32 | |
604 | + | 14 HOUSE BILL 1205 | |
630 | 605 | ||
631 | - | (VI) THE SYSTEM’S EFFECTIVENESS IN M EETING THE NEEDS OF | |
632 | - | CITIZENS AND CUSTOME RS; | |
633 | 606 | ||
634 | - | (VII) THE COSTS TO MAINTAIN AN D OPERATE THE SYSTEM ; | |
607 | + | (G) THE REPORT SUBMITTED UNDER SUBSECTION (F)(4) OF THIS SECTION 1 | |
608 | + | MAY NOT CONTAIN INFO RMATION ABOUT THE SE CURITY OF AN INFORMATION 2 | |
609 | + | SYSTEM. 3 | |
635 | 610 | ||
636 | - | ||
611 | + | 3A–316. 4 | |
637 | 612 | ||
638 | - | (IX) THE EFFECTIVENESS OF THE SYSTEM IN REGARD TO THE | |
639 | - | UNIT’S OBJECTIVES; | |
613 | + | (A) THIS SECTION DOES NOT APPLY TO: 5 | |
640 | 614 | ||
641 | - | (X) IMPROVEMENTS TO THE UNIT’S RELATIVE AUDIT FIN DINGS | |
642 | - | ATTRIBUTABLE TO THE SYSTEM; AND | |
643 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
615 | + | (1) THE MARYLAND PORT ADMINISTRATION ; 6 | |
644 | 616 | ||
645 | - | – 15 – | |
646 | - | (XI) AN ASSESSMENT OF THE SYSTEM USING THE NATIONAL | |
647 | - | INSTITUTE OF STANDARDS AND TECHNOLOGY CYBERSECURITY FRAMEWORK . | |
617 | + | (2) THE UNIVERSITY SYSTEM OF MARYLAND; 7 | |
648 | 618 | ||
649 | - | (B) (C) EACH UNIT SHALL PROMP TLY PROVIDE THE CONTRACTOR A | |
650 | - | CONTRACTOR EMPLOYED UNDER SUBSECTION (B) OF THIS SECTION WITH THE | |
651 | - | INFORMATION NECESSAR Y TO PERFORM THE ASS ESSMENTS. | |
619 | + | (3) ST. MARY’S COLLEGE OF MARYLAND; 8 | |
652 | 620 | ||
653 | - | (C) (D) (1) EACH YEAR, THE EVERY 3 2 YEARS, A CONTRACTOR SHALL | |
654 | - | PROVIDE THE RESULTS OF THE ASSESSMENTS T O: | |
621 | + | (4) MORGAN STATE UNIVERSITY; 9 | |
655 | 622 | ||
656 | - | (I) THE STATEWIDE REPORTING FRAMEWORK AND | |
657 | - | OVERSIGHT MODERNIZE MARYLAND COMMISSION ESTABLISHE D UNDER § 3A–315 | |
658 | - | OF THIS SUBTITLE; AND | |
623 | + | (5) THE MARYLAND STADIUM AUTHORITY; 10 | |
659 | 624 | ||
660 | - | (II) IN ACCORDANCE WITH § 2–1257 OF THE STATE | |
661 | - | GOVERNMENT ARTICLE, THE SENATE BUDGET AND TAXATION COMMITTEE, THE | |
662 | - | SENATE EDUCATION, HEALTH, AND ENVIRONMENTAL AFFAIRS COMMITTEE, AND | |
663 | - | THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE. | |
625 | + | (6) BALTIMORE CITY COMMUNITY COLLEGE; OR 11 | |
664 | 626 | ||
665 | - | (2) THE REPORT SUBMITTED UNDER PARAGRAPH (1)(II) OF THIS | |
666 | - | SUBSECTION MAY NOT C ONTAIN INFORMATION A BOUT THE SECURITY OF AN | |
667 | - | INFORMATION SYSTEM . | |
627 | + | (7) THE STATE BOARD OF ELECTIONS.; 12 | |
668 | 628 | ||
669 | - | (D) (E) THE DEPARTMENT MAY USE FUNDS AVAILABLE FROM THE | |
670 | - | ISSUANCE OF BONDS IN ACCORDANCE WITH § 10–650.1 OF THE ECONOMIC | |
671 | - | DEVELOPMENT ARTICLE TO PAY FOR TH E INDEPENDENT CONTRA CTOR REQUIRED | |
672 | - | UNDER MULTIPLE CONTRACTORS AT A TIME TO MEET TH E REQUIREMENTS OF THIS | |
673 | - | SECTION. | |
629 | + | (8) THE OFFICE OF THE ATTORNEY GENERAL; 13 | |
674 | 630 | ||
675 | - | ||
631 | + | (9) THE COMPTROLLER ; OR 14 | |
676 | 632 | ||
677 | - | (A) THE DEPARTMENT SHALL CONS ULT WITH THE MARYLAND STADIUM | |
678 | - | AUTHORITY REGARDING THE ISS UANCE OF BONDS FOR U PGRADES TO | |
679 | - | INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT | |
680 | - | INFRASTRUCTURE IN AC CORDANCE WITH § 10–650.1 OF THE ECONOMIC | |
681 | - | DEVELOPMENT ARTICLE. | |
633 | + | (10) THE STATE TREASURER. 15 | |
682 | 634 | ||
683 | - | (B) THE DEPARTMENT MAY USE TH E PROCEEDS FROM BOND S ISSUED FOR | |
684 | - | UPGRADES TO INFORMAT ION TECHNOLOGY AND C YBERSECURITY –RELATED STATE | |
685 | - | GOVERNMENT INFRASTRU CTURE UNDER § 10–650.1 OF THE ECONOMIC | |
686 | - | DEVELOPMENT ARTICLE ONLY FOR PROJ ECTS THAT RELATE TO RESEARCH INTO , | |
687 | - | ACQUISITION OF , INSTALLATION OF , MAINTENANCE OF , AND RELATED EXPENSES | |
688 | - | FOR UPGRADES TO INFO RMATION TECHNOLOGY A ND CYBERSECURITY –RELATED | |
689 | - | STATE GOVERNMENT INFR ASTRUCTURE . Ch. 243 2022 LAWS OF MARYLAND | |
635 | + | (A) (B) (1) THE DEPARTMENT SHALL HIRE AN INDEPENDENT 16 | |
636 | + | CONTRACTOR CONTRACTORS TO: 17 | |
690 | 637 | ||
691 | - | – 16 – | |
638 | + | (I) DEVELOP A FRAMEWORK FOR INVESTMENTS IN 18 | |
639 | + | TECHNOLOGY ; AND 19 | |
692 | 640 | ||
693 | - | (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS | |
694 | - | INDICATED. | |
641 | + | (II) AT LEAST ONCE EVERY 3 2 YEARS, IN ACCORDANCE WITH 20 | |
642 | + | THE FRAMEWORK , ANNUALLY ASSESS THE CYBERSECU RITY AND INFORMATION 21 | |
643 | + | TECHNOLOGY SYSTEMS I N EACH UNIT OF STATE GOVERNMENT . 22 | |
695 | 644 | ||
696 | - | (2) | |
645 | + | (2) THE FRAMEWORK SHALL I NCLUDE THE FOLLOWING CRITERIA: 23 | |
697 | 646 | ||
698 | - | (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, | |
699 | - | LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. | |
647 | + | (I) SECURITY RISKS TO TH E SYSTEM; 24 | |
700 | 648 | ||
701 | - | (B) (1) THERE IS A LOCAL CYBERSECURITY SUPPORT FUND. | |
649 | + | (II) SYSTEM PERFORMANCE ; 25 | |
650 | + | HOUSE BILL 1205 15 | |
702 | 651 | ||
703 | - | (2) THE PURPOSE OF THE FUND IS TO: | |
704 | 652 | ||
705 | - | ( | |
706 | - | ||
653 | + | (III) THE SYSTEM ’S DEPENDENCE ON OTHE R INFORMATION 1 | |
654 | + | TECHNOLOGY OR CYBERS ECURITY SYSTEMS AND DATA; 2 | |
707 | 655 | ||
708 | - | | |
709 | - | ||
656 | + | (IV) THE SYSTEM ’S ABILITY TO CREATE AN EFFICIENT AND 3 | |
657 | + | SEAMLESS EXPERIENCE FOR USERS; 4 | |
710 | 658 | ||
711 | - | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , | |
712 | - | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY | |
713 | - | PREPAREDNESS ; | |
659 | + | (V) THE SYSTEM ’S EFFECTIVENESS IN A CHIEVING UNIT 5 | |
660 | + | OBJECTIVES; 6 | |
714 | 661 | ||
715 | - | | |
716 | - | ||
662 | + | (VI) THE SYSTEM’S EFFECTIVENESS IN M EETING THE NEEDS OF 7 | |
663 | + | CITIZENS AND CUSTOME RS; 8 | |
717 | 664 | ||
718 | - | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY | |
719 | - | STAFF TRAINING ; AND | |
665 | + | (VII) THE COSTS TO MAINTAI N AND OPERATE THE SY STEM; 9 | |
720 | 666 | ||
721 | - | (II) ASSIST LOCAL GOVERNM ENTS APPLYING FOR FE DERAL | |
722 | - | CYBERSECURITY PREPAR EDNESS GRANTS. | |
667 | + | (VIII) THE SPEED OF GOVERNM ENT RESPONSE TIME ; 10 | |
723 | 668 | ||
724 | - | (3) THE SECRETARY SHALL ADMIN ISTER THE FUND. | |
669 | + | (IX) THE EFFECTIVENESS OF THE SYSTEM IN REGARD TO THE 11 | |
670 | + | UNIT’S OBJECTIVES; 12 | |
725 | 671 | ||
726 | - | ( | |
727 | - | ||
672 | + | (X) IMPROVEMENTS TO THE UNIT’S RELATIVE AUDIT FIN DINGS 13 | |
673 | + | ATTRIBUTABLE TO THE SYSTEM; AND 14 | |
728 | 674 | ||
729 | - | ( | |
730 | - | ||
675 | + | (XI) AN ASSESSMENT OF THE SYSTEM USING THE NATIONAL 15 | |
676 | + | INSTITUTE OF STANDARDS AND TECHNOLOGY CYBERSECURITY FRAMEWORK . 16 | |
731 | 677 | ||
732 | - | (5) THE FUND CONSISTS OF : | |
678 | + | (B) (C) EACH UNIT SHALL PROMP TLY PROVIDE THE CONTRACTOR A 17 | |
679 | + | CONTRACTOR EMPLOYED UNDER SUBSECTION (B) OF THIS SECTION WITH THE 18 | |
680 | + | INFORMATION NECESSAR Y TO PERFORM THE ASS ESSMENTS. 19 | |
733 | 681 | ||
734 | - | ( | |
735 | - | ||
682 | + | (C) (D) (1) EACH YEAR, THE EVERY 3 2 YEARS, A CONTRACTOR SHALL 20 | |
683 | + | PROVIDE THE RESULTS OF THE ASSESSMENTS T O: 21 | |
736 | 684 | ||
737 | - | – 17 – | |
685 | + | (I) THE STATEWIDE REPORTING FRAMEWORK AND 22 | |
686 | + | OVERSIGHT MODERNIZE MARYLAND COMMISSION ESTABLISHE D UNDER § 3A–315 23 | |
687 | + | OF THIS SUBTITLE; AND 24 | |
738 | 688 | ||
739 | - | (II) INTEREST EARNINGS ; AND | |
689 | + | (II) IN ACCORDANCE WITH § 2–1257 OF THE STATE 25 | |
690 | + | GOVERNMENT ARTICLE, THE SENATE BUDGET AND TAXATION COMMITTEE, THE 26 | |
691 | + | SENATE EDUCATION, HEALTH, AND ENVIRONMENTAL AFFAIRS COMMITTEE, AND 27 | |
692 | + | THE HOUSE HEALTH AND GOVERNMENT OPERATIONS COMMITTEE. 28 | |
740 | 693 | ||
741 | - | (III) ANY OTHER MONEY FROM ANY OTHER SOURCE ACC EPTED | |
742 | - | FOR THE BENEFIT OF T HE FUND. | |
694 | + | (2) THE REPORT SUBMITTED UNDER PARAGRAPH (1)(II) OF THIS 29 | |
695 | + | SUBSECTION MAY NOT C ONTAIN INFORMATION A BOUT THE SECURITY OF AN 30 | |
696 | + | INFORMATION SYSTEM . 31 16 HOUSE BILL 1205 | |
743 | 697 | ||
744 | - | (6) THE FUND MAY BE USED ONLY : | |
745 | 698 | ||
746 | - | (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL | |
747 | - | GOVERNMENTS TO IMPRO VE CYBERSECURITY PRE PAREDNESS, INCLUDING: | |
748 | 699 | ||
749 | - | 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH | |
750 | - | THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; | |
700 | + | (D) (E) THE DEPARTMENT MAY USE FUNDS AVAILABLE FROM THE 1 | |
701 | + | ISSUANCE OF BONDS IN ACCORDANCE WITH § 10–650.1 OF THE ECONOMIC 2 | |
702 | + | DEVELOPMENT ARTICLE TO PAY FOR TH E INDEPENDENT CONTRA CTOR REQUIRED 3 | |
703 | + | UNDER MULTIPLE CONTRACTORS AT A TIME TO MEET TH E REQUIREMENTS OF THIS 4 | |
704 | + | SECTION. 5 | |
751 | 705 | ||
752 | - | 2. SUPPORTIN G THE PURCHASE OF NE W HARDWARE , | |
753 | - | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY | |
754 | - | PREPAREDNESS ; | |
706 | + | 3A–317. 6 | |
755 | 707 | ||
756 | - | 3. RECRUITING AND HIRIN G INFORMATION | |
757 | - | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND | |
708 | + | (A) THE DEPARTMENT SHALL CONS ULT WITH THE MARYLAND STADIUM 7 | |
709 | + | AUTHORITY REGARDING T HE ISSUANCE OF BONDS FOR UPGRADES TO 8 | |
710 | + | INFORMATION TECHNOLO GY AND CYBERSECURITY –RELATED STATE GOVERNMENT 9 | |
711 | + | INFRASTRUCTURE IN AC CORDANCE WITH § 10–650.1 OF THE ECONOMIC 10 | |
712 | + | DEVELOPMENT ARTICLE. 11 | |
758 | 713 | ||
759 | - | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY | |
760 | - | STAFF TRAINING ; | |
714 | + | (B) THE DEPARTMENT MAY USE TH E PROCEEDS FROM BONDS ISSUED FOR 12 | |
715 | + | UPGRADES TO INFORMAT ION TECHNOLOGY AND C YBERSECURITY –RELATED STATE 13 | |
716 | + | GOVERNMENT INFRASTRU CTURE UNDER § 10–650.1 OF THE ECONOMIC 14 | |
717 | + | DEVELOPMENT ARTICLE ONLY FOR PROJ ECTS THAT RELATE TO RESEARCH INTO , 15 | |
718 | + | ACQUISITION OF , INSTALLATION OF , MAINTENANCE OF, AND RELATED EXPENSES 16 | |
719 | + | FOR UPGRADES TO INFO RMATION TECHNOLOGY A ND CYBERSECURITY –RELATED 17 | |
720 | + | STATE GOVERNMENT INFR ASTRUCTURE . 18 | |
761 | 721 | ||
762 | - | ( | |
763 | - | ||
722 | + | (A) (1) IN THIS SECTION THE F OLLOWING WORDS HAVE THE MEANINGS 19 | |
723 | + | INDICATED. 20 | |
764 | 724 | ||
765 | - | (III) FOR ADMINISTRATIVE E XPENSES ASSOCIATED W ITH | |
766 | - | PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH . | |
725 | + | (2) “FUND” MEANS THE LOCAL CYBERSECURITY SUPPORT FUND. 21 | |
767 | 726 | ||
768 | - | ( | |
769 | - | ||
727 | + | (3) “LOCAL GOVERNMENT ” INCLUDES LOCAL SCHOO L SYSTEMS, 22 | |
728 | + | LOCAL SCHOOL BOARDS , AND LOCAL HEALTH DEP ARTMENTS. 23 | |
770 | 729 | ||
771 | - | (II) ANY INTEREST EARNINGS OF THE FUND SHALL BE | |
772 | - | CREDITED TO THE FUND. | |
730 | + | (B) (1) THERE IS A LOCAL CYBERSECURITY SUPPORT FUND. 24 | |
773 | 731 | ||
774 | - | (8) EXPENDITURES FROM THE FUND MA Y BE MADE ONLY IN | |
775 | - | ACCORDANCE WITH THE STATE BUDGET . | |
732 | + | (2) THE PURPOSE OF THE FUND IS TO: 25 | |
776 | 733 | ||
777 | - | (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL | |
778 | - | GOVERNMENT SHALL UND ERGO A CYBERSECURITY PREPAREDNESS ASSESSM ENT | |
779 | - | PROVIDED BY THE DEPARTMENT AT A COST TO THE LOCAL GOVERNM ENT THAT | |
780 | - | DOES NOT EXCEED THE COST TO THE DEPARTMENT OF PROVIDI NG THE | |
781 | - | ASSESSMENT . Ch. 243 2022 LAWS OF MARYLAND | |
734 | + | (I) PROVIDE FINANCIAL AS SISTANCE TO LOCAL GO VERNMENTS 26 | |
735 | + | TO IMPROVE CYBERSECU RITY PREPAREDNESS , INCLUDING: 27 | |
782 | 736 | ||
783 | - | – 18 – | |
737 | + | 1. UPDATING CURRENT DEV ICES AND NETWORKS WI TH 28 | |
738 | + | THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 29 | |
784 | 739 | ||
785 | - | 6–226. | |
740 | + | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 30 | |
741 | + | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 31 | |
742 | + | PREPAREDNESS ; 32 HOUSE BILL 1205 17 | |
786 | 743 | ||
787 | - | (a) (2) (i) Notwithstanding any other provision of law, and unless | |
788 | - | inconsistent with a federal law, grant agreement, or other federal requirement or with the | |
789 | - | terms of a gift or settlement agreement, net interest on all State money allocated by the | |
790 | - | State Treasurer under this section to special funds or accounts, and otherwise entitled to | |
791 | - | receive interest earnings, as accounted for by the Comptroller, shall accrue to the General | |
792 | - | Fund of the State. | |
793 | 744 | ||
794 | - | (ii) The provisions of subparagraph (i) of this paragraph do not apply | |
795 | - | to the following funds: | |
796 | 745 | ||
797 | - | | |
798 | - | ||
746 | + | 3. RECRUITING AND HIRIN G INFORMATION 1 | |
747 | + | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND 2 | |
799 | 748 | ||
800 | - | 145. the Access to Counsel in Evictions Special Fund; AND | |
749 | + | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 3 | |
750 | + | STAFF TRAINING; AND 4 | |
801 | 751 | ||
802 | - | | |
803 | - | CYBERSECURITY | |
752 | + | (II) ASSIST LOCAL GOVERNM ENTS APPLYING FOR FE DERAL 5 | |
753 | + | CYBERSECURITY PREPAR EDNESS GRANTS . 6 | |
804 | 754 | ||
805 | - | ||
755 | + | (3) THE SECRETARY SHALL ADMIN ISTER THE FUND. 7 | |
806 | 756 | ||
807 | - | (a) In this Division II the following words have the meanings indicated unless: | |
757 | + | (4) (I) THE FUND IS A SPECIAL, NONLAPSING FUND THAT IS NOT 8 | |
758 | + | SUBJECT TO § 7–302 OF THE STATE FINANCE AND PROCUREMENT ARTICLE. 9 | |
808 | 759 | ||
809 | - | (1) the context clearly requires a different meaning; or | |
760 | + | (II) THE STATE TREASURER SHALL HOLD THE FUND 10 | |
761 | + | SEPARATELY, AND THE COMPTROLLER SHALL ACC OUNT FOR THE FUND. 11 | |
810 | 762 | ||
811 | - | ( | |
763 | + | (5) THE FUND CONSISTS OF : 12 | |
812 | 764 | ||
813 | - | (m) “Primary procurement units” means: | |
765 | + | (I) MONEY APPROPRIATED I N THE STATE BUDGET TO THE 13 | |
766 | + | FUND; 14 | |
814 | 767 | ||
815 | - | ( | |
768 | + | (II) INTEREST EARNI NGS; AND 15 | |
816 | 769 | ||
817 | - | (2) the Department of General Services; | |
770 | + | (III) ANY OTHER MONEY FROM ANY OTHER SOURCE ACC EPTED 16 | |
771 | + | FOR THE BENEFIT OF T HE FUND. 17 | |
818 | 772 | ||
819 | - | ( | |
773 | + | (6) THE FUND MAY BE USED ONLY : 18 | |
820 | 774 | ||
821 | - | (4) the University System of Maryland; | |
775 | + | (I) TO PROVIDE FINANCIAL ASSISTANCE TO LOCAL 19 | |
776 | + | GOVERNMENTS TO IMPRO VE CYBERSECURITY PRE PAREDNESS, INCLUDING: 20 | |
822 | 777 | ||
823 | - | (5) the Maryland Port Commission; | |
778 | + | 1. UPDATING CURRENT DEVICES A ND NETWORKS WITH 21 | |
779 | + | THE MOST UP–TO–DATE CYBERSECURITY P ROTECTIONS; 22 | |
824 | 780 | ||
825 | - | (6) the Morgan State University; [and] | |
781 | + | 2. SUPPORTING THE PURCH ASE OF NEW HARDWARE , 23 | |
782 | + | SOFTWARE, DEVICES, AND FIREWALLS TO IMP ROVE CYBERSECURITY 24 | |
783 | + | PREPAREDNESS ; 25 | |
826 | 784 | ||
827 | - | (7) the St. Mary’s College of Maryland; AND | |
828 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
785 | + | 3. RECRUITING AND HIRIN G INFORMATION 26 | |
786 | + | TECHNOLOGY STAFF FOC USED ON CYBERSECURIT Y; AND 27 | |
787 | + | 18 HOUSE BILL 1205 | |
829 | 788 | ||
830 | - | – 19 – | |
831 | - | (8) THE DEPARTMENT OF INFORMATION TECHNOLOGY . | |
832 | 789 | ||
833 | - | 12–101. | |
790 | + | 4. PAYING OUTSIDE VENDO RS FOR CYBERSECURITY 1 | |
791 | + | STAFF TRAINING ; 2 | |
834 | 792 | ||
835 | - | (a) This section does not apply to: | |
793 | + | (II) TO ASSIST LOCAL GOVE RNMENTS APPLYING FOR FEDERAL 3 | |
794 | + | CYBERSECURITY PREPAR EDNESS GRANTS ; AND 4 | |
836 | 795 | ||
837 | - | (1) capital expenditures by the Department of Transportation or the | |
838 | - | Maryland Transportation Authority, in connection with State roads, bridges, or highways, | |
839 | - | as provided in § 12–202 of this title; OR | |
796 | + | (III) FOR ADMINISTRATIVE E XPENSES ASSOCIAT ED WITH 5 | |
797 | + | PROVIDING THE ASSIST ANCE DESCRIBED UNDER ITEM (I) OF THIS PARAGRAPH . 6 | |
840 | 798 | ||
841 | - | (2) PROCUREMENTS BY THE DEPARTMENT OF INFORMATION | |
842 | - | TECHNOLOGY GENERAL SERVICES FOR THE PURPOSE OF MODERNIZI NG | |
843 | - | CYBERSECURITY INFRAS TRUCTURE FOR THE STATE VALUED BELOW $1,000,000. | |
799 | + | (7) (I) THE STATE TREASURER SHALL INVES T THE MONEY OF THE 7 | |
800 | + | FUND IN THE SAME MANN ER AS OTHER STATE MONEY MAY BE IN VESTED. 8 | |
844 | 801 | ||
845 | - | (b) (1) The Board may control procurement by units. | |
802 | + | (II) ANY INTEREST EARNINGS OF THE FUND SHALL BE 9 | |
803 | + | CREDITED TO THE FUND. 10 | |
846 | 804 | ||
847 | - | (2) To implement the provisions of this Division II, the Board may: | |
805 | + | (8) EXPENDITURES FROM THE FUND MAY BE MADE ONLY IN 11 | |
806 | + | ACCORDANCE WITH THE STATE BUDGET . 12 | |
848 | 807 | ||
849 | - | (i) set policy; | |
808 | + | (C) TO BE ELIGIBLE TO REC EIVE ASSISTANCE FROM THE FUND, A LOCAL 13 | |
809 | + | GOVERNMENT SHALL UND ERGO A CYBERSECURITY PREPAREDNESS ASSESSM ENT 14 | |
810 | + | PROVIDED BY THE DEPARTMENT AT A COST TO THE LOCAL GOVERNM ENT THAT 15 | |
811 | + | DOES NOT EXCEED THE COST TO THE DEPARTMENT OF PROVIDI NG THE 16 | |
812 | + | ASSESSMENT . 17 | |
850 | 813 | ||
851 | - | (ii) adopt regulations, in accordance with Title 10, Subtitle 1 of the | |
852 | - | State Government Article; and | |
814 | + | 6–226. 18 | |
853 | 815 | ||
854 | - | (iii) establish internal operational procedures consistent with this | |
855 | - | Division II. | |
816 | + | (a) (2) (i) Notwithstanding any other provision of law, and unless 19 | |
817 | + | inconsistent with a federal law, grant agreement, or other federal requirement or with the 20 | |
818 | + | terms of a gift or settlement agreement, net interest on all State money allocated by the 21 | |
819 | + | State Treasurer under this section to special funds or accounts, and otherwise entitled to 22 | |
820 | + | receive interest earnings, as accounted for by the Comptroller, shall accrue to the General 23 | |
821 | + | Fund of the State. 24 | |
856 | 822 | ||
857 | - | (3) The Board shall ensure that the regulations of the primary | |
858 | - | procurement units provide for procedures that are consistent with this Division II and Title | |
859 | - | 13, Subtitle 4 of the State Personnel and Pensions Article and, to the extent the | |
860 | - | circumstances of a particular type of procurement or a particular unit do not require | |
861 | - | otherwise, are substantially the same. | |
823 | + | (ii) The provisions of subparagraph (i) of this paragraph do not apply 25 | |
824 | + | to the following funds: 26 | |
862 | 825 | ||
863 | - | (4) The Board may delegate any of its authority that it determines to be | |
864 | - | appropriate for delegation and may require prior Board approval for specified procurement | |
865 | - | actions. | |
826 | + | 144. the Health Equity Resource Community Reserve Fund; 27 | |
827 | + | [and] 28 | |
866 | 828 | ||
867 | - | (5) Except as limited by the Maryland Constitution, the Board may | |
868 | - | exercise any control authority conferred on a primary procurement unit by this Division II | |
869 | - | and, to the extent that its action conflicts with the action of the primary procurement unit, | |
870 | - | the action of the Board shall prevail. | |
829 | + | 145. the Access to Counsel in Evictions Special Fund; AND 29 | |
871 | 830 | ||
872 | - | (6) The Board shall develop and submit to the General Assembly, in | |
873 | - | accordance with § 2–1257 of the State Government Article, an annual report on the | |
874 | - | procurement system that includes information on actions necessary to improve effective | |
875 | - | broad–based competition in procurement. | |
876 | - | Ch. 243 2022 LAWS OF MARYLAND | |
831 | + | 146. THE INFORMATION TECHNOLOGY AND LOCAL 30 | |
832 | + | CYBERSECURITY INFRASTRUCTURE SUPPORT FUND. 31 | |
877 | 833 | ||
878 | - | – 20 – | |
879 | - | (C) ON OR BEFORE DECEMBER 1 EACH YEAR, THE DEPARTMENT OF | |
880 | - | INFORMATION TECHNOLOGY GENERAL SERVICES SHALL SUBMIT A REPOR T TO THE | |
881 | - | BOARD ON PROCUREMENTS MADE UNDER SUBSECTIO N (A)(2) OF THIS SECTION | |
882 | - | THAT SHALL INCLUDE F OR EACH PROCUREMENT : | |
834 | + | 11–101. 32 HOUSE BILL 1205 19 | |
883 | 835 | ||
884 | - | (1) THE PURPOSE OF THE P ROCUREMENT ; | |
885 | 836 | ||
886 | - | (2) THE NAME OF THE CONT RACTOR; | |
887 | 837 | ||
888 | - | ( | |
838 | + | (a) In this Division II the following words have the meanings indicated unless: 1 | |
889 | 839 | ||
890 | - | ( | |
840 | + | (1) the context clearly requires a different meaning; or 2 | |
891 | 841 | ||
892 | - | ( | |
842 | + | (2) a different definition is provided for a particular title or provision. 3 | |
893 | 843 | ||
894 | - | ( | |
844 | + | (m) “Primary procurement units” means: 4 | |
895 | 845 | ||
896 | - | ||
846 | + | (1) the State Treasurer; 5 | |
897 | 847 | ||
898 | - | (b) Subject to the authority of the Board, jurisdiction over procurement is as | |
899 | - | follows: | |
848 | + | (2) the Department of General Services; 6 | |
900 | 849 | ||
901 | - | ( | |
850 | + | (3) the Department of Transportation; 7 | |
902 | 851 | ||
903 | - | ( | |
852 | + | (4) the University System of Maryland; 8 | |
904 | 853 | ||
905 | - | 8. construction and construction–related services for State | |
906 | - | correctional facilities; AND | |
854 | + | (5) the Maryland Port Commission; 9 | |
907 | 855 | ||
908 | - | 9. supplies, materials, and equipment in support of | |
909 | - | construction and construction–related services for State correctional facilities in | |
910 | - | accordance with this Division II and Title 2 and Title 10, Subtitle 1 of the Correctional | |
911 | - | Services Article; AND | |
856 | + | (6) the Morgan State University; [and] 10 | |
912 | 857 | ||
913 | - | 10. [information processing equipment and associated | |
914 | - | services, as provided in Title 3A, Subtitle 3 of this article; and | |
858 | + | (7) the St. Mary’s College of Maryland; AND 11 | |
915 | 859 | ||
916 | - | 11.] telecommunication equipment, systems, or services, as | |
917 | - | provided in Title 3A, Subtitle 4 of this article; | |
860 | + | (8) THE DEPARTMENT OF INFORMATION TECHNOLOGY . 12 | |
918 | 861 | ||
919 | - | (3) the Department of Transportation and the Maryland Transportation | |
920 | - | Authority, without the approval of any of the other primary procurement units, may engage | |
921 | - | in the procurement of: | |
922 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
862 | + | 12–101. 13 | |
923 | 863 | ||
924 | - | – 21 – | |
925 | - | (vi) services for aeronautics related activities, including information | |
926 | - | processing services, but excluding banking and financial services under the authority of the | |
927 | - | State Treasurer under item (1) of this subsection; [and] | |
864 | + | (a) This section does not apply to: 14 | |
928 | 865 | ||
929 | - | (4) the Maryland Port Commission, without the approval of any of the | |
930 | - | other primary procurement units, may engage in the procurement of: | |
866 | + | (1) capital expenditures by the Department of Transportation or the 15 | |
867 | + | Maryland Transportation Authority, in connection with State roads, bridges, or highways, 16 | |
868 | + | as provided in § 12–202 of this title; OR 17 | |
931 | 869 | ||
932 | - | (v) leases of real property for port related activities unless the lease | |
933 | - | payments are from the General Fund of the State; AND | |
870 | + | (2) PROCUREMENTS BY THE DEPARTMENT OF INFORMATION 18 | |
871 | + | TECHNOLOGY GENERAL SERVICES FOR THE PURPOSE OF M ODERNIZING 19 | |
872 | + | CYBERSECURITY INFRAS TRUCTURE FOR THE STATE VALUED BELOW $1,000,000. 20 | |
934 | 873 | ||
935 | - | (5) THE DEPARTMENT OF INFORMATION TECHNOLOGY GENERAL | |
936 | - | SERVICES, WITHOUT THE APPROVAL OF ANY OTHER PRIMARY PROCUREMENT UNIT , | |
937 | - | MAY ENGAGE IN OR CON TROL PROCUREMENT OF : | |
874 | + | (b) (1) The Board may control procurement by units. 21 | |
938 | 875 | ||
939 | - | (I) INFORMATION PROCESSI NG EQUIPMENT , CLOUD | |
940 | - | COMPUTING EQUIPMENT , AND ASSOCIATED SERVI CES, AS PROVIDED IN TITLE 3A, | |
941 | - | SUBTITLE 3 OF THIS ARTICLE; AND | |
876 | + | (2) To implement the provisions of this Division II, the Board may: 22 | |
942 | 877 | ||
943 | - | (II) INFORMATION TECHNOLO GY SYSTEM AND | |
944 | - | MODERNIZATION , AS PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE; | |
878 | + | (i) set policy; 23 | |
945 | 879 | ||
946 | - | (III) TELECOMMUNICATION EQ UIPMENT, SYSTEMS, OR | |
947 | - | SERVICES, AS PROVIDED IN TITLE 3A, SUBTITLE 4 OF THIS ARTICLE; AND | |
880 | + | (ii) adopt regulations, in accordance with Title 10, Subtitle 1 of the 24 | |
881 | + | State Government Article; and 25 | |
882 | + | 20 HOUSE BILL 1205 | |
948 | 883 | ||
949 | - | (IV) CYBERSECURITY UPGRAD ES AND MODERNIZATION , AS | |
950 | - | PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE . | |
951 | 884 | ||
952 | - | 15–112. | |
885 | + | (iii) establish internal operational procedures consistent with this 1 | |
886 | + | Division II. 2 | |
953 | 887 | ||
954 | - | (a) (1) (i) Except as provided in subparagraph (ii) of this paragraph, this | |
955 | - | section applies to State procurement contracts for: | |
888 | + | (3) The Board shall ensure that the regulations of the primary 3 | |
889 | + | procurement units provide for procedures that are consistent with this Division II and Title 4 | |
890 | + | 13, Subtitle 4 of the State Personnel and Pensions Article and, to the extent the 5 | |
891 | + | circumstances of a particular type of procurement or a particular unit do not require 6 | |
892 | + | otherwise, are substantially the same. 7 | |
956 | 893 | ||
957 | - | 1. construction; | |
894 | + | (4) The Board may delegate any of its authority that it determines to be 8 | |
895 | + | appropriate for delegation and may require prior Board approval for specified procurement 9 | |
896 | + | actions. 10 | |
958 | 897 | ||
959 | - | 2. INFORMATION PROCESSI NG EQUIPMENT , CLOUD | |
960 | - | COMPUTING EQUIPMENT SERVICES, AND ASSOCIATED SERVI CES; AND | |
898 | + | (5) Except as limited by the Maryland Constitution, the Board may 11 | |
899 | + | exercise any control authority conferred on a primary procurement unit by this Division II 12 | |
900 | + | and, to the extent that its action conflicts with the action of the primary procurement unit, 13 | |
901 | + | the action of the Board shall prevail. 14 | |
961 | 902 | ||
962 | - | 3. IN ACCORDANCE WITH TITLE 3A, SUBTITLE 3 OF THIS | |
963 | - | ARTICLE, INFORMATION TECHN OLOGY SYSTEM AND CYB ERSECURITY UPGRADES | |
964 | - | AND MODERNIZATION . | |
903 | + | (6) The Board shall develop and submit to the General Assembly, in 15 | |
904 | + | accordance with § 2–1257 of the State Government Article, an annual report on the 16 | |
905 | + | procurement system that includes information on actions necessary to improve effective 17 | |
906 | + | broad–based competition in procurement. 18 | |
965 | 907 | ||
966 | - | ( | |
967 | - | ||
968 | - | ||
969 | - | ||
908 | + | (C) ON OR BEFORE DECEMBER 1 EACH YEAR, THE DEPARTMENT OF 19 | |
909 | + | INFORMATION TECHNOLOGY GENERAL SERVICES SHALL SUBMIT A REPOR T TO THE 20 | |
910 | + | BOARD ON PROCUREMENTS MADE UNDER S UBSECTION (A)(2) OF THIS SECTION 21 | |
911 | + | THAT SHALL INCLUDE F OR EACH PROCUREMENT : 22 | |
970 | 912 | ||
971 | - | – 22 – | |
972 | - | (ii) After work is completed, a unit shall: | |
913 | + | (1) THE PURPOSE OF THE P ROCUREMENT ; 23 | |
973 | 914 | ||
974 | - | 1. determine the actual quantity used to complete the | |
975 | - | contract; and | |
915 | + | (2) THE NAME OF THE CONT RACTOR; 24 | |
976 | 916 | ||
977 | - | 2. if necessary, issue a final adjustment change order to the | |
978 | - | contractor. | |
917 | + | (3) THE CONTRACT AMOUNT ; AND 25 | |
979 | 918 | ||
980 | - | (4) AN INDEPEND ENT CONTRACTOR WHO P ERFORMS AN | |
981 | - | ASSESSMENT UNDER § 3A–316 OF THIS ARTICLE MAY ISSUE A CHANGE ORDER ON | |
982 | - | THE ORIGINAL ASSESSM ENT CONTRACT FOR ANY SUBSEQUENT CYBERSECU RITY | |
983 | - | UPGRADES. | |
919 | + | (4) THE METHOD OF PROCUR EMENT UTILIZED ; 26 | |
984 | 920 | ||
985 | - | SECTION 2. AND BE IT FURTHER ENACTED, That this Act shall take effect July | |
986 | - | 1, 2022. | |
921 | + | (5) THE NUMBER OF BIDDER S WHO BID ON THE PROCU REMENT; AND 27 | |
987 | 922 | ||
988 | - | SECTION 2. AND BE IT FURTHER ENACTED, That for fiscal year 2023, funds | |
989 | - | from the Dedicated Purpose Account may be transferred by budget amendment in | |
990 | - | accordance with § 7–310 of the State Finance and Procurement Article to implement this | |
991 | - | Act. | |
923 | + | (4) (6) THE CONTRACT TERM . 28 | |
992 | 924 | ||
993 | - | SECTION 3. AND BE IT FURTHER ENACTED, That for fiscal year 2024, the | |
994 | - | Governor shall include in the annual budget bill an appropriation in an amount that is not | |
995 | - | less than 20% of the aggregated amount appropriated for information technology and | |
996 | - | cybersecurity resources in the annual budget bill for fiscal year 2023 for the Dedicated | |
997 | - | Purpose Account for cybersecurity. | |
925 | + | 12–107. 29 | |
998 | 926 | ||
999 | - | SECTION 4. AND BE IT FURTHER ENACTED, That: | |
927 | + | (b) Subject to the authority of the Board, jurisdiction over procurement is as 30 | |
928 | + | follows: 31 | |
1000 | 929 | ||
1001 | - | (a) On or before December 1, 2023, a public or private water or sewer system that | |
1002 | - | serves 10,000 or more users and receives financial assistance from the State shall: | |
930 | + | (2) the Department of General Services may: 32 HOUSE BILL 1205 21 | |
1003 | 931 | ||
1004 | - | (1) assess its vulnerability to a cyber attack; | |
1005 | 932 | ||
1006 | - | (2) if appropriate, develop a cybersecurity plan; and | |
1007 | 933 | ||
1008 | - | (3) submit a report to the General Assembly, in accordance with § 2–1257 of | |
1009 | - | the State Government Article, on the findings of the assessment conducted under this | |
1010 | - | subsection and any recommendations for statutory changes needed for the system to | |
1011 | - | appropriately address its cybersecurity. | |
934 | + | (i) engage in or control procurement of: 1 | |
1012 | 935 | ||
1013 | - | (b) The Maryland Water Quality Financing Administration may provide financial | |
1014 | - | assistance to a public water or wastewater system to assess system cybersecurity | |
1015 | - | vulnerabilities and develop a cybersecurity plan. | |
1016 | - | LAWRENCE J. HOGAN, JR., Governor Ch. 243 | |
936 | + | 8. construction and construction–related services for State 2 | |
937 | + | correctional facilities; AND 3 | |
1017 | 938 | ||
1018 | - | – 23 – | |
1019 | - | SECTION 4. 5. AND BE IT FURTHER ENACTED, That this Act is an emergency | |
1020 | - | measure, is necessary for the immediate preservation of the public health or safety, has been | |
1021 | - | passed by a yea and nay vote supported by three–fifths of all the members elected to each of | |
1022 | - | the two Houses of the General Assembly, and shall take effect from the date it is enacted. | |
939 | + | 9. supplies, materials, and equipment in support of 4 | |
940 | + | construction and construction–related services for State correctional facilities in 5 | |
941 | + | accordance with this Division II and Title 2 and Title 10, Subtitle 1 of the Correctional 6 | |
942 | + | Services Article; AND 7 | |
1023 | 943 | ||
1024 | - | Approved by the Governor, May 12, 2022. | |
944 | + | 10. [information processing equipment and associated 8 | |
945 | + | services, as provided in Title 3A, Subtitle 3 of this article; and 9 | |
946 | + | ||
947 | + | 11.] telecommunication equipment, systems, or services, as 10 | |
948 | + | provided in Title 3A, Subtitle 4 of this article; 11 | |
949 | + | ||
950 | + | (3) the Department of Transportation and the Maryland Transportation 12 | |
951 | + | Authority, without the approval of any of the other primary procurement units, may engage 13 | |
952 | + | in the procurement of: 14 | |
953 | + | ||
954 | + | (vi) services for aeronautics related activities, including information 15 | |
955 | + | processing services, but excluding banking and financial services under the authority of the 16 | |
956 | + | State Treasurer under item (1) of this subsection; [and] 17 | |
957 | + | ||
958 | + | (4) the Maryland Port Commission, without the approval of any of the 18 | |
959 | + | other primary procurement units, may engage in the procurement of: 19 | |
960 | + | ||
961 | + | (v) leases of real property for port related activities unless the lease 20 | |
962 | + | payments are from the General Fund of the State; AND 21 | |
963 | + | ||
964 | + | (5) THE DEPARTMENT OF INFORMATION TECHNOLOGY GENERAL 22 | |
965 | + | SERVICES, WITHOUT THE APPROVAL OF ANY OTHER PRIMARY PROCUREMENT UNIT , 23 | |
966 | + | MAY ENGAGE IN OR CON TROL PROCUREMENT OF : 24 | |
967 | + | ||
968 | + | (I) INFORMATION PROCESSI NG EQUIPMENT , CLOUD 25 | |
969 | + | COMPUTING EQUIPMENT , AND ASSOCIATED SERVI CES, AS PROVIDED IN TITLE 3A, 26 | |
970 | + | SUBTITLE 3 OF THIS ARTICLE; AND 27 | |
971 | + | ||
972 | + | (II) INFORMATION TECHNOLO GY SYSTEM AND 28 | |
973 | + | MODERNIZATION , AS PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE; 29 | |
974 | + | ||
975 | + | (III) TELECOMMUNICATION EQ UIPMENT, SYSTEMS, OR 30 | |
976 | + | SERVICES, AS PROVIDED IN TITLE 3A, SUBTITLE 4 OF THIS ARTICLE; AND 31 | |
977 | + | 22 HOUSE BILL 1205 | |
978 | + | ||
979 | + | ||
980 | + | (IV) CYBERSECURITY UPGRAD ES AND MODERNIZATION , AS 1 | |
981 | + | PROVIDED IN TITLE 3A, SUBTITLE 3 OF THIS ARTICLE . 2 | |
982 | + | ||
983 | + | 15–112. 3 | |
984 | + | ||
985 | + | (a) (1) (i) Except as provided in subparagraph (ii) of this paragraph, this 4 | |
986 | + | section applies to State procurement contracts for: 5 | |
987 | + | ||
988 | + | 1. construction; 6 | |
989 | + | ||
990 | + | 2. INFORMATION PROCESSI NG EQUIPMENT , CLOUD 7 | |
991 | + | COMPUTING EQUIPMENT SERVICES, AND ASSOCIATED SERVI CES; AND 8 | |
992 | + | ||
993 | + | 3. IN ACCORDANCE WITH TITLE 3A, SUBTITLE 3 OF THIS 9 | |
994 | + | ARTICLE, INFORMATION TECHNOLOGY SYSTEM AN D CYBERSECURITY UPGR ADES 10 | |
995 | + | AND MODERNIZATION . 11 | |
996 | + | ||
997 | + | (b) (3) (i) If a unit is to pay for a contract or a part of a contract using a 12 | |
998 | + | unit price methodology, a change order may not be required for work to continue and be 13 | |
999 | + | completed beyond the estimated quantities in the contract. 14 | |
1000 | + | ||
1001 | + | (ii) After work is completed, a unit shall: 15 | |
1002 | + | ||
1003 | + | 1. determine the actual quantity used to complete the 16 | |
1004 | + | contract; and 17 | |
1005 | + | ||
1006 | + | 2. if necessary, issue a final adjustment change order to the 18 | |
1007 | + | contractor. 19 | |
1008 | + | ||
1009 | + | (4) AN INDEPEND ENT CONTRACTOR WHO P ERFORMS AN 20 | |
1010 | + | ASSESSMENT UNDER § 3A–316 OF THIS ARTICLE MAY ISSUE A CHANGE ORDER ON 21 | |
1011 | + | THE ORIGINAL ASSESSM ENT CONTRACT FOR ANY SUBSEQUENT CYBERSECU RITY 22 | |
1012 | + | UPGRADES. 23 | |
1013 | + | ||
1014 | + | SECTION 2. AND BE IT FURTHER ENACTED, That this Act shall take effect July 24 | |
1015 | + | 1, 2022. 25 | |
1016 | + | ||
1017 | + | SECTION 2. AND BE IT FURTHER ENACTED, That for fiscal year 2023, funds 26 | |
1018 | + | from the Dedicated Purpose Account may be transferred by budget amendment in 27 | |
1019 | + | accordance with § 7–310 of the State Finance and Procurement Article to implement this 28 | |
1020 | + | Act. 29 | |
1021 | + | ||
1022 | + | SECTION 3. AND BE IT FURTHER ENACTED, That for fiscal year 2024, the 30 | |
1023 | + | Governor shall include in the annual budget bill an appropriation in an amount that is not 31 | |
1024 | + | less than 20% of the aggregated amount appropriated for information technology and 32 HOUSE BILL 1205 23 | |
1025 | + | ||
1026 | + | ||
1027 | + | cybersecurity resources in the annual budget bill for fiscal year 2023 for the Dedicated 1 | |
1028 | + | Purpose Account for cybersecurity. 2 | |
1029 | + | ||
1030 | + | SECTION 4. AND BE IT FURTHER ENACTED, That: 3 | |
1031 | + | ||
1032 | + | (a) On or before December 1, 2023, a public or private water or sewer system that 4 | |
1033 | + | serves 10,000 or more users and receives financial assistance from the State shall: 5 | |
1034 | + | ||
1035 | + | (1) assess its vulnerability to a cyber attack; 6 | |
1036 | + | ||
1037 | + | (2) if appropriate, develop a cybersecurity plan; and 7 | |
1038 | + | ||
1039 | + | (3) submit a report to the General Assembly, in accordance with § 2–1257 of 8 | |
1040 | + | the State Government Article, on the findings of the assessment conducted under this 9 | |
1041 | + | subsection and any recommendations for statutory changes needed for the system to 10 | |
1042 | + | appropriately address its cybersecurity. 11 | |
1043 | + | ||
1044 | + | (b) The Maryland Water Quality Financing Administration may provide financial 12 | |
1045 | + | assistance to a public water or wastewater system to assess system cybersecurity 13 | |
1046 | + | vulnerabilities and develop a cybersecurity plan. 14 | |
1047 | + | ||
1048 | + | SECTION 4. 5. AND BE IT FURTHER ENACTED, That this Act is an emergency 15 | |
1049 | + | measure, is necessary for the immediate preservation of the public health or safety, has been 16 | |
1050 | + | passed by a yea and nay vote supported by three–fifths of all the members elected to each of 17 | |
1051 | + | the two Houses of the General Assembly, and shall take effect from the date it is enacted. 18 | |
1052 | + | ||
1053 | + | ||
1054 | + | ||
1055 | + | ||
1056 | + | Approved: | |
1057 | + | ________________________________________________________________________________ | |
1058 | + | Governor. | |
1059 | + | ________________________________________________________________________________ | |
1060 | + | Speaker of the House of Delegates. | |
1061 | + | ________________________________________________________________________________ | |
1062 | + | President of the Senate. |