Maryland 2023 Regular Session

Maryland Senate Bill SB868 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11
22
33 EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW.
44 [Brackets] indicate matter deleted from existing law.
55 *sb0868*
66
77 SENATE BILL 868
88 S2 3lr2724
99
1010 By: Senator Hester
1111 Introduced and read first time: February 6, 2023
1212 Assigned to: Education, Energy, and the Environment
1313
1414 A BILL ENTITLED
1515
1616 AN ACT concerning 1
1717
1818 State and Local Cybersecurity – Revisions 2
1919
2020 FOR the purpose of establishing the Director of Cybersecurity Preparedness in the Cyber 3
2121 Preparedness Unit of the Maryland Department of Emergency Management; 4
2222 establishing certain duties of the Director; specifying the amount of a certain annual 5
2323 appropriation made by the Governor to the Unit; establishing that the State Chief 6
2424 Information Security Officer in the Office of Security Management reports to the 7
2525 Governor; altering certain qualifications and duties of the State Chief Information 8
2626 Security Officer; altering certain duties of the Office; altering certain duties of the 9
2727 Secretary of Information Technology; altering the membership of the Modernize 10
2828 Maryland Oversight Commission and providing for the appointment of the chair and 11
2929 vice chair of the Commission; altering the duties of certain independent contractors 12
3030 hired by the Department of Information Technology; establishing that certain 13
3131 information related to cybersecurity incidents reported by local governments may 14
3232 not be used in a certain manner; authorizing the Office to ensure compliance of an 15
3333 agency’s cybersecurity with cybersecurity standards in a certain manner; requiring 16
3434 a certain independent contractor hired by the Department of Information Technology 17
3535 to provide certain quarterly updates on its work; requiring a certain report by the 18
3636 Commission to include a certain evaluation; requiring the Department of 19
3737 Information Technology to hire an independent contractor to conduct a certain 20
3838 review; and generally relating to State and local cybersecurity. 21
3939
4040 BY repealing and reenacting, with amendments, 22
4141 Article – Public Safety 23
4242 Section 14–104.1 24
4343 Annotated Code of Maryland 25
4444 (2022 Replacement Volume) 26
4545
4646 BY repealing and reenacting, without amendments, 27
4747 Article – State Finance and Procurement 28
4848 Section 3.5–2A–02 and 3.5–301(a) 29 2 SENATE BILL 868
4949
5050
5151 Annotated Code of Maryland 1
5252 (2021 Replacement Volume and 2022 Supplement) 2
5353
5454 BY repealing and reenacting, with amendments, 3
5555 Article – State Finance and Procurement 4
5656 Section 3.5–2A–03, 3.5–2A–04(b)(11), 3.5–301(i), 3.5–303(a) and (d), 3.5–316, 5
5757 3.5–317(b)(1), and 3.5–407(d) 6
5858 Annotated Code of Maryland 7
5959 (2021 Replacement Volume and 2022 Supplement) 8
6060
6161 BY adding to 9
6262 Article – State Finance and Procurement 10
6363 Section 3.5–318 11
6464 Annotated Code of Maryland 12
6565 (2021 Replacement Volume and 2022 Supplement) 13
6666
6767 BY repealing and reenacting, with amendments, 14
6868 Chapter 242 of the Acts of the General Assembly of 2022 15
6969 Section 5 and 6 16
7070
7171 SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 17
7272 That the Laws of Maryland read as follows: 18
7373
7474 Article – Public Safety 19
7575
7676 14–104.1. 20
7777
7878 (a) (1) In this section the following words have the meanings indicated. 21
7979
8080 (2) “Local government” includes local school systems, local school boards, 22
8181 and local health departments. 23
8282
8383 (3) “Unit” means the Cyber Preparedness Unit. 24
8484
8585 (b) (1) There is a Cyber Preparedness Unit in the Department. 25
8686
8787 (2) (I) THE HEAD OF THE UNIT IS THE DIRECTOR OF 26
8888 CYBERSECURITY PREPAREDNESS . 27
8989
9090 (II) THE DIRECTOR SHALL WORK I N COORDINATIO N WITH THE 28
9191 DIRECTOR OF LOCAL CYBERSECURITY IN THE OFFICE OF SECURITY MANAGEMENT 29
9292 TO PROVIDE TECHNICAL ASSISTANCE, COORDINATE RESOURCES , AND IMPROVE 30
9393 CYBERSECURITY PREPAR EDNESS FOR UNITS OF LOCAL GOVERNMENT . 31
9494
9595 [(2)] (3) In coordination with the State Chief Information Security 32
9696 Officer, the Unit shall: 33 SENATE BILL 868 3
9797
9898
9999
100100 (i) support local governments in developing a vulnerability 1
101101 assessment and cyber assessment, including providing local governments with the 2
102102 resources and information on best practices to complete the assessments; 3
103103
104104 (ii) develop and regularly update an online database of cybersecurity 4
105105 training resources for local government personnel, including technical training resources, 5
106106 cybersecurity continuity of operations templates, consequence management plans, and 6
107107 trainings on malware and ransomware detection; 7
108108
109109 (iii) assist local governments in: 8
110110
111111 1. the development of cybersecurity preparedness and 9
112112 response plans; 10
113113
114114 2. implementing best practices and guidance developed by 11
115115 the State Chief Information Security Officer; and 12
116116
117117 3. identifying and acquiring resources to complete 13
118118 appropriate cybersecurity vulnerability assessments; 14
119119
120120 (iv) connect local governments to appropriate resources for any other 15
121121 purpose related to cybersecurity preparedness and response; 16
122122
123123 (v) as necessary and in coordination with the National Guard, local 17
124124 emergency managers, and other State and local entities, conduct regional cybersecurity 18
125125 preparedness exercises; and 19
126126
127127 (vi) establish regional assistance groups to deliver and coordinate 20
128128 support services to local governments, agencies, or regions. 21
129129
130130 [(3)] (4) The Unit shall support the Office of Security Management in the 22
131131 Department of Information Technology during emergency response efforts. 23
132132
133133 (c) (1) Each local government shall report a cybersecurity incident, including 24
134134 an attack on a State system being used by the local government, to the appropriate local 25
135135 emergency manager and the State Security Operations Center in the Department of 26
136136 Information Technology [and to the Maryland Joint Operations Center in the Department] 27
137137 in accordance with paragraph (2) of this subsection. 28
138138
139139 (2) For the reporting of cybersecurity incidents under paragraph (1) of this 29
140140 subsection, the State Chief Information Security Officer shall determine: 30
141141
142142 (i) the criteria for determining when an incident must be reported; 31
143143
144144 (ii) the manner in which to report; and 32
145145 4 SENATE BILL 868
146146
147147
148148 (iii) the time period within which a report must be made. 1
149149
150150 (3) The State Security Operations Center shall immediately notify 2
151151 appropriate agencies of a cybersecurity incident reported under this subsection through the 3
152152 State Security Operations Center. 4
153153
154154 (d) (1) Five Position Identification Numbers (PINs) shall be created for the 5
155155 purpose of hiring staff to conduct the duties of the Maryland Department of Emergency 6
156156 Management Cybersecurity Preparedness Unit. 7
157157
158158 (2) For fiscal year 2024 and each fiscal year thereafter, the Governor shall 8
159159 include in the annual budget bill an appropriation [of at least: 9
160160
161161 (i) $220,335 for 3 PINs for Administrator III positions; and 10
162162
163163 (ii) $137,643 for 2 PINs for Administrator II positions] SUFFICIENT 11
164164 FOR THE POSITIONS CR EATED UNDER PARAGRAP H (1) OF THIS SUBSECTION . 12
165165
166166 Article – State Finance and Procurement 13
167167
168168 3.5–2A–02. 14
169169
170170 There is an Office of Security Management within the Department. 15
171171
172172 3.5–2A–03. 16
173173
174174 (a) The head of the Office is the State Chief Information Security Officer. 17
175175
176176 (b) The State Chief Information Security Officer shall: 18
177177
178178 (1) be appointed by the Governor with the advice and consent of the Senate; 19
179179
180180 (2) serve at the pleasure of the Governor; AND 20
181181
182182 (3) be supervised by the [Secretary; and 21
183183
184184 (4) serve as the chief information security officer of the Department] 22
185185 GOVERNOR. 23
186186
187187 (c) An individual appointed as the State Chief Information Security Officer under 24
188188 subsection (b) of this section shall: 25
189189
190190 (1) [at a minimum, hold a bachelor’s degree; 26
191191
192192 (2)] hold appropriate information technology or cybersecurity certifications; 27
193193 SENATE BILL 868 5
194194
195195
196196 [(3)] (2) have experience: 1
197197
198198 (i) identifying, implementing, or assessing security controls; 2
199199
200200 (ii) in infrastructure, systems engineering, or cybersecurity; 3
201201
202202 (iii) managing highly technical security, security operations centers, 4
203203 and incident response teams in a complex cloud environment and supporting multiple sites; 5
204204 and 6
205205
206206 (iv) working with common information security management 7
207207 frameworks; 8
208208
209209 [(4)] (3) have extensive knowledge of information technology and 9
210210 cybersecurity field concepts, best practices, and procedures, with an understanding of 10
211211 existing enterprise capabilities and limitations to ensure the secure integration and 11
212212 operation of security networks and systems; and 12
213213
214214 [(5)] (4) have knowledge of current security regulations. 13
215215
216216 (d) The State Chief Information Security Officer shall: 14
217217
218218 (1) provide cybersecurity advice and recommendations to the Governor on 15
219219 request; AND 16
220220
221221 (2) DEVELOP AND MAINTAIN A STATEWIDE CYBERSEC URITY 17
222222 STRATEGY THAT WILL : 18
223223
224224 (I) CENTRALIZE THE MANAG EMENT AND DIRECTION OF 19
225225 CYBERSECURITY STRATE GY WITHIN THE EXECUTIVE BRANCH OF STATE 20
226226 GOVERNMENT UNDER THE CONTROL OF THE DEPARTMENT ; AND 21
227227
228228 (II) SERVE AS THE BASIS F OR BUDGET ALLOCATION S FOR 22
229229 CYBERSECURITY PREPAR EDNESS FOR THE EXECUTIVE BRANCH OF STATE 23
230230 GOVERNMENT . 24
231231
232232 (e) (1) (i) There is a Director of Local Cybersecurity, who shall be 25
233233 appointed by the State Chief Information Security Officer. 26
234234
235235 (ii) The Director of Local Cybersecurity shall: 27
236236
237237 1. work in coordination with the Maryland Department of 28
238238 Emergency Management to provide technical assistance, coordinate resources, and improve 29
239239 cybersecurity preparedness for units of local government; AND 30
240240 6 SENATE BILL 868
241241
242242
243243 2. IN CONSULTATION WITH THE MARYLAND 1
244244 CYBERSECURITY COORDINATING COUNCIL, DEVELOP GUIDANCE ON CONSISTENT 2
245245 CYBERSECURITY STRATE GIES FOR COUNTIES , MUNICIPAL CORPORATIO NS, SCHOOL 3
246246 SYSTEMS, AND ALL OTHER POLITI CAL SUBDIVISIONS OF THE STATE. 4
247247
248248 (2) (i) There is a Director of State Cybersecurity, who shall be 5
249249 appointed by the State Chief Information Security Officer. 6
250250
251251 (ii) The Director of State Cybersecurity is responsible for 7
252252 implementation of this section with respect to units of State government. 8
253253
254254 (III) IN CONSULTATION WITH THE MARYLAND CYBERSECURITY 9
255255 COORDINATING COUNCIL, THE DIRECTOR OF STATE CYBERSECURITY SHALL 10
256256 ADVISE AND OVERSEE A CONSISTENT CYBERSECU RITY STRATEGY FOR UN ITS OF 11
257257 STATE GOVERNMENT , INCLUDING INSTITUT IONS UNDER THE CONTR OL OF THE 12
258258 GOVERNING BOARDS OF THE PUBLIC INSTITUTI ONS OF HIGHER EDUCAT ION. 13
259259
260260 (f) The Department shall provide the Office with sufficient staff to perform the 14
261261 functions of this subtitle. 15
262262
263263 (G) THE GOVERNOR SHALL INCLUD E AN APPROPRIATION IN THE ANNUAL 16
264264 BUDGET BILL IN AN AM OUNT NECESSARY TO CO VER THE COSTS OF IMP LEMENTING 17
265265 THE STATEWIDE CYBERS ECURITY STRATEGY DEV ELOPED UNDER SUBSECT ION (D) 18
266266 OF THIS SECTION WITH OUT THE NEED FOR THE OFFICE TO OPERATE A 19
267267 CHARGE–BACK MODEL FOR CYBER SECURITY SERVIC ES PROVIDED TO OTHER UNITS 20
268268 OF STATE GOVERNMENT OR U NITS OF LOCAL GOVERN MENT. 21
269269
270270 3.5–2A–04. 22
271271
272272 (b) The Office shall: 23
273273
274274 (11) develop and maintain information technology security policy, 24
275275 standards, and guidance documents, consistent with [best practices developed by the] A 25
276276 WIDELY RECOGNIZED SE CURITY STANDARD , INCLUDING: 26
277277
278278 (I) National Institute of Standards and Technology (NIST) 27
279279 CYBERSECURITY FRAMEWORK , NIST 800–53, OR INTERNATIONAL ORGANIZATION 28
280280 FOR STANDARDIZATION (ISO) ISO 27001; OR 29
281281
282282 (II) IN THE CASE OF ORGANIZATIONS HANDLING CONTROLLED 30
283283 UNCLASSIFIED INFORMA TION, NIST SP 800–171 OR THE CYBERSECURITY 31
284284 MATURITY MODEL CERTIFICATION FROM TH E U.S. DEPARTMENT OF DEFENSE; 32
285285
286286 3.5–301. 33
287287 SENATE BILL 868 7
288288
289289
290290 (a) In this subtitle the following words have the meanings indicated. 1
291291
292292 (i) “Master plan” means the statewide information technology master plan [and 2
293293 statewide cybersecurity strategy]. 3
294294
295295 3.5–303. 4
296296
297297 (a) The Secretary is responsible for carrying out the following duties: 5
298298
299299 (1) developing, maintaining, revising, and enforcing inform ation 6
300300 technology policies, procedures, and standards; 7
301301
302302 (2) providing technical assistance, advice, and recommendations to the 8
303303 Governor and any unit of State government concerning information technology matters; 9
304304
305305 (3) reviewing the annual project plan for each unit of State government to 10
306306 make information and services available to the public over the Internet; 11
307307
308308 (4) developing and maintaining a statewide information technology master 12
309309 plan that will: 13
310310
311311 (i) centralize the management and direction of information 14
312312 technology policy within the Executive Branch of State government under the control of the 15
313313 Department; 16
314314
315315 (ii) include all aspects of State information technology including 17
316316 telecommunications, security, data processing, and information management; 18
317317
318318 (iii) consider interstate transfers as a result of federal legislation and 19
319319 regulation; 20
320320
321321 (iv) ensure that the State information technology plan and related 21
322322 policies and standards are consistent with State goals, objectives, and resources, and 22
323323 represent a long–range vision for using information technology to improve the overall 23
324324 effectiveness of State government; 24
325325
326326 (v) include standards to assure nonvisual access to the information 25
327327 and services made available to the public over the Internet; and 26
328328
329329 (vi) allows a State agency to maintain the agency’s own information 27
330330 technology unit that provides for information technology services to support the mission of 28
331331 the agency; 29
332332
333333 (5) [developing and maintaining a statewide cybersecurity strategy that 30
334334 will: 31
335335 8 SENATE BILL 868
336336
337337
338338 (i) centralize the management and direction of cybersecurity 1
339339 strategy within the Executive Branch of State government under the control of the 2
340340 Department; and 3
341341
342342 (ii) serve as the basis for budget allocations for cybersecurity 4
343343 preparedness for the Executive Branch of State government; 5
344344
345345 (6)] adopting by regulation and enforcing nonvisual access standards to be 6
346346 used in the procurement of information technology services by or on behalf of units of State 7
347347 government in accordance with subsection (b) of this section; 8
348348
349349 [(7) in consultation with the Maryland Cybersecurity Coordinating Council, 9
350350 advising and overseeing a consistent cybersecurity strategy for units of State government, 10
351351 including institutions under the control of the governing boards of the public institutions 11
352352 of higher education; 12
353353
354354 (8)] (6) advising and consulting with the Legislative and Judicial 13
355355 branches of State government regarding a cybersecurity strategy; 14
356356
357357 [(9) in consultation with the Maryland Cybersecurity Coordinating Council, 15
358358 developing guidance on consistent cybersecurity strategies for counties, municipal 16
359359 corporations, school systems, and all other political subdivisions of the State; 17
360360
361361 (10)] (7) upgrading information technology and cybersecurity–related 18
362362 State government infrastructure; and 19
363363
364364 [(11)] (8) annually evaluating: 20
365365
366366 (i) the feasibility of units of State government providing public 21
367367 services using artificial intelligence, machine learning, commercial cloud computer 22
368368 services, device–as–a–service procurement models, and other emerging technologies; and 23
369369
370370 (ii) the development of data analytics capabilities to enable 24
371371 data–driven policymaking by units of State government. 25
372372
373373 (d) [(1) The Governor shall include an appropriation in the annual budget bill 26
374374 in an amount necessary to cover the costs of implementing the statewide cybersecurity 27
375375 master plan developed under subsection (a) of this section without the need for the 28
376376 Department to operate a charge–back model for cybersecurity services provided to other 29
377377 units of State government or units of local government. 30
378378
379379 (2)] On or before January 31 each year, in a separate report or included 31
380380 within a general budget report, the Governor shall submit a report in accordance with § 32
381381 2–1257 of the State Government Article to the Senate Budget and Taxation Committee and 33
382382 the House Appropriations Committee that includes: 34
383383 SENATE BILL 868 9
384384
385385
386386 [(i)] (1) specific information on the information technology budget 1
387387 and cybersecurity budget that the Governor has submitted to the General Assembly for the 2
388388 upcoming fiscal year; and 3
389389
390390 [(ii)] (2) how the budgets listed under item [(i)] (1) of this 4
391391 [paragraph] SUBSECTION compare to the annual overview of the U.S. President’s budget 5
392392 submission on information technology and cybersecurity to Congress conducted by the U.S. 6
393393 Office of Management and Budget. 7
394394
395395 3.5–316. 8
396396
397397 (a) (1) In this section the following words have the meanings indicated. 9
398398
399399 (2) “Commission” means the Modernize Maryland Oversight Commission. 10
400400
401401 (3) “Critical system” means an information technology or cybersecurity 11
402402 system that is severely outdated, as determined by the Department. 12
403403
404404 (b) There is an independent Modernize Maryland Oversight Commission. 13
405405
406406 (c) The purpose of the Commission is to: 14
407407
408408 (1) ensure the confidentiality, integrity, and availability of information 15
409409 held by the State concerning State residents; and 16
410410
411411 (2) advise the Secretary and State Chief Information Security Officer on: 17
412412
413413 (i) the appropriate information technology and cybersecurity 18
414414 investments and upgrades; 19
415415
416416 (ii) the funding sources for the appropriate information technology 20
417417 and cybersecurity upgrades; and 21
418418
419419 (iii) future mechanisms for the procurement of appropriate 22
420420 information technology and cybersecurity upgrades, including ways to increase the 23
421421 efficiency of procurements made for information technology and cybersecurity upgrades. 24
422422
423423 (d) The Commission consists of the following members: 25
424424
425425 (1) the Secretary; 26
426426
427427 (2) the State Chief Information Security Officer; 27
428428
429429 (3) three chief information security officers representing different units of 28
430430 State government, appointed by the Governor; 29
431431 10 SENATE BILL 868
432432
433433
434434 (4) one information technology modernization expert with experience in 1
435435 the private sector, appointed by the Governor; 2
436436
437437 (5) one representative from the Maryland Chamber of Commerce with 3
438438 knowledge of cybersecurity issues; 4
439439
440440 (6) ONE REPRESENTATIVE F ROM THE MARYLAND CHAMBER OF 5
441441 COMMERCE WITH EXPERTI SE IN INFORMATION TE CHNOLOGY MODERNIZATI ON IN 6
442442 THE PRIVATE SECTOR ; 7
443443
444444 [(6)] (7) two individuals who are end users of State information 8
445445 technology systems AND WHO ARE NOT STATE EMPLOYEES , appointed by the Governor; 9
446446
447447 [(7)] (8) one representative from the Cybersecurity Association of 10
448448 Maryland; [and] 11
449449
450450 [(8)] (9) one individual who is either an instructor or a professional in the 12
451451 academic field of cybersecurity OR INFORMATION TECHN OLOGY MODERNIZATION at a 13
452452 college or university in the State, appointed by the Governor; AND 14
453453
454454 (10) ONE INDIVIDUAL WITH EXPERIENCE WORKI NG WITH THE STATE 15
455455 BUDGET AND APPROPRIA TIONS, APPOINTED JOINTLY BY THE PRESIDENT OF THE 16
456456 SENATE AND THE SPEAKER OF THE HOUSE. 17
457457
458458 (e) The cochairs of the Joint Committee on Cybersecurity, Information 18
459459 Technology, and Biotechnology shall serve as advisory, nonvoting members of the 19
460460 Commission. 20
461461
462462 (F) THE CHAIR OF THE COMMISSION MAY APPOIN T THREE ADDITIONAL 21
463463 MEMBERS, AS NECESSARY. 22
464464
465465 (G) THE CHAIR AND VICE CH AIR OF THE COMMISSION SHALL BE ELECTED 23
466466 FROM AMONG THE MEMBE RS OF THE COMMISSION WHO ARE NO T EMPLOYED BY 24
467467 STATE OR LOCAL GOVERNMENT . 25
468468
469469 [(f)] (H) The Commission shall: 26
470470
471471 (1) advise the Secretary AND THE STATE CHIEF INFORMATION 27
472472 SECURITY OFFICER on a strategic roadmap with a timeline and budget that will: 28
473473
474474 (i) require the updates and investments of critical information 29
475475 technology and cybersecurity systems identified by the Commission in the first 30
476476 recommendations reported under paragraph (2) of this subsection to be completed on or 31
477477 before December 31, 2025; and 32
478478 SENATE BILL 868 11
479479
480480
481481 (ii) require all updates and investments of information technology 1
482482 and cybersecurity to be made on or before December 31, 2030; 2
483483
484484 (2) make periodic recommendations on investments in State information 3
485485 technology structures based on the assessments completed in accordance with the 4
486486 framework developed in § 3.5–317 of this subtitle; 5
487487
488488 (3) review and provide recommendations on the Department’s basic 6
489489 security standards for use of the network established under § 3.5–404(b) of this title; and 7
490490
491491 (4) each year, in accordance with § 2–1257 of the State Government Article, 8
492492 report its findings and recommendations to the Senate Budget and Taxation Committee, 9
493493 the Senate [Education, Health, and Environmental Affairs] EDUCATION, ENERGY, AND 10
494494 THE ENVIRONMENT Committee, the House Appropriations Committee, the House Health 11
495495 and Government Operations Committee, and the Joint Committee on Cybersecurity, 12
496496 Information Technology, and Biotechnology. 13
497497
498498 [(g)] (I) The report submitted under subsection [(f)(4)] (H)(4) of this section 14
499499 may not contain information about the security of an information system. 15
500500
501501 3.5–317. 16
502502
503503 (b) (1) The Department shall hire independent contractors to: 17
504504
505505 (i) develop a framework for investments in technology, INCLUDING 18
506506 FOUNDATIONAL INFORMA TION TECHNOLOGY PROJ ECTS THAT IMPACT MUL TIPLE 19
507507 UNITS OF STATE GOVERNMENT ; and 20
508508
509509 (ii) at least once every 2 years, in accordance with the framework, 21
510510 assess the cybersecurity and information technology systems in each unit of State 22
511511 government. 23
512512
513513 3.5–318. 24
514514
515515 (A) FOR FISCAL YEAR 2025 AND EACH FISCAL YEAR THEREAFTER , THE 25
516516 GOVERNOR SHA LL INCLUDE IN THE AN NUAL BUDGET BILL AN APPROPRIATION IN 26
517517 AN AMOUNT THAT IS NO T LESS THAN 20% OF THE AGGREGATED AM OUNT 27
518518 APPROPRIATED FOR INF ORMATION TECHNOLOGY RESOURCES IN THE ANN UAL 28
519519 BUDGET BILL FOR THE PRIOR FISCAL YEAR FO R THE DEDICATED PURPOSE 29
520520 ACCOUNT FO R CYBERSECURITY . 30
521521
522522 (B) THE APPROPRIATIONS FO R EACH FISCAL YEAR U NDER SUBSECTION (A) 31
523523 OF THIS SECTION SHAL L BE USED TO SUPPLEM ENT, NOT SUPPLANT , ANY EXISTING 32
524524 FUNDS IN THE DEDICATED PURPOSE ACCOUNT FOR CYBERSECU RITY THAT MAY 33
525525 HAVE ACCRUED FROM A PRIOR FISCAL YEAR. 34 12 SENATE BILL 868
526526
527527
528528
529529 3.5–407. 1
530530
531531 (d) (1) Each local government shall report a cybersecurity incident, including 2
532532 an attack on a State system being used by the local government, to the appropriate local 3
533533 emergency manager and the State Security Operations Center in the Department in 4
534534 accordance with paragraph (2) of this subsection. 5
535535
536536 (2) For the reporting of cybersecurity incidents to local emergency 6
537537 managers under subparagraph (i) of this paragraph, the State Chief Information Security 7
538538 Officer shall determine: 8
539539
540540 (i) the criteria for determining when an incident must be reported; 9
541541
542542 (ii) the manner in which to report; and 10
543543
544544 (iii) the time period within which a report must be made. 11
545545
546546 (3) The State Security Operations Center shall immediately notify the 12
547547 appropriate agencies of a cybersecurity incident reported under this subsection through the 13
548548 State Security Operations Center. 14
549549
550550 (4) INFORMATION REPORTED BY A LOCAL GOVERNMEN T UNDER THIS 15
551551 SUBSECTION MAY NOT B E USED BY THE STATE AS A BASIS FOR IMPOSING A FINE , 16
552552 RESTRICTING FUNDING , OR OTHERWISE PENALIZ ING THE LOCAL GOVERN MENT. 17
553553
554554 Chapter 242 of the Acts of 2022 18
555555
556556 SECTION 5. AND BE IT FURTHE R ENACTED, That: 19
557557
558558 (a) (1) On or before June 30, 2023, each agency in the Executive Branch of 20
559559 State government shall certify to the Office of Security Management compliance with State 21
560560 minimum cybersecurity standards established by the Department of Infor mation 22
561561 Technology. 23
562562
563563 (2) Except as provided in paragraph (3) of this subsection, certification 24
564564 shall be reviewed by independent auditors, and any findings must be remediated. 25
565565
566566 (3) Certification for the Department of Public Safety and Correctional 26
567567 Services and any State criminal justice agency shall be reviewed by the Office of Legislative 27
568568 Audits, and any findings must be remediated. 28
569569
570570 (b) Except as provided in subsection (c) of this section, if an agency has not 29
571571 remediated [any] THE findings pertaining to State cybersecurity standards found by the 30
572572 independent audit required under subsection (a) of this section TO BECOME COMPLIANT 31
573573 WITH STATE MINIMUM CYBERSE CURITY STANDARDS by July 1, 2024, the Office of 32 SENATE BILL 868 13
574574
575575
576576 Security Management shall ensure compliance of an agency’s cybersecurity with 1
577577 cybersecurity standards through a shared service agreement[, administrative privileges, or 2
578578 access to Network Maryland] TO ONBOARD THE AGENC Y TO DEPARTMENT OF 3
579579 INFORMATION TECHNOLOGY CYBERSECUR ITY SERVICES AND PRO VIDE OFFICE OF 4
580580 SECURITY MANAGEMENT STAFF ADMI NISTRATIVE PRIVILEGE S TO THE AGENCY ’S 5
581581 INFORMATION TECHNOLO GY ASSETS. 6
582582
583583 (c) Subsection (b) of this section does not apply if a federal law or regulation 7
584584 forbids the Office of Security Management from managing a specific system. 8
585585
586586 SECTION 6. AND BE IT FURTHER ENACTED, That: 9
587587
588588 (a) The Department of Information Technology shall hire a contractor to conduct 10
589589 a performance and capacity assessment of the Department to: 11
590590
591591 (1) evaluate the Department’s capacity to implement provisions of this Act; 12
592592 and 13
593593
594594 (2) recommend additional resources necessary for the Department to 14
595595 implement provisions of this title and meet future needs, including additional budget 15
596596 appropriations, additional staff, altered contracting authority, and pay increases for staff. 16
597597
598598 (b) The contractor hired by the Department to complete the assessment and 17
599599 report required by this section shall: 18
600600
601601 (1) PROVIDE QUARTERLY UP DATES ON ITS WORK UN DER THIS 19
602602 SECTION TO THE COCHA IRS OF THE JOINT COMMITTEE ON CYBERSECURITY , 20
603603 INFORMATION TECHNOLOGY , AND BIOTECHNOLOGY ; 21
604604
605605 [(1)] (2) on or before December 1, 2023, submit an interim report of its 22
606606 findings and recommendations to the Governor and, in accordance with § 2–1257 of the 23
607607 State Government Article, the General Assembly; and 24
608608
609609 [(2)] (3) on or before December 1, 2024, submit a final report of its 25
610610 findings and recommendations to the Governor and, in accordance with § 2–1257 of the 26
611611 State Government Article, the General Assembly. 27
612612
613613 SECTION 2. AND BE IT FURTHER ENACTED, That the report submitted by the 28
614614 Modernize Maryland Oversight Commission under § 3.5–316(h) of the State Finance and 29
615615 Procurement Article, as enacted by Section 1 of this Act, in calendar year 2024 shall include 30
616616 an evaluation of services provided by the Department of Information Technology and an 31
617617 assessment of whether those services meet the needs of the agencies being served. 32
618618
619619 SECTION 3. AND BE IT F URTHER ENACTED, That, on or before November 1, 33
620620 2023, the Modernize Maryland Oversight Commission shall report to the General 34
621621 Assembly, in accordance with § 2–1257 of the State Government Article, recommendations 35 14 SENATE BILL 868
622622
623623
624624 to improve the format for the Secretary of Information Technology to report on major 1
625625 information technology development projects under § 3.5–309 of the State Finance and 2
626626 Procurement Article to meet the needs for strategic planning and investment. 3
627627
628628 SECTION 4. AND BE IT FURTHER ENACTED, That: 4
629629
630630 (1) the Department of Information Technology shall hire an independent 5
631631 contractor to review the efficiency and effectiveness of foundational information technology 6
632632 projects that impact multiple units of State government, including MDThink and OneStop, 7
633633 according to the framework developed under § 3.5–317(b) of the State Finance and 8
634634 Procurement Article, as enacted by Section 1 of this Act; and 9
635635
636636 (2) on or before November 1, 2023, the independent contractor hired under 10
637637 item (1) of this section shall report its findings and recommendations to the General 11
638638 Assembly, in accordance with § 2–1257 of the State Government Article. 12
639639
640640 SECTION 5. AND BE IT FURTHER ENACTED, That this Act shall take effect June 13
641641 1, 2023. 14
642642