Maryland 2025 Regular Session

Maryland House Bill HB1309 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11
22
33 EXPLANATION: CAPITALS INDICATE MAT TER ADDED TO EXISTIN G LAW.
44 [Brackets] indicate matter deleted from existing law.
55 *hb1309*
66
77 HOUSE BILL 1309
88 F1, S2 5lr3329
99 CF SB 907
1010 By: Delegate Wu
1111 Introduced and read first time: February 7, 2025
1212 Assigned to: Health and Government Operations and Ways and Means
1313
1414 A BILL ENTITLED
1515
1616 AN ACT concerning 1
1717
1818 Cybersecurity – Standards, Compliance, and Audits – Alterations 2
1919
2020 FOR the purpose of repealing the requirement that county boards of education prioritize 3
2121 the purchase of digital devices with certain funds; requiring each local school system 4
2222 to comply with, and certify compliance with, the State minimum cybersecurity 5
2323 standards and to conduct a cybersecurity maturity assessment every 2 years; 6
2424 requiring the Office of Security Management within the Department of Information 7
2525 Technology to annually update the State minimum cybersecurity standards; 8
2626 requiring the Department of Information Technology to provide a certain number of 9
2727 information security officers to assist local school systems with certain functions and 10
2828 to focus on a certain standard for a certain school year; requiring the Office of 11
2929 Legislative Audits within the Department of Legislative Services to refer to the State 12
3030 minimum cybersecurity standards when conducting certain audits; and generally 13
3131 relating to cybersecurity. 14
3232
3333 BY repealing and reenacting, with amendments, 15
3434 Article – Education 16
3535 Section 5–212 17
3636 Annotated Code of Maryland 18
3737 (2022 Replacement Volume and 2024 Supplement) 19
3838
3939 BY adding to 20
4040 Article – Education 21
4141 Section 5–213(e) and (f) 22
4242 Annotated Code of Maryland 23
4343 (2022 Replacement Volume and 2024 Supplement) 24
4444
4545 BY repealing and reenacting, with amendments, 25
4646 Article – State Finance and Procurement 26
4747 Section 3.5–101, 3.5–2A–04(b), and 3.5–405 27
4848 Annotated Code of Maryland 28 2 HOUSE BILL 1309
4949
5050
5151 (2021 Replacement Volume and 2024 Supplement) 1
5252
5353 BY repealing and reenacting, without amendments, 2
5454 Article – State Finance and Procurement 3
5555 Section 3.5–2A–02 and 3.5–301(a) and (c) 4
5656 Annotated Code of Maryland 5
5757 (2021 Replacement Volume and 2024 Supplement) 6
5858
5959 BY repealing and reenacting, with amendments, 7
6060 Article – State Government 8
6161 Section 2–1221 9
6262 Annotated Code of Maryland 10
6363 (2021 Replacement Volume and 2024 Supplement) 11
6464
6565 SECTION 1. BE IT ENACTED BY THE GENERAL ASSEMBLY OF MARYLAND, 12
6666 That the Laws of Maryland read as follows: 13
6767
6868 Article – Education 14
6969
7070 5–212. 15
7171
7272 (a) The target per pupil foundation amount includes costs associated with 16
7373 implementing the Blueprint for Maryland’s Future including: 17
7474
7575 (1) Increasing salaries; 18
7676
7777 (2) Additional teachers to provide professional learning and collaborative 19
7878 time for teachers; 20
7979
8080 (3) Career counseling; 21
8181
8282 (4) Behavioral health; 22
8383
8484 (5) Instructional opportunities for students who are college and career 23
8585 ready and those who are not; 24
8686
8787 (6) Maintenance and operation of schools; 25
8888
8989 (7) Supplies and materials for teachers; and 26
9090
9191 (8) Educational technology including digital devices, broadband 27
9292 connectivity, [and] information technology staff, AND CYBERSECURITY . 28
9393
9494 (b) Schools may use funds provided under this section to provide the programs 29
9595 required under COMAR 13A.04.16.01. 30
9696
9797 (c) (1) [County boards of education and schools shall prioritize the purchase 31 HOUSE BILL 1309 3
9898
9999
100100 of digital devices for using funds under subsection (a)(8) of this section. 1
101101
102102 (2)] Additional funds provided in the target per pupil foundation amount for 2
103103 educational technology are intended to supplement and not supplant existing funding 3
104104 provided for educational technology. 4
105105
106106 [(3)] (2) (i) On or before [November 15 each year] AUGUST 15, 2025, 5
107107 AND EACH AUGUST 15 THEREAFTER , each county board shall submit a report to the 6
108108 Department detailing, for the previous fiscal year: 7
109109
110110 1. The amount spent by the local school system on 8
111111 [technology disaggregated by digital devices, connectivity, and] information technology 9
112112 staff[; and] DISAGGREGATED BY : 10
113113
114114 A. FULL–TIME EMPLOYEES ; 11
115115
116116 B. VENDOR–SUPPORTED STAFF OR C ONTRACTORS ; AND 12
117117
118118 C. DEDICATED CYBERSECURI TY PROFESSIONALS BY 13
119119 TYPE, INCLUDING CHIEF INFO RMATION SECURITY OFF ICERS AND CYBERSECUR ITY 14
120120 SPECIALISTS; 15
121121
122122 2. The percentage of students, teachers, and staff with 16
123123 digital devices and adequate connectivity in their homes in accordance with the Federal 17
124124 Communications Commission standards for broadband; AND 18
125125
126126 3. CYBERSECURITY EXPENDI TURES RELATED TO THE 19
127127 STATE MINIMUM CYBERSE CURITY STANDARDS EST ABLISHED BY THE DEPARTMENT 20
128128 OF INFORMATION TECHNOLOGY . 21
129129
130130 (ii) On or before December 15 each year, the Department shall 22
131131 submit to the General Assembly, in accordance with § 2–1257 of the State Government 23
132132 Article, a compilation of the reports submitted to the Department under subparagraph (i) 24
133133 of this paragraph. 25
134134
135135 (iii) On or before September 1, 2021, the Department shall establish 26
136136 uniform reporting requirements, including definitions to ensure that consistent and 27
137137 comparable reports are submitted under subparagraph (i) of this paragraph. 28
138138
139139 5–213. 29
140140
141141 (E) (1) EACH COUNTY BOARD SHA LL PROVIDE SUFFICIENT 30
142142 CYBERSECURITY STAFFI NG AS DETERMINED BY THE STATE CHIEF INFORMATION 31
143143 SECURITY OFFICER. 32
144144 4 HOUSE BILL 1309
145145
146146
147147 (2) LOCAL SCHOOL SYSTEMS MAY SHARE SERVICES , CONTRACTORS , 1
148148 OR REGIONAL SUPPORT FROM THE DEPARTMENT TO MEET THE REQUIREMENTS OF 2
149149 PARAGRAPH (1) OF THIS SUBSECTION, PROVIDED THAT EACH L OCAL SCHOOL 3
150150 SYSTEM ENSURES TIMEL Y AND ADEQUATE SUPPO RT FOR CYBERSECURITY . 4
151151
152152 (F) (1) BEGINNING IN 2026, EACH LOCAL SCHOOL SY STEM SHALL: 5
153153
154154 (I) COMPLY WITH THE STATE MINIMUM CYBERSECURIT Y 6
155155 STANDARDS; AND 7
156156
157157 (II) CONDUCT A CYBERSECURI TY MATURITY ASSESSME NT 8
158158 EVERY 2 YEARS. 9
159159
160160 (2) ON OR BEFORE JUNE 30, 2026, AND EACH JUNE 30 EVERY 2 10
161161 YEARS THEREAFTER , EACH LOCAL SCHOOL SY STEM SHALL CERTIFY T O THE OFFICE 11
162162 OF SECURITY MANAGEMENT WITHIN THE DEPARTMENT OF INFORMATION 12
163163 TECHNOLOGY COMPLIANCE WITH THE STATE MINIMUM CYBERSE CURITY 13
164164 STANDARDS. 14
165165
166166 Article – State Finance and Procurement 15
167167
168168 3.5–101. 16
169169
170170 (a) In this title the following words have the meanings indicated. 17
171171
172172 (b) “Cloud computing” means a service that enables on–demand self–service 18
173173 network access to a shared pool of configurable computer resources, including data storage, 19
174174 analytics, commerce, streaming, e–mail, document sharing, and document editing. 20
175175
176176 (c) “Department” means the Department of Information Technology. 21
177177
178178 (d) “Secretary” means the Secretary of Information Technology. 22
179179
180180 (E) “STATE MINIMUM CYBERSE CURITY STANDARDS ” MEANS THE STATE 23
181181 MINIMUM CYBERSECURIT Y STANDARDS ESTABLIS HED BY THE DEPARTMENT OF 24
182182 INFORMATION TECHNOLOGY . 25
183183
184184 [(e)] (F) “Telecommunication” means the transmission of information, images, 26
185185 pictures, voice, or data by radio, video, or other electronic or impulse means. 27
186186
187187 [(f)] (G) “Unit of State government” means an agency or unit of the Executive 28
188188 Branch of State government. 29
189189
190190 3.5–2A–02. 30
191191 HOUSE BILL 1309 5
192192
193193
194194 There is an Office of Security Management within the Department. 1
195195
196196 3.5–2A–04. 2
197197
198198 (b) The Office shall: 3
199199
200200 (1) establish standards to categorize all information collected or 4
201201 maintained by or on behalf of each unit of State government; 5
202202
203203 (2) establish standards to categorize all information systems maintained 6
204204 by or on behalf of each unit of State government; 7
205205
206206 (3) develop guidelines governing the types of information and information 8
207207 systems to be included in each category; 9
208208
209209 (4) establish security requirements for information and information 10
210210 systems in each category; 11
211211
212212 (5) assess the categorization of information and information systems and 12
213213 the associated implementation of the security requirements established under item (4) of 13
214214 this subsection; 14
215215
216216 (6) if the State Chief Information Security Officer determines that there 15
217217 are security vulnerabilities or deficiencies in any information systems, determine and direct 16
218218 or take actions necessary to correct or remediate the vulnerabilities or deficiencies, which 17
219219 may include requiring the information system to be disconnected; 18
220220
221221 (7) if the State Chief Information Security Officer determines that there is 19
222222 a cybersecurity threat caused by an entity connected to the network established under § 20
223223 3.5–404 of this title that introduces a serious risk to entities connected to the network or to 21
224224 the State, take or direct actions required to mitigate the threat; 22
225225
226226 (8) manage security awareness training for all appropriate employees of 23
227227 units of State government; 24
228228
229229 (9) assist in the development of data management, data governance, and 25
230230 data specification standards to promote standardization and reduce risk; 26
231231
232232 (10) assist in the development of a digital identity standard and 27
233233 specification applicable to all parties communicating, interacting, or conducting business 28
234234 with or on behalf of a unit of State government; 29
235235
236236 (11) develop and maintain information technology security policy, 30
237237 standards, and guidance documents, consistent with best practices developed by the 31
238238 National Institute of Standards and Technology; 32
239239
240240 (12) to the extent practicable, seek, identify, and inform relevant 33 6 HOUSE BILL 1309
241241
242242
243243 stakeholders of any available financial assistance provided by the federal government or 1
244244 non–State entities to support the work of the Office; 2
245245
246246 (13) provide technical assistance to localities in mitigating and recovering 3
247247 from cybersecurity incidents; [and] 4
248248
249249 (14) ANNUALLY REVIEW AND UPDATE THE STATE MINIMUM 5
250250 CYBERSECURITY STANDA RDS; AND 6
251251
252252 (15) provide technical services, advice, and guidance to units of local 7
253253 government to improve cybersecurity preparedness, prevention, response, and recovery 8
254254 practices. 9
255255
256256 3.5–301. 10
257257
258258 (a) In this subtitle the following words have the meanings indicated. 11
259259
260260 (c) “Cybersecurity” means processes or capabilities wherein systems, 12
261261 communications, and information are protected and defended against damage, 13
262262 unauthorized use or modification, and exploitation. 14
263263
264264 3.5–405. 15
265265
266266 (a) This section does not apply to municipal governments. 16
267267
268268 (b) In a manner and frequency established in regulations adopted by the 17
269269 Department, each county government, local school system, and local health department 18
270270 shall, in consultation with the local emergency manager, create or update a cybersecurity 19
271271 preparedness and response plan and complete a cybersecurity preparedness assessment. 20
272272
273273 (C) THE DEPARTMENT SHALL ASSI GN AT LEAST THREE IN FORMATION 21
274274 SECURITY OFFICERS TO SUPPORT LOCAL SCHOOL SYSTEMS WITH : 22
275275
276276 (1) COMPLIANCE WITH THE STATE MINIMUM CYBERSE CURITY 23
277277 STANDARDS; 24
278278
279279 (2) CONDUCTING CYBERSECU RITY MATURITY ASSESSMENTS EV ERY 2 25
280280 YEARS; AND 26
281281
282282 (3) REMEDIATION EFFORTS . 27
283283
284284 (D) ON OR BEFORE JUNE 30, 2026, AND EACH JUNE 30 EVERY 2 YEARS 28
285285 THEREAFTER , EACH LOCAL SCHOOL SY STEM SHALL CERTIFY T O THE OFFICE OF 29
286286 SECURITY MANAGEMENT COMPLIANCE WITH THE STATE MINIMUM 30
287287 CYBERSECURITY STANDARDS . 31 HOUSE BILL 1309 7
288288
289289
290290
291291 Article – State Government 1
292292
293293 2–1221. 2
294294
295295 (a) A fiscal/compliance audit conducted by the Office of Legislative Audits shall 3
296296 include: 4
297297
298298 (1) examining financial transactions and records and internal controls; 5
299299
300300 (2) evaluating compliance with applicable laws and regulations; 6
301301
302302 (3) examining electronic data processing operations; and 7
303303
304304 (4) evaluating compliance with applicable laws and regulations relating to 8
305305 the acquisition of goods and services from Maryland Correctional Enterprises. 9
306306
307307 (b) A performance audit conducted by the Office of Legislative Audits may 10
308308 include: 11
309309
310310 (1) evaluating the efficiency, effectiveness, and economy with which 12
311311 resources are used; 13
312312
313313 (2) determining whether desired program results are achieved; and 14
314314
315315 (3) determining the reliability of performance measures, as defined in § 15
316316 3–1001(g) of the State Finance and Procurement Article, identified in: 16
317317
318318 (i) the managing for results agency strategic plan developed under 17
319319 § 3–1002(c) of the State Finance and Procurement Article; or 18
320320
321321 (ii) the StateStat agency strategic plan developed under § 3–1003(d) 19
322322 of the State Finance and Procurement Article. 20
323323
324324 (c) The purpose of financial statement audits conducted by the Office of 21
325325 Legislative Audits shall be to express an opinion regarding the fairness of the presentation 22
326326 of a unit’s financial statements. 23
327327
328328 (d) (1) The audits referred to in subsections (a), (b), and (c) of this section shall 24
329329 be conducted in accordance with generally accepted government auditing standards. 25
330330
331331 (2) FOR THE AUDITS REFERRE D TO IN SUBSECTIONS (A), (B), AND (C) 26
332332 OF THIS SECTION, THE OFFICE OF LEGISLATIVE AUDITS SHALL BE GUIDE D BY THE 27
333333 DEPARTMENT OF INFORMATION TECHNOLOGY ’S STATE MINIMUM CYBERSE CURITY 28
334334 STANDARDS. 29
335335 8 HOUSE BILL 1309
336336
337337
338338 (e) (1) Upon approval of the Joint Audit and Evaluation Committee, the Office 1
339339 of Legislative Audits shall develop and use a rating system that is based on the results of 2
340340 a fiscal/compliance audit to determine an overall evaluation of a unit’s financial 3
341341 transactions, records, and internal controls and compliance with applicable laws and 4
342342 regulations as a means of comparing the various units of State government. 5
343343
344344 (2) When an evaluation is issued, it shall be provided to the unit and shall 6
345345 be available to the Joint Audit and Evaluation Committee and the Budget Committees of 7
346346 the Maryland General Assembly. 8
347347
348348 SECTION 2. AND BE IT FURTHER ENACTED, That, for the 2025 –2026 school 9
349349 year, the Department of Information Technology shall focus on Standard 6.2 Protect (PR) 10
350350 Controls of the State minimum cybersecurity standards. 11
351351
352352 SECTION 3. AND BE IT FURTHER ENACTED, That this Act shall take effect July 12
353353 1, 2025. 13
354354
355355