New Jersey 2022-2023 Regular Session

New Jersey Assembly Bill A1983

Introduced
1/11/22  
Refer
1/11/22  

Caption

Requires municipalities, counties, and school districts to report cybersecurity incidents.

Impact

The implications of A1983 on state law are significant, as it sets into place a structured reporting framework for cybersecurity incidents. This is expected to enhance the overall cybersecurity posture of municipalities and school districts by necessitating audits conducted by independent cybersecurity firms following an incident report. The involvement of the New Jersey Cybersecurity and Communications Integration Cell further underscores state support for local entities to bolster their cybersecurity measures.

Summary

Assembly Bill A1983 mandates that municipalities, counties, and school districts in New Jersey are required to report any cybersecurity incidents that jeopardize the integrity, confidentiality, or availability of their information systems. This bill emphasizes the growing importance of cybersecurity in public governance and aims to ensure that public entities take responsibility for and respond effectively to cybersecurity threats.

Sentiment

General sentiment around the bill appears to be positive, primarily due to the increasing incidence of cyber threats targeting public institutions. Stakeholders recognize the need for better preparation and a standardized response process. There is, however, an underlying concern regarding the cost implications, as compliance with the reporting and auditing mandates may strain local budgets. This tension suggests a need for accompanying measures to support these entities financially.

Contention

Notable points of contention revolve around the resources required to meet the compliance mandates of the bill. Critics argue that while the intent behind the bill is commendable, the financial burden of audits and potential cybersecurity upgrades may overwhelm smaller municipalities and school districts. Additionally, there are concerns regarding the privacy of data shared in these incident reports, which is exempt from disclosure under the Open Public Records Act, potentially sparking debates about transparency and accountability.

Companion Bills

No companion bills found.

Similar Bills

NJ A3897

Requires municipalities, counties, and school districts to report cybersecurity incidents.

NJ S3313

Requires certain procedures and training for municipalities, counties, and school districts in response to cybersecurity incidents.

NJ A3949

Requires certain procedures, reports, and training for municipalities, counties, and school districts in response to cybersecurity incidents.

CA AB2326

School cybersecurity.

CA AB405

Public postsecondary education: community college districts: baccalaureate degree cybersecurity pilot program.

NJ S3222

Requires instruction on cybersecurity in grades nine through 12; requires Office of Secretary of Higher Education to develop cybersecurity model curricula; establishes loan redemption programs for individuals in certain cybersecurity occupations.

CA AB1023

California Cybersecurity Integration Center: school cybersecurity.

NJ A1982

Requires instruction on cybersecurity in grades nine through 12; requires Office of Secretary of Higher Education to develop cybersecurity model curricula; establishes loan redemption programs for individuals in certain cybersecurity occupations.