New Mexico 2025 Regular Session

New Mexico Senate Bill SB254 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 underscored material = new
22 [bracketed material] = delete
33 1
44 2
55 3
66 4
77 5
88 6
99 7
1010 8
1111 9
1212 10
1313 11
1414 12
1515 13
1616 14
1717 15
1818 16
1919 17
2020 18
2121 19
2222 20
2323 21
2424 22
2525 23
2626 24
2727 25
2828 SENATE BILL 254
2929 57
3030 TH LEGISLATURE
3131 -
3232
3333 STATE
3434
3535 OF
3636
3737 NEW
3838
3939 MEXICO
4040
4141 -
4242 FIRST SESSION
4343 ,
4444
4545 2025
4646 INTRODUCED BY
4747 Michael Padilla
4848 AN ACT
4949 RELATING TO CYBERSECURITY; AMENDING THE CYBERSECURITY ACT;
5050 CHANGING THE NAME AND DUTIES OF THE CYBERSECURITY OFFICE;
5151 CHANGING THE MEMBERSHIP OF THE CYBERSECURITY ADVISORY
5252 COMMITTEE.
5353 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF NEW MEXICO:
5454 SECTION 1. Section 9-27A-3 NMSA 1978 (being Laws 2023,
5555 Chapter 115, Section 3) is amended to read:
5656 "9-27A-3. [CYBERSECURITY ] OFFICE OF CYBERSECURITY
5757 CREATED--SECURITY OFFICER--DUTIES AND POWERS.--
5858 A. The "[cybersecurity ] office of cybersecurity " is
5959 created and is administratively attached to the department of
6060 information technology. The office shall be managed by the
6161 security officer.
6262 B. Except as required by federal law, the
6363 .229897.2 underscored material = new
6464 [bracketed material] = delete
6565 1
6666 2
6767 3
6868 4
6969 5
7070 6
7171 7
7272 8
7373 9
7474 10
7575 11
7676 12
7777 13
7878 14
7979 15
8080 16
8181 17
8282 18
8383 19
8484 20
8585 21
8686 22
8787 23
8888 24
8989 25
9090 [cybersecurity] office of cybersecurity shall oversee, in a
9191 fiscally responsible manner, cybersecurity- and information
9292 security-related functions for agencies and may:
9393 (1) adopt and implement rules establishing
9494 minimum security standards and policies to protect agency
9595 information technology systems and infrastructure and provide
9696 appropriate governance and application of the standards and
9797 policies across information technology resources used by
9898 agencies to promote the availability, security and integrity of
9999 the information processed, transacted or stored by agencies in
100100 the state's information technology infrastructure and systems;
101101 (2) develop minimum cybersecurity controls for
102102 managing and protecting information technology assets and
103103 infrastructure for all entities that are connected to [an
104104 agency-operated or -owned ] a state-operated or state-owned
105105 telecommunications network;
106106 (3) consistent with information security
107107 standards, monitor agency information technology networks to
108108 detect security incidents and support mitigation efforts as
109109 necessary and within capabilities;
110110 (4) as reasonably necessary to perform its
111111 monitoring and detection duties, obtain agency system event
112112 logs to support monitoring and detection pursuant to Paragraph
113113 (3) of this subsection;
114114 (5) in coordination with state and federal
115115 .229897.2
116116 - 2 - underscored material = new
117117 [bracketed material] = delete
118118 1
119119 2
120120 3
121121 4
122122 5
123123 6
124124 7
125125 8
126126 9
127127 10
128128 11
129129 12
130130 13
131131 14
132132 15
133133 16
134134 17
135135 18
136136 19
137137 20
138138 21
139139 22
140140 23
141141 24
142142 25
143143 cybersecurity emergency management agencies as appropriate,
144144 create a model incident-response plan for public bodies to
145145 adopt with the [cybersecurity ] office of cybersecurity as the
146146 incident-response coordinator for incidents that:
147147 (a) impact multiple public bodies;
148148 (b) impact more than ten thousand
149149 residents of the state;
150150 (c) involve a nation-state actor; or
151151 (d) involve the marketing or transfer of
152152 confidential data derived from a breach of cybersecurity;
153153 (6) serve as a cybersecurity resource for
154154 local governments;
155155 (7) develop a service catalog of cybersecurity
156156 services to be offered to agencies and to political
157157 subdivisions of the state;
158158 (8) collaborate with agencies in developing
159159 standards, functions and services in order to ensure the agency
160160 regulatory environments are understood and considered as part
161161 of a cybersecurity incident response;
162162 (9) establish core services to support minimum
163163 security standards and policies;
164164 (10) establish minimum data classification
165165 policies and standards and design controls to support
166166 compliance with classifications and report on exceptions;
167167 (11) develop and issue cybersecurity awareness
168168 .229897.2
169169 - 3 - underscored material = new
170170 [bracketed material] = delete
171171 1
172172 2
173173 3
174174 4
175175 5
176176 6
177177 7
178178 8
179179 9
180180 10
181181 11
182182 12
183183 13
184184 14
185185 15
186186 16
187187 17
188188 18
189189 19
190190 20
191191 21
192192 22
193193 23
194194 24
195195 25
196196 policies and training standards and develop and offer
197197 cybersecurity training services; and
198198 (12) establish a centralized cybersecurity and
199199 data breach reporting process for agencies and political
200200 subdivisions of the state."
201201 SECTION 2. Section 9-27A-5 NMSA 1978 (being Laws 2023,
202202 Chapter 115, Section 5) is amended to read:
203203 "9-27A-5. CYBERSECURITY ADVISORY COMMITTEE CREATED--
204204 MEMBERSHIP--DUTIES.--
205205 A. The "cybersecurity advisory committee" is
206206 created within the [cybersecurity ] office of cybersecurity and
207207 shall:
208208 (1) assist the office in the development of:
209209 (a) a statewide cybersecurity plan;
210210 (b) guidelines for best cybersecurity
211211 practices for agencies; and
212212 (c) recommendations on how to respond to
213213 a specific cybersecurity threat or attack; and
214214 (2) have authority over the hiring,
215215 supervision, discipline and compensation of the security
216216 officer.
217217 B. The security officer or the security officer's
218218 designee shall chair [and be an advisory nonvoting member of ]
219219 the cybersecurity advisory committee; provided that the
220220 security officer shall be recused from deliberations and votes
221221 .229897.2
222222 - 4 - underscored material = new
223223 [bracketed material] = delete
224224 1
225225 2
226226 3
227227 4
228228 5
229229 6
230230 7
231231 8
232232 9
233233 10
234234 11
235235 12
236236 13
237237 14
238238 15
239239 16
240240 17
241241 18
242242 19
243243 20
244244 21
245245 22
246246 23
247247 24
248248 25
249249 concerning supervision, discipline or compensation of the
250250 security officer and the secretary of information technology
251251 shall chair those deliberations. The remaining members consist
252252 of:
253253 (1) the secretary of information technology or
254254 the secretary's designee;
255255 (2) [the principal information technology
256256 staff person for the administrative office of the courts or the
257257 director's designee] one member appointed by the chief justice
258258 of the supreme court who is experienced with cybersecurity
259259 issues;
260260 (3) [the director of the legislative council
261261 service or the director's designee ] a member of the legislature
262262 appointed by the New Mexico legislative council who is familiar
263263 with cybersecurity issues ;
264264 (4) one member appointed by the secretary
265265 of Indian affairs who is experienced with cybersecurity issues;
266266 (5) [three] two members appointed by the chair
267267 of the board of directors of the New Mexico association of
268268 counties who represent county governmental agencies and who are
269269 experienced with cybersecurity issues; provided that at least
270270 one member shall represent a county other than a class A or H
271271 class county;
272272 (6) [three] two members appointed by the chair
273273 of the board of directors of the New Mexico municipal league
274274 .229897.2
275275 - 5 - underscored material = new
276276 [bracketed material] = delete
277277 1
278278 2
279279 3
280280 4
281281 5
282282 6
283283 7
284284 8
285285 9
286286 10
287287 11
288288 12
289289 13
290290 14
291291 15
292292 16
293293 17
294294 18
295295 19
296296 20
297297 21
298298 22
299299 23
300300 24
301301 25
302302 who represent municipal governmental agencies and who are
303303 experienced with cybersecurity issues; provided that only one
304304 member may represent a home rule municipality; and
305305 (7) [three] four members appointed by the
306306 governor who [may represent separate agencies other than the
307307 department of information technology and ] are experienced with
308308 cybersecurity issues; provided that at least one appointee
309309 shall be:
310310 (a) an educator or employed by an
311311 education institution;
312312 (b) a health care provider or employed
313313 by a health care provider;
314314 (c) employed by the homeland security
315315 and emergency management department; and
316316 (d) a private sector cybersecurity
317317 expert or employed by a business offering cybersecurity
318318 services.
319319 C. The cybersecurity advisory committee may invite
320320 representatives of unrepresented county, municipal or tribal
321321 agencies or other public entities to participate as advisory
322322 members of the committee as it determines that their
323323 participation would be useful to the deliberations of the
324324 committee.
325325 D. A meeting of and material presented to or
326326 generated by the cybersecurity advisory committee are subject
327327 .229897.2
328328 - 6 - underscored material = new
329329 [bracketed material] = delete
330330 1
331331 2
332332 3
333333 4
334334 5
335335 6
336336 7
337337 8
338338 9
339339 10
340340 11
341341 12
342342 13
343343 14
344344 15
345345 16
346346 17
347347 18
348348 19
349349 20
350350 21
351351 22
352352 23
353353 24
354354 25
355355 to the Open Meetings Act and the Inspection of Public Records
356356 Act subject to an exception for a meeting or material
357357 concerning information that could, if made public, expose a
358358 vulnerability in:
359359 (1) an information system owned or operated by
360360 a public entity; or
361361 (2) a cybersecurity solution implemented by a
362362 public entity.
363363 E. Pursuant to the Cybersecurity Act or other
364364 statutory authority, the security officer may issue orders
365365 regarding the compliance of agencies with guidelines or
366366 recommendations of the cybersecurity advisory committee;
367367 however, compliance with those guidelines or recommendations by
368368 non-executive agencies or county, municipal or tribal
369369 governments shall be strictly voluntary.
370370 F. The cybersecurity advisory committee shall hold
371371 its first meeting on or before August 16, 2023 and shall meet
372372 every two months at minimum after that; provided that the
373373 security officer shall have the discretion to call for more
374374 frequent meetings as circumstances warrant. At the discretion
375375 of the security officer, the committee may issue advisory
376376 reports regarding cybersecurity issues.
377377 G. The cybersecurity advisory committee shall
378378 present a report to the legislative finance committee and the
379379 appropriate legislative interim committee concerned with
380380 .229897.2
381381 - 7 - underscored material = new
382382 [bracketed material] = delete
383383 1
384384 2
385385 3
386386 4
387387 5
388388 6
389389 7
390390 8
391391 9
392392 10
393393 11
394394 12
395395 13
396396 14
397397 15
398398 16
399399 17
400400 18
401401 19
402402 20
403403 21
404404 22
405405 23
406406 24
407407 25
408408 information technology at those committees' November 2023
409409 meetings and to the governor by November 30, 2023 regarding the
410410 status of cybersecurity preparedness within agencies and
411411 elsewhere in the state. On or before October 30, 2024 and on
412412 or before October 30 of each subsequent year, the
413413 [cybersecurity] office of cybersecurity shall present updated
414414 reports to the legislative committees and the governor. The
415415 reports to legislative committees shall be in executive
416416 session, and any materials connected with the report
417417 presentations are exempt from the Inspection of Public Records
418418 Act.
419419 H. The members of the cybersecurity advisory
420420 committee shall receive no pay for their services as members of
421421 the committee, but shall be allowed per diem and mileage
422422 pursuant to the provisions of the Per Diem and Mileage Act.
423423 All per diem and contingent expenses incurred by the
424424 [cybersecurity] office of cybersecurity shall be paid upon
425425 warrants of the secretary of finance and administration,
426426 supported by vouchers of the security officer."
427427 - 8 -
428428 .229897.2