10 | 40 | | |
---|
11 | 41 | | |
---|
12 | 42 | | |
---|
13 | 43 | | |
---|
14 | 44 | | |
---|
15 | 45 | | An Act relating to public finance; amending 62 O.S. |
---|
16 | 46 | | 2011, Section 34.32, as last amended by Section 1, |
---|
17 | 47 | | Chapter 331, O.S.L. 2019 (62 O.S. Supp. 20 20, Section |
---|
18 | 48 | | 34.32), which relates to state agency information |
---|
19 | 49 | | technology systems; making certain provisions |
---|
20 | 50 | | inapplicable to the Oklahoma Military Department; |
---|
21 | 51 | | providing an effective date; and declaring an |
---|
22 | 52 | | emergency. |
---|
23 | 53 | | |
---|
24 | 54 | | |
---|
25 | 55 | | |
---|
26 | 56 | | |
---|
51 | 102 | | C. A state agency with an information technology system that is |
---|
52 | 103 | | not consolidated under the Information Technology Consolidation and |
---|
53 | 104 | | Coordination Act or that is otherwise retained by the agency s hall |
---|
54 | 105 | | additionally be required to have an information security audit |
---|
55 | 106 | | conducted by a firm approved by the Information Services Division |
---|
56 | 107 | | that is based upon the most current version of the NIST Cyber - |
---|
57 | 108 | | Security Framework, and shall submit a final report of the |
---|
58 | 109 | | information security risk assessment and information security audit |
---|
59 | 110 | | findings to the Information Services Division each year on a |
---|
60 | 111 | | schedule set by the Information Services Division. Agencies shall |
---|
61 | 112 | | also submit a list of remedies and a timeline for the repair of any |
---|
62 | 113 | | deficiencies to the Information Services Divi sion within ten (10) |
---|
63 | 114 | | days of the completion of the audit. The final information security |
---|
64 | 115 | | risk assessment report shall identify, prioritize, and document |
---|
65 | 116 | | information security vulnerabilities for each of t he state agencies |
---|
70 | 147 | | D. Subject to the provisions of subsection C of Section 34.12 |
---|
71 | 148 | | of this title, the Information Servi ces Division shall report the |
---|
72 | 149 | | results of the state a gency assessments and information security |
---|
73 | 150 | | audit findings required pursuant to this section to the Governor, |
---|
74 | 151 | | the Speaker of the House of Representatives, and the President Pro |
---|
75 | 152 | | Tempore of the Senate by the first day of January of each year. Any |
---|
76 | 153 | | state agency with an information technology system that is not |
---|
77 | 154 | | consolidated under the Information Technology Consolidation and |
---|
78 | 155 | | Coordination Act that cannot comply with the provisions of this |
---|
79 | 156 | | section shall consolidat e under the Information Technology |
---|
80 | 157 | | Consolidation and Coordination Act. |
---|
82 | 158 | | E. This act shall not apply to state agencies subject to |
---|
83 | 159 | | mandatory North American Electric Reliability Corporation (NERC) |
---|
84 | 160 | | cybersecurity standards and institutions within The Oklahoma S tate |
---|
85 | 161 | | System of Higher Education, the Oklahoma State Regents for Higher |
---|
86 | 162 | | Education and the telecommunications network known as OneNet that |
---|
87 | 163 | | follow the International Organization for Standardization (ISO) , the |
---|
88 | 164 | | Oklahoma Military Department (OMD), and the International |
---|
89 | 165 | | Electrotechnical Commission (IEC) -Security techniques-Code of |
---|
90 | 166 | | Practice for Information Security Controls or National Institute of |
---|
99 | | - | ENR. H. B. NO. 2331 Page 4 |
---|
100 | | - | Passed the House of Repres entatives the 1st day of March, 2021. |
---|
101 | | - | |
---|
102 | | - | |
---|
103 | | - | |
---|
104 | | - | |
---|
105 | | - | Presiding Officer of the House |
---|
106 | | - | of Representatives |
---|
107 | | - | |
---|
108 | | - | |
---|
109 | | - | Passed the Senate the 15th day of April, 2021. |
---|
110 | | - | |
---|
111 | | - | |
---|
112 | | - | |
---|
113 | | - | |
---|
114 | | - | Presiding Officer of the Senate |
---|
115 | | - | |
---|
116 | | - | |
---|
117 | | - | |
---|
118 | | - | OFFICE OF THE GOVERNOR |
---|
119 | | - | Received by the Office of the Governor this ___ _________________ |
---|
120 | | - | day of ___________________, 20_______, at _______ o'clock _______ M. |
---|
121 | | - | By: _________________________________ |
---|
122 | | - | Approved by the Governor of the State of Oklahoma this _________ |
---|
123 | | - | day of ___________________, 20_______, at _______ o'clock _______ M. |
---|
124 | | - | |
---|
125 | | - | |
---|
126 | | - | _________________________________ |
---|
127 | | - | Governor of the State of Oklahoma |
---|
128 | | - | |
---|
129 | | - | OFFICE OF THE SECRETARY OF STATE |
---|
130 | | - | Received by the Office of the Secretary of State this __________ |
---|
131 | | - | day of ___________________, 20_______, at _______ o'clock _______ M. |
---|
132 | | - | By: _________________________________ |
---|
133 | | - | |
---|
| 200 | + | COMMITTEE REPORT BY: COMMITTEE ON GENERAL GOVERNMENT |
---|
| 201 | + | March 31, 2021 - DO PASS |
---|