Oklahoma 2022 Regular Session

Oklahoma House Bill HB3067 Compare Versions

OldNewDifferences
11
22
3-HB3067 HFLR Page 1
4-BOLD FACE denotes Committee Amendments. 1
3+Req. No. 8982 Page 1 1
54 2
65 3
76 4
87 5
98 6
109 7
1110 8
1211 9
1312 10
1413 11
1514 12
1615 13
1716 14
1817 15
1918 16
2019 17
2120 18
2221 19
2322 20
2423 21
2524 22
2625 23
2726 24
28-
29-HOUSE OF REPRESENTATIVES - FLOOR VERSION
3027
3128 STATE OF OKLAHOMA
3229
3330 2nd Session of the 58th Legislature (2022)
3431
3532 HOUSE BILL 3067 By: Manger
3633
3734
3835
3936
4037
4138 AS INTRODUCED
4239
4340 An Act relating to public finance; amending 62 O.S.
4441 2021, Section 34.32, which relates to state agency
4542 information technology systems; ma king certain
4643 provisions inapplicable to the Oklahoma State Bureau
4744 of Investigation; providing an effective date; and
4845 declaring an emergency.
4946
5047
5148
5249
5350 BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA:
5451 SECTION 1. AMENDATORY 62 O.S. 2021, Section 34.3 2, is
5552 amended to read as follo ws:
5653 Section 34.32 A. The Information Services Division of the
5754 Office of Management and Enterprise Services shall create a standard
5855 security risk assessment for st ate agency information technology
5956 systems that complies with t he International Organization for
6057 Standardization (ISO) and the International Electrotechnical
6158 Commission (IEC) Information Technology - Code of Practice for
6259 Security Management (ISO/IEC 27002).
6360 B. Each state agency that has an i nformation technology syst em
6461 shall obtain an information sec urity risk assessment to identify
62+vulnerabilities associated with the information system. The
6563
66-HB3067 HFLR Page 2
67-BOLD FACE denotes Committee Amendments. 1
64+Req. No. 8982 Page 2 1
6865 2
6966 3
7067 4
7168 5
7269 6
7370 7
7471 8
7572 9
7673 10
7774 11
7875 12
7976 13
8077 14
8178 15
8279 16
8380 17
8481 18
8582 19
8683 20
8784 21
8885 22
8986 23
9087 24
9188
92-vulnerabilities associated with the information system. The
9389 Information Services Division of the Office of Management and
9490 Enterprise Services shall approve not l ess than two firms which
9591 state agencies may choose from to c onduct the information security
9692 risk assessment.
9793 C. A state agency with an information technology system that is
9894 not consolidated under the Information Technol ogy Consolidation and
9995 Coordination Act or that is otherwise re tained by the agency shall
10096 additionally be required to have an information security audit
10197 conducted by a firm approved by the Information Services Division
10298 that is based upon the most current ve rsion of the NIST Cyber-
10399 Security Framework, and shall submit a final report of the
104100 information security risk assessment and information security audit
105101 findings to the Information Services Division each year on a
106102 schedule set by the Information Services Div ision. Agencies shall
107103 also submit a list of remedies and a ti meline for the repair of any
108104 deficiencies to the Information Services Division within ten (10)
109105 days of the completion of the audit. The final information security
110106 risk assessment report shall i dentify, prioritize, and document
111107 information security vulnera bilities for each of the state age ncies
112108 assessed. The Information Services Division may assist agencies in
113109 repairing any vulnerabilities to ensure compliance in a timely
114110 manner.
111+D. Subject to the provisions of subsection C of Se ction 34.12
112+of this title, the Information Services Division shall report the
115113
116-HB3067 HFLR Page 3
117-BOLD FACE denotes Committee Amendments. 1
114+Req. No. 8982 Page 3 1
118115 2
119116 3
120117 4
121118 5
122119 6
123120 7
124121 8
125122 9
126123 10
127124 11
128125 12
129126 13
130127 14
131128 15
132129 16
133130 17
134131 18
135132 19
136133 20
137134 21
138135 22
139136 23
140137 24
141138
142-D. Subject to the provisions of subsection C of Se ction 34.12
143-of this title, the Information Services Division shall report the
144139 results of the state agency assessments and information security
145140 audit findings required pursuant to this section to the Governor,
146141 the Speaker of the House of Representatives, and the President Pro
147142 Tempore of the Senate by the first day o f January of each year. Any
148143 state agency with an information technology system that is not
149144 consolidated under the Information Technology Consolidation and
150145 Coordination Act that cannot c omply with the provisions of this
151146 section shall consolidate under the Information Technology
152147 Consolidation and Coordination Act.
153148 E. This act shall not apply to state agencies subject to
154149 mandatory North American Electric Reliabili ty Corporation (NERC)
155150 cybersecurity standards and institutions within The Oklahoma State
156151 System of Higher Education, the Oklahoma State Bureau of
157152 Investigation (OSBI), the Oklahoma State Regents for Higher
158153 Education and the telecommunications network known as OneNet that
159154 follow the Internation al Organization for Stan dardization (ISO), the
160155 Oklahoma Military Department (OMD), and the International
161156 Electrotechnical Commission (IEC) -Security techniques-Code of
162157 Practice for Information Security Controls or Natio nal Institute of
163158 Standards and Technol ogy.
164159 SECTION 2. This act shall become eff ective July 1, 2022.
160+SECTION 3. It being immediately necessary for the preservation
161+of the public peace, health or safety, an emergency is here by
165162
166-HB3067 HFLR Page 4
167-BOLD FACE denotes Committee Amendments. 1
163+Req. No. 8982 Page 4 1
168164 2
169165 3
170166 4
171167 5
172168 6
173169 7
174170 8
175171 9
176172 10
177173 11
178174 12
179175 13
180176 14
181177 15
182178 16
183179 17
184180 18
185181 19
186182 20
187183 21
188184 22
189185 23
190186 24
191187
192-SECTION 3. It being immediately necessary for the preservation
193-of the public peace, health or safety, an emergency is here by
194188 declared to exist, by reason whereo f this act shall take effect and
195189 be in full force from and after its passage and approval.
196190
197-COMMITTEE REPORT BY: COMMITTEE ON TECHNOLOGY, dated 02/16/2022 - DO
198-PASS.
191+58-2-8982 MJ 12/09/21