Oklahoma 2022 Regular Session

Oklahoma Senate Bill SB570 Compare Versions

OldNewDifferences
11
22
3-SB570 HFLR Page 1
4-BOLD FACE denotes Committee Amendments. 1
3+ENGR. S. B. NO. 570 Page 1 1
54 2
65 3
76 4
87 5
98 6
109 7
1110 8
1211 9
1312 10
1413 11
1514 12
1615 13
1716 14
1817 15
1918 16
2019 17
2120 18
2221 19
2322 20
2423 21
2524 22
2625 23
2726 24
28-
29-HOUSE OF REPRESENTATIVES - FLOOR VERSION
30-
31-STATE OF OKLAHOMA
32-
33-1st Session of the 58th Legislature (2021)
3427
3528 ENGROSSED SENATE
3629 BILL NO. 570 By: Newhouse of the Senate
3730
3831 and
3932
4033 Steagall of the House
4134
4235
4336
4437
4538 An Act relating to public finance; amending 62 O.S.
4639 2011, Section 34.32, as last ame nded by Section 1,
4740 Chapter 331, O.S.L. 2019 (62 O.S. Supp. 20 20, Section
4841 34.32), which relates to state agency information
4942 technology systems; making certain provisions
5043 inapplicable to the Military Department of the State
5144 of Oklahoma; providing an effective date; and
5245 declaring an emergency.
5346
5447
5548
5649
5750 BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA:
5851 SECTION 1. AMENDATORY 62 O.S. 2011, Section 34.32, as
5952 last amended by Section 1, Chapter 331, O.S.L. 2019 (62 O.S. Sup p.
6053 2020, Section 34.32), is amended to read as follows:
6154 Section 34.32. A. The Information Services Division of the
6255 Office of Management and Enterprise Services shall create a standard
6356 security risk assessment for state agency information technology
6457 systems that complies with the International Organization for
6558 Standardization (ISO) and the International Electrotechnical
59+Commission (IEC) Information Technology - Code of Practice for
60+Security Management (ISO/IEC 27002).
61+B. Each state agency that has an info rmation technology system
62+shall obtain an information security risk assessment to identify
6663
67-SB570 HFLR Page 2
68-BOLD FACE denotes Committee Amendments. 1
64+ENGR. S. B. NO. 570 Page 2 1
6965 2
7066 3
7167 4
7268 5
7369 6
7470 7
7571 8
7672 9
7773 10
7874 11
7975 12
8076 13
8177 14
8278 15
8379 16
8480 17
8581 18
8682 19
8783 20
8884 21
8985 22
9086 23
9187 24
9288
93-Commission (IEC) Information Technology - Code of Practice for
94-Security Management (ISO/IEC 27002).
95-B. Each state agency that ha s an information technology system
96-shall obtain an information security risk assessment to identify
9789 vulnerabilities associated with the information system. The
9890 Information Services Division of the Office of Management and
9991 Enterprise Services shall approve not less than two firms which
10092 state agencies may choose from to conduct the information security
10193 risk assessment.
10294 C. A state agency with an information technology system that is
10395 not consolidated under the Information Technology Consolidation and
10496 Coordination Act or that is otherwise retained by the agency shall
10597 additionally be required to h ave an information security audit
10698 conducted by a firm approved by the Information Services Division
10799 that is based upon the most current version of the NIST Cyber -
108100 Security Framework, and shall submit a final report of the
109101 information security risk assessmen t and information security audit
110102 findings to the Information Services Division each year on a
111103 schedule set by the Information Services Division. Agencies shall
112104 also submit a list of remedies and a timeline for the repair of any
113105 deficiencies to the Informa tion Services Division within ten (10)
114106 days of the completion of the audit. The final information security
115107 risk assessment report shall identify, prioritize, and document
116108 information security vulnerabilities for each of the state agencies
109+assessed. The Information Services Division may assist agencies in
110+repairing any vulnerabilities to ensure compliance in a timely
111+manner.
117112
118-SB570 HFLR Page 3
119-BOLD FACE denotes Committee Amendments. 1
113+ENGR. S. B. NO. 570 Page 3 1
120114 2
121115 3
122116 4
123117 5
124118 6
125119 7
126120 8
127121 9
128122 10
129123 11
130124 12
131125 13
132126 14
133127 15
134128 16
135129 17
136130 18
137131 19
138132 20
139133 21
140134 22
141135 23
142136 24
143137
144-assessed. The Information Services Division may assist agencies in
145-repairing any vulnerabilities to ensure compliance in a timely
146-manner.
147138 D. Subject to the provisions of subsection C of Secti on 34.12
148139 of this title, the Information Services Division shall report the
149140 results of the state agency assessments and information security
150141 audit findings required pursuant to this section to the Governor,
151142 the Speaker of the House of Representatives, and t he President Pro
152143 Tempore of the Senate by the first day of January of each year . Any
153144 state agency with an information technology system that is not
154145 consolidated under the Information Technology Consolidation and
155146 Coordination Act that cannot comply with th e provisions of this
156147 section shall consolidate under the Information Technology
157148 Consolidation and Coordination Act.
158149 E. This act shall not apply to state agencies subject to
159150 mandatory North American Electric Reliability Corporation (NERC)
160151 cybersecurity standards and institutions within The Oklahoma State
161152 System of Higher Education, t he Oklahoma State Regents for Higher
162153 Education and the telecommunications network known as OneNet that
163154 follow the International Organization for Standardization (ISO) , the
164155 Military Department of the State of Oklahoma (OMD) and the
165156 International Electrotech nical Commission (IEC)-Security techniques-
166157 Code of Practice for Information Security Controls or National
167158 Institute of Standards and Technology.
159+SECTION 2. This act shall become effective July 1, 20 21.
160+SECTION 3. It being immediately necessary for the preservation
161+of the public peace, health or safety, an emergency is hereby
168162
169-SB570 HFLR Page 4
170-BOLD FACE denotes Committee Amendments. 1
163+ENGR. S. B. NO. 570 Page 4 1
171164 2
172165 3
173166 4
174167 5
175168 6
176169 7
177170 8
178171 9
179172 10
180173 11
181174 12
182175 13
183176 14
184177 15
185178 16
186179 17
187180 18
188181 19
189182 20
190183 21
191184 22
192185 23
193186 24
194187
195-SECTION 2. This act shall become effective July 1, 2021.
196-SECTION 3. It being immediately necessary for the preservation
197-of the public peace, health or safety, an emergency is hereby
198188 declared to exist, by reason whereof this act shall take effect and
199189 be in full force from and after its passage an d approval.
190+Passed the Senate the 9th day of March, 2021.
200191
201-COMMITTEE REPORT BY: COMMITTEE ON GOVERNMENT MODERNIZATION AND
202-EFFICIENCY, dated 04/06/2021 - DO PASS.
192+
193+
194+ Presiding Officer of the Senate
195+
196+
197+Passed the House of Representatives the ____ day of __________,
198+2021.
199+
200+
201+
202+ Presiding Officer of the House
203+ of Representatives
204+