Oklahoma 2023 Regular Session

Oklahoma Senate Bill SB320 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11
22
33
44 Req. No. 511 Page 1 1
55 2
66 3
77 4
88 5
99 6
1010 7
1111 8
1212 9
1313 10
1414 11
1515 12
1616 13
1717 14
1818 15
1919 16
2020 17
2121 18
2222 19
2323 20
2424 21
2525 22
2626 23
2727 24
2828 1
2929 2
3030 3
3131 4
3232 5
3333 6
3434 7
3535 8
3636 9
3737 10
3838 11
3939 12
4040 13
4141 14
4242 15
4343 16
4444 17
4545 18
4646 19
4747 20
4848 21
4949 22
5050 23
5151 24
5252
5353 STATE OF OKLAHOMA
5454
5555 1st Session of the 59th Legislature (2023)
5656
5757 SENATE BILL 320 By: Bergstrom
5858
5959
6060
6161
6262
6363 AS INTRODUCED
6464
6565 An Act relating to state government; defining levels
6666 of certain incidents; amending 74 O.S. 2021, Section
6767 63, which relates to the Off ice of Management and
6868 Enterprise Services; modifying powers and authority
6969 of the Office of Management and Enterprise Services;
7070 defining requirements for reporting certain incidents
7171 to certain state agency; providing for codifica tion;
7272 and providing an effec tive date.
7373
7474
7575
7676
7777 BE IT ENACTED BY THE PEOPLE OF THE STATE OF OKLAHOMA:
7878 SECTION 1. NEW LAW A new section of law to be codified
7979 in the Oklahoma Statutes as Section 63.7 of Title 74, unless there
8080 is created a duplication in numb ering, reads as follows:
8181 The level of severity of a cybersecurity incident shall be
8282 defined pursuant to the National Cyber Incident Response Plan of the
8383 United States Department of Homeland Security a s follows:
8484 1. Level 5 is an emergency -level incident within the specified
8585 jurisdiction that poses an imminent threat t o wide-scale critical
8686 infrastructure services; national, state, or municipal security; or
8787 the lives of the country’s, state’s, or municipality’s residents;
8888
8989
9090 Req. No. 511 Page 2 1
9191 2
9292 3
9393 4
9494 5
9595 6
9696 7
9797 8
9898 9
9999 10
100100 11
101101 12
102102 13
103103 14
104104 15
105105 16
106106 17
107107 18
108108 19
109109 20
110110 21
111111 22
112112 23
113113 24
114114 1
115115 2
116116 3
117117 4
118118 5
119119 6
120120 7
121121 8
122122 9
123123 10
124124 11
125125 12
126126 13
127127 14
128128 15
129129 16
130130 17
131131 18
132132 19
133133 20
134134 21
135135 22
136136 23
137137 24
138138
139139 2. Level 4 is a severe-level incident that is likely to result
140140 in a significant impact in the affected jurisdiction t o public
141141 health or safety; the national, state, or municipal economic or
142142 physical security; or civil liberties;
143143 3. Level 3 is a high-level incident that is likely to result in
144144 a demonstrable impact in the affected jurisdiction to public health
145145 or safety; national, state, or municipal economic or physical
146146 security; civil liberties; or public confidence ;
147147 4. Level 2 is a medium-level incident that may impact public
148148 health or safety; national, state, or municipal economic or physical
149149 security; civil liberties; or public c onfidence; and
150150 5. Level 1 is a low-level incident that is unlikely to impact
151151 public health or safet y; national, state, or municipal economic or
152152 physical security; civil liberties; or public confidence.
153153 SECTION 2. AMENDATORY 74 O.S. 202 1, Section 63, is
154154 amended to read as follows:
155155 Section 63. A. The Office of Management and En terprise
156156 Services shall have power to promulgate rules not inco nsistent with
157157 the laws of this state.
158158 B. The Office of Management and Enterprise Services shall hav e
159159 charge of the construction, repa ir, maintenance, insurance, and
160160 operation of all buildings owned, used, or occupied by or on behalf
161161 of the state including buildings owned by the Oklahoma Capitol
162162 Improvement Authority where s uch services are carried out b y
163163
164164
165165 Req. No. 511 Page 3 1
166166 2
167167 3
168168 4
169169 5
170170 6
171171 7
172172 8
173173 9
174174 10
175175 11
176176 12
177177 13
178178 14
179179 15
180180 16
181181 17
182182 18
183183 19
184184 20
185185 21
186186 22
187187 23
188188 24
189189 1
190190 2
191191 3
192192 4
193193 5
194194 6
195195 7
196196 8
197197 9
198198 10
199199 11
200200 12
201201 13
202202 14
203203 15
204204 16
205205 17
206206 18
207207 19
208208 20
209209 21
210210 22
211211 23
212212 24
213213
214214 contract with the Authority, exc ept as otherwise provided by law.
215215 Whenever feasible, the O ffice of Management and Enterprise Services
216216 may utilize the Construction Division of the Department of
217217 Corrections for the constructi on and repair of buildings for the
218218 Department of Corrections.
219219 C. The Director of the Office of Management and Enterprise
220220 Services shall have authority to purchase all material and perfo rm
221221 all other duties necessary in the construction, repair, and
222222 maintenance of all buildings under it s management or control, shall
223223 make all necessary contracts by or on behalf of the state for any
224224 buildings or rooms rented for the use of the state or any o f the
225225 officers thereof, and shall have charge of t he arrangement and
226226 allotment of space in such buil dings among the different state
227227 officers except as otherwise provided by law.
228228 D. The Office of Management and Enterprise Services shall not
229229 have any authority or responsibility for buildings, rooms or spac e
230230 under the management or control of the Universit y Hospitals
231231 Authority.
232232 E. The Office of Management and Enterprise Services shall have
233233 the custody and control of all state property, and all other
234234 property managed or used by the state, except military sto res and
235235 such property under the control of the Sta te Banking Department and
236236 the two houses of the State Legislature, shall procure all necessar y
237237 insurance thereon against loss and shall allot the use of the
238238
239239
240240 Req. No. 511 Page 4 1
241241 2
242242 3
243243 4
244244 5
245245 6
246246 7
247247 8
248248 9
249249 10
250250 11
251251 12
252252 13
253253 14
254254 15
255255 16
256256 17
257257 18
258258 19
259259 20
260260 21
261261 22
262262 23
263263 24
264264 1
265265 2
266266 3
267267 4
268268 5
269269 6
270270 7
271271 8
272272 9
273273 10
274274 11
275275 12
276276 13
277277 14
278278 15
279279 16
280280 17
281281 18
282282 19
283283 20
284284 21
285285 22
286286 23
287287 24
288288
289289 property to the several offices of the state, and prescribe where
290290 the property shall be kept for pu blic use.
291291 F. The Office of Manage ment and Enterprise Services shall keep
292292 an accurate account of all property purchased for the state or any
293293 of the departments or officers thereof, except that purchased for
294294 and by the two houses of the State Legislature. The two houses
295295 shall have the exclusive use, care, and custody of their respective
296296 chambers, committee rooms, furniture, and property, and shall keep
297297 their respective records of said furniture and property.
298298 G. The Office of Management and Enterprise Servi ces shall not
299299 have any authority o r responsibility for property purchased for or
300300 under the management or control of the University Hospitals
301301 Authority except as expressly provided by law.
302302 H. The Office of Management and Enter prise Services shall not
303303 have any authority or responsibility fo r property purchased for or
304304 under the management or control of CompSource Oklahoma if CompSource
305305 Oklahoma is operating pur suant to a pilot program authorized by
306306 Sections 3316 and 3317 of this title.
307307 I. The Office of Management and Enterprise Services shall have
308308 the responsibility to assess and track all levels of cybersecurity
309309 incidents occurring within state agencies, count ies, municipalities,
310310 and political subdivisions as defined in Section 1 of this act .
311311
312312
313313 Req. No. 511 Page 5 1
314314 2
315315 3
316316 4
317317 5
318318 6
319319 7
320320 8
321321 9
322322 10
323323 11
324324 12
325325 13
326326 14
327327 15
328328 16
329329 17
330330 18
331331 19
332332 20
333333 21
334334 22
335335 23
336336 24
337337 1
338338 2
339339 3
340340 4
341341 5
342342 6
343343 7
344344 8
345345 9
346346 10
347347 11
348348 12
349349 13
350350 14
351351 15
352352 16
353353 17
354354 18
355355 19
356356 20
357357 21
358358 22
359359 23
360360 24
361361
362362 SECTION 3. NEW LAW A new section of law to be codified
363363 in the Oklahoma Stat utes as Section 63.8 of Title 74, unless there
364364 is created a duplication in numbering, reads as follows:
365365 The cybersecurity incident reporting process shall specify the
366366 information that shall be reported by a state agency , county,
367367 municipality, or political subdivision, to the Office of Management
368368 and Enterprise Services following a cybersecurity or ransomware
369369 incident, which, at a minimum, shall include the following:
370370 1. A summary of the facts surrounding the cybersecurity
371371 incident or ransomware inciden t;
372372 2. The date on which the state agency most recently backed up
373373 its data, the physical location of the backup, if the backup was
374374 affected, and if the backup was created using cloud computing;
375375 3. The types of data compromised by the cybersecurity incident
376376 or ransomware incident;
377377 4. The estimated fiscal impact of the cybersecuri ty incident or
378378 ransomware incident; and
379379 5. In the case of a ransomware incident, the details of the
380380 ransom demanded.
381381 SECTION 4. This act shall become effective Novemb er 1, 2023.
382382
383383 59-1-511 KR 1/13/2023 8:56:46 AM