1 | 1 | | 81R8189 MCK-F |
---|
2 | 2 | | By: McCall H.B. No. 3187 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | A BILL TO BE ENTITLED |
---|
6 | 6 | | AN ACT |
---|
7 | 7 | | relating to information technology security practices of state |
---|
8 | 8 | | agencies. |
---|
9 | 9 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
10 | 10 | | SECTION 1. Section 411.081(i), Government Code, is amended |
---|
11 | 11 | | to read as follows: |
---|
12 | 12 | | (i) A criminal justice agency may disclose criminal history |
---|
13 | 13 | | record information that is the subject of an order of nondisclosure |
---|
14 | 14 | | to the following noncriminal justice agencies or entities only: |
---|
15 | 15 | | (1) the State Board for Educator Certification; |
---|
16 | 16 | | (2) a school district, charter school, private school, |
---|
17 | 17 | | regional education service center, commercial transportation |
---|
18 | 18 | | company, or education shared service arrangement; |
---|
19 | 19 | | (3) the Texas Medical Board; |
---|
20 | 20 | | (4) the Texas School for the Blind and Visually |
---|
21 | 21 | | Impaired; |
---|
22 | 22 | | (5) the Board of Law Examiners; |
---|
23 | 23 | | (6) the State Bar of Texas; |
---|
24 | 24 | | (7) a district court regarding a petition for name |
---|
25 | 25 | | change under Subchapter B, Chapter 45, Family Code; |
---|
26 | 26 | | (8) the Texas School for the Deaf; |
---|
27 | 27 | | (9) the Department of Family and Protective Services; |
---|
28 | 28 | | (10) the Texas Youth Commission; |
---|
29 | 29 | | (11) the Department of Assistive and Rehabilitative |
---|
30 | 30 | | Services; |
---|
31 | 31 | | (12) the Department of State Health Services, a local |
---|
32 | 32 | | mental health service, a local mental retardation authority, or a |
---|
33 | 33 | | community center providing services to persons with mental illness |
---|
34 | 34 | | or retardation; |
---|
35 | 35 | | (13) the Texas Private Security Board; |
---|
36 | 36 | | (14) a municipal or volunteer fire department; |
---|
37 | 37 | | (15) the Texas Board of Nursing; |
---|
38 | 38 | | (16) a safe house providing shelter to children in |
---|
39 | 39 | | harmful situations; |
---|
40 | 40 | | (17) a public or nonprofit hospital or hospital |
---|
41 | 41 | | district; |
---|
42 | 42 | | (18) the Texas Juvenile Probation Commission; |
---|
43 | 43 | | (19) the securities commissioner, the banking |
---|
44 | 44 | | commissioner, the savings and mortgage lending commissioner, or the |
---|
45 | 45 | | credit union commissioner; |
---|
46 | 46 | | (20) the Texas State Board of Public Accountancy; |
---|
47 | 47 | | (21) the Texas Department of Licensing and Regulation; |
---|
48 | 48 | | (22) the Health and Human Services Commission; |
---|
49 | 49 | | (23) the Department of Aging and Disability Services; |
---|
50 | 50 | | [and] |
---|
51 | 51 | | (24) the Texas Education Agency; and |
---|
52 | 52 | | (25) the Department of Information Resources. |
---|
53 | 53 | | SECTION 2. Subchapter F, Chapter 411, Government Code, is |
---|
54 | 54 | | amended by adding Section 411.14055 to read as follows: |
---|
55 | 55 | | Sec. 411.14055. ACCESS TO CRIMINAL HISTORY RECORD |
---|
56 | 56 | | INFORMATION: DEPARTMENT OF INFORMATION RESOURCES. (a) The |
---|
57 | 57 | | Department of Information Resources is entitled to obtain from the |
---|
58 | 58 | | department or another law enforcement agency the criminal history |
---|
59 | 59 | | record information maintained by the department or other law |
---|
60 | 60 | | enforcement agency that relates to a person who: |
---|
61 | 61 | | (1) is an employee or an applicant for employment with |
---|
62 | 62 | | the Department of Information Resources; |
---|
63 | 63 | | (2) may perform services for the Department of |
---|
64 | 64 | | Information Resources; or |
---|
65 | 65 | | (3) is an employee or subcontractor, or an applicant |
---|
66 | 66 | | to be an employee or subcontractor, of a contractor that provides |
---|
67 | 67 | | services to the Department of Information Resources. |
---|
68 | 68 | | (b) Criminal history record information obtained by the |
---|
69 | 69 | | Department of Information Resources under Subsection (a) may be |
---|
70 | 70 | | used only to evaluate: |
---|
71 | 71 | | (1) an employee or an applicant for employment with |
---|
72 | 72 | | the Department of Information Resources; |
---|
73 | 73 | | (2) a person who may perform services for the |
---|
74 | 74 | | Department of Information Resources; or |
---|
75 | 75 | | (3) a person who is an employee or subcontractor, or an |
---|
76 | 76 | | applicant to be an employee or subcontractor, of a contractor that |
---|
77 | 77 | | provides services to the Department of Information Resources. |
---|
78 | 78 | | (c) Criminal history record information obtained by the |
---|
79 | 79 | | Department of Information Resources under this section may not be |
---|
80 | 80 | | released or disclosed to any person or agency except on court order |
---|
81 | 81 | | or with the consent of the person who is the subject of the |
---|
82 | 82 | | information. |
---|
83 | 83 | | (d) The Department of Information Resources shall destroy |
---|
84 | 84 | | the criminal history record information obtained under this section |
---|
85 | 85 | | after the information is used for the purposes authorized by this |
---|
86 | 86 | | section. |
---|
87 | 87 | | SECTION 3. Subchapter D, Chapter 551, Government Code, is |
---|
88 | 88 | | amended by adding Section 551.089 to read as follows: |
---|
89 | 89 | | Sec. 551.089. DEPARTMENT OF INFORMATION RESOURCES. This |
---|
90 | 90 | | chapter does not require the governing board of the Department of |
---|
91 | 91 | | Information Resources to conduct an open meeting to deliberate: |
---|
92 | 92 | | (1) security assessments or deployments relating to |
---|
93 | 93 | | information resources technology; |
---|
94 | 94 | | (2) network security information as described by |
---|
95 | 95 | | Section 2059.055(b); or |
---|
96 | 96 | | (3) the deployment, or specific occasions for |
---|
97 | 97 | | implementation, of security personnel, critical infrastructure, or |
---|
98 | 98 | | security devices. |
---|
99 | 99 | | SECTION 4. Section 552.139, Government Code, is amended to |
---|
100 | 100 | | read as follows: |
---|
101 | 101 | | Sec. 552.139. EXCEPTION: GOVERNMENT INFORMATION RELATED TO |
---|
102 | 102 | | SECURITY OR INFRASTRUCTURE ISSUES FOR COMPUTERS. (a) Information |
---|
103 | 103 | | is excepted from the requirements of Section 552.021 if it is |
---|
104 | 104 | | information that relates to computer network security, to |
---|
105 | 105 | | restricted information under Section 2059.055, or to the design, |
---|
106 | 106 | | operation, or defense of a computer network. |
---|
107 | 107 | | (b) The following information is confidential: |
---|
108 | 108 | | (1) a computer network vulnerability report; and |
---|
109 | 109 | | (2) any other assessment of the extent to which data |
---|
110 | 110 | | processing operations, a computer, [or] a computer program, |
---|
111 | 111 | | network, system, or system interface, or software of a governmental |
---|
112 | 112 | | body or of a contractor of a governmental body is vulnerable to |
---|
113 | 113 | | unauthorized access or harm, including an assessment of the extent |
---|
114 | 114 | | to which the governmental body's or contractor's electronically |
---|
115 | 115 | | stored information containing sensitive or critical information is |
---|
116 | 116 | | vulnerable to alteration, damage, [or] erasure, or inappropriate |
---|
117 | 117 | | use. |
---|
118 | 118 | | (c) Notwithstanding the confidential nature of the |
---|
119 | 119 | | information described by this section, the information may be |
---|
120 | 120 | | disclosed to a bidder if the governmental body determines that |
---|
121 | 121 | | providing the information is necessary for the bidder to provide an |
---|
122 | 122 | | accurate bid. A disclosure under this subsection is not a voluntary |
---|
123 | 123 | | disclosure for purposes of Section 552.007. |
---|
124 | 124 | | SECTION 5. Sections 2054.077(b), (d), and (e), Government |
---|
125 | 125 | | Code, are amended to read as follows: |
---|
126 | 126 | | (b) In addition to any assessment required under other law, |
---|
127 | 127 | | the [The] information resources manager of a state agency may |
---|
128 | 128 | | prepare or have prepared a report, including an executive summary |
---|
129 | 129 | | of the findings of the report, assessing the extent to which a |
---|
130 | 130 | | computer, a computer program, a computer network, a computer |
---|
131 | 131 | | system, an interface to a computer system, computer software, or |
---|
132 | 132 | | data processing of the agency or of a contractor of the agency is |
---|
133 | 133 | | vulnerable to unauthorized access or harm, including the extent to |
---|
134 | 134 | | which the agency's or contractor's electronically stored |
---|
135 | 135 | | information containing sensitive or critical information is |
---|
136 | 136 | | vulnerable to alteration, damage, [or] erasure, or inappropriate |
---|
137 | 137 | | use. |
---|
138 | 138 | | (d) The [On request, the] information resources manager |
---|
139 | 139 | | shall provide an electronic [a] copy of the vulnerability report on |
---|
140 | 140 | | its completion to: |
---|
141 | 141 | | (1) the department; |
---|
142 | 142 | | (2) the state auditor; [and] |
---|
143 | 143 | | (3) the agency's executive director; and |
---|
144 | 144 | | (4) any other information technology security |
---|
145 | 145 | | oversight group specifically authorized by the legislature to |
---|
146 | 146 | | receive the report. |
---|
147 | 147 | | (e) Separate from the executive summary described by |
---|
148 | 148 | | Subsection (b), a [A] state agency whose information resources |
---|
149 | 149 | | manager has prepared or has had prepared a vulnerability report |
---|
150 | 150 | | shall prepare a summary of the report that does not contain any |
---|
151 | 151 | | information the release of which might compromise the security of |
---|
152 | 152 | | the state agency's or state agency contractor's computers, computer |
---|
153 | 153 | | programs, computer networks, computer systems, computer software, |
---|
154 | 154 | | data processing, or electronically stored information. The summary |
---|
155 | 155 | | is available to the public on request. |
---|
156 | 156 | | SECTION 6. This Act takes effect September 1, 2009. |
---|