Texas 2017 - 85th Regular

Texas House Bill HB1467 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 By: Capriglione H.B. No. 1467
22
33
44 A BILL TO BE ENTITLED
55 AN ACT
66 relating to reports on and purchase of information technology by
77 state agencies.
88 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
99 SECTION 1. Section 552.139(b), Government Code, is amended
1010 by adding subsection (4) to read as follows:
1111 (b) The following information is confidential:
1212 (1) a computer network vulnerability report;
1313 (2) any other assessment of the extent to which data
1414 processing operations, a computer, a computer program, network,
1515 system, or system interface, or software of a governmental body or
1616 of a contractor of a governmental body is vulnerable to
1717 unauthorized access or harm, including an assessment of the extent
1818 to which the governmental body's or contractor's electronically
1919 stored information containing sensitive or critical information is
2020 vulnerable to alteration, damage, erasure, or inappropriate use;
2121 and
2222 (3) a photocopy or other copy of an identification
2323 badge issued to an official or employee of a governmental body.
2424 (4) information collected, assembled, or maintained
2525 by or for a governmental entity to prevent, detect, or investigate
2626 security incidents.
2727 SECTION 2. Subchapter C, Chapter 2054, Government Code, is
2828 amended by adding Section 2054.068 to read as follows:
2929 Sec. 2054.068. INFORMATION TECHNOLOGY INFRASTRUCTURE
3030 REPORT. (a) In this section, "information technology" includes
3131 information resources and information resources technologies.
3232 (b) The department shall collect from each state agency
3333 information on the status and condition of the agency's information
3434 technology infrastructure, including information regarding:
3535 (1) the agency's information security program;
3636 (2) an inventory of the agency's servers, mainframes,
3737 and other information technology equipment;
3838 (3) identification of vendors that operate and manage
3939 the agency's information technology infrastructure; and
4040 (4) any additional related information requested by
4141 the department.
4242 (c) A state agency shall provide the information required by
4343 Subsection (b) to the department according to a schedule determined
4444 by the department.
4545 (d) Not later than August 31 of each even-numbered year, the
4646 department shall submit to the governor, chair of the house
4747 appropriations committee, chair of the senate finance committee,
4848 speaker of the house of representatives, lieutenant governor, and
4949 staff of the Legislative Budget Board a consolidated report of the
5050 information submitted by state agencies under Subsection (b).
5151 (e) The consolidated report required by Subsection (d)
5252 must:
5353 (1) include an analysis and assessment of each state
5454 agency's security and operational risks; and
5555 (2) for a state agency found to be at higher security
5656 and operational risks, include a detailed analysis of the
5757 requirements for the agency to address the risks and related
5858 vulnerabilities and the cost estimates to implement those
5959 requirements.
6060 (f) With the exception of information that is confidential
6161 under Chapter 552, including Section 552.139, or other state or
6262 federal law, the consolidated report submitted under Subsection (d)
6363 is public information and must be released or made available to the
6464 public upon request. A governmental body as defined by Section
6565 552.003, Government Code, may withhold information confidential
6666 under Chapter 552, including Section 552.139, or other state or
6767 federal law that is contained in a consolidated report released
6868 under this section without the necessity of requesting a decision
6969 from the attorney general under Subchapter G, Chapter 552,
7070 Government Code.
7171 (g) This section does not apply to an institution of higher
7272 education or university system, as defined by Section 61.003,
7373 Education Code.
7474 SECTION 3. Section 2054.0965(a), Government Code, is
7575 amended to read as follows:
7676 (a) Not later than March 31 [December 1] of each
7777 even-numbered [odd-numbered] year, a state agency shall complete a
7878 review of the operational aspects of the agency's information
7979 resources deployment following instructions developed by the
8080 department.
8181 SECTION 4. Section 2157.007, Government Code, is amended by
8282 amending Subsection (b) and adding Subsection (e) to read as
8383 follows:
8484 (b) A state agency shall [may] consider cloud computing
8585 service options, including any cost savings associated with
8686 purchasing those service options from a commercial cloud computing
8787 service provider and a statewide technology center established by
8888 the department, when making purchases for a major information
8989 resources project under Section 2054.118.
9090 (e) Not later than August 1 of each even-numbered year, the
9191 department, using existing resources, shall submit a report to the
9292 governor, lieutenant governor, and speaker of the house of
9393 representatives on the use of cloud computing service options by
9494 state agencies. The report must include use cases that provided
9595 cost savings and other benefits, including security enhancements.
9696 A state agency shall cooperate with the department in the creation
9797 of the report by providing timely and accurate information and any
9898 assistance required by the department.
9999 SECTION 5. This Act takes effect September 1, 2017.