Texas 2017 - 85th Regular

Texas House Bill HB1604 Compare Versions

OldNewDifferences
11 85R23797 YDB-D
22 By: Blanco, Elkins, Capriglione, H.B. No. 1604
33 Gonzales of Williamson, Lucio III
44 Substitute the following for H.B. No. 1604:
55 By: Elkins C.S.H.B. No. 1604
66
77
88 A BILL TO BE ENTITLED
99 AN ACT
1010 relating to the requirements for and approval of a state agency's
1111 information security plan.
1212 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1313 SECTION 1. Section 2054.133, Government Code, is amended by
1414 adding Subsections (b-1), (b-2), (b-3), and (b-4) to read as
1515 follows:
1616 (b-1) The executive head and chief information security
1717 officer of each state agency shall annually review and approve in
1818 writing the agency's information security plan and strategies for
1919 addressing the agency's information resources systems that are at
2020 highest risk for security breaches. If a state agency does not have
2121 a chief information security officer, the highest ranking
2222 information security employee for the agency shall review and
2323 approve the plan and strategies. The executive head retains full
2424 responsibility for the agency's information security and any risks
2525 to that security.
2626 (b-2) Before submitting to the Legislative Budget Board a
2727 legislative appropriation request for a state fiscal biennium, a
2828 state agency must file with the board the written approval required
2929 under Subsection (b-1) for each year of the current state fiscal
3030 biennium.
3131 (b-3) Each state agency shall include in the agency's
3232 information security plan the actions the agency is taking to
3333 incorporate into the plan the core functions of "identify, protect,
3434 detect, respond, and recover" as recommended in the "Framework for
3535 Improving Critical Infrastructure Cybersecurity" of the United
3636 States Department of Commerce National Institute of Standards and
3737 Technology. The agency shall, at a minimum, identify any
3838 information the agency requires individuals to provide to the
3939 agency or the agency retains that is not necessary for the agency's
4040 operations. The agency may incorporate the core functions over a
4141 period of years.
4242 (b-4) A state agency's information security plan must
4343 include appropriate privacy and security standards that, at a
4444 minimum, require a vendor who offers cloud computing services or
4545 other software, applications, online services, or information
4646 technology solutions to any state agency to demonstrate that data
4747 provided by the state to the vendor will be maintained in compliance
4848 with all applicable state and federal laws and rules.
4949 SECTION 2. Section 2054.133, Government Code, as amended by
5050 this Act, applies only to an information security plan submitted on
5151 or after the effective date of this Act.
5252 SECTION 3. This Act takes effect September 1, 2017.