Texas 2019 - 86th Regular

Texas House Bill HB3834 Compare Versions

OldNewDifferences
1-H.B. No. 3834
1+By: Capriglione (Senate Sponsor - Paxton) H.B. No. 3834
2+ (In the Senate - Received from the House April 26, 2019;
3+ April 29, 2019, read first time and referred to Committee on
4+ Business & Commerce; May 20, 2019, reported favorably by the
5+ following vote: Yeas 9, Nays 0; May 20, 2019, sent to printer.)
6+Click here to see the committee vote
27
38
9+ A BILL TO BE ENTITLED
410 AN ACT
511 relating to the requirement that certain state and local government
612 employees and state contractors complete a cybersecurity training
713 program certified by the Department of Information Resources.
814 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
915 SECTION 1. The heading to Subchapter N-1, Chapter 2054,
1016 Government Code, is amended to read as follows:
1117 SUBCHAPTER N-1. [STATE] CYBERSECURITY
1218 SECTION 2. Section 2054.518(a), Government Code, is amended
1319 to read as follows:
1420 (a) The department shall develop a plan to address
1521 cybersecurity risks and incidents in this state. The department
1622 may enter into an agreement with a national organization, including
1723 the National Cybersecurity Preparedness Consortium, to support the
1824 department's efforts in implementing the components of the plan for
1925 which the department lacks resources to address internally. The
2026 agreement may include provisions for:
2127 (1) [providing fee reimbursement for appropriate
2228 industry-recognized certification examinations for and training to
2329 state agencies preparing for and responding to cybersecurity risks
2430 and incidents;
2531 [(2) developing and maintaining a cybersecurity risks
2632 and incidents curriculum using existing programs and models for
2733 training state agencies;
2834 [(3) delivering to state agency personnel with access
2935 to state agency networks routine training related to appropriately
3036 protecting and maintaining information technology systems and
3137 devices, implementing cybersecurity best practices, and mitigating
3238 cybersecurity risks and vulnerabilities;
3339 [(4)] providing technical assistance services to
3440 support preparedness for and response to cybersecurity risks and
3541 incidents;
3642 (2) [(5)] conducting cybersecurity [training and]
3743 simulation exercises for state agencies to encourage coordination
3844 in defending against and responding to cybersecurity risks and
3945 incidents;
4046 (3) [(6)] assisting state agencies in developing
4147 cybersecurity information-sharing programs to disseminate
4248 information related to cybersecurity risks and incidents; and
4349 (4) [(7)] incorporating cybersecurity risk and
4450 incident prevention and response methods into existing state
4551 emergency plans, including continuity of operation plans and
4652 incident response plans.
4753 SECTION 3. Subchapter N-1, Chapter 2054, Government Code,
4854 is amended by adding Sections 2054.519, 2054.5191, and 2054.5192 to
4955 read as follows:
5056 Sec. 2054.519. STATE CERTIFIED CYBERSECURITY TRAINING
5157 PROGRAMS. (a) The department, in consultation with the
5258 cybersecurity council established under Section 2054.512 and
5359 industry stakeholders, shall annually:
5460 (1) certify at least five cybersecurity training
5561 programs for state and local government employees; and
5662 (2) update standards for maintenance of certification
5763 by the cybersecurity training programs under this section.
5864 (b) To be certified under Subsection (a), a cybersecurity
59- training program must:
65+ training program must include activities, case studies,
66+ hypothetical situations, and other methods that:
6067 (1) focus on forming information security habits and
6168 procedures that protect information resources; and
6269 (2) teach best practices for detecting, assessing,
6370 reporting, and addressing information security threats.
64- (c) The department may identify and certify under
65- Subsection (a) training programs provided by state agencies and
66- local governments that satisfy the training requirements described
67- by Subsection (b).
68- (d) The department may contract with an independent third
71+ (c) The department may contract with an independent third
6972 party to certify cybersecurity training programs under this
7073 section.
71- (e) The department shall annually publish on the
74+ (d) The department shall annually publish on the
7275 department's Internet website the list of cybersecurity training
7376 programs certified under this section.
74- (f) Notwithstanding Subsection (a), a local government that
77+ (e) Notwithstanding Subsection (a), a local government that
7578 employs a dedicated information resources cybersecurity officer
7679 may offer to its employees a cybersecurity training program that
7780 satisfies the requirements described by Subsection (b).
7881 Sec. 2054.5191. CYBERSECURITY TRAINING REQUIRED: CERTAIN
79- EMPLOYEES. (a) Each state agency shall identify state employees
80- who use a computer to complete at least 25 percent of the employee's
81- required duties. At least once each year, an employee identified by
82- the state agency and each elected or appointed officer of the agency
83- shall complete a cybersecurity training program certified under
84- Section 2054.519.
85- (a-1) At least once each year, a local government shall
86- identify local government employees who have access to a local
87- government computer system or database and require those employees
88- and elected officials of the local government to complete a
89- cybersecurity training program certified under Section 2054.519 or
90- offered under Section 2054.519(f).
82+ EMPLOYEES. (a) At least once each year, a state employee that uses a
83+ computer to complete at least 25 percent of the employee's required
84+ duties shall complete a cybersecurity training program certified
85+ under Section 2054.519.
86+ (a-1) At least once each year, a local government employee
87+ that uses a computer to complete at least 25 percent of the
88+ employee's required duties shall complete a cybersecurity training
89+ program certified under Section 2054.519 or offered under Section
90+ 2054.519(e).
9191 (b) The governing body of a local government may select the
9292 most appropriate cybersecurity training program certified under
93- Section 2054.519 or offered under Section 2054.519(f) for employees
93+ Section 2054.519 or offered under Section 2054.519(e) for employees
9494 of the local government to complete. The governing body shall:
9595 (1) verify and report on the completion of a
9696 cybersecurity training program by employees of the local government
9797 to the department; and
9898 (2) require periodic audits to ensure compliance with
9999 this section.
100100 (c) A state agency may select the most appropriate
101101 cybersecurity training program certified under Section 2054.519
102102 for employees of the state agency. The executive head of each state
103103 agency shall verify completion of a cybersecurity training program
104104 by employees of the state agency in a manner specified by the
105105 department.
106106 (d) The executive head of each state agency shall
107- periodically require an internal review of the agency to ensure
108- compliance with this section.
107+ periodically audit the agency to ensure compliance with this
108+ section and send the results to the department.
109109 Sec. 2054.5192. CYBERSECURITY TRAINING REQUIRED: CERTAIN
110110 STATE CONTRACTORS. (a) In this section, "contractor" includes a
111111 subcontractor, officer, or employee of the contractor.
112112 (b) A state agency shall require any contractor who has
113113 access to a state computer system or database to complete a
114114 cybersecurity training program certified under Section 2054.519 as
115115 selected by the agency.
116116 (c) The cybersecurity training program must be completed by
117117 a contractor during the term of the contract and during any renewal
118118 period.
119119 (d) Required completion of a cybersecurity training program
120120 must be included in the terms of a contract awarded by a state
121121 agency to a contractor.
122122 (e) A contractor required to complete a cybersecurity
123123 training program under this section shall verify completion of the
124- program to the contracting state agency. The person who oversees
125- contract management for the agency shall:
124+ program to the contracting state agency. The agency's contract
125+ manager shall:
126126 (1) report the contractor's completion to the
127127 department; and
128- (2) periodically review agency contracts to ensure
129- compliance with this section.
128+ (2) conduct periodic audits to ensure compliance with
129+ this section.
130130 SECTION 4. Section 2054.518(c), Government Code, is
131131 repealed.
132132 SECTION 5. The changes in law made by this Act apply to a
133133 contract entered into or renewed on or after the effective date of
134134 this Act. A contract entered into or renewed before the effective
135135 date of this Act is governed by the law in effect on the date the
136136 contract was entered into or renewed, and the former law is
137137 continued in effect for that purpose.
138138 SECTION 6. This Act takes effect immediately if it receives
139139 a vote of two-thirds of all the members elected to each house, as
140140 provided by Section 39, Article III, Texas Constitution. If this
141141 Act does not receive the vote necessary for immediate effect, this
142142 Act takes effect September 1, 2019.
143- ______________________________ ______________________________
144- President of the Senate Speaker of the House
145- I certify that H.B. No. 3834 was passed by the House on April
146- 25, 2019, by the following vote: Yeas 130, Nays 2, 1 present, not
147- voting; and that the House concurred in Senate amendments to H.B.
148- No. 3834 on May 24, 2019, by the following vote: Yeas 140, Nays 0,
149- 2 present, not voting.
150- ______________________________
151- Chief Clerk of the House
152- I certify that H.B. No. 3834 was passed by the Senate, with
153- amendments, on May 22, 2019, by the following vote: Yeas 31, Nays
154- 0.
155- ______________________________
156- Secretary of the Senate
157- APPROVED: __________________
158- Date
159- __________________
160- Governor
143+ * * * * *