1 | 1 | | 87R2931 MWC-D |
---|
2 | 2 | | By: Paxton S.B. No. 345 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | A BILL TO BE ENTITLED |
---|
6 | 6 | | AN ACT |
---|
7 | 7 | | relating to state agency and local government compliance with |
---|
8 | 8 | | cybersecurity training requirements. |
---|
9 | 9 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
10 | 10 | | SECTION 1. Subchapter A, Chapter 772, Government Code, is |
---|
11 | 11 | | amended by adding Section 772.012 to read as follows: |
---|
12 | 12 | | Sec. 772.012. COMPLIANCE WITH CYBERSECURITY TRAINING |
---|
13 | 13 | | REQUIREMENTS. (a) In this section, "local government" has the |
---|
14 | 14 | | meaning assigned by Section 2054.003. |
---|
15 | 15 | | (b) To apply for a grant under this chapter, a local |
---|
16 | 16 | | government must submit with the grant application a written |
---|
17 | 17 | | certification of the local government's compliance with the |
---|
18 | 18 | | cybersecurity training required by Section 2054.5191. |
---|
19 | 19 | | (c) On a determination by the criminal justice division |
---|
20 | 20 | | established under Section 772.006 that a local government awarded a |
---|
21 | 21 | | grant under this chapter has not complied with the cybersecurity |
---|
22 | 22 | | training required by Section 2054.5191, the local government shall |
---|
23 | 23 | | pay to this state an amount equal to the amount of the grant award. |
---|
24 | 24 | | A local government that is the subject of a determination described |
---|
25 | 25 | | by this subsection is ineligible for another grant under this |
---|
26 | 26 | | chapter until the second anniversary of the date the local |
---|
27 | 27 | | government is determined ineligible. |
---|
28 | 28 | | SECTION 2. The heading to Section 2054.5191, Government |
---|
29 | 29 | | Code, is amended to read as follows: |
---|
30 | 30 | | Sec. 2054.5191. CYBERSECURITY TRAINING REQUIRED: CERTAIN |
---|
31 | 31 | | EMPLOYEES AND OFFICIALS. |
---|
32 | 32 | | SECTION 3. Sections 2054.5191(a-1) and (b), Government |
---|
33 | 33 | | Code, are amended to read as follows: |
---|
34 | 34 | | (a-1) At least once each year, a local government shall: |
---|
35 | 35 | | (1) identify local government employees and elected |
---|
36 | 36 | | and appointed officials who have access to a local government |
---|
37 | 37 | | computer system or database and use a computer to perform at least |
---|
38 | 38 | | 25 percent of the employee's or official's required duties; and |
---|
39 | 39 | | (2) require the [those] employees and [elected] |
---|
40 | 40 | | officials identified under Subdivision (1) [of the local |
---|
41 | 41 | | government] to complete a cybersecurity training program certified |
---|
42 | 42 | | under Section 2054.519 or offered under Section 2054.519(f). |
---|
43 | 43 | | (b) The governing body of a local government may select the |
---|
44 | 44 | | most appropriate cybersecurity training program certified under |
---|
45 | 45 | | Section 2054.519 or offered under Section 2054.519(f) for employees |
---|
46 | 46 | | and officials of the local government to complete. The governing |
---|
47 | 47 | | body shall: |
---|
48 | 48 | | (1) verify and report on the completion of a |
---|
49 | 49 | | cybersecurity training program by employees and officials of the |
---|
50 | 50 | | local government to the department; and |
---|
51 | 51 | | (2) require periodic audits to ensure compliance with |
---|
52 | 52 | | this section. |
---|
53 | 53 | | SECTION 4. Section 2056.002(b), Government Code, is amended |
---|
54 | 54 | | to read as follows: |
---|
55 | 55 | | (b) The Legislative Budget Board and the governor's office |
---|
56 | 56 | | shall determine the elements required to be included in each |
---|
57 | 57 | | agency's strategic plan. Unless modified by the Legislative Budget |
---|
58 | 58 | | Board and the governor's office, and except as provided by |
---|
59 | 59 | | Subsection (c), a plan must include: |
---|
60 | 60 | | (1) a statement of the mission and goals of the state |
---|
61 | 61 | | agency; |
---|
62 | 62 | | (2) a description of the indicators developed under |
---|
63 | 63 | | this chapter and used to measure the output and outcome of the |
---|
64 | 64 | | agency; |
---|
65 | 65 | | (3) identification of the groups of people served by |
---|
66 | 66 | | the agency, including those having service priorities, or other |
---|
67 | 67 | | service measures established by law, and estimates of changes in |
---|
68 | 68 | | those groups expected during the term of the plan; |
---|
69 | 69 | | (4) an analysis of the use of the agency's resources to |
---|
70 | 70 | | meet the agency's needs, including future needs, and an estimate of |
---|
71 | 71 | | additional resources that may be necessary to meet future needs; |
---|
72 | 72 | | (5) an analysis of expected changes in the services |
---|
73 | 73 | | provided by the agency because of changes in state or federal law; |
---|
74 | 74 | | (6) a description of the means and strategies for |
---|
75 | 75 | | meeting the agency's needs, including future needs, and achieving |
---|
76 | 76 | | the goals established under Section 2056.006 for each area of state |
---|
77 | 77 | | government for which the agency provides services; |
---|
78 | 78 | | (7) a description of the capital improvement needs of |
---|
79 | 79 | | the agency during the term of the plan and a statement, if |
---|
80 | 80 | | appropriate, of the priority of those needs; |
---|
81 | 81 | | (8) identification of each geographic region of this |
---|
82 | 82 | | state, including the Texas-Louisiana border region and the |
---|
83 | 83 | | Texas-Mexico border region, served by the agency, and if |
---|
84 | 84 | | appropriate the agency's means and strategies for serving each |
---|
85 | 85 | | region; |
---|
86 | 86 | | (9) a description of the training of the agency's |
---|
87 | 87 | | contract managers under Section 656.052; |
---|
88 | 88 | | (10) an analysis of the agency's expected expenditures |
---|
89 | 89 | | that relate to federally owned or operated military installations |
---|
90 | 90 | | or facilities, or communities where a federally owned or operated |
---|
91 | 91 | | military installation or facility is located; |
---|
92 | 92 | | (11) an analysis of the strategic use of information |
---|
93 | 93 | | resources as provided by the instructions prepared under Section |
---|
94 | 94 | | 2054.095; [and] |
---|
95 | 95 | | (12) a written certification of the agency's |
---|
96 | 96 | | compliance with the cybersecurity training required under Sections |
---|
97 | 97 | | 2054.5191 and 2054.5192; and |
---|
98 | 98 | | (13) other information that may be required. |
---|
99 | 99 | | SECTION 5. (a) Section 772.012, Government Code, as added |
---|
100 | 100 | | by this Act, applies only to a grant application submitted by a |
---|
101 | 101 | | local government on or after September 1, 2021. |
---|
102 | 102 | | (b) Section 2056.002(b), Government Code, as amended by |
---|
103 | 103 | | this Act, applies only to a strategic plan submitted by a state |
---|
104 | 104 | | agency on or after January 1, 2022. |
---|
105 | 105 | | SECTION 6. This Act takes effect immediately if it receives |
---|
106 | 106 | | a vote of two-thirds of all the members elected to each house, as |
---|
107 | 107 | | provided by Section 39, Article III, Texas Constitution. If this |
---|
108 | 108 | | Act does not receive the vote necessary for immediate effect, this |
---|
109 | 109 | | Act takes effect September 1, 2021. |
---|