1 | 1 | | 88R3800 SCP-F |
---|
2 | 2 | | By: Capriglione H.B. No. 2156 |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | A BILL TO BE ENTITLED |
---|
6 | 6 | | AN ACT |
---|
7 | 7 | | relating to the position of chief information security officer in |
---|
8 | 8 | | the Department of Information Resources. |
---|
9 | 9 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
10 | 10 | | SECTION 1. Subchapter N-1, Chapter 2054, Government Code, |
---|
11 | 11 | | is amended by adding Section 2054.510 to read as follows: |
---|
12 | 12 | | Sec. 2054.510. CHIEF INFORMATION SECURITY OFFICER. (a) In |
---|
13 | 13 | | this section, "state information security program" means the |
---|
14 | 14 | | policies, standards, procedures, elements, structure, strategies, |
---|
15 | 15 | | objectives, plans, metrics, reports, services, and resources that |
---|
16 | 16 | | establish the information resources security function for this |
---|
17 | 17 | | state. |
---|
18 | 18 | | (b) The department shall employ a chief information |
---|
19 | 19 | | security officer. |
---|
20 | 20 | | (c) The chief information security officer shall oversee |
---|
21 | 21 | | cybersecurity matters for this state including: |
---|
22 | 22 | | (1) implementing the duties described by Section |
---|
23 | 23 | | 2054.059; |
---|
24 | 24 | | (2) responding to reports received under Section |
---|
25 | 25 | | 2054.1125; |
---|
26 | 26 | | (3) developing a statewide information security |
---|
27 | 27 | | framework; |
---|
28 | 28 | | (4) overseeing the development of statewide |
---|
29 | 29 | | information security policies and standards; |
---|
30 | 30 | | (5) developing, in coordination with state agencies, |
---|
31 | 31 | | local governmental entities, and other entities operating or |
---|
32 | 32 | | exercising control over state information systems or |
---|
33 | 33 | | state-controlled data, information security policies, standards, |
---|
34 | 34 | | and guidelines to strengthen this state's cybersecurity; |
---|
35 | 35 | | (6) overseeing the implementation of the policies, |
---|
36 | 36 | | standards, and guidelines developed under Subdivisions (3), (4), |
---|
37 | 37 | | and (5); |
---|
38 | 38 | | (7) providing information security leadership, |
---|
39 | 39 | | strategic direction, and coordination for the state information |
---|
40 | 40 | | security program; and |
---|
41 | 41 | | (8) providing strategic direction to: |
---|
42 | 42 | | (A) the network security center established |
---|
43 | 43 | | under Section 2059.101, Government Code; and |
---|
44 | 44 | | (B) statewide technology centers operated under |
---|
45 | 45 | | Subchapter L. |
---|
46 | 46 | | (d) Not later than November 15 of each even-numbered year, |
---|
47 | 47 | | the chief information security officer shall submit a written |
---|
48 | 48 | | report on the status and effectiveness of the state information |
---|
49 | 49 | | security program to: |
---|
50 | 50 | | (1) the executive director; |
---|
51 | 51 | | (2) the governor; |
---|
52 | 52 | | (3) the lieutenant governor; |
---|
53 | 53 | | (4) the speaker of the house of representatives; and |
---|
54 | 54 | | (5) each standing committee of the legislature with |
---|
55 | 55 | | primary jurisdiction over matters related to the department. |
---|
56 | 56 | | SECTION 2. This Act takes effect September 1, 2023. |
---|