Texas 2023 - 88th Regular

Texas House Bill HB2494 Compare Versions

OldNewDifferences
11 By: Jetton H.B. No. 2494
22
33
44 A BILL TO BE ENTITLED
55 AN ACT
66 relating to information security officers and network threat
77 detection and response for state agencies.
88 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
99 SECTION 1. Section 2054.133(b), Government Code, is amended
1010 to read as follows:
1111 (b) In developing the plan, the state agency shall:
1212 (1) consider any vulnerability report prepared under
1313 Section 2054.077 for the agency;
1414 (2) incorporate the network security services
1515 provided by the department to the agency under Chapter 2059;
1616 (3) identify and define the responsibilities of agency
1717 staff who produce, access, use, or serve as custodians of the
1818 agency's information;
1919 (4) identify risk management and other measures taken
2020 to protect the agency's information from unauthorized access,
2121 disclosure, modification, or destruction;
2222 (5) include:
2323 (A) the best practices for information security
2424 developed by the department; or
2525 (B) a written explanation of why the best
2626 practices are not sufficient for the agency's security; [and]
2727 (6) omit from any written copies of the plan
2828 information that could expose vulnerabilities in the agency's
2929 network or online systems; and
3030 (7) consider whether network threat detection and
3131 response solutions, that permit anonymized security reports to be
3232 shared among participating entities in as close to real time as
3333 possible, would enhance the plan and include those solutions as
3434 part of the plan as the agency determines appropriate.
3535 SECTION 2. Section 2054.136, Government Code, is amended to
3636 read as follows:
3737 Sec. 2054.136. DESIGNATED INFORMATION SECURITY OFFICER.
3838 Each state agency shall designate an information security officer
3939 who:
4040 (1) acts independently of the agency in the
4141 performance of the officer's duties under this chapter and reports
4242 to the department on information security issues and to the
4343 agency's executive-level management on other issues;
4444 (2) has authority over information security for the
4545 entire agency;
4646 (3) possesses the training and experience required to
4747 perform the duties required by department rules; and
4848 (4) to the extent feasible, has information security
4949 duties as the officer's primary duties.
5050 SECTION 3. Sections 2054.512(d) and (e), Government Code,
5151 are amended to read as follows:
5252 (d) The cybersecurity council shall:
5353 (1) consider the costs and benefits of establishing a
5454 computer emergency readiness team to address cyber attacks
5555 occurring in this state during routine and emergency situations;
5656 (2) establish criteria and priorities for addressing
5757 cybersecurity threats to critical state installations;
5858 (3) consolidate and synthesize best practices to
5959 assist state agencies in understanding and implementing
6060 cybersecurity measures, including network threat detection and
6161 response solutions, that are most beneficial to this state; and
6262 (4) assess the knowledge, skills, and capabilities of
6363 the existing information technology and cybersecurity workforce to
6464 mitigate and respond to cyber threats and develop recommendations
6565 for addressing immediate workforce deficiencies and ensuring a
6666 long-term pool of qualified applicants.
6767 (e) The cybersecurity council shall provide recommendations
6868 to the legislature on any legislation necessary to implement
6969 cybersecurity best practices and remediation strategies for this
7070 state, including network threat detection and response solutions.
7171 SECTION 4. Section 2054.518(a), Government Code, is amended
7272 to read as follows:
7373 (a) The department shall develop a plan to address
7474 cybersecurity risks and incidents in this state. The department
7575 may enter into an agreement with a national organization, including
7676 the National Cybersecurity Preparedness Consortium, to support the
7777 department's efforts in implementing the components of the plan for
7878 which the department lacks resources to address internally. The
7979 agreement may include provisions for:
8080 (1) providing technical assistance services to
8181 support preparedness for and response to cybersecurity risks and
8282 incidents;
8383 (2) conducting cybersecurity simulation exercises for
8484 state agencies to encourage coordination in defending against and
8585 responding to cybersecurity risks and incidents;
8686 (3) assisting state agencies in developing
8787 cybersecurity information-sharing programs to disseminate
8888 information related to cybersecurity risks and incidents; [and]
8989 (4) incorporating cybersecurity risk and incident
9090 prevention and response methods into existing state emergency
9191 plans, including continuity of operation plans and incident
9292 response plans; and
9393 (5) incorporating network threat detection and
9494 response solutions into state agency cybersecurity plans, that
9595 permit anonymized security reports to be shared among participating
9696 entities in as close to real time as possible, to assist state
9797 agencies with monitoring agency networks for security threats and
9898 responding to detected security threats.
9999 SECTION 5. This Act takes effect September 1, 2023.