Texas 2023 - 88th Regular

Texas House Bill HB3217 Compare Versions

OldNewDifferences
11 88R12618 CXP-D
22 By: Lujan H.B. No. 3217
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to a biennial audit by the Department of Information
88 Resources of state agency information technology infrastructure.
99 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1010 SECTION 1. The heading to Section 2054.068, Government
1111 Code, is amended to read as follows:
1212 Sec. 2054.068. INFORMATION TECHNOLOGY INFRASTRUCTURE AUDIT
1313 AND REPORT.
1414 SECTION 2. Sections 2054.068(b), (c), (d), and (e),
1515 Government Code, are amended to read as follows:
1616 (b) The department shall conduct a biennial audit of
1717 [collect from each state agency information on] the status and
1818 condition of each state [the] agency's information technology
1919 infrastructure, including a review of [information regarding]:
2020 (1) the agency's:
2121 (A) information security program, including any
2222 information technology security measures used by the agency;
2323 (B) hardware, including [(2)] an inventory of the
2424 agency's servers, mainframes, cloud services, and other
2525 information technology equipment;
2626 (C) [(3) identification of] vendors that operate
2727 and manage the agency's information technology infrastructure;
2828 (D) software and licenses, including:
2929 (i) purchase date and cost;
3030 (ii) license length;
3131 (iii) date of last use; and
3232 (iv) the purpose of the software or
3333 license;
3434 (E) information technology governance policies;
3535 (F) cloud services;
3636 (G) vendor-managed services;
3737 (H) support services and the cost of those
3838 services;
3939 (I) network systems;
4040 (J) digital data storage systems and security
4141 measures;
4242 (K) future information technology projects; and
4343 (L) information technology needs;
4444 (2) any information technology issues reported by the
4545 public; and
4646 (3) [(4)] any additional related issue [information
4747 requested by] the department considers necessary.
4848 (c) A state agency shall provide to the department:
4949 (1) [the] information related to the subjects
5050 described [required] by Subsection (b) [to the department]
5151 according to a schedule determined by the department; and
5252 (2) access to the state agency's information
5353 technology infrastructure.
5454 (d) Not later than December 1 [November 15] of each
5555 even-numbered year, the department shall submit to the governor,
5656 chair of the house appropriations committee, chair of the senate
5757 finance committee, speaker of the house of representatives,
5858 lieutenant governor, and staff of the Legislative Budget Board a
5959 consolidated report on the audits conducted [of the information
6060 submitted by state agencies] under Subsection (b).
6161 (e) The consolidated report required by Subsection (d) must
6262 include:
6363 (1) [include] an analysis and assessment of each state
6464 agency's security and operational risks; [and]
6565 (2) for a state agency found to be at higher security
6666 and operational risks, [include] a detailed analysis of agency
6767 efforts to address the risks and related vulnerabilities;
6868 (3) the information submitted by state agencies under
6969 Subsection (c);
7070 (4) the department's recommendations relating to the
7171 state agency's information technology infrastructure; and
7272 (5) a ranking of each state agency based on the
7373 efficacy and ease of use of the agency's information technology
7474 infrastructure.
7575 SECTION 3. This Act takes effect September 1, 2023.