Texas 2023 - 88th Regular

Texas House Bill HB4892 Compare Versions

OldNewDifferences
11 88R2648 JXC-D
22 By: Raymond H.B. No. 4892
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to physical security and cybersecurity practices for
88 certain utilities that provide electricity service and an
99 independent organization certified to manage a power region.
1010 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1111 SECTION 1. The heading to Subchapter B, Chapter 31,
1212 Utilities Code, is amended to read as follows:
1313 SUBCHAPTER B. PHYSICAL SECURITY AND CYBERSECURITY
1414 SECTION 2. The heading to Section 31.052, Utilities Code,
1515 is amended to read as follows:
1616 Sec. 31.052. PHYSICAL SECURITY AND CYBERSECURITY
1717 COORDINATION PROGRAM FOR UTILITIES.
1818 SECTION 3. Section 31.052(a), Utilities Code, is amended to
1919 read as follows:
2020 (a) The commission shall establish a program to monitor and
2121 support physical security and cybersecurity efforts among
2222 utilities in this state. The program shall:
2323 (1) provide guidance, technical assistance, and
2424 training on best practices in physical security and cybersecurity
2525 and facilitate the sharing of cybersecurity information between
2626 utilities; [and]
2727 (2) provide guidance, technical assistance, and
2828 training on best practices for physical security and cybersecurity
2929 controls for supply chain risk management of cybersecurity systems
3030 used by utilities, which may include, as applicable, best practices
3131 related to:
3232 (A) software integrity and authenticity;
3333 (B) vendor risk management and procurement
3434 controls, including notification by vendors of incidents related to
3535 the vendor's products and services; and
3636 (C) vendor remote access;
3737 (3) develop models, assessments, and auditing
3838 procedures for a utility to self-assess physical security and
3939 cybersecurity; and
4040 (4) provide opportunities for utilities to share with
4141 each other best practices for and information on physical security
4242 and cybersecurity.
4343 SECTION 4. Section 39.151(o), Utilities Code, is amended to
4444 read as follows:
4545 (o) An independent organization certified by the commission
4646 under this section shall:
4747 (1) conduct internal physical security and
4848 cybersecurity risk assessment, vulnerability testing, and employee
4949 training to the extent the independent organization is not
5050 otherwise required to do so under applicable state and federal
5151 physical security, cybersecurity, and information security laws;
5252 and
5353 (2) submit a report annually to the commission on the
5454 independent organization's compliance with applicable physical
5555 security, cybersecurity, and information security laws.
5656 SECTION 5. This Act takes effect immediately if it receives
5757 a vote of two-thirds of all the members elected to each house, as
5858 provided by Section 39, Article III, Texas Constitution. If this
5959 Act does not receive the vote necessary for immediate effect, this
6060 Act takes effect September 1, 2023.