Texas 2023 - 88th Regular

Texas Senate Bill SB2001 Compare Versions

OldNewDifferences
11 88R13152 MPF-F
22 By: Hall S.B. No. 2001
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to the security of election systems.
88 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
99 SECTION 1. Chapter 279, Election Code, is amended by
1010 amending Sections 279.002 and 279.003 and adding Sections 279.004
1111 and 279.005 to read as follows:
1212 Sec. 279.002. ELECTION CYBERSECURITY: SECRETARY OF STATE.
1313 (a) The secretary of state shall adopt rules defining classes of
1414 protected election data and establishing best practices for
1515 identifying, [and] reducing, and eliminating the risk to the
1616 electronic use, storage, and transmission of election data and the
1717 security of election systems, including:
1818 (1) methods of encrypting data at rest and during
1919 transmission; and
2020 (2) restricting access to sensitive data to only users
2121 with a specific need to access that data.
2222 (a-1) The secretary of state shall appoint a dedicated
2323 cybersecurity expert to implement cybersecurity measures to
2424 protect all election data and other election-related data held by
2525 the state or a county in the state, including technology that
2626 blocks, notifies, and reports on unauthorized attempts to access or
2727 transfer data.
2828 (b) The secretary of state shall direct the cybersecurity
2929 expert to offer training on best practices:
3030 (1) on a biennial [an annual] basis, to all
3131 appropriate personnel or contractors with [in] the secretary of
3232 state's office with access to sensitive information; and
3333 (2) on request, to county election officers and any
3434 employees or contractors of the county election officers with
3535 access to sensitive information [in this state].
3636 (b-1) Access to sensitive data shall be revoked for any
3737 employee or contractor that is required to receive training under
3838 Subsection (b) but does not complete the training.
3939 (c) If the secretary of state becomes aware of a breach of
4040 cybersecurity that impacts election data, the secretary shall
4141 immediately notify the governor, lieutenant governor, speaker of
4242 the house of representatives, and members of the standing
4343 committees of each house of the legislature with jurisdiction over
4444 elections. The secretary shall direct the cybersecurity expert to
4545 conduct an investigation of the breach and report any findings to
4646 the governor, lieutenant governor, speaker of the house of
4747 representatives, and standing committees of the legislature with
4848 jurisdiction over elections.
4949 (d) During an investigation conducted under Subsection (c),
5050 access to the election system is restricted to only individuals
5151 designated by the secretary of state until the standing committees
5252 confirm that the breach has been mitigated.
5353 (e) If the investigation under Subsection (c) reveals that
5454 individuals' personal data has been breached, the secretary of
5555 state shall promptly notify the affected individuals by written
5656 letter of the occurrence and extent of the breach.
5757 (f) The secretary of state, in cooperation with the
5858 cybersecurity expert, shall contract with a provider of
5959 cybersecurity assessments to biennially conduct an assessment of
6060 the cybersecurity of the state's election system.
6161 (g) The cybersecurity expert shall implement cybersecurity
6262 measures to ensure that all devices with access to election data
6363 held by the state comply to the highest extent possible with rules
6464 adopted by the secretary of state under Subsection (a).
6565 Sec. 279.003. ELECTION CYBERSECURITY: COUNTY ELECTION
6666 OFFICERS. (a) A county election officer shall biennially
6767 [annually] request training on cybersecurity from the
6868 cybersecurity expert [secretary of state]. The secretary of state
6969 shall pay the costs associated with the training with available
7070 state funds.
7171 (b) A county election officer shall contract with a provider
7272 of cybersecurity assessments to biennially conduct [request] an
7373 assessment of the cybersecurity of the county's election system
7474 [from a provider of cybersecurity assessments if the secretary of
7575 state recommends an assessment and the necessary funds are
7676 available].
7777 (b-1) The county election officer shall deliver a report on
7878 any recommended improvements to the county's election system by the
7979 assessment conducted under Subsection (b) to the secretary of
8080 state.
8181 (c) If a county election officer becomes aware of a breach
8282 of cybersecurity that impacts election data, the officer shall
8383 immediately notify the secretary of state. During an investigation
8484 by the secretary of state made aware of a breach under this section,
8585 access to sensitive data in the county shall be restricted to
8686 specific personnel.
8787 (d) A [To the extent that state funds are available for the
8888 purpose, a] county election officer shall implement cybersecurity
8989 measures to ensure that all devices with access to election data
9090 comply to the highest extent possible with rules adopted by the
9191 secretary of state under Section 279.002.
9292 Sec. 279.004. INTERNAL PERSONNEL VIOLATION. If a data
9393 breach under this section is conducted by an employee of the
9494 secretary of state's or county election officer's office, the
9595 employee may not be provided access to election-related data until
9696 an investigation under this section is concluded. If an
9797 investigation determines that the employee intentionally breached
9898 an election system, the secretary of state may pursue all available
9999 legal remedies against the employee, including criminal
100100 prosecution.
101101 Sec. 279.005. COMPUTER NETWORK CONNECTIVITY. (a) Except
102102 as expressly authorized by this code, an election system that is
103103 capable of being connected to the Internet or any other computer
104104 network may not be used, except for the use of a visible wired
105105 connection to an isolated local area network within the building.
106106 (b) The cybersecurity expert appointed by the secretary of
107107 state under Section 279.002 shall annually verify compliance with
108108 this section by each county conducting an election in this state.
109109 SECTION 2. Section 123.034, Election Code, is amended to
110110 read as follows:
111111 Sec. 123.034. MAINTENANCE AND STORAGE OF EQUIPMENT. (a)
112112 The governing body of a political subdivision shall provide for the
113113 proper maintenance and storage of the equipment that the
114114 subdivision acquires for use in the operation of a voting system.
115115 (b) Equipment used in the operation of a voting system must
116116 have a documented chain of custody and be stored in a locked
117117 facility with video surveillance monitoring the storage facility at
118118 all times.
119119 SECTION 3. As soon as practicable after the effective date
120120 of this Act, the secretary of state shall:
121121 (1) adopt the rules required by Section 279.002(a),
122122 Election Code, as amended by this Act; and
123123 (2) appoint a cybersecurity expert in accordance with
124124 Section 279.002(a-1), Election Code, as added by this Act.
125125 SECTION 4. This Act takes effect September 1, 2023.