Texas 2023 - 88th Regular

Texas Senate Bill SB2358 Compare Versions

OldNewDifferences
11 By: Parker, Paxton S.B. No. 2358
22
33
44 A BILL TO BE ENTITLED
55 AN ACT
66 relating to security procedures for digital applications that pose
77 a network security risk to state agencies.
88 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
99 SECTION 1. Chapter 2054, Government Code, is amended by
1010 adding Subchapter S to read as follows:
1111 SUBCHAPTER S. DIGITAL APPLICATION SECURITY PROCEDURES
1212 Sec. 2054.621. DEFINITIONS. In this subchapter:
1313 (1) "Digital application" means an Internet website or
1414 application that is open to the public, allows a user to create an
1515 account, and enables a user to communicate with other users by
1616 posting information, comments, messages, images, or video. The
1717 term does not include:
1818 (A) an Internet service provider, as defined by
1919 Section 324.055, Business & Commerce Code;
2020 (B) e-mail; or
2121 (C) an online service, application, or Internet
2222 website:
2323 (i) that consists primarily of news,
2424 sports, entertainment, or other content preselected by the provider
2525 that is not user generated; and
2626 (ii) for which any chat, comment, or
2727 interactive functionality is incidental to, directly related to, or
2828 dependent on provision of the content described by Subparagraph
2929 (i).
3030 (2) "Network security" has the meaning assigned by
3131 Section 2059.001.
3232 (3) "User" means a person who posts, uploads,
3333 transmits, shares, or otherwise publishes or receives content
3434 through a digital application.
3535 Sec. 2054.622. DIGITAL APPLICATION SECURITY RISK LIST. The
3636 department shall:
3737 (1) compile, maintain, and annually update a list of
3838 digital applications that create a network security risk to state
3939 agencies;
4040 (2) limit or prohibit the placement and use of digital
4141 applications on the list under Subdivision (1) on:
4242 (A) state-owned cell phones, computers, and
4343 other communication devices; and
4444 (B) personal communication devices of state
4545 agency employees that are used in the agency's office or other
4646 workplace; and
4747 (3) post the list under Subdivision (1) on a publicly
4848 accessible web page on the department's Internet website.
4949 Sec. 2054.623. DIGITAL APPLICATION SECURITY MODEL POLICY
5050 FOR STATE AGENCIES. The department shall develop, maintain, and
5151 periodically update a model policy for state agencies to use under
5252 Section 2054.624 in limiting or prohibiting the placement and use
5353 on communication devices of the digital applications included on
5454 the list compiled under Section 2054.622.
5555 Sec. 2054.624. STATE AGENCY DIGITAL APPLICATION SECURITY
5656 POLICY. (a) Each state agency shall develop, implement, and
5757 periodically update a policy limiting or prohibiting the placement
5858 and use of digital applications included on the list compiled under
5959 Section 2054.622 on:
6060 (1) state-owned cell phones, computers, and other
6161 communication devices; and
6262 (2) personal communication devices of state agency
6363 employees that are used in the agency's office or other workplace.
6464 (b) Each state agency shall submit to the department a copy
6565 of the policy required under Subsection (a) and updates to the
6666 policy.
6767 (c) The department:
6868 (1) may offer recommendations for improvements to
6969 submitted policies;
7070 (2) shall retain each copy and update submitted under
7171 Subsection (b); and
7272 (3) shall notify each member of the legislature and
7373 the governor when a state agency submits a policy or update.
7474 Sec. 2054.625. DISCLOSURE EXEMPTION. The model policy and
7575 state agency policies developed under this subchapter are exempt
7676 from disclosure under Chapter 552.
7777 Sec. 2054.626. RULEMAKING AUTHORITY. The department may
7878 adopt rules to implement this subchapter.
7979 SECTION 2. (a) As soon as practicable after the effective
8080 date of this Act, but not later than January 1, 2024, the Department
8181 of Information Resources shall develop the digital application
8282 security risk list and model policy as required by Subchapter S,
8383 Chapter 2054, Government Code, as added by this Act.
8484 (b) A state agency is not required to comply with Section
8585 2054.624, Government Code, as added by this Act, until May 1, 2024.
8686 SECTION 3. This Act takes effect September 1, 2023.