Texas 2023 - 88th Regular

Texas Senate Bill SB2377 Compare Versions

OldNewDifferences
11 88R2127 JCG-D
22 By: Campbell S.B. No. 2377
33
44
55 A BILL TO BE ENTITLED
66 AN ACT
77 relating to homeland security, including the creation of the Texas
88 Homeland Security Division in the Department of Public Safety, the
99 operations of the Homeland Security Council, the creation of a
1010 homeland security fusion center, and the duties of state agencies
1111 and local governments in preparing for, reporting, and responding
1212 to cybersecurity breaches; providing administrative penalties;
1313 creating criminal offenses.
1414 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:
1515 SECTION 1. (a) The legislature finds that the federal
1616 government's inadequate border security measures, the trafficking
1717 of fentanyl across the borders of this state, Central America's
1818 turn towards authoritarian regimes, China's hostile rhetoric
1919 regarding Taiwan, and Russia's invasion of Ukraine create an
2020 ever-changing threat landscape to the security of this state.
2121 (b) Due to these continuous threats, this state must
2222 continue taking serious measures to secure its critical
2323 infrastructure, cyber networks, and border and monitor security
2424 threats from hostile nations and non-state actors.
2525 (c) These present and future threats require this state to
2626 create a unified security organization under the Department of
2727 Public Safety of the State of Texas whose sole mission is to
2828 safeguard the people and infrastructure that make this state great.
2929 (d) The Texas Homeland Security Division, as established by
3030 this Act, will unify this state's security responsibilities into
3131 one entity that reports directly to the governor and the public
3232 safety director of the Department of Public Safety of the State of
3333 Texas.
3434 SECTION 2. Chapter 411, Government Code, is amended by
3535 adding Subchapter S to read as follows:
3636 SUBCHAPTER S. TEXAS HOMELAND SECURITY DIVISION
3737 Sec. 411.551. DEFINITIONS. In this subchapter:
3838 (1) "Division" means the Texas Homeland Security
3939 Division established in the department under this subchapter.
4040 (2) "Division director" means the director of the
4141 Texas Homeland Security Division appointed under this subchapter.
4242 Sec. 411.552. ESTABLISHMENT; DIRECTOR; EMPLOYEES. (a) The
4343 Texas Homeland Security Division is established in the department.
4444 (b) Notwithstanding Section 411.006(a)(6), the public
4545 safety director shall appoint, with the advice and consent of the
4646 governor, a homeland security director to manage the division.
4747 (c) The division director may hire employees as necessary to
4848 carry out the duties of the division.
4949 Sec. 411.553. GENERAL DUTIES. The division shall, in
5050 consultation with the governor:
5151 (1) develop and implement strategic homeland security
5252 operations; and
5353 (2) unify governmental activities and
5454 responsibilities related to homeland security under the direction
5555 of the division.
5656 Sec. 411.554. BORDER SECURITY: INTELLIGENCE. (a) The
5757 division shall coordinate with the Texas Military Department, state
5858 and local law enforcement agencies, federal agencies, and any other
5959 entity the division determines appropriate to secure the
6060 international border.
6161 (b) In coordinating with the entities described by
6262 Subsection (a), the division shall:
6363 (1) collect, analyze, and provide intelligence for
6464 each major operation to secure the international border, including
6565 consulting with the Texas Military Department and other appropriate
6666 agencies that collect, analyze, or provide intelligence to the
6767 governor, the department, and other entities deployed on major
6868 operations;
6969 (2) make recommendations on essential tasks and
7070 desired results for each element of a major operation;
7171 (3) provide augmented equipment and personnel for a
7272 major operation; and
7373 (4) conduct periodic internal reviews of
7474 interoperability among agencies deployed on a major operation and
7575 make available reports on subsequent efforts to improve
7676 interoperability.
7777 (c) Each month, the division shall provide a report to the
7878 governor on the major operations conducted by this state to secure
7979 the international border.
8080 Sec. 411.555. BORDER SECURITY: GRANT RECOMMENDATIONS. The
8181 division shall advise the criminal justice division of the
8282 governor's office on the allocation of grants under the prosecution
8383 of border crime grant program established under Section 772.0071.
8484 Sec. 411.556. CRITICAL INFRASTRUCTURE AND POWER GRID. (a)
8585 The division shall coordinate with federal, state, and local
8686 agencies, and any other entity the division determines appropriate,
8787 to protect the critical infrastructure of this state and the ERCOT
8888 power grid from remote and physical attacks, including:
8989 (1) oil and gas infrastructure, including:
9090 (A) oil, gas, and chemical pipelines;
9191 (B) oil and gas drilling sites; and
9292 (C) oil, gas, and chemical production
9393 facilities;
9494 (2) electrical power generating facilities,
9595 substations, switching stations, and electrical control centers;
9696 (3) petroleum and alumina refineries and chemical,
9797 polymer, and rubber manufacturing facilities; and
9898 (4) water intake structures, water treatment
9999 facilities, wastewater treatment plants, and pump stations.
100100 (b) In coordinating the efforts of this state to secure
101101 critical infrastructure and the ERCOT power grid, the division
102102 shall cooperate with the Cybersecurity and Infrastructure Security
103103 Agency, the United States Department of Energy, and the Homeland
104104 Security Fusion Center.
105105 Sec. 411.557. CRITICAL INFRASTRUCTURE: INVESTIGATION OF
106106 CERTAIN PURCHASES. The division shall investigate any purchases of
107107 substantial portions of land or infrastructure in this state by a
108108 designated country, as that term is defined by Section 2274.0101,
109109 as added by Chapter 975 (S.B. 2116), Acts of the 87th Legislature,
110110 Regular Session, 2021.
111111 Sec. 411.558. PROHIBITED EQUIPMENT REPORTS. At least
112112 annually, the division shall issue a report to the governor,
113113 lieutenant governor, members of the legislature, and all state
114114 agencies identifying equipment that the United States Department of
115115 Defense has prohibited entities that contract with the department
116116 of defense from using.
117117 Sec. 411.559. CYBERSECURITY: WEBSITE FOR REPORTING THREATS
118118 AND ATTACKS. The division shall develop a secure Internet website
119119 that is accessible by state agencies and local governments and
120120 permits those entities to report to the division suspected
121121 cybersecurity threats and attacks against those entities.
122122 Sec. 411.560. BUDGET REQUESTS. (a) Not later than April 1
123123 of each even-numbered year, the division director shall submit to
124124 the public safety director a request for appropriations that
125125 estimates the cost of the division's operations.
126126 (b) A request for appropriations described by Subsection
127127 (a) may not be aggregated with any other appropriation request made
128128 by the department when the request is submitted to a legislative
129129 committee with jurisdiction over appropriations.
130130 SECTION 3. Section 421.021, Government Code, is amended by
131131 adding Subsection (a-1) to read as follows:
132132 (a-1) The Homeland Security Council is composed of:
133133 (1) the governor or the governor's designee;
134134 (2) the lieutenant governor or the lieutenant
135135 governor's designee;
136136 (3) the director of the Texas Homeland Security
137137 Division of the Department of Public Safety; and
138138 (4) other persons appointed by the governor or
139139 lieutenant governor.
140140 SECTION 4. Section 421.023, Government Code, is amended by
141141 amending Subsections (c) and (d) and adding Subsection (f) to read
142142 as follows:
143143 (c) The governor shall designate the director of the Texas
144144 Homeland Security Division of the Department of Public Safety as
145145 the presiding officer of the council.
146146 (d) The council shall meet at the call of the presiding
147147 officer [governor] and shall meet at least once each quarter in a
148148 calendar year.
149149 (f) The presiding officer shall appoint a secretary, who may
150150 be a member of the council, to record meeting minutes and
151151 attendance.
152152 SECTION 5. Section 421.024, Government Code, is amended to
153153 read as follows:
154154 Sec. 421.024. DUTIES. The council shall advise the
155155 governor on:
156156 (1) the implementation of the governor's homeland
157157 security strategy by state and local agencies and provide specific
158158 suggestions for helping those agencies implement the strategy;
159159 [and]
160160 (2) recommendations from the Texas Homeland Security
161161 Division of the Department of Public Safety on improving the
162162 security of this state; and
163163 (3) other matters related to the planning,
164164 development, coordination, and implementation of initiatives to
165165 promote the governor's homeland security strategy.
166166 SECTION 6. Chapter 421, Government Code, is amended by
167167 adding Subchapter E-1 to read as follows:
168168 SUBCHAPTER E-1. HOMELAND SECURITY FUSION CENTER
169169 Sec. 421.0901. DEFINITIONS. In this subchapter:
170170 (1) "Board" means the oversight board of the homeland
171171 security fusion center.
172172 (2) "Director" means the director of the Texas
173173 Homeland Security Division of the Department of Public Safety.
174174 Sec. 421.0902. HOMELAND SECURITY FUSION CENTER. (a) From
175175 funds available for this purpose, the director may:
176176 (1) establish the homeland security fusion center; and
177177 (2) hire employees to operate the homeland security
178178 fusion center.
179179 (b) The homeland security fusion center shall:
180180 (1) collect, receive, generate, and disseminate
181181 intelligence critical for homeland security policy and homeland
182182 security activities in this state, including the issuance of
183183 relevant threat warnings;
184184 (2) promote and improve intelligence sharing:
185185 (A) among public safety and public service
186186 agencies at the federal, state, local, and tribal levels; and
187187 (B) with entities in the private sector operating
188188 critical infrastructure and other key resources;
189189 (3) otherwise support federal, state, local, and
190190 tribal agencies and private organizations in preventing, preparing
191191 for, responding to, and recovering from homeland security threats
192192 and attacks; and
193193 (4) maintain intelligence collected, received, or
194194 generated in compliance with applicable state and federal law and
195195 in a secure manner, including:
196196 (A) providing appropriate security for a
197197 facility that contains sensitive information;
198198 (B) compartmentalizing sensitive information;
199199 and
200200 (C) adopting appropriate internal procedures for
201201 the security of the facility and the information.
202202 Sec. 421.0903. OVERSIGHT BOARD; QUALIFICATIONS; RULES. (a)
203203 If the homeland security fusion center is established under Section
204204 421.0902, there is also established an oversight board that shall
205205 govern the operations of the homeland security fusion center.
206206 (b) The board is composed of:
207207 (1) the director;
208208 (2) the adjutant general; and
209209 (3) other persons appointed by the director.
210210 (c) The director serves as the chair of the board and the
211211 adjutant general serves as the vice chair.
212212 (d) A member of the board must have and maintain a secret
213213 security clearance granted by the United States government. A
214214 person who has applied for a secret security clearance and has been
215215 granted an interim secret security clearance may serve as a member
216216 of the board but may not be given access to classified information,
217217 participate in a briefing involving classified information, or vote
218218 on an issue involving classified information before the person is
219219 granted a secret security clearance.
220220 (e) The board may adopt rules, policies, and procedures for
221221 the operation of the homeland security fusion center.
222222 Sec. 421.0904. GIFTS, GRANTS, AND DONATIONS; DEDICATED
223223 ACCOUNT. (a) The homeland security fusion center may accept gifts,
224224 grants, and donations of any kind from any public or private source,
225225 including services or property, for the purpose of paying the costs
226226 to establish, maintain, or operate the homeland security fusion
227227 center.
228228 (b) The homeland security fusion center shall remit all
229229 amounts received under this section to the comptroller. The
230230 comptroller shall deposit the amounts to the credit of an account in
231231 the general revenue fund that may be appropriated only to the
232232 Department of Public Safety to provide funding for establishing,
233233 maintaining, or operating the homeland security fusion center.
234234 (c) The board must approve expenditures made for the
235235 purposes described by Subsection (b).
236236 Sec. 421.0905. ADMINISTRATIVE SUPPORT. The Texas Homeland
237237 Security Division of the Department of Public Safety shall provide
238238 administrative support for the homeland security fusion center and
239239 the board, including securely maintaining the records of the board.
240240 SECTION 7. Section 2054.077(d), Government Code, is amended
241241 to read as follows:
242242 (d) The information security officer shall provide an
243243 electronic copy of the vulnerability report on its completion to:
244244 (1) the Texas Homeland Security Division of the
245245 Department of Public Safety;
246246 (2) the department;
247247 (3) [(2)] the state auditor;
248248 (4) [(3)] the agency's executive director;
249249 (5) [(4)] the agency's designated information
250250 resources manager; and
251251 (6) [(5)] any other information technology security
252252 oversight group specifically authorized by the legislature to
253253 receive the report.
254254 SECTION 8. Section 2054.1125, Government Code, is amended
255255 by amending Subsection (b) and adding Subsections (d) and (e) to
256256 read as follows:
257257 (b) A state agency that owns, licenses, or maintains
258258 computerized data that includes sensitive personal information,
259259 confidential information, or information the disclosure of which is
260260 regulated by law shall, in the event of a breach or suspected breach
261261 of system security or an unauthorized exposure of that information:
262262 (1) comply with the notification requirements of
263263 Section 521.053, Business & Commerce Code, to the same extent as a
264264 person who conducts business in this state; and
265265 (2) not later than 48 hours after the discovery of the
266266 breach, suspected breach, or unauthorized exposure, notify:
267267 (A) the Texas Homeland Security Division of the
268268 Department of Public Safety;
269269 (B) the department, including the chief
270270 information security officer; and
271271 (C) [or (B)] if the breach, suspected breach, or
272272 unauthorized exposure involves election data, the secretary of
273273 state.
274274 (d) The Texas Homeland Security Division of the Department
275275 of Public Safety shall notify the governor of any breach or
276276 suspected breach reported to the division under this section.
277277 (e) The administrative head of a state agency commits an
278278 offense if the person intentionally or knowingly fails to notify
279279 the Texas Homeland Security Division of the Department of Public
280280 Safety of a breach, suspected breach, or unauthorized exposure, as
281281 required by Subsection (b)(2)(A). An offense under this subsection
282282 is a Class C misdemeanor.
283283 SECTION 9. Section 2054.133(f), Government Code, is amended
284284 to read as follows:
285285 (f) Not later than November 15 of each even-numbered year,
286286 the department shall submit a written report to the governor, the
287287 lieutenant governor, and each standing committee of the legislature
288288 with primary jurisdiction over matters related to the department
289289 evaluating information security for this state's information
290290 resources. In preparing the report, the department shall consider
291291 the information security plans submitted by state agencies under
292292 this section, any vulnerability reports submitted under Section
293293 2054.077, any relevant information provided by the Texas Homeland
294294 Security Division of the Department of Public Safety, and other
295295 available information regarding the security of this state's
296296 information resources. The department shall omit from any written
297297 copies of the report information that could expose specific
298298 vulnerabilities in the security of this state's information
299299 resources.
300300 SECTION 10. Section 2054.511, Government Code, is amended
301301 to read as follows:
302302 Sec. 2054.511. CYBERSECURITY COORDINATOR. (a) The
303303 executive director shall designate an employee of the department as
304304 the state cybersecurity coordinator to oversee cybersecurity
305305 matters for this state.
306306 (b) The director of the Texas Homeland Security Division of
307307 the Department of Public Safety and the cybersecurity coordinator
308308 shall jointly improve the efficacy and efficiency of this state's
309309 response to and investigations of cyber attacks occurring in this
310310 state.
311311 SECTION 11. Section 2054.512(b), Government Code, is
312312 amended to read as follows:
313313 (b) The cybersecurity council must include:
314314 (1) one member who is an employee of the office of the
315315 governor;
316316 (2) one member of the senate appointed by the
317317 lieutenant governor;
318318 (3) one member of the house of representatives
319319 appointed by the speaker of the house of representatives;
320320 (4) the director of the Texas Homeland Security
321321 Division of the Department of Public Safety;
322322 (5) one member who is an employee of the Elections
323323 Division of the Office of the Secretary of State; and
324324 (6) [(5)] additional members appointed by the state
325325 cybersecurity coordinator, including representatives of
326326 institutions of higher education and private sector leaders.
327327 SECTION 12. Section 2054.515(b), Government Code, as
328328 amended by Chapters 567 (S.B. 475) and 856 (S.B. 800), Acts of the
329329 87th Legislature, Regular Session, 2021, is reenacted and amended
330330 to read as follows:
331331 (b) Not later than December 1 of the year [November 15 of
332332 each even-numbered year] in which a state agency conducts the
333333 assessment under Subsection (a) or the 60th day after the date the
334334 agency completes the assessment, whichever occurs first, the agency
335335 shall report the results of the assessment to:
336336 (1) the Texas Homeland Security Division of the
337337 Department of Public Safety;
338338 (2) the department; and
339339 (3) [(2)] on request, the governor, the lieutenant
340340 governor, and the speaker of the house of representatives.
341341 SECTION 13. Section 2054.518(a), Government Code, is
342342 amended to read as follows:
343343 (a) In consultation with the Texas Homeland Security
344344 Division of the Department of Public Safety, the [The] department
345345 shall develop a plan to address cybersecurity risks and incidents
346346 in this state. The department may enter into an agreement with a
347347 national organization, including the National Cybersecurity
348348 Preparedness Consortium, to support the department's efforts in
349349 implementing the components of the plan for which the department
350350 lacks resources to address internally. The agreement may include
351351 provisions for:
352352 (1) providing technical assistance services to
353353 support preparedness for and response to cybersecurity risks and
354354 incidents;
355355 (2) conducting cybersecurity simulation exercises for
356356 state agencies to encourage coordination in defending against and
357357 responding to cybersecurity risks and incidents;
358358 (3) assisting state agencies in developing
359359 cybersecurity information-sharing programs to disseminate
360360 information related to cybersecurity risks and incidents; and
361361 (4) incorporating cybersecurity risk and incident
362362 prevention and response methods into existing state emergency
363363 plans, including continuity of operation plans and incident
364364 response plans.
365365 SECTION 14. Subchapter F, Chapter 2270, Government Code, is
366366 amended by adding Section 2270.0254 to read as follows:
367367 Sec. 2270.0254. ADMINISTRATIVE PENALTY. The Department of
368368 Public Safety may impose an administrative penalty in the same
369369 manner and using the same procedures as Subchapter R, Chapter 411,
370370 against a person who violates this chapter.
371371 SECTION 15. Chapter 2274, Government Code, as added by
372372 Chapter 975 (S.B. 2116), Acts of the 87th Legislature, Regular
373373 Session, 2021, is amended by adding Section 2274.0104 to read as
374374 follows:
375375 Sec. 2274.0104. ADMINISTRATIVE PENALTY. The Department of
376376 Public Safety may impose an administrative penalty in the same
377377 manner and using the same procedures as Subchapter R, Chapter 411,
378378 against a person who violates this chapter.
379379 SECTION 16. Section 205.010(a), Local Government Code, is
380380 amended by adding Subdivision (1-a) to read as follows:
381381 (1-a) "Local government" means a municipality,
382382 county, special district or authority, or any other political
383383 subdivision of this state.
384384 SECTION 17. Section 205.010, Local Government Code, is
385385 amended by adding Subsections (c), (d), and (e) to read as follows:
386386 (c) In addition to notifying the attorney general under
387387 Section 521.053, Business & Commerce Code, of a breach of system
388388 security, the local government shall report the breach to the Texas
389389 Homeland Security Division of the Department of Public Safety. The
390390 division shall notify the governor of a breach of system security
391391 reported to the division under this section.
392392 (d) Not later than the 10th business day after the date of
393393 the eradication, closure, and recovery from a breach, a local
394394 government shall notify the Department of Information Resources,
395395 including the chief information security officer, of the details of
396396 the event and include in the notification an analysis of the cause
397397 of the event.
398398 (e) The administrative head of a local government commits an
399399 offense if the person intentionally or knowingly fails to notify
400400 the Texas Homeland Security Division of the Department of Public
401401 Safety of a breach of system security as required by Subsection (c).
402402 An offense under this subsection is a Class C misdemeanor.
403403 SECTION 18. (a) Section 421.021(a), Government Code, as
404404 amended by Chapters 93 (S.B. 686), 616 (S.B. 1393), and 1217 (S.B.
405405 1536), Acts of the 83rd Legislature, Regular Session, 2013, is
406406 repealed.
407407 (b) Section 421.021(c), Government Code, is repealed.
408408 SECTION 19. As soon as practicable after the Texas Homeland
409409 Security Division of the Department of Public Safety of the State of
410410 Texas is established, the division shall notify each state agency
411411 and local government of the requirements to notify the division of a
412412 breach of system security under Section 2054.1125, Government Code,
413413 as amended by this Act, and Section 205.010, Local Government Code,
414414 as amended by this Act, including the criminal penalties that may be
415415 imposed for failure to comply with those requirements.
416416 SECTION 20. It is the intent of the 88th Legislature,
417417 Regular Session, 2023, that the amendments made by this Act be
418418 harmonized with another Act of the 88th Legislature, Regular
419419 Session, 2023, relating to nonsubstantive additions to and
420420 corrections in enacted codes.
421421 SECTION 21. This Act takes effect September 1, 2023.