1 | 1 | | S.B. No. 271 |
---|
2 | 2 | | |
---|
3 | 3 | | |
---|
4 | 4 | | AN ACT |
---|
5 | 5 | | relating to state agency and local government security incident |
---|
6 | 6 | | procedures. |
---|
7 | 7 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
8 | 8 | | SECTION 1. Section 2054.1125, Government Code, is |
---|
9 | 9 | | transferred to Subchapter R, Chapter 2054, Government Code, |
---|
10 | 10 | | redesignated as Section 2054.603, Government Code, and amended to |
---|
11 | 11 | | read as follows: |
---|
12 | 12 | | Sec. 2054.603 [2054.1125]. SECURITY INCIDENT [BREACH] |
---|
13 | 13 | | NOTIFICATION BY STATE AGENCY OR LOCAL GOVERNMENT. (a) In this |
---|
14 | 14 | | section: |
---|
15 | 15 | | (1) "Security incident" means: |
---|
16 | 16 | | (A) a breach or suspected breach ["Breach] of |
---|
17 | 17 | | system security as defined [security" has the meaning assigned] by |
---|
18 | 18 | | Section 521.053, Business & Commerce Code; and |
---|
19 | 19 | | (B) the introduction of ransomware, as defined by |
---|
20 | 20 | | Section 33.023, Penal Code, into a computer, computer network, or |
---|
21 | 21 | | computer system. |
---|
22 | 22 | | (2) "Sensitive personal information" has the meaning |
---|
23 | 23 | | assigned by Section 521.002, Business & Commerce Code. |
---|
24 | 24 | | (b) A state agency or local government that owns, licenses, |
---|
25 | 25 | | or maintains computerized data that includes sensitive personal |
---|
26 | 26 | | information, confidential information, or information the |
---|
27 | 27 | | disclosure of which is regulated by law shall, in the event of a |
---|
28 | 28 | | security incident [breach or suspected breach of system security or |
---|
29 | 29 | | an unauthorized exposure of that information]: |
---|
30 | 30 | | (1) comply with the notification requirements of |
---|
31 | 31 | | Section 521.053, Business & Commerce Code, to the same extent as a |
---|
32 | 32 | | person who conducts business in this state; [and] |
---|
33 | 33 | | (2) not later than 48 hours after the discovery of the |
---|
34 | 34 | | security incident [breach, suspected breach, or unauthorized |
---|
35 | 35 | | exposure], notify: |
---|
36 | 36 | | (A) the department, including the chief |
---|
37 | 37 | | information security officer; or |
---|
38 | 38 | | (B) if the security incident [breach, suspected |
---|
39 | 39 | | breach, or unauthorized exposure] involves election data, the |
---|
40 | 40 | | secretary of state; and |
---|
41 | 41 | | (3) comply with all department rules relating to |
---|
42 | 42 | | reporting security incidents as required by this section. |
---|
43 | 43 | | (c) Not later than the 10th business day after the date of |
---|
44 | 44 | | the eradication, closure, and recovery from a security incident |
---|
45 | 45 | | [breach, suspected breach, or unauthorized exposure], a state |
---|
46 | 46 | | agency or local government shall notify the department, including |
---|
47 | 47 | | the chief information security officer, of the details of the |
---|
48 | 48 | | security incident [event] and include in the notification an |
---|
49 | 49 | | analysis of the cause of the security incident [event]. |
---|
50 | 50 | | (d) This section does not apply to a security incident that |
---|
51 | 51 | | a local government is required to report to an independent |
---|
52 | 52 | | organization certified by the Public Utility Commission of Texas |
---|
53 | 53 | | under Section 39.151, Utilities Code. |
---|
54 | 54 | | SECTION 2. This Act takes effect September 1, 2023. |
---|
55 | 55 | | ______________________________ ______________________________ |
---|
56 | 56 | | President of the Senate Speaker of the House |
---|
57 | 57 | | I hereby certify that S.B. No. 271 passed the Senate on |
---|
58 | 58 | | March 21, 2023, by the following vote: Yeas 31, Nays 0. |
---|
59 | 59 | | ______________________________ |
---|
60 | 60 | | Secretary of the Senate |
---|
61 | 61 | | I hereby certify that S.B. No. 271 passed the House on |
---|
62 | 62 | | May 6, 2023, by the following vote: Yeas 134, Nays 2, one present |
---|
63 | 63 | | not voting. |
---|
64 | 64 | | ______________________________ |
---|
65 | 65 | | Chief Clerk of the House |
---|
66 | 66 | | Approved: |
---|
67 | 67 | | ______________________________ |
---|
68 | 68 | | Date |
---|
69 | 69 | | ______________________________ |
---|
70 | 70 | | Governor |
---|