1 | 1 | | By: Johnson, Campbell S.B. No. 1625 |
---|
2 | 2 | | |
---|
3 | 3 | | |
---|
4 | 4 | | |
---|
5 | 5 | | |
---|
6 | 6 | | A BILL TO BE ENTITLED |
---|
7 | 7 | | AN ACT |
---|
8 | 8 | | relating to the reporting of certain security incidents by public |
---|
9 | 9 | | water systems to the Texas Commission on Environmental Quality and |
---|
10 | 10 | | the Department of Information Resources. |
---|
11 | 11 | | BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS: |
---|
12 | 12 | | SECTION 1. Section 341.033, Health and Safety Code, is |
---|
13 | 13 | | amended by amending Subsections (i) and (i-1) and adding Subsection |
---|
14 | 14 | | (i-2) to read as follows: |
---|
15 | 15 | | (i) An owner, agent, manager, operator, or other person in |
---|
16 | 16 | | charge of a public water supply system that furnishes water for |
---|
17 | 17 | | public or private use or a wastewater system that provides |
---|
18 | 18 | | wastewater services for public or private use shall maintain |
---|
19 | 19 | | internal procedures to notify the commission immediately of the |
---|
20 | 20 | | following events: |
---|
21 | 21 | | (1) [,] if the event may negatively impact the |
---|
22 | 22 | | production or delivery of safe and adequate drinking water: |
---|
23 | 23 | | (A) [(1)] an unusual or unexplained unauthorized |
---|
24 | 24 | | entry at property of the public water supply or wastewater system; |
---|
25 | 25 | | (B) [(2)] an act of terrorism against the public |
---|
26 | 26 | | water supply or wastewater system; |
---|
27 | 27 | | (C) [(3) an unauthorized attempt to probe for or |
---|
28 | 28 | | gain access to proprietary information that supports the key |
---|
29 | 29 | | activities of the public water supply or wastewater system; |
---|
30 | 30 | | [(4)] a theft of property that supports the key |
---|
31 | 31 | | activities of the public water supply or wastewater system; |
---|
32 | 32 | | (D) [(5)] a natural disaster, accident, or act |
---|
33 | 33 | | that results in damage to the public water supply or wastewater |
---|
34 | 34 | | system; or |
---|
35 | 35 | | (E) [(6)] for a nonindustrial public water |
---|
36 | 36 | | supply system, an unplanned condition that has caused a public |
---|
37 | 37 | | water supply outage or the public water supply system to issue a |
---|
38 | 38 | | do-not-use advisory, do-not-consume advisory, or boil water |
---|
39 | 39 | | notice; or |
---|
40 | 40 | | (2) a security incident during which: |
---|
41 | 41 | | (A) an unauthorized disclosure of sensitive |
---|
42 | 42 | | personal information, as defined by Section 521.002(a)(2)(A), |
---|
43 | 43 | | Business & Commerce Code, held by the public water supply or |
---|
44 | 44 | | wastewater system occurred; |
---|
45 | 45 | | (B) ransomware, as defined by Section 33.023, |
---|
46 | 46 | | Penal Code, was introduced into a computer, computer network, or |
---|
47 | 47 | | computer system of the public water supply or wastewater system; |
---|
48 | 48 | | (C) the public water supply or wastewater system |
---|
49 | 49 | | experienced an unauthorized attempt to probe for or gain access to |
---|
50 | 50 | | proprietary information that supports the key activities of the |
---|
51 | 51 | | system; or |
---|
52 | 52 | | (D) a computer, computer network, or computer |
---|
53 | 53 | | system problem disrupted the operation of the public water supply |
---|
54 | 54 | | or wastewater system. |
---|
55 | 55 | | (i-1) The commission may collaborate with the Texas |
---|
56 | 56 | | Division of Emergency Management in administering the notification |
---|
57 | 57 | | requirement in Subsection (i)(1)(E) [(i)(6)], including |
---|
58 | 58 | | determining the method by which the notifications are |
---|
59 | 59 | | provided. Subsection (i)(1)(E) [(i)(6)] does not require an |
---|
60 | 60 | | owner, agent, manager, operator, or other person in charge of a |
---|
61 | 61 | | nonindustrial public water supply system to provide notice of a |
---|
62 | 62 | | weather or emergency alert, warning, or watch issued by the |
---|
63 | 63 | | National Weather Service, the National Oceanic and Atmospheric |
---|
64 | 64 | | Administration, or the Texas Division of Emergency Management or a |
---|
65 | 65 | | successor federal or state agency. |
---|
66 | 66 | | (i-2) The commission shall establish and maintain |
---|
67 | 67 | | procedures to report each security incident described by Subsection |
---|
68 | 68 | | (i)(2) to the Department of Information Resources. |
---|
69 | 69 | | SECTION 2. This Act takes effect September 1, 2025. |
---|