14 | 22 | | |
---|
15 | 23 | | |
---|
16 | 24 | | |
---|
17 | 25 | | Be it enacted by the General Assembly of Virginia: |
---|
18 | 26 | | |
---|
19 | 27 | | 1. That the Code of Virginia is amended by adding a section numbered 2.2-4321.4 and by adding in Chapter 55.3 of Title 2.2 sections numbered 2.2-5514.2 and 2.2-5514.3 as follows: |
---|
20 | 28 | | |
---|
21 | 29 | | 2.2-4321.4. Prohibition on procurement of uncrewed aircraft systems by noncompliant public body. |
---|
22 | 30 | | |
---|
23 | 31 | | No public body shall contract with a nongovernmental source for the purchase, lease, or use, whether directly or through work with or on behalf of another public body, of an uncrewed aircraft system, as that term is defined in 2.2-5514.2, if such public body is not compliant with the provisions of 2.2-5514.2. |
---|
24 | 32 | | |
---|
25 | 33 | | 2.2-5514.2. Prohibition on procurement and use of insecure uncrewed aircraft systems. |
---|
26 | 34 | | |
---|
27 | 35 | | A. For the purposes of this section: |
---|
28 | 36 | | |
---|
29 | 37 | | "Advanced air mobility" or "AAM" means the integration of highly automated, uncrewed, or non-piloted aircraft into airspace systems to provide innovative and efficient transportation solutions for passengers or cargo. |
---|
30 | 38 | | |
---|
31 | 39 | | "Cybersecurity incident" means any event that jeopardizes the confidentiality, integrity, or availability of data stored, processed, or transmitted by a UAS, including unauthorized access, data breaches, or system vulnerabilities. |
---|
32 | 40 | | |
---|
33 | 41 | | "Insecure UAS" means a UAS that includes components, software, or hardware flagged for cybersecurity vulnerabilities; is manufactured, assembled, or controlled by entities domiciled in countries identified as foreign adversaries pursuant to 55.1-507; and does not meet supply chain security standards or has not been certified by VITA. |
---|
34 | 42 | | |
---|
35 | 43 | | "Public body" means the same as that term is defined in 2.2-3701. |
---|
36 | 44 | | |
---|
37 | 45 | | "Secure UAS" means a UAS that meets cybersecurity, operational safety, and data privacy standards as defined by the Virginia Information Technologies Agency (VITA) and is certified by VITA as compliant with state standards and included in the approved list of secure UAS. |
---|
38 | 46 | | |
---|
39 | 47 | | "Uncrewed aircraft system" or "UAS" means an aircraft system operated without an onboard human pilot, including the aircraft, control stations, communication links, and components required for its safe operation. This includes drones and systems that may be remotely piloted or autonomous but excludes platforms specifically designed for passenger or large cargo transport under AAM. |
---|
40 | 48 | | |
---|
45 | | - | D. In the event of a cybersecurity incident involving a UAS, VITA shall be responsible for administering, coordinating, and otherwise managing the response. Public bodies shall report all cybersecurity incidents involving UAS within 24 hours of the discovery of such incident to the Virginia Fusion Intelligence Center established in Chapter 11 ( 52-47 et seq.) of Title 52. The Virginia Fusion Intelligence Center shall share such reports with the Chief Information Officer, as described in 2.2-2005, or his designee at VITA, promptly upon receipt. |
---|
| 53 | + | D. VITA shall establish cybersecurity standards for certification of UAS as secure and maintain a list of approved secure UAS manufacturers and models published on its website. VITA shall employ a UAS cybersecurity specialist to provide technical expertise on cybersecurity risks, evaluate UAS, and deliver training on UAS to public bodies. VITA shall also employ a statewide UAS compliance officer to certify secure UAS, conduct annual compliance audits of public bodies, and otherwise monitor such compliance. Public bodies shall submit annual reports on or before December 1 of each year to VITA detailing UAS procurement and usage and steps taken by such bodies to comply with this section. |
---|
47 | | - | E. The Joint Commission on Technology and Science (JCOTS) shall review cybersecurity standards published by VITA and make recommendations every two years to ensure alignment with emerging UAS technologies, evolving cybersecurity threats, the operational and safety needs of public bodies, and public safety priorities within the Commonwealth. Such review shall involve consultation with VITA, the Department of Criminal Justice Services, the Department of Aviation, public safety agencies, cybersecurity experts, and other relevant stakeholders. Findings and recommendations from these reviews shall be submitted to the House Committee on Public Safety and the Senate Committee for Courts of Justice for consideration. |
---|
| 55 | + | E. In the event of a cybersecurity incident involving a UAS, VITA shall be responsible for administering, coordinating, and otherwise managing the response. Public bodies shall report all cybersecurity incidents involving UAS within 24 hours of the discovery of such incident to the Virginia Fusion Intelligence Center established in Chapter 11 ( 52-47 et seq.) of Title 52. The Virginia Fusion Intelligence Center shall share such reports with the Chief Information Officer, as described in 2.2-2005, or his designee at VITA, promptly upon receipt. |
---|
49 | | - | F. VITA shall submit an annual report to the General Assembly on or before December 1 of each year detailing the compliance rate of public bodies with this section, the perceived impact of the Uncrewed Aircraft Replacement Grant Program, established pursuant to 2.2-5514.3,on the transition of public bodies away from insecure UAS, and any recommendations for updates based on emerging cybersecurity threats or operational needs. |
---|
| 57 | + | F. The Joint Commission on Technology and Science (JCOTS) shall review cybersecurity standards published by VITA and make recommendations every two years to ensure alignment with emerging UAS technologies, evolving cybersecurity threats, the operational and safety needs of public bodies, and public safety priorities within the Commonwealth. Such review shall involve consultation with VITA, the Department of Criminal Justice Services, the Department of Aviation, public safety agencies, cybersecurity experts, and other relevant stakeholders. Findings and recommendations from these reviews shall be submitted to the House Committee on Public Safety and the Senate Committee for Courts of Justice for consideration. |
---|
| 58 | + | |
---|
| 59 | + | G. VITA shall submit an annual report to the General Assembly on or before December 1 of each year detailing the compliance rate of public bodies with this section, the perceived impact of the Uncrewed Aircraft Replacement Grant Program, established pursuant to 2.2-5514.3,on the transition of public bodies away from insecure UAS, and any recommendations for updates based on emerging cybersecurity threats or operational needs. |
---|
50 | 60 | | |
---|
51 | 61 | | 2.2-5514.3. Uncrewed Aircraft Replacement Grant Program. |
---|
52 | 62 | | |
---|
53 | 63 | | A. As used in this section: |
---|
54 | 64 | | |
---|
55 | 65 | | "Insecure UAS" means a UAS that includes components, software, or hardware flagged for cybersecurity vulnerabilities; is manufactured, assembled, or controlled by entities domiciled in countries identified as foreign adversaries pursuant to 55.1-507; and does not meet supply chain security standards or has not been certified by VITA. |
---|
56 | 66 | | |
---|
57 | 67 | | "Public body" means the same as that term is defined in 2.2-3701. |
---|
58 | 68 | | |
---|
59 | 69 | | "Secure UAS" means a UAS that meets cybersecurity, operational safety, and data privacy standards as defined by the Virginia Information Technologies Agency (VITA) and is certified by VITA as compliant with state standards and included in the approved list of secure UAS. |
---|
60 | 70 | | |
---|
61 | 71 | | "Uncrewed aircraft system" or "UAS" means an aircraft system operated without an onboard human pilot, including the aircraft, control stations, communication links, and components required for its safe operation. This includes drones and systems that may be remotely piloted or autonomous but excludes platforms specifically designed for passenger or large cargo transport under AAM. |
---|
62 | 72 | | |
---|
63 | | - | B. With all funds appropriated for such purpose and any gifts, donations, grants, bequests, and other funds received on its behalf, the Uncrewed Aircraft Replacement Grant Program (the Program) is hereby established to provide grants to public bodies for the purpose of aiding such bodies with the transition from insecure UAS to secure UAS. Public bodies that fail to comply with the provisions of 2.2-5514.2 are ineligible for an award under the Program. Public bodies with significant operational reliance on UAS and limited resources for replacing insecure UAS shall be given priority when awarding grant funds. |
---|
| 73 | + | B. With all funds appropriated for such purpose and any gifts, donations, grants, bequests, and other funds received on its behalf, the Uncrewed Aircraft Replacement Grant Program (the Program) is hereby established to provide grants to public bodies for the purpose of aiding such bodies with the transition from insecure UAS to secure UAS. Public bodies that fail to comply with the provisions of 2.2-5514.2 are ineligible for an award under the Program. |
---|