Idaho 2025 Regular Session

Idaho House Bill H0004

Introduced
1/9/25  

Caption

Amends and adds to existing law to require the implementation of cybersecurity best practices and the use of multifactor identification in Idaho state government.

Summary

House Bill 4 updates Idaho’s information technology and cybersecurity statutes to strengthen statewide cyber defenses and authentication requirements. It expands the duties of the Office of Information Technology Services to include coordinating cybersecurity policy, information security needs, penetration testing and vulnerability scanning, employee training, a statewide cybersecurity information website, public outreach, and the implementation of cybersecurity best practices across state agencies. The bill also creates a new statutory definition of “multifactor identification” and requires state agencies to use it for access to information technology devices and services, including email, cloud storage, web applications, networks, databases, and servers. In addition, it separately requires the legislative branch, judicial branch, and elected constitutional officers and their staffs to implement multifactor identification. The act is declared an emergency measure and would take effect July 1, 2025.

Impact

The bill amends Section 67-827A and Section 67-831 of the Idaho Code and adds a new Section 67-2362. It broadens the Office of Information Technology Services’ authority and responsibilities, imposes cybersecurity best-practice obligations on state agencies, and establishes a statewide multifactor authentication requirement for executive-branch state agencies as well as the legislature, judiciary, and elected constitutional offices. It also clarifies terminology used in the information technology chapter and authorizes rulemaking to carry out the act.

Sentiment

Based on the bill text and available context, the measure appears to be framed as a straightforward government cybersecurity modernization effort rather than a controversial policy change. The caption and statutory changes suggest a generally supportive posture toward improving security, risk management, and consistency across branches of state government. No committee transcript or recorded votes were provided, so there is no documented public debate in the supplied materials.

Contention

The main points of potential contention are operational and institutional rather than ideological. The bill requires multifactor identification across multiple branches of government, including the legislature and judiciary, which may raise concerns about branch autonomy, implementation costs, and administrative burden. It also gives the Office of Information Technology Services broad coordinating and directive authority over cybersecurity practices, training, testing, and reporting, which could prompt questions about centralized control versus agency discretion. No specific objections or supporters are identified in the provided record.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.