Idaho 2025 Regular Session

Idaho House Bill H0035

Introduced
1/22/25  
Engrossed
1/27/25  
Refer
1/28/25  
Report Pass
2/10/25  
Enrolled
2/24/25  
Chaptered
2/25/25  

Caption

Amends and adds to existing law to require the implementation of cybersecurity best practices and the use of multifactor identification in Idaho state government.

Summary

House Bill 35 updates Idaho’s information technology and cybersecurity statutes to strengthen statewide cyber defenses and authentication requirements. It expands the duties of the Office of Information Technology Services to include overseeing cybersecurity policy implementation, coordinating with agencies on information security needs, penetration testing, vulnerability scanning, employee training, a statewide cybersecurity website, and public outreach on protecting personal and sensitive data. The bill also directs the office to ensure state agencies implement and maintain cybersecurity best practices. A central feature of the bill is a new requirement that state agencies use multifactor identification to access information technology devices and services, including email, cloud storage, web applications, networks, databases, and servers. The bill defines multifactor identification as using two or more credential types, such as passwords, tokens or smartphone apps, and biometric traits like fingerprints or facial recognition. It also adds a separate new section requiring the legislative branch, judicial branch, and elected constitutional officers and their staffs to adopt multifactor identification. The bill’s impact on state law is to broaden the cybersecurity authority of the Office of Information Technology Services and impose specific security obligations across Idaho state government. It amends existing definitions in the information technology chapter, adds a new statutory section for the legislative, judicial, and constitutional offices, and authorizes rulemaking to carry out the act. The measure takes effect July 1, 2025, under an emergency clause. The general sentiment reflected in the voting history appears favorable, with the bill passing the House 54-16 and the Senate 31-4. That margin suggests broad bipartisan support for stronger cybersecurity protections and modern authentication standards in state government. No committee transcript was provided, so there is no recorded discussion to indicate detailed debate. Any likely contention would center on the scope and cost of implementation, especially for smaller agencies and for the legislative, judicial, and constitutional offices that are newly required to comply. Potential concerns may also involve operational flexibility, privacy implications of biometric authentication, and the extent of centralized control by the Office of Information Technology Services. However, the recorded votes indicate that such concerns did not prevent strong overall support.

Impact

The bill amends Idaho Code sections governing the Office of Information Technology Services and information technology definitions, and adds a new section requiring multifactor identification for the legislative branch, judicial branch, and elected constitutional officers. It expands statewide cybersecurity oversight, mandates cybersecurity best practices and employee training coordination, and requires MFA for access to specified systems and accounts. The act becomes effective July 1, 2025, and authorizes rulemaking to implement its provisions.

Sentiment

The bill appears to have been received positively overall, as reflected by strong passage in both chambers: 54-16 in the House and 31-4 in the Senate. Those margins suggest broad agreement that Idaho state government should strengthen cybersecurity and authentication requirements. No committee transcript was provided, so there is no direct record of floor or committee debate, but the vote totals indicate limited opposition.

Contention

The main points of contention likely relate to implementation burden, cost, and administrative flexibility. Requiring multifactor identification across executive agencies, and newly across the legislative, judicial, and constitutional offices, may raise concerns about procurement, training, and compatibility with existing systems. Some may also question the use of biometric methods or the degree of centralized authority given to the Office of Information Technology Services. Even so, the recorded votes suggest these concerns were outweighed by support for stronger cyber protections.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.