SB1542 revises the Illinois Department of Innovation and Technology Act and the Illinois Information Security Improvement Act. The bill updates terminology throughout the DoIT Act by repealing the definition of “client agency,” replacing references to “transferring agency” with “transferred agency,” and revising related definitions for “dedicated unit,” “State agency,” and other terms. It also expands and clarifies DoIT’s authority over information technology services, including the ability to provide services more broadly to State agencies under the Governor’s jurisdiction and to set charges for those services.
The bill also shifts and expands cybersecurity-related responsibilities. It moves a local-government cybersecurity point-of-contact requirement into the Illinois Information Security Improvement Act, requiring certain units of local government to designate a local official or employee as the primary contact for cybersecurity issues and to share that information with the Statewide Chief Information Security Officer. In addition, it updates the duties of the Office of the Statewide Chief Information Security Officer and the Secretary of Innovation and Technology, including risk assessment, incident response, training, standards-setting, and coordination with State agencies and local governments.
Impact
SB1542 would amend two major state technology and cybersecurity statutes, changing how DoIT is defined, how it serves executive-branch agencies, and how it charges for information technology services. It would also repeal one section of the DoIT Act, add a new local cybersecurity contact requirement to the Illinois Information Security Improvement Act, and revise the scope of duties for the Statewide Chief Information Security Officer and the Secretary of Innovation and Technology. The practical effect is to broaden and modernize the statutory framework for state IT governance and cybersecurity coordination, while creating a formal reporting link between certain local governments and the state cybersecurity office.
Sentiment
No committee transcripts or recorded votes were provided, so there is no direct evidence of support or opposition in the available context. Based on the bill text alone, the measure appears administrative and technical in nature, focused on reorganizing statutory language and strengthening cybersecurity coordination rather than making a highly partisan policy change. The overall tone of the proposal is functional and modernization-oriented.
Contention
The main potential points of contention are the expansion of DoIT’s service and fee authority, which could affect how state agencies are billed for technology services, and the new cybersecurity designation requirement for local governments, which may be viewed as an added administrative obligation. Another possible issue is the broader centralization of authority in the Department and the Statewide Chief Information Security Officer, especially where the bill authorizes more oversight, standards-setting, and incident-response coordination across agencies and some local entities. No specific objections or supporters are identified in the available record.
House Substitute for SB 51 by Committee on Legislative Modernization - Authorizing the chief information security officer to receive audit reports, updating statutes related to services provided by the chief information technology officer and authorizing the office of information technology services to provide certain services to political subdivisions and hospitals.