Kansas 2023-2024 Regular Session

Kansas House Bill HB2019

Introduced
1/11/23  
Refer
1/11/23  
Report Pass
2/7/23  
Engrossed
3/1/23  
Refer
3/2/23  
Report Pass
3/16/23  
Enrolled
4/24/23  

Caption

Implementing additional reporting requirements for information technology projects and state agencies, requiring additional information technology security training and status reports, requiring reporting of significant cybersecurity audits and changing the membership requirements, terms of members and the quorum requirements for the information technology executive council.

Impact

If enacted, HB2019 will amend various statutes to reinforce state expectations concerning information security and incident reporting. The bill enhances the Chief Information Security Officer's powers by requiring them to oversee compliance and reporting for state-agency technology projects. This could lead to a more coordinated and effective response to cybersecurity threats, potentially reducing vulnerability across state-operated platforms. Additionally, it necessitates agencies provide annual cybersecurity assessments, ensuring accountability and systematic improvements.

Summary

House Bill 2019 focuses on enhancing cybersecurity practices across Kansas government entities. The bill mandates that public agencies report significant cybersecurity incidents and establishes timeliness for notifications, including a 12-hour report requirement for discovered incidents. The legislation aims to improve the overall cybersecurity posture of state information systems by ensuring immediate transparency regarding breaches and incidents. Furthermore, it outlines specific corrective measures and training requirements for agency personnel on cybersecurity protocols.

Sentiment

The sentiment surrounding HB2019 appears supportive overall, particularly among proponents who stress the importance of safeguarding sensitive data against growing cyber threats. Legislators who support the bill argue it will fortify Kansas's defense against cyberattacks, thereby instilling public confidence in government operations. Conversely, some critics express concern regarding potential privacy issues and the effectiveness of rapid response protocols, fearing that such processes may not be sufficiently robust or prompt to avert significant damage in the event of an incident.

Contention

The main points of contention regarding HB2019 center around the balance between transparency and the management of sensitive data. Some stakeholders argue that immediate reporting could lead to breaches of privacy and possible misuse of information during investigations. Additionally, the correct implementation of these requirements poses administrative burdens on state agencies, particularly smaller departments that may lack the resources to effectively comply with stringent reporting and training mandates specified in the bill.

Companion Bills

No companion bills found.

Previously Filed As

KS SB581

Department of Information Technology - Statewide Information Technology Master Plan - Reporting

KS HB0861

Department of Information Technology - Statewide Information Technology Master Plan - Reporting

KS HB861

Department of Information Technology - Statewide Information Technology Master Plan - Reporting

KS HB0861

Department of Information Technology - Statewide Information Technology Master Plan - Reporting

KS S7024

OGSR/Cybersecurity, Information Technology, and Operational Technology Information

KS HB2574

Removing the expiration on certain cybersecurity requirements, modifying the duties of chief information security officers and cybersecurity programs, requiring assessment of executive branch agency compliance with cybersecurity requirements, providing for consideration of such compliance by the legislature during the budget process and creating the judicial branch technology oversight council.

KS S0480

Information Technology

KS S7026

Information Technology

KS SB179

Information technology; directing state agencies to manage information technology services. Effective date. Emergency.

KS SB179

Information technology; directing state agencies to manage information technology services. Effective date. Emergency.

Similar Bills

NJ A3959

Establishes Office of Cybersecurity Infrastructure.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

CA AB979

California Cybersecurity Integration Center: artificial intelligence.

NJ A1550

Requires adoption and implementation of cybersecurity standards by casinos and sportsbooks; establishes safe gaming certification program.

NM SB254

Cybersecurity Act & Office Changes

NJ S2940

Establishes Office of Cybersecurity Infrastructure.

NJ A1549

Establishes Gaming Cybersecurity Intelligence and Response Council.

TX HB150

Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.