Relating to the continuation and functions of the Department of Information Resources, including the composition of the governing body of the department.
SB 2404 is a Department of Information Resources (DIR) continuation and reform bill that updates how the agency is governed and how it supports state technology procurement and cybersecurity. It extends DIR’s sunset date to September 1, 2037, restructures the governing board into 11 members with seven voting members and four nonvoting members, and replaces the prior rotating ex officio model with appointed members drawn from higher education and state agencies that are major DIR customers or smaller agencies. The bill also revises board training requirements, requires a training manual, and changes how replacement members are appointed if a board member is found constitutionally ineligible.
The bill adds several new DIR duties and programs focused on procurement, information security, and agency oversight. DIR must create a voluntary certification course on procurement of information resources technologies, provide annual training for upper management on best practices for technology purchasing, establish a procurement services pilot program for participating agencies, and conduct limited evaluations of agency deployment reviews every two years. It also requires DIR to establish advisory committees covering procurement, information security, and the state strategic plan, including a statewide information security advisory committee and a customer advisory committee. In addition, the bill expands reporting and assessment requirements related to agency data governance, cybersecurity training, and penetration testing.
SB 2404 also makes a number of conforming and technical changes across Chapter 2054 of the Government Code. It updates definitions, revises complaint and public-information provisions, modifies the annual DIR report content, and changes accessibility language to use “persons with disabilities” and “employees with disabilities.” It requires state agencies to conduct biennial data governance assessments, report results to DIR, and undergo biennial information security assessments and penetration tests. The bill repeals several existing provisions related to board composition, strategic planning, and prior reporting requirements, while also clarifying that certain higher education entities are excluded from some new cybersecurity requirements.
The overall sentiment reflected by the bill text and context is generally administrative and reform-oriented rather than overtly partisan. The bill appears designed to modernize DIR’s governance, improve procurement expertise, and strengthen cybersecurity oversight for state agencies. Because there are no recorded committee transcripts or votes in the provided context, there is no direct evidence of public debate or opposition in the materials supplied.
The main points of potential contention are structural and operational: the shift away from ex officio board participation toward appointed members, the expanded role of DIR in procurement assistance, and the new mandatory cybersecurity and assessment requirements for state agencies. Smaller agencies may be especially affected by the customer advisory committee and board composition changes, while universities and institutions of higher education are treated differently in several sections. The procurement pilot program’s limits on participation and the bill’s confidentiality provisions for security assessments may also draw scrutiny from agencies concerned about oversight, workload, or transparency.
SB 2404 amends multiple provisions of the Government Code governing the Department of Information Resources, extending the agency’s sunset date, revising board composition and training rules, and adding new statutory duties related to procurement assistance, advisory committees, cybersecurity assessments, and agency data governance. It affects state agencies, DIR board members, upper management officials, information resources managers, and local government cybersecurity training obligations, while also excluding institutions of higher education from some new security requirements. The bill repeals or replaces several existing DIR provisions and updates reporting, accessibility, and complaint-related statutes.
The bill’s apparent sentiment is broadly supportive of strengthening DIR’s oversight and service functions. Its provisions emphasize modernization, cybersecurity, procurement expertise, and better representation of customer agencies, suggesting a management-focused reform effort. No committee testimony or recorded votes were provided, so there is no direct evidence of opposition or support beyond the bill’s structure and stated objectives.
Likely areas of contention include the restructured DIR board, especially the removal of the prior rotating ex officio model and the shift to governor-appointed nonvoting members from selected agencies. Agencies may also question the added compliance burden from biennial assessments, penetration tests, annual cybersecurity training, and new reporting requirements. The procurement services pilot program could raise concerns about DIR’s role in agency purchasing authority, while confidentiality protections for security assessments may be debated by those seeking greater transparency. Smaller agencies and institutions of higher education may have particular interest because the bill treats them differently in several provisions.