New Jersey 2022-2023 Regular Session

New Jersey Senate Bill S297

Introduced
1/11/22  
Refer
1/11/22  
Report Pass
3/21/22  
Engrossed
5/26/22  
Refer
5/26/22  
Report Pass
1/19/23  
Enrolled
1/26/23  
Chaptered
3/13/23  

Caption

Requires public agencies and government contractors to report cybersecurity incidents to New Jersey Office of Homeland Security and Preparedness.

Impact

The implementation of S297 is expected to have significant implications for state laws, particularly concerning data security and incident reporting protocols. The bill requires the establishment of a cyber incident reporting system that public agencies and contractors must use to notify the OHSP of cybersecurity incidents. Additionally, the bill stipulates that the information submitted will be treated as confidential and protected from public disclosure, which aims to encourage timely and honest reporting without the fear of operational repercussions.

Summary

S297 is a legislative measure in New Jersey aimed at enhancing the reporting and management of cybersecurity incidents by public agencies and government contractors. The bill mandates that these entities report any cybersecurity incidents to the New Jersey Office of Homeland Security and Preparedness (OHSP) within 72 hours of becoming aware of such incidents. This requirement is designed to facilitate a more robust and timely response to cybersecurity threats, thereby improving the overall cybersecurity posture of state and local government networks.

Sentiment

The sentiment surrounding S297 appears largely supportive among legislators and cybersecurity advocates who recognize the pressing need for improved cybersecurity measures. Supporters argue that the bill will lead to better resource allocation and response capabilities for the state, which is essential given the increasing frequency of cyber threats. However, there may be concerns from some stakeholders regarding the implications of confidentiality provisions and the potential bureaucratic burden placed on public agencies to adhere to reporting timelines.

Contention

Potential points of contention related to S297 could arise from the enforcement of the reporting requirement and the interpretation of what constitutes a reportable cybersecurity incident. Some entities may feel overwhelmed by the additional administrative responsibilities or may question whether the 72-hour timeframe is feasible. Additionally, while confidentiality is a key element designed to protect sensitive information, it raises questions about transparency and public accountability in the management of cybersecurity incidents.

Companion Bills

NJ A493

Same As Requires public agencies and government contractors to report cybersecurity incidents to New Jersey Office of Homeland Security and Preparedness.

NJ S493

Same As Establishes sexual assault victim's right to appeal prosecutor decision not to file criminal charges; directs sexual assault unit in DLPS to review appeals.

Previously Filed As

NJ S1176

Requires certain procedures and training for municipalities, counties, and school districts in response to cybersecurity incidents.

NJ S07672

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

NJ A06769

Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.

NJ S1262

Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.

NJ S1225

Requires New Jersey Cybersecurity and Communications Integration Cell to study cybersecurity infastructure and establish cybersecurity guidelines.

NJ A4198

Requires New Jersey Cybersecurity and Communications Integration Cell to study cybersecurity infastructure and establish cybersecurity guidelines.

NJ A3231

Requires businesses in financial, essential infrastructure, and health care industries to report cybersecurity incidents.

NJ A711

Requires public institution of higher education to establish plans concerning cyber security and prevention of cyber attacks.

NJ SJR107

Establishes "New Jersey Cybersecurity Task Force."

NJ HB1220

Cybersecurity; governmental and certain commercial entities substantially complying with standards not liable for incidents relating to.

Similar Bills

No similar bills found.