Nevada 2025 Regular Session

Nevada Assembly Bill AB432

Introduced
3/13/25  
Refer
3/13/25  
Report Pass
4/21/25  
Refer
4/21/25  
Failed
6/2/25  

Caption

Revises provisions relating to governmental administration. (BDR 19-551)

Summary

AB 432 reorganizes and expands Nevada’s state information technology and cybersecurity framework within the Office of the Chief Information Officer in the Office of the Governor. The bill creates a new Security Operations Center and assigns it responsibility for cybersecurity services for state agencies and elected state officers, including real-time monitoring of cyberinfrastructure, threat mitigation, incident response, and cybersecurity enforcement. It also requires the center to develop cybersecurity policies and procedures, coordinate with the Nevada Office of Cyber Defense Coordination, and produce an annual report on its effectiveness, threats handled, goals, and challenges. The bill also broadens the Office’s role in serving “using agencies,” a term expanded to include certain state agencies, elected state officers, local governmental agencies, and school district boards of trustees. It revises multiple statutes to reflect this broader structure, including rules on confidentiality of cybersecurity records, reporting of cyber incidents, managerial control of state-owned or leased equipment, fee-setting and billing, and the Office’s authority to investigate breaches. AB 432 creates a dedicated Account for the Security Operations Center in the State General Fund, authorizes the pooling of federal grant funds, and establishes a Cybersecurity Talent Pipeline Program with the Nevada System of Higher Education to develop student career pathways in cybersecurity.

Impact

AB 432 would significantly amend Chapter 242 of NRS by embedding cybersecurity operations into the Office of the Chief Information Officer and by shifting statutory language from a narrower focus on state agencies to a broader category of “using agencies.” It would create new duties, reporting requirements, confidentiality protections, funding mechanisms, and compliance enforcement tools, while repealing NRS 242.141 and reorganizing provisions governing services to agencies outside the Governor’s control and local governments. The bill would also affect school districts, local governments, state agencies, and higher education institutions by making them eligible for services and, in some cases, subject to new cybersecurity standards, incident reporting obligations, and cost recovery fees.

Sentiment

No committee transcripts or recorded votes were provided, so there is no direct evidence of debate or formal support/opposition in the available materials. Based on the bill text, the overall policy direction appears favorable toward strengthening cybersecurity readiness, coordination, and workforce development, with an emphasis on centralized state support and incident response. The measure also suggests an administrative modernization approach rather than a partisan policy shift.

Contention

The main points of potential contention are the bill’s expansion of centralized oversight and compliance authority, and the costs associated with implementing the new Security Operations Center and related services. Section 3 allows the Chief to impose additional oversight or audit requirements on agencies that do not comply with cybersecurity policies, which could raise concerns among affected agencies about autonomy and administrative burden. There may also be questions about funding, since the bill depends in part on available appropriations and federal grants, and about the practical impact on local governmental agencies and school districts newly brought within the statutory framework. The bill also preserves tribal sovereignty and existing tribal agreements, indicating sensitivity to jurisdictional issues in that area.

Companion Bills

No companion bills found.

Similar Bills

No similar bills found.