Directs that state agencies require that procurement of personal computing goods, services and solutions meet the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Same As
Directs that state agencies require that procurement of personal computing goods, services and solutions meet the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Aligns state and local procurement laws with federal law prohibiting the procurement of certain technology and electronic parts or products which are determined to pose a risk to state and national security; relates to the authority of the office of information technology services to issue certain guidance relating thereto.
Aligns state and local procurement laws with federal law prohibiting the procurement of certain technology and electronic parts or products which are determined to pose a risk to state and national security; relates to the authority of the office of information technology services to issue certain guidance relating thereto.
Establishes the "secure our data act"; relates to cybersecurity protection by state entities; requires the office of information technology services to develop standards for data protection of state entity-maintained information.
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.
Requires all municipal corporations to report cybersecurity incidents and demands of ransom payments to the division of homeland security and emergency services; defines terms; requires cybersecurity incident reviews; requires cybersecurity awareness training, cybersecurity protection and data protection standards for state maintained information systems.
Requires state agencies to expend funds no later than ninety days after receipt of a certificate of approval from the director of the budget; reduces the budget of an agency that violates such requirement for the upcoming fiscal year by 1% of the amount of the late award.
Enacts the "critical infrastructure standards and procedures (CRISP) act"; requires the office of information technology, along with the division of homeland security and emergency services and the department of financial services to identify critical infrastructure, both public and private, that could be comprised by cyber-attacks.