Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Summary
Bill A00426 amends the state finance law to establish procurement requirements for end point devices used by state agencies. The bill mandates that these devices must adhere to relevant standards and guidelines set forth by the National Institute of Standards and Technology (NIST) Cybersecurity Framework, ensuring that the security of personal computing goods, such as desktops, laptops, and mobile devices, meets established cybersecurity benchmarks. This legislative change aims to enhance the security posture of state agencies by standardizing the procurement process for technology that is critical to operations and data protection.
Impact
The bill will impact state laws by formalizing the requirement for state agencies to align their procurement practices for end point devices with recognized cybersecurity standards. This change is expected to improve the overall security of state-operated technology and reduce vulnerabilities associated with outdated or insecure devices. Additionally, it may influence the procurement processes of state agencies, necessitating adjustments in how they evaluate and select technology vendors and products.
Sentiment
The sentiment surrounding Bill A00426 appears to be overwhelmingly positive, as indicated by the unanimous support in committee and floor votes. The bill received favorable recommendations from both the Assembly Science and Technology Committee and the Assembly Rules Committee, followed by a final passage with no opposition in either the Assembly or the Senate. This suggests a strong consensus among lawmakers regarding the importance of cybersecurity in state procurement practices.
Contention
There are no notable points of contention reported in the discussions or voting history related to Bill A00426. The bill has moved through the legislative process without opposition, indicating a shared understanding among legislators of the necessity for enhanced cybersecurity measures in state procurement.
Same As
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Directs that state agencies require that procurement of personal computing goods, services and solutions meet the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Aligns state and local procurement laws with federal law prohibiting the procurement of certain technology and electronic parts or products which are determined to pose a risk to state and national security; relates to the authority of the office of information technology services to issue certain guidance relating thereto.
Aligns state and local procurement laws with federal law prohibiting the procurement of certain technology and electronic parts or products which are determined to pose a risk to state and national security; relates to the authority of the office of information technology services to issue certain guidance relating thereto.