Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Summary
Bill S02671 amends the state finance law to establish procurement requirements for end point devices used by state agencies. The bill mandates that these procurement processes align with the standards and guidelines set forth by the National Institute of Standards and Technology (NIST) Cybersecurity Framework. This includes personal computing devices such as desktops, laptops, tablets, and multifunctional devices, ensuring that the state maintains a high level of cybersecurity in its technology acquisitions.
Impact
The passage of this bill will enhance the cybersecurity posture of state agencies by ensuring that all procured end point devices meet established national standards. This could lead to improved security measures across the state's technology infrastructure, potentially reducing vulnerabilities to cyber threats. Additionally, it may necessitate updates to existing procurement processes and guidelines to align with the new requirements set forth by the NIST framework.
Sentiment
The sentiment surrounding Bill S02671 appears to be generally positive, as it aims to strengthen cybersecurity measures within state agencies. However, there may be concerns regarding the implementation of these standards and the potential costs associated with compliance, which could lead to discussions in future committee meetings or legislative sessions.
Contention
Notable points of contention may arise regarding the financial implications of adhering to the NIST standards, particularly concerning budget constraints for state agencies. Some legislators may express concerns about the feasibility of updating procurement processes and whether the state has the resources necessary to implement these changes effectively. Additionally, there may be differing opinions on the adequacy of the NIST standards themselves, with some advocating for stricter measures while others may argue for more flexibility.
Same As
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Directs that state agencies require that procurement of personal computing goods, services and solutions meet the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Aligns state and local procurement laws with federal law prohibiting the procurement of certain technology and electronic parts or products which are determined to pose a risk to state and national security; relates to the authority of the office of information technology services to issue certain guidance relating thereto.
Aligns state and local procurement laws with federal law prohibiting the procurement of certain technology and electronic parts or products which are determined to pose a risk to state and national security; relates to the authority of the office of information technology services to issue certain guidance relating thereto.
Requires an office within the department of financial services to establish minimum standards for large frontier developers' frontier AI frameworks to prevent unreasonable levels of catastrophic risk.