Texas 2023 - 88th Regular

Texas Senate Bill SB535

Voted on by Senate
 
Out of House Committee
 
Voted on by House
 
Governor Action
 
Bill Becomes Law
 

Caption

Relating to state agency information technology infrastructure and information security assessments.

Impact

If enacted, the bill would create a standardized process for assessing and reporting on the information security status of state agencies. Agencies would be required to submit detailed reports concerning their infrastructure and information security programs to the department overseeing these assessments. An important component of SB535 is the introduction of information security ratings for state agencies, which would categorize agencies based on their risk profiles—ranging from above average to below average. This system aims to identify areas needing improvement and facilitate state-level oversight.

Summary

SB535 focuses on enhancing the information technology infrastructure and information security assessments for state agencies in Texas. The bill mandates that each state agency conduct an information security assessment at least once every two years, in consultation with a designated department or a vendor appointed by that department. This effort is aimed at ensuring that state agencies are equipped to manage their information security risks effectively, ultimately aiming to bolster the overall security posture of state-operated systems and data management practices.

Sentiment

The sentiment surrounding SB535 appears to be cautiously optimistic. Proponents argue that the bill is a proactive step toward safeguarding sensitive state information and resources from cyber threats. They believe that regular assessments will not only enhance security but also improve public trust in state agencies. Critically, there is concern among some stakeholders about the implementation of confidentiality around the reports, which may hinder transparency and accountability in the management of state information systems.

Contention

Notable contention revolves around the balance between transparency and the need to protect sensitive information. Some members of the legislature express worries that making audit results confidential could inhibit public scrutiny, thereby reducing accountability for state agencies in how they manage information security. The bill's provisions might lead to varying interpretations regarding the extent of disclosure required, which could subsequently influence the effectiveness of oversight committees tasked with reviewing these assessments.

Companion Bills

TX HB1657

Identical Relating to state agency information technology infrastructure and information security assessments.

Previously Filed As

TX SB179

Information technology; directing state agencies to manage information technology services. Effective date. Emergency.

TX SB179

Information technology; directing state agencies to manage information technology services. Effective date. Emergency.

TX S1522

Security of State Information Technology Systems

TX A838

Requires State agencies to develop and submit information technology strategic plan.

TX SB21

OMES information technology infrastructure; creating the Oklahoma Employment Security Commission Information Technology Innovation Revolving Fund. Emergency.

TX S31

Relative to the modernization of state agency information technology systems

TX HB1724

Statewide Information Technology Optimization Program; create for coordinated efforts across agencies.

TX SB373

In boards and offices, providing for information technology and security.

TX SB185

Enhance Security of Office of Information Technology

TX HB1333

Department of Information Technology Services; require all state agencies to use for computer equipment and services.

Similar Bills

US HB1664

Deploying American Blockchains Act of 2025

US SB1492

Deploying American Blockchains Act of 2025

MS SB2653

Mississippi IT Optimization Act; enact.

KS SB51

House Substitute for SB 51 by Committee on Legislative Modernization - Authorizing the chief information security officer to receive audit reports, updating statutes related to services provided by the chief information technology officer and authorizing the office of information technology services to provide certain services to political subdivisions and hospitals.

NJ S1298

Provides that fusion energy and fusion technology companies are eligible to receive benefits under certain economic incentive programs.

MS HB1724

Statewide Information Technology Optimization Program; create for coordinated efforts across agencies.

NJ A838

Requires State agencies to develop and submit information technology strategic plan.

CA SB1079

Department of Forestry and Fire Protection: Fire Innovation Unit.