Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officer
Summary
HB5638 revises West Virginia’s cybersecurity program by formally creating and defining the West Virginia Cybersecurity Office within the Office of Technology and clarifying the role of the Chief Information Security Officer (CISO). The bill gives the CISO authority to develop enterprise cybersecurity policies, standards, risk assessments, training requirements, privacy-impact guidance, and incident-response support for state government systems. It also authorizes the office to offer fee-based cybersecurity services to otherwise exempt entities or local political subdivisions that choose to participate voluntarily.
The bill requires covered information custodians to undergo cyber risk assessments, follow statewide cybersecurity standards, submit exception requests for approval, and participate in an annual cybersecurity program review. It also directs the Department of Administration to propose implementing rules and requires the CISO to report annually to the Governor and the Joint Committee on Government and Finance on the status of the program, review results, and modernization efforts. The bill further protects sensitive cybersecurity-related materials from disclosure under the state’s public records law and limits state software licensing contracts from restricting where the state may install or run software.
Impact
HB5638 amends and reenacts West Virginia Code §5A-6B-1 through §5A-6B-6, expanding and clarifying the statutory framework for state cybersecurity governance. It strengthens the authority of the CISO and Office of Technology over cybersecurity standards, assessments, training, and incident preparedness for most state agencies, while continuing exemptions for higher education, the State Police, constitutional officers, the Legislature, and the Judiciary. It also creates a confidentiality exemption for cybersecurity assessments and related documents under the state Freedom of Information Act and adds reporting and rulemaking obligations that affect state agencies and information custodians.
Sentiment
The bill appears to have been broadly supported and noncontroversial in the Legislature. It passed the House 90-0, the Senate 32-0, and the House concurrence vote 93-1, indicating strong bipartisan agreement on the need to update and formalize cybersecurity oversight. The voting pattern suggests general confidence in the Department of Administration’s proposal and in strengthening statewide cyber defenses.
Contention
No committee testimony or floor debate was provided, and the recorded votes show little opposition. The only apparent point that could draw concern is the bill’s expansion of centralized authority in the CISO and Office of Technology, including mandatory assessments, annual reviews, and the ability to charge agencies for nonparticipation. Another possible issue is the broad exemption from public disclosure for cybersecurity-related records, which may raise transparency concerns, but the available record does not show organized opposition to those provisions.
Requires businesses in financial essential infrastructure, and health care industries to develop cybersecurity plans and report cybersecurity incidents.
Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.