Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the State It Reform topic
No spam. Unsubscribe anytime.
Committee opens informational session on state IT unification, modernization funding and cyber incident reporting
Summary
After completing business on House Bill 3592, the Joint Legislative Committee on Information Management and Technology held an informational meeting reviewing options for executive‑branch IT unification, a technology modernization fund and statewide cyber incident reporting.
Get email alerts on the State It Reform topic
No spam. Unsubscribe anytime.
After completing business on House Bill 3592, the Joint Legislative Committee on Information Management and Technology on June 11 held an informational meeting that briefed members on three related topics: potential unification of executive‑branch information technology, a technology modernization fund and the option of statewide cyber incident notification and reporting.
Committee staff told members the state's IT environment is highly decentralized, with roughly 2,300 IT positions spread across about 50 state agencies and "no supervisory reporting relationship" between most agency IT staff and the state chief information officer. Staff said 75–80% of the state's IT budget currently pays for maintaining legacy systems, limiting funds available for innovation and increasing the risk profile for cyber attacks.
Staff presented prior legislative efforts and options for change. Among materials posted to OLIS and described in the briefing: a history of prior hearings, reference to work on Senate Bill 872 (2017) that sought a Department of Information Technology, and the concept behind Senate Bill 1090 and a proposed technology modernization fund, which the committee previously recommended and which sponsors argued could be modeled on programs used in other states. Committee staff also noted an alternative approach suggested by Co Chair Nathanson: instead of new monies, pool approved agency IT project funds into a centrally managed technology modernization fund to prioritize enterprise investments.
On cyber incident reporting, staff said 15 other states have statutory requirements for public bodies to report cyber incidents to a central entity and asked whether Oregon should pursue similar reporting to improve information sharing, analysis and coordinated response.
Members expressed interest in continuing work on these topics in the interim. Committee staff said they will coordinate follow‑up briefings, outreach to stakeholders and a potential site visit to Oregon State University to learn about university work on robotics, AI, and cybersecurity. "I have posted some detailed documents on OLIS on each topic," staff member Sean told the committee, and he encouraged members to review the materials and provide questions for future sessions.
The informational session closed with members requesting more stakeholder engagement and follow‑up, and some members noting that funding and prioritization questions will be decided ultimately in Ways and Means and future sessions.
