Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Lawmakers review House substitute for SB 291 to centralize cybersecurity, set NIST targets and new reporting rules

2166756 · January 29, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

The Legislative Modernization Committee heard an overview of the House substitute for Senate Bill 291, a broad cybersecurity and IT governance bill that would centralize cybersecurity functions under branch chief technology officers, set NIST Cybersecurity Framework milestones and create new reporting and appropriation requirements.

The Legislative Modernization Committee heard a detailed overview on Jan. 29 of the House substitute for Senate Bill 291, a bill that would consolidate many state cybersecurity functions and set new standards and reporting requirements across Kansas government.

Natalie, Reviser of Statutes, told the committee the measure transfers cybersecurity services to the chief information technology officer (CTO) for each branch, creates chief information security officers (CSOs) in the judicial and legislative branches, and requires CSOs in several constitutional offices to implement minimum cybersecurity standards tied to the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF). "If an audit results in a failure to meet those standards, then the CSO has to report that failure to the speaker of the house, the president of the Senate, and then the minority leaders," Natalie said, adding that those audit results would be confidential and exempt from open records.

The bill would also require an Information Technology Executive Council (ITEC) plan to integrate executive-branch IT services under the executive branch CTO; move agency websites to the .gov domain; require separate line-item appropriations for IT and cybersecurity projects; authorize specified appropriations, and create a mechanism by which the director of the budget could certify a 5% budget amount for agencies found out of compliance for potential lapse by appropriations committees.

Jeff Max, Chief Information Technology Officer for the Executive Branch, described the agency response and ongoing implementation work. Max said the Office of Information Technology Services (OITS) has engaged third-party vendors to perform a NIST CSF baseline assessment and a year-long IT integration planning effort. He outlined implementation activities already under way: device inventory planning, migrating agency websites onto a unified platform, firewall replacements, a statewide identity/access management roadmap (multi-factor authentication and single sign-on), and creation of a 24/7 security operations center. On appropriations, Natalie noted specific funding items in the substitute: $659,368 to the judicial branch judiciary operations fund; a $15,000,000 appropriation to the Kansas Information Security Office for FY2026; and $250,000 to the Adjutant General for two full-time positions in the Kansas Intelligence Fusion Center.

Committee members asked about specific changes made in conference committee, the bill's sunset provision, and how the proposed governance changes would work in practice. Natalie said conference committee amended criminal-disclosure language and added reporting to minority leaders and that the sunset provision would revert changes if no further action occurs.

Max said OITS has started vendor engagements and expects a roadmap deliverable; he described ITEC's move from quarterly to monthly meetings and said ITEC now includes additional membership and that the executive branch CTO is the permanent chair. He emphasized the need for organizational change management and coordination with agencies and said the state would pursue training, a large "red team/blue team" cybersecurity exercise involving local and university partners, and a focus on water-sector cybersecurity with KDHE and federal partners.

The committee did not take a formal vote on the bill at the Jan. 29 meeting. Members asked the reviser to provide a list of conference-committee changes to the committee ahead of further consideration.

Ending: Committee staff will circulate the documented conference changes and the committee will consider SB 291 at a future meeting; no final action or vote on the bill occurred during this session.