Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
House approves multifactor authentication requirement for access to state data
Summary
The Idaho House passed House Bill 35 requiring multifactor authentication for access to state data and giving the state ITS stronger authority over agency cybersecurity operations; the measure passed 54-16 and will be sent to the Senate.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
BOISE — The Idaho House of Representatives on Jan. 27 passed House Bill 35, a bill that requires anyone accessing state data to use multifactor authentication and gives the state Office of Information Technology Services (ITS) broader authority to direct cybersecurity operations across executive-branch agencies.
Supporters said the measure addresses rising cyberattacks on state systems and clarifies ITS authority where past language left enforcement to agencies’ discretion. "Everyone who's accessing state data needs to do so using multifactor authentication," the representative from District 34 said while presenting the bill. She told members the change gives ITS the power to direct agencies when equipment or support is out of date, saying agencies had sometimes treated "coordination" as a nonbinding suggestion.
The bill outlines multiple options for a second authentication factor and does not require any single method, the presenter said. "If you want to use your personal smartphone for the purposes of providing that second factor authentication, you can do so. If you do not want to use your personal device, there's the option that you can secure it through an additional email account or even your desk phone," the representative said. She also noted alternatives for locations without wireless access, citing a YubiKey-style physical security token used in Department of Corrections facilities.
Members asked about public-records implications for using personal phones as a second factor. "Our cell phones are already subject to public records request if we conduct any official state business on them," the representative from District 34 replied when asked by Representative John Fippoor. She added that for multifactor purposes, "you are simply providing verification that the device that you own is held by you, and you're providing the verification. There would be nothing to solicit other than the fact confirmation that you were the 1 that authorized access to the account."
Supporters emphasized cyberthreats and the need for stronger protections. "I received a ... top secret brief on the cybersecurity threats within the state, and it would make your hair curl," the representative from District 14 told the chamber in a floor comment in favor of the bill.
The House closed debate without further amendments and approved the measure by roll call, 54 ayes to 16 nays. The House clerk recorded that the bill "has passed the house" and the title was approved for transmission to the Senate.
Clarifying details provided on the floor included that the bill's fiscal note lists no additional cost because services are already provided through the statewide cost assessment (SWICAP), according to the bill's presenter. The bill language references device-based and possession-based credentials but leaves users discretion over the method.
The bill came to the floor from committee with unanimous committee support, the presenter said. The House action was a passage vote only; any final legal effect will depend on Senate consideration and the governor's approval.
