Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Legislature adopts NIST CSF v2 roadmap; priorities include MFA rollout, asset inventories, incident exercises
Summary
Legislative security staff presented a NIST CSF v2 assessment and implementation roadmap. The roadmap prioritizes (1) formal cybersecurity policies and leadership sign‑off, (2) full asset and dependency inventories, (3) 100% adoption of strong multifactor authentication for privileged and remote accounts, (4) annual tabletop incident exercises and
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Legislative security staff presented a NIST Cybersecurity Framework (CSF v2) assessment and an implementation roadmap aimed at meeting SB291's tier requirements for the legislative branch.
Bob Murphy, the legislature's security analyst, said current capabilities vary across the six CSF functions (govern, identify, protect, detect, respond, recover). Key near‑term priorities include formalizing enterprise cybersecurity policies and governance, completing a verified asset inventory (hardware, software and data), and accelerating multifactor authentication (MFA) adoption for privileged and remote accounts (the immediate objective is 100% adoption for privileged users). Murphy recommended an annual, enterprise‑level risk assessment and the creation of a centralized platform to integrate asset and risk data.
On incident readiness, Murphy said existing incident response and recovery plans exist in parts (individual departments have plans) but lack an enterprise‑level coordination plan and consistent tabletop testing. He proposed immediate updates to incident response documentation, midterm cross‑department tabletop exercises with documented lessons learned, and longer term automation of recovery workflows to reduce RTOs (recovery time objectives).
Why it matters: SB291 requires branch cybersecurity programs to reach a higher maturity tier (tier 3 by July 1, 2028, and tier 4 by July 1, 2030). Murphy's roadmap identifies actions intended to move the legislature from partial/risk‑informed practices to repeatable and adaptive management across governance, identity, protection controls and incident response.
What remains open: The roadmap assigns responsibilities (CISO, CTO, SEDO and departmental IT leads), but several tasks depend on appointing a permanent legislative CISO and completing current asset inventories. The committee asked that periodic progress updates be provided to JCIT as work proceeds.

