Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Legislature adopts NIST CSF v2 roadmap; priorities include MFA rollout, asset inventories, incident exercises

Joint Committee on Information Technology (JCIT) · October 29, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Legislative security staff presented a NIST CSF v2 assessment and implementation roadmap. The roadmap prioritizes (1) formal cybersecurity policies and leadership sign‑off, (2) full asset and dependency inventories, (3) 100% adoption of strong multifactor authentication for privileged and remote accounts, (4) annual tabletop incident exercises and

Legislative security staff presented a NIST Cybersecurity Framework (CSF v2) assessment and an implementation roadmap aimed at meeting SB291's tier requirements for the legislative branch.

Bob Murphy, the legislature's security analyst, said current capabilities vary across the six CSF functions (govern, identify, protect, detect, respond, recover). Key near‑term priorities include formalizing enterprise cybersecurity policies and governance, completing a verified asset inventory (hardware, software and data), and accelerating multifactor authentication (MFA) adoption for privileged and remote accounts (the immediate objective is 100% adoption for privileged users). Murphy recommended an annual, enterprise‑level risk assessment and the creation of a centralized platform to integrate asset and risk data.

On incident readiness, Murphy said existing incident response and recovery plans exist in parts (individual departments have plans) but lack an enterprise‑level coordination plan and consistent tabletop testing. He proposed immediate updates to incident response documentation, midterm cross‑department tabletop exercises with documented lessons learned, and longer term automation of recovery workflows to reduce RTOs (recovery time objectives).

Why it matters: SB291 requires branch cybersecurity programs to reach a higher maturity tier (tier 3 by July 1, 2028, and tier 4 by July 1, 2030). Murphy's roadmap identifies actions intended to move the legislature from partial/risk‑informed practices to repeatable and adaptive management across governance, identity, protection controls and incident response.

What remains open: The roadmap assigns responsibilities (CISO, CTO, SEDO and departmental IT leads), but several tasks depend on appointing a permanent legislative CISO and completing current asset inventories. The committee asked that periodic progress updates be provided to JCIT as work proceeds.