Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity Reporting topic

No spam. Unsubscribe anytime.

Committee advances bill requiring state entities to report security incidents to Legislative Audit within five days

TRANSPORTATION, TECHNOLOGY & LEGISLATIVE AFFAIRS - SENATE · February 25, 2021
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A House bill requiring state entities to provide an initial written notice of known facts about security incidents to Legislative Audit within five days passed the Senate committee after auditors argued timely notice helps determine financial and control risks and lawmakers discussed scope, FOIA exemption and auditor judgment.

Senate Transportation, Technology & Legislative Affairs — The committee advanced a House bill that would require state entities to notify Legislative Audit of data-security incidents within five days of discovery and provide an initial written report of known facts.

Frank (legal counsel, Legislative Audit) told the committee the bill has two purposes: to give the General Assembly accurate, complete information about data breaches affecting public entities and to allow auditors to assess whether a breach endangers an entity’s financial viability. He said Legislative Audit would collect initial reports, maintain records, and produce annual summaries for legislative bodies; significant incidents would be reported promptly to officials who may need to respond.

David Coles (field audit supervisor, Legislative Audit) said breach reporting affects audit planning and materiality judgments. He described a recent case in which a major agency breach was not disclosed for a year and said auditors need timely notice to determine whether controls failed or whether a one-off incident occurred. Coles said auditors use judgment to triage incidents: small, isolated events are documented and monitored; major incidents (forensics, ransomware) trigger deeper audit work.

Senator Garner asked whether the bill imposes penalties if entities fail to report in five days; Frank said failure to report would generate an audit finding. Garner also asked how litigation or federal confidentiality rules that limit disclosure would be handled; auditors said they could not override federal confidentiality but that the bill’s exemption from FOIA was intended to avoid publicly flagging compromised entities and to preserve investigative confidentiality.

Representative Meeks described the bill as the first part of a broader cybersecurity package, including a proposal to create a chief cybersecurity officer for the state. After questions about scope and whether minimal incidents would trigger broad document production, auditors pointed to the bill’s initial-report requirement and to auditor judgment to limit burden.

The committee took a motion, approved the bill by voice vote and adjourned. No public testimony was recorded in the transcript.