Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Sb291 Draft topic
No spam. Unsubscribe anytime.
Joint Committee on Information Technology advances draft corrective bill tied to Senate Bill 291
Summary
The Joint Committee on Information Technology reviewed a drafted corrective replacement for Senate Bill 291 that adds a judicial-branch technology oversight council, standardizes CISO language across elected offices, requires cybersecurity assessments and reporting, and moved the draft forward for introduction after a voice vote. (Natalie; Representative Haskin motioned).
Get email alerts on the Sb291 Draft topic
No spam. Unsubscribe anytime.
The Joint Committee on Information Technology voted to advance a drafted corrective replacement for Senate Bill 291 after a staff presentation and committee discussion.
Natalie, committee staff, summarized the draft, saying, "essentially, what this bill does is try to bring in all the recommendations that you guys made over the course of your last couple of joint committee meetings," and walked members through sections that would: create a judicial branch technology oversight council; align Commissioner-of-Information-Security-Officer (CISO) language for elected offices; remove statutory "maturity" requirements while requiring agencies to report cybersecurity maturity levels to JCIT and legislative budget committees; make audit reports confidential under a CORA exception; give the executive branch CISO authority to adopt statewide cybersecurity standards and establish recurring agency assessment cycles; and change the process for a budget lapse of 10% of an agency's IT budget for persistent noncompliance.
The draft retains statutes from a February version for member review but would omit unchanged sections before introduction, Natalie said. On assessments, the draft states the CISO "may" establish an assessment cycle; committee members flagged that wording. Representative Haskin pointed out the phrasing and the Chair agreed it "should say shall," and members directed that change.
Senator Tyson said embedding the NIST framework level in statute "really bothers me being in statute," arguing the statute should require cybersecurity safeguards but leave framework versioning and technical detail to rules or a standards-setting council; he offered to provide alternate language. Several members discussed strengthening JCIT or an umbrella ITEC-like council to set standards and oversee procurement processes such as RFPs, which could keep technical detail out of statute.
Senator Francisco suggested changing website-hosting language to require state sites be on a .gov domain and asked how a new auditing process would interact with existing legislative post-audit responsibilities; the Chair and members said that overlap will need follow-up discussion and possibly budget support or third-party assessors.
On budget enforcement, the draft would require, beginning 10/01/2028 and annually thereafter, the executive branch CISO to report to the legislative budget committee on agencies not meeting assessment expectations; agencies would then present plans of action and milestones. The executive branch CISO would submit a detailed written report before the legislative session on agencies failing to make progress, and during the regular session budget committees could consider lapsing 10% of an agency's IT budget for continued failures.
Representative Haskin moved to advance the draft "as amended." The Chair accepted the motion; the second was recorded as Senator Bowser. The committee approved the motion by voice vote and the Chair said the motion carries. Members were encouraged to provide additional suggested changes before formal introduction.
Next steps: the committee will refine statutory language (including changing "may" to "shall" for assessment cycles), consider alternatives to embedding NIST versioning in statute, work out reporting and audit-resourcing details with legislative budget staff, and prepare the bill for formal introduction this week.

