Existing law establishes the Office of Information Security in the Department of Technology for purposes of ensuring the confidentiality, integrity, and availability of state systems and applications and promoting and protecting privacy as part of the development and operations of state systems and applications, as specified. Existing law requires the office to be under the direction of a chief.
This bill would require the chief to submit an annual statewide information security status report to the Assembly Committee on Privacy and Consumer Protection, Protection and the Senate Governmental Organization Committee, as described. The bill would require the
first report to be submitted no later than January 2023. The bill would require the status report and any information or records included with the status report to be confidential and prohibit the information or records from being disclosed, except as provided.
Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest.
This bill would make legislative findings to that effect.