Bill Text: CA AB2748 | 2017-2018 | Regular Session | Amended
Bill Title: Election infrastructure: independent security assessments.
Spectrum: Partisan Bill (Democrat 2-0)
Status: (Engrossed - Dead) 2018-08-20 - Ordered to inactive file at the request of Senator Stern. [AB2748 Detail]
Download: California-2017-AB2748-Amended.html
Amended
IN
Assembly
March 23, 2018 |
Assembly Bill | No. 2748 |
Introduced by Assembly Member Chau |
February 16, 2018 |
LEGISLATIVE COUNSEL'S DIGEST
Existing law requires the Department of Technology, on or before July 1, 2018, to update the Technology Recovery Plan element of the State Administrative Manual to ensure the inclusion of cybersecurity strategy incident response standards for each state agency, as specified.
This bill would make a nonsubstantive change to that provision.
Digest Key
Vote: MAJORITY Appropriation: NO Fiscal Committee:Bill Text
The people of the State of California do enact as follows:
SECTION 1.
The Legislature finds and declares all of the following:SEC. 2.
Section 11549.45 is added to the Government Code, to read:11549.45.
(a) The office, the Office of Emergency Services, and the California Military Department shall establish a pilot program to conduct, or require to be conducted, an independent security assessment of election infrastructure in participating counties. The office, the Office of Emergency Services, and the California Military Department shall consult with county elections officials to identify and select counties to participate in the pilot program. The independent security assessments for the first group of participating counties shall be completed no later than January 1, 2020. After completion of those assessments, the office, the Office of Emergency Services, and the California Military Department may conduct additional independent security assessments of election infrastructure in other counties.(a)(1)On or before July 1, 2018, the department shall, in consultation with the office and compliance with Section 11549.3, update the Technology Recovery Plan element of the State Administrative Manual to ensure the inclusion of cybersecurity strategy incident response standards for each state agency to secure its critical infrastructure controls and critical infrastructure information.
(2)In updating the standards in paragraph (1), the department shall consider, but not be limited to considering, each of the following:
(A)Costs to implement the standards.
(B)Security of critical infrastructure information.
(C)Centralized management of risk.
(D)Industry best practices.
(E)Continuity of operations.
(F)Protection of personal information.
(b)Each state agency shall provide the department with a copy of its updated Technology Recovery Plan.
(c)Each state agency shall, as part of its Technology Recovery Plan, provide the department with an inventory of all critical infrastructure controls, and their associated
assets, in the possession of the agency.