Enhance Security of Office of Information Technology
What changed between versions
Added authority for the Joint Technology Committee to formally request special IT security audits if audit recommendations are over two years old or if significant discrepancies exist between reports and previous audits.
Mandated that the State Auditor must conduct special IT security audits when requested and approved, with input from the Office of Information Technology regarding the audit scope.
Required the Office of Information Technology to establish, maintain, and quarterly update a list of all active IT vendor contracts for state agencies, including vendor names, contract values, expiration dates, and data criticality tiers.
Added a process for the Office to submit a one-time budget request to the Joint Technology Committee to fund the creation and maintenance of the new vendor contract list.
Required the State Auditor to submit the final audit report to the Legislative Audit Committee, Joint Technology Committee, Joint Budget Committee, and the Governor.
Added new rules for emergency security standards, requiring them to be posted online within 72 hours and automatically expiring after 90 days unless formalized under standard procedures.
Established that the Office of Information Technology must reimburse the State Auditor for audit costs using the Technology Risk Prevention and Response Fund.
Specified that the State Auditor must produce the special audit report within twelve months of the Legislative Audit Committee's affirmative vote.