CYBERSECURITY ACT & OFFICE CHANGES
What changed between versions
Updated definitions to include modern technology like cloud systems, voice/video communications, and user credentials, ensuring the law covers current digital infrastructure.
Added new duties for the Office of Cybersecurity including developing a service catalog, establishing data classification policies, and creating a centralized breach reporting process.
Reordered the Cybersecurity Advisory Committee's duties to prioritize statewide planning and best practice guidelines before incident response coordination.
Adjusted committee membership numbers and representation requirements, reducing some positions from three to two members and clarifying representation for counties and municipalities.
Changed reporting deadlines from 2023 to 2024 and subsequent years, aligning with the new legislative session timeline.
Clarified that the security officer can issue compliance orders for executive agencies but that compliance by non-executive and local governments remains voluntary.