Showing 4 of 4
bills
All technology bills
SB 1370 amends Tennessee law to add a cybersecurity-focused state employee to the Information Systems Council, appointed by the governor. This new member serves as a nonvoting council member, increasing the council's total membership. The bill specifies that members appointed under this provision (including the new cybersecurity role) are eligible for reappointment. These changes update Tennessee Code Annotated, Title 4, Chapter 3, specifically sections 4-3-5501(b)(1), (b)(3), and (c)(3).
HB 1033 (Tennessee) creates a legal defense for businesses that experience a data breach, provided they maintained a cybersecurity program meeting specific standards at the time of the breach. It applies to "covered entities" - businesses handling personal information, health data, or sensitive restricted information - requiring them to have written security protocols aligned with industry frameworks (like NIST). If compliant, these entities can use this defense against lawsuits alleging negligence in data security, excluding breaches from law enforcement requests or authorized employee transmissions. The bill does not change breach notification rules but offers legal protection for businesses meeting its cybersecurity criteria.
HB 481 would add a cybersecurity expert to Tennessee's Information Systems Council, appointed by the governor. The new member would serve as a nonvoting council member, expanding the council's membership to include specialized cybersecurity expertise. The bill updates council membership rules to include this position in reappointment eligibility and clarifies that all newly appointed members (including this cybersecurity role) are nonvoting. This change directly affects the council's composition and advisory capacity regarding state information systems.
SB 1421 creates an affirmative defense for businesses that experience data breaches if they maintained a written cybersecurity program meeting industry-recognized standards at the time of the breach. It applies to "covered entities" (businesses handling personal information, health data, or sensitive restricted information) and requires written security protocols based on frameworks like NIST, annual risk assessments, and employee training. Businesses using this defense must prove their program met these criteria when the breach occurred. This defense applies only to lawsuits alleging inadequate security controls, not to breaches resulting from known threats the business ignored.