An act relating to the creation of the Cybersecurity Advisory Council
What changed between versions
Removed two legislative members (one House member appointed by the Speaker and one Senate member appointed by the Committee on Committees) from the Council, reducing membership from 13 to 11.
Expanded the Council's stated purpose to include 'best practices, communications protocols, standards, training' in addition to infrastructure and safeguards, and expanded subsection (G) to specifically include recommendations for establishing statewide communication protocols in the event of a cybersecurity incident.
Eliminated the entire section 4663 that required the Council to biennially review and approve cybersecurity standards for critical infrastructure domains, including specific requirements for risk identification, security controls, testing, incident response plans, training, data protection, and compliance. Also removed provisions requiring the Public Utility Commission and Green Mountain Care Board to develop sector-specific standards.
Added a new duty requiring the Council to conduct an inventory and review of cybersecurity standards and protocols for critical sector infrastructures and make recommendations on whether improved or additional standards are necessary.
Added a new duty (subsection H) requiring the Council to identify and advise on opportunities to access cyber-insurance, including how to increase availability and affordability for critical industries.
Extended the sunset/repeal date from June 30, 2026 to June 30, 2028, giving the Council two additional years of authority before the chapter is automatically repealed.
Added a new Section 3 requiring the Council to include in its January 15, 2024 report recommendations on whether to amend the definition of 'essential supply chain' to include additional supply chains.
Changed appointment authorities for four council seats: the utility representative is now appointed by the Commissioner of Public Service (previously the Governor), the water system representative by the Secretary of Natural Resources (previously the Governor), the hospital representative by the President of the Vermont Association of Hospitals and Health Systems (previously the Governor), and the business representative by the Chair of the Vermont Business Roundtable (previously the Governor).
Added executive session authority allowing the Council to consider sensitive cybersecurity incident testimony and standards discussions in closed session, with a non-disclosure obligation on members and witnesses if public disclosure would jeopardize public safety.
Added a Public Records Act exemption making records regarding cybersecurity standards, protocols, and incident responses confidential if disclosure would jeopardize public safety. The exemption is explicitly made permanent and not subject to review for repeal under 1 V.S.A. section 317(e).
Simplified compensation provisions by removing the separate per diem and expense reimbursement provision for legislative members under 2 V.S.A. section 23, retaining only the provision for other members under 32 V.S.A. section 1010 paid from Agency of Digital Services appropriations.