Relating to the requirements of the state’s cyber security program and responsibilities and authority of the state chief information security officer
What changed between versions
The definition of 'Cyber risk assessment Cybersecurity program review' was corrected to simply 'Cybersecurity program review,' removing redundant and confusing text.
The definition of 'Information custodian' was expanded to explicitly list 'office, board, commission,' clarifying which state entities are responsible for data security.
Specific deadlines for submitting reports (e.g., December 31, 2020) were removed, replacing them with recurring annual requirements to allow for ongoing compliance rather than one-time fixes.
The requirement for agencies to complete a specific self-assessment report by a past date was removed, focusing instead on the ongoing requirement to participate in annual cybersecurity program reviews.
Several grammatical errors and redundant phrases were removed from the text, such as 'authority to may' and 'functions and duties as provided by lawand as or directed,' to improve clarity and legal precision.