Cybersecurity.
Summary
Existing law establishes the Office of Information Security within the Department of Technology, under the direction of the Chief of the Office of Information Security, for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. The law requires an entity within the executive branch that is under the direct authority of the Governor to implement the policies and procedures issued by the office. The law additionally authorizes the office to conduct, or require to be conducted, an independent security assessment of every state agency, department, or office, as specified. The law authorizes the Military Department to perform an independent security assessment of any state agency, department, or office. This bill would require all state agencies, as generally defined, to review and implement specified National Institute of Standards and Technology (NIST) guidelines for, among other things, reporting, coordinating, publishing, and receiving information about a security vulnerability relating to information systems and the resolution thereof, no later than July 1, 2023. The bill would require the chief to review the NIST guidelines and to create, update, and publish any appropriate standards or procedures in the State Administrative Manual and Statewide Information Management Manual to apply the NIST guidelines to state agencies and state entities no later than April 1, 2023. The bill would authorize a state agency, and require certain state agencies and state entities, to satisfy their requirement to implement NIST guidelines by adopting those standards and procedures published in the State Administrative Manual and Statewide Information Management Manual. The bill would require the office to provide assistance to any state agency or state entity that requests assistance in implementing the guidelines or the standards and procedures, and to provide operational and technical assistance to state agencies and state entities on reporting, coordinating, publishing, and receiving information about cybersecurity vulnerabilities of information systems, until that agency or entity withdraws their request for assistance with implementation or cybersecurity.
Bill status
passed
3 of 5 stages cleared
Introduction
Feb 2021
Committee Review
Aug 2022
Assembly Passage
Jan 2022
Senate Passage
Governor
Introduced Feb 11, 2021
Last action Aug 11, 2022
Floor votes · Assembly Jan 31, 2022
How they voted
75–0
Passed · 1 other
Total votes 76
Jan 31, 2022
D
Democratic56
100% Yea
I
Independent1
100% Yea
R
Republican19
94% Yea
Vote distribution
All Yea
All Nay
Mixed
No data
Full legislative history
Actions timeline
Total actions
20
Key actions
9
Committee
12
Amendments
4
Aug 11, 2022
Upper · Passed
In committee: Held under submission.
upper
Jun 27, 2022
Committee
In committee: Referred to suspense file.
upper
Jun 20, 2022
Introduced
From committee chair, with author's amendments: Amend, and re-refer to committee. Read second time, amended, and re-referred to Com. on APPR.
upper
Jun 15, 2022
Upper · Passed
From committee: Do pass and re-refer to Com. on APPR. (Ayes 14. Noes 0.) (June 14). Re-referred to Com. on APPR.
upper
Jun 8, 2022
Introduced
From committee chair, with author's amendments: Amend, and re-refer to committee. Read second time, amended, and re-referred to Com. on G.O.
upper
May 4, 2022
Committee
Referred to Com. on G.O.
upper
Jan 31, 2022
Lower · Passed
Read third time. Passed. Ordered to the Senate. (Ayes 75. Noes 0. Page 3425.)
lower
Jan 24, 2022
Lower · Passed
Read third time and amended. Ordered to third reading. (Page 3364.)
lower
Jan 20, 2022
Lower · Passed
From committee: Do pass. (Ayes 15. Noes 0.) (January 20).
lower
May 20, 2021
Lower · Passed
In committee: Hearing postponed by committee.
lower
May 12, 2021
Committee
In committee: Set, first hearing. Referred to APPR. suspense file.
lower
Apr 29, 2021
Lower · Passed
From committee: Do pass and re-refer to Com. on APPR. (Ayes 7. Noes 0.) (April 28). Re-referred to Com. on APPR.
lower
Apr 8, 2021
Lower · Passed
From committee: Do pass and re-refer to Com. on A. & A.R. with recommendation: To Consent Calendar. (Ayes 11. Noes 0.) (April 8). Re-referred to Com. on A. & A.R.
lower
Mar 26, 2021
Committee
Re-referred to Com. on P. & C.P.
lower
Mar 26, 2021
Introduced
From committee chair, with author's amendments: Amend, and re-refer to Com. on P. & C.P. Read second time and amended.
lower
Feb 18, 2021
Committee
Referred to Coms. on P. & C.P. and A. & A.R.
lower
Feb 12, 2021
Lower · Passed
From printer. May be heard in committee March 14.
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Jacqui Irwin
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about AB 581
Scope: CA
Hi! I can help you understand AB 581. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline