State agencies: information security: uniform standards.
Summary
Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. The law requires state entities, as specified, to implement the policies and procedures issued by the office. The law additionally authorizes the office, under direction of the chief, to conduct, or require to be conducted, an independent security assessment of every state agency, department, or office, as specified. State agencies must certify, by February 1 annually, to the President pro Tempore of the Senate and the Speaker of the Assembly that the agency is in compliance with all adopted policies, standards, and procedures and to include a plan of action and milestones, as specified. This bill would require every state agency, as defined and subject to specified exceptions, to implement Zero Trust architecture for all data, hardware, software, internal systems, and essential third-party software, including for on-premises, cloud, and hybrid environments, to achieve prescribed levels of maturity based on the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model, as defined, by specified dates. In implementing Zero Trust architecture, the bill would require state agencies to prioritize the use of solutions that comply with, are authorized by, or align to federal guidelines, programs, and frameworks and, at a minimum, prioritize multifactor authentication for access to all systems and data, enterprise endpoint detection and response solutions, and robust logging practices, as specified. The bill would require the office's chief, no later than January 1, 2025, to develop or revise uniform technology policies, standards, and procedures for use by all state agencies in Zero Trust architecture to achieve specified maturity levels on all systems in the State Administrative Manual and Statewide Information Management Manual. The bill would require the chief to update requirements for existing annual reporting activities to collect information relating to the progress state agencies are making to increase internal defenses of agency systems. The bill would authorize the chief to update existing annual reporting activities to include how a state agency is progressing with respect to specified goals. The bill would also state the Legislature's intent that the bill's provisions be implemented in a manner consistent with the state's timely compliance with requirements that are conditions to receipt of federal funds. The bill would also make related legislative findings and declarations.
Bill status
passed
3 of 5 stages cleared
Introduction
Feb 2023
Committee Review
Sep 2023
Assembly Passage
May 2023
Senate Passage
Governor
Introduced Feb 13, 2023
Last action Sep 1, 2023
Floor votes · Assembly May 30, 2023
How they voted
80–0
Passed
Total votes 80
May 30, 2023
D
Democratic62
100% Yea
R
Republican18
100% Yea
Vote distribution
All Yea
All Nay
Mixed
No data
Full legislative history
Actions timeline
Total actions
22
Key actions
7
Committee
12
Amendments
6
Sep 1, 2023
Upper · Passed
In committee: Held under submission.
upper
Aug 21, 2023
Committee
In committee: Referred to APPR suspense file.
upper
Aug 14, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to committee. Read second time, amended, and re-referred to Com. on APPR.
upper
Jul 11, 2023
Upper · Passed
From committee: Do pass and re-refer to Com. on APPR. (Ayes 14. Noes 0.) (July 11). Re-referred to Com. on APPR.
upper
Jul 3, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to committee. Read second time, amended, and re-referred to Com. on G.O.
upper
Jun 7, 2023
Committee
Referred to Com. on G.O.
upper
May 30, 2023
Lower · Passed
Read third time. Passed. Ordered to the Senate. (Ayes 80. Noes 0. Page 1867.)
lower
May 18, 2023
Lower · Passed
From committee: Do pass. (Ayes 15. Noes 0.) (May 18).
lower
May 10, 2023
Committee
In committee: Set, first hearing. Referred to APPR. suspense file.
lower
Apr 26, 2023
Committee
Re-referred to Com. on APPR.
lower
Apr 25, 2023
Lower · Passed
Read second time and amended.
lower
Apr 24, 2023
Introduced
From committee: Amend, and do pass as amended and re-refer to Com. on APPR. with recommendation: To Consent Calendar. (Ayes 6. Noes 0.) (April 19).
lower
Apr 17, 2023
Committee
Re-referred to Com. on A. & A.R.
lower
Apr 13, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to Com. on A. & A.R. Read second time and amended.
lower
Mar 22, 2023
Lower · Passed
From committee: Do pass and re-refer to Com. on A. & A.R. with recommendation: To Consent Calendar. (Ayes 11. Noes 0.) (March 21). Re-referred to Com. on A. & A.R.
lower
Mar 15, 2023
Committee
Re-referred to Com. on P. & C.P.
lower
Mar 14, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to Com. on P. & C.P. Read second time and amended.
lower
Feb 23, 2023
Committee
Referred to Coms. on P. & C.P. and A. & A.R.
lower
Feb 14, 2023
Lower · Passed
From printer. May be heard in committee March 16.
lower
1 primary · 0 co-sponsors
Sponsors
Role
Legislator
Party
State
District
P
Jacqui Irwin
DDemocratic
Ask Maddy
·
AI policy assistant
Ask Maddy about AB 749
Scope: CA
Hi! I can help you understand AB 749. What would you like to know?
Try one of these
i
Maddy answers using official bill text and legislative records. Always verify before sharing.
Sources cited inline