AB 749 California Assembly · 2023-2024 Regular Session

State agencies: information security: uniform standards.

Summary
Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. The law requires state entities, as specified, to implement the policies and procedures issued by the office. The law additionally authorizes the office, under direction of the chief, to conduct, or require to be conducted, an independent security assessment of every state agency, department, or office, as specified. State agencies must certify, by February 1 annually, to the President pro Tempore of the Senate and the Speaker of the Assembly that the agency is in compliance with all adopted policies, standards, and procedures and to include a plan of action and milestones, as specified. This bill would require every state agency, as defined and subject to specified exceptions, to implement Zero Trust architecture for all data, hardware, software, internal systems, and essential third-party software, including for on-premises, cloud, and hybrid environments, to achieve prescribed levels of maturity based on the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model, as defined, by specified dates. In implementing Zero Trust architecture, the bill would require state agencies to prioritize the use of solutions that comply with, are authorized by, or align to federal guidelines, programs, and frameworks and, at a minimum, prioritize multifactor authentication for access to all systems and data, enterprise endpoint detection and response solutions, and robust logging practices, as specified. The bill would require the office's chief, no later than January 1, 2025, to develop or revise uniform technology policies, standards, and procedures for use by all state agencies in Zero Trust architecture to achieve specified maturity levels on all systems in the State Administrative Manual and Statewide Information Management Manual. The bill would require the chief to update requirements for existing annual reporting activities to collect information relating to the progress state agencies are making to increase internal defenses of agency systems. The bill would authorize the chief to update existing annual reporting activities to include how a state agency is progressing with respect to specified goals. The bill would also state the Legislature's intent that the bill's provisions be implemented in a manner consistent with the state's timely compliance with requirements that are conditions to receipt of federal funds. The bill would also make related legislative findings and declarations.
Bill status passed 3 of 5 stages cleared
Introduction
Feb 2023
Committee Review
Sep 2023
Assembly Passage
May 2023
Senate Passage
Governor
Introduced Feb 13, 2023 Last action Sep 1, 2023
Floor votes · Assembly May 30, 2023

How they voted

800
Passed
Total votes 80
May 30, 2023
D Democratic62
62 Yea
100% Yea
R Republican18
18 Yea
100% Yea
Vote distribution
All Yea All Nay Mixed No data
Full legislative history

Actions timeline

Total actions
22
Key actions
7
Committee
12
Amendments
6
Sep 1, 2023
Upper · Passed
In committee: Held under submission.
upper
Aug 21, 2023
Committee
In committee: Referred to APPR suspense file.
upper
Aug 14, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to committee. Read second time, amended, and re-referred to Com. on APPR.
upper
Jul 11, 2023
Upper · Passed
From committee: Do pass and re-refer to Com. on APPR. (Ayes 14. Noes 0.) (July 11). Re-referred to Com. on APPR.
upper
Jul 3, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to committee. Read second time, amended, and re-referred to Com. on G.O.
upper
Jun 7, 2023
Committee
Referred to Com. on G.O.
upper
May 30, 2023
Lower · Passed
Read third time. Passed. Ordered to the Senate. (Ayes 80. Noes 0. Page 1867.)
lower
May 18, 2023
Lower · Passed
From committee: Do pass. (Ayes 15. Noes 0.) (May 18).
lower
May 10, 2023
Committee
In committee: Set, first hearing. Referred to APPR. suspense file.
lower
Apr 26, 2023
Committee
Re-referred to Com. on APPR.
lower
Apr 25, 2023
Lower · Passed
Read second time and amended.
lower
Apr 24, 2023
Introduced
From committee: Amend, and do pass as amended and re-refer to Com. on APPR. with recommendation: To Consent Calendar. (Ayes 6. Noes 0.) (April 19).
lower
Apr 17, 2023
Committee
Re-referred to Com. on A. & A.R.
lower
Apr 13, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to Com. on A. & A.R. Read second time and amended.
lower
Mar 22, 2023
Lower · Passed
From committee: Do pass and re-refer to Com. on A. & A.R. with recommendation: To Consent Calendar. (Ayes 11. Noes 0.) (March 21). Re-referred to Com. on A. & A.R.
lower
Mar 15, 2023
Committee
Re-referred to Com. on P. & C.P.
lower
Mar 14, 2023
Introduced
From committee chair, with author's amendments: Amend, and re-refer to Com. on P. & C.P. Read second time and amended.
lower
Feb 23, 2023
Committee
Referred to Coms. on P. & C.P. and A. & A.R.
lower
Feb 14, 2023
Lower · Passed
From printer. May be heard in committee March 16.
lower
1 primary · 0 co-sponsors

Sponsors

Role
Legislator
Party
State
District
P
Photo of Jacqui Irwin
Jacqui Irwin
DDemocratic
CA
42