Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center, which is composed of representatives from specified organizations, including the State Threat Assessment Center. Existing law requires the California Cybersecurity Integration Center to operate in close coordination with the California State Threat Assessment System and the United States Department of Homeland Security for specified information-sharing purposes. This bill would state that it is the intent of the Legislature to enact legislation that would require the State Threat Assessment Center to develop an intelligence sharing plan that respects individual's privacy and civil rights.
Existing law establishes the Instructional Quality Commission and requires the commission to, among other things, advise and recommend to the State Board of Education the policies and activities that are needed to implement the state's academic content standards. Existing law requires the commission, on or before July 31, 2019, to consider developing and recommending to the state board computer science content standards for kindergarten and grades 1 to 12, inclusive, pursuant to recommendations developed by a group of computer science experts, as specified. This bill would require the commission, when the computer science content standards are next revised after January 1, 2027, to consider incorporating cybersecurity skills, as defined, into those standards.
Existing law requires an individual or a business that conducts business in California, and that owns or licenses computerized data that includes personal information, to disclose a breach of the security of the system following discovery or notification of the breach in the security of the data to a resident of California whose unencrypted personal information was compromised, as specified, and requires that disclosure to be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as specified, or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system. This bill would require that data breach disclosure to be made within 30 calendar days of discovery or notification of the data breach but would authorize an individual or business to delay the disclosure to accommodate the legitimate needs of law enforcement, as specified, or as necessary to determine the scope of the breach and restore the reasonable integrity of the data system. Existing law also requires an individual or business that is required to issue the security breach notification described above to more than 500 California residents as a result of a single breach of the security system to electronically submit a single sample copy of that security breach notification, excluding any personally identifiable information, to the Attorney General. This bill would require that submission to the Attorney General to be made within 15 calendar days of notifying affected consumers of the security breach.
Existing law, the California Emergency Services Act, establishes the California Cybersecurity Integration Center within the Office of Emergency Services to serve as the central organizing hub of state government's cybersecurity activities and to coordinate information sharing with various entities. Existing law also requires the Technology Recovery Plan element of the State Administrative Manual to ensure the inclusion of cybersecurity strategy incident response standards for each state agency to secure its critical infrastructure controls and information, as prescribed. This bill would require, on or before July 1, 2026, an operator, defined as a state agency responsible for operating, managing, overseeing, or controlling access to critical infrastructure, that deploys a covered artificial intelligence (AI) system, as defined, to establish a human oversight mechanism that ensures a human monitors the system's operations in real time and reviews and approves any plan or action proposed by the covered AI system before execution, except as provided. The bill would require the Department of Technology to develop specialized training in AI safety protocols and risk management techniques to oversight personnel. The bill would require oversight personnel for an operator to conduct an annual assessment of its covered AI systems, as specified, and to submit a summary of the findings to the department. The bill would make findings and declarations related to its provisions. The bill would preclude disclosure of specified information by the office. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.
Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires specified state entities to implement the policies and procedures issued by the office. Existing law additionally authorizes the office to conduct, or require to be conducted, an independent security assessment of every state agency, department, or office, as specified. Existing law requires every state agency, as specified, to certify, by February 1 annually, to the office that the agency is in compliance with all adopted policies, standards, and procedures and to include a plan of action and milestones, as specified. This bill would require every state agency, as specified, and subject to specified exceptions, to implement Zero Trust architecture for all data, hardware, software, internal systems, and essential third-party software, including for on-premises, cloud, and hybrid environments, to achieve prescribed levels of maturity based on the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model, as defined, by specified dates. In implementing Zero Trust architecture, the bill would require state agencies to prioritize the use of solutions that comply with, are authorized by, or align to federal guidelines, programs, and frameworks and, at a minimum, prioritize multifactor authentication for access to all systems and data, enterprise endpoint detection and response solutions, and robust logging practices, as specified. The bill would require the office's chief to develop or revise uniform technology policies, standards, and procedures for use by all state agencies in Zero Trust architecture to achieve specified maturity levels on all systems in the State Administrative Manual and Statewide Information Management Manual. The bill would require the chief to update requirements for existing annual reporting activities to collect information relating to the progress state agencies are making to increase internal defenses of agency systems. The bill would authorize the chief to update existing annual reporting activities to include how a state agency is progressing with respect to specified goals. The bill would also state the Legislature's intent that the bill's provisions be implemented in a manner consistent with the state's timely compliance with requirements that are conditions to receipt of federal funds. The bill would also make related legislative findings and declarations.
Existing law requires the Office of Emergency Services to establish and lead the California Cybersecurity Integration Center. Existing law states that the center's mission is to reduce the likelihood and severity of cyber incidents that could damage California's economy, its critical infrastructure, or public and private sector computer networks in the state. Existing law requires the center to serve as the central organizing hub of state government's cybersecurity activities and coordinate information sharing with specified entities, including local, state, and federal agencies. This bill would require the California Cybersecurity Integration Center to develop, on or before January 1, 2027, in consultation with the Office of Information Security and the Government Operations Agency, a California AI Cybersecurity Collaboration Playbook, as specified, to facilitate information sharing across the cyber and artificial intelligence communities and to strengthen collective cyber defenses against emerging threats. The bill would require the center to review federal requirements, standards, and industry best practices, as specified, and to use those resources to inform the development of the California AI Cybersecurity Collaboration Playbook. Except as specified, the bill would provide that any information related to cyber threat indicators or defensive measures for a cybersecurity purpose shared in accordance with the California AI Cybersecurity Collaboration Playbook is confidential and would prohibit that information from being disclosed, except as specified. The bill would also make findings and declarations related to its provisions. Existing constitutional provisions require that a statute that limits the right of access to the meetings of public bodies or the writings of public officials and agencies be adopted with findings demonstrating the interest protected by the limitation and the need for protecting that interest. This bill would make legislative findings to that effect.