Information Technology
What changed between versions
DIGIT must now review all state agency IT legislative budget requests for compliance with enterprise architecture, project planning standards, and cybersecurity, and report findings to the Governor's Office of Policy and Budget for consideration in funding decisions. This gives DIGIT a gatekeeping role over IT spending before it reaches the Governor.
A new 12-part project planning framework is required that state agencies must follow when planning IT projects, including business case development with full life cycle cost estimates, market research via request for information, stakeholder engagement, risk assessment, procurement strategy, system design, change management, monitoring and reporting, postimplementation review, and solicitation documentation.
The standard for alternative IT standards adopted by the three Cabinet departments (Legal Affairs, Financial Services, Agriculture) is expanded from requiring 'best practices and industry standards that allow for open data interoperability' to 'industry recognized best practices and industry standards that enable open data exchange, interoperability, and vendor neutral integration.'
DIGIT's quarterly high-risk project report to the Legislature now must specifically identify projects exceeding acceptable variance thresholds and include a list of all projects with uncorrected performance deficiencies reported under s. 287.057(26)(d)1., in addition to risk assessments and corrective action recommendations.
The scope of coordination between the Division of State Purchasing and DIGIT on IT solicitations is expanded from simply evaluating vendor responses and answering vendor questions to also include reviewing solicitation specifications for compliance with enterprise architecture and cybersecurity standards, evaluating vendor responses under established criteria, and providing any other technical expertise necessary.
DIGIT's training obligation is expanded from simply providing 'training opportunities to assist in the adoption of project management standards' to developing specific IT project management training that supplements existing department and CFO training, must be evaluated every 2 years for effectiveness, and must address unique requirements and risk profiles of state IT projects, procurements, contract management, and vendor management.
Two new senior positions are created within DIGIT: state chief technology officer and state chief technology procurement officer, in addition to the previously included state chief information security officer and state chief data officer.
The direction of consultation on cross-department IT projects is reversed: in the original, DIGIT was required to consult with the Cabinet departments; in the substitute, the state agency implementing the project must consult with DIGIT and work cooperatively with the affected Cabinet department.
Inspector general IT compliance reviews are broadened from evaluating 'compliance with information technology reporting requirements' to reviewing whether 'agency practices related to information technology reporting, projects, contracts, and procurements are consistent with applicable reporting requirements and standards.'
Comprehensive risk assessments may now be completed by an 'independent third party' rather than just a 'private sector vendor,' and the risk assessment methodology must be aligned with NIST Cybersecurity Framework best practices.
Two new definitions are added to s. 282.0041: 'Project oversight' (an independent review and assessment of an IT project providing information on scope, completion timeframes, budget, and identifying risks) and 'Risk assessment' (the process of identifying operational and security risks, determining their magnitude, and identifying areas needing safeguards).