Rep. Norm Thurston — Voting Record

Utah House District 62 · complete roll-call record from le.utah.gov
← All votes

Bill

Data Security Management Council
Number
S.B. 255 First Substitute (2015GS)
Sponsor
Sen. Harper, W.
Final action
Governor Signed 3/30/2015
Outcome
Became law — signed by Gov. Gary R. Herbert

Summary

This bill creates a Data Security Management Council to develop recommendations for data security and risk assessment.

What it does

  • This bill:
  • creates the Data Security Management Council; and
  • directs the council to study statewide data security issues and develop best practice recommendations.

Every vote on this bill

3/4/2015Senate/ passed 3rd reading
Clerk of the House
24 0 5not eligible / no record
3/11/2015House/ passed 3rd reading
Senate Secretary
70 0 5YEA
3/11/2015Senate/ concurs with House amendment
House Speaker
24 0 5not eligible / no record

Bill text

enrolled version · official source
DATA SECURITY MANAGEMENT COUNCIL
GENERAL SESSION
STATE OF UTAH
Chief Sponsor: Wayne A. Harper
House Sponsor: 
Sophia M. DiCaro
LONG TITLE
General Description:
This bill creates a Data Security Management Council to develop recommendations for
data security and risk assessment.
Highlighted Provisions:
This bill:
▸ creates the Data Security Management Council; and
▸ directs the council to study statewide data security issues and develop best practice
recommendations.
Money Appropriated in this Bill:
None
Other Special Clauses:
None
Utah Code Sections Affected:
ENACTS:
63F-2-101
, Utah Code Annotated 1953
63F-2-102
, Utah Code Annotated 1953
63F-2-103
, Utah Code Annotated 1953
Be it enacted by the Legislature of the state of Utah:
Section 1. Section 
63F-2-101
 is enacted to read:
CHAPTER 2. DATA SECURITY MANAGEMENT COUNCIL
 63F-2-101.
Title.
This chapter is known as "Data Security Management Council."
Section 2. Section 
63F-2-102
 is enacted to read:
 63F-2-102.
Data Security Management Council -- Membership -- Duties.
(1) There is created the Data Security Management Council composed of nine
members as follows:
(a) the chief information officer appointed under Section 
63F-1-201
, or the chief
information officer's designee;
(b) one individual appointed by the governor;
(c) one individual appointed by the speaker of the House of Representatives and the
president of the Senate from the Legislative Information Technology Steering Committee; and
(d) the highest ranking information technology official, or the highest ranking
information technology official's designee, from each of:
(i) the Judicial Council;
(ii) the State Board of Regents;
(iii) the State Office of Education;
(iv) the Utah College of Applied Technology;
(v) the State Tax Commission; and
(vi) the Office of the Attorney General.
(2) The council shall elect a chair of the council by majority vote.
(3) (a) A majority of the members of the council constitutes a quorum.
(b) Action by a majority of a quorum of the council constitutes an action of the council.
(4) The Department of Technology Services shall provide staff to the council.
(5) The council shall meet monthly, or as often as necessary, to:
(a) review existing state government data security policies;
(b) assess ongoing risks to state government information technology;
(c) create a method to notify state and local government entities of new risks;
(d) coordinate data breach simulation exercises with state and local government
entities; and
(e) develop data security best practice recommendations for state government that
include recommendations regarding:
(i) hiring and training a chief information security officer for each government entity;
(ii) continuous risk monitoring;
(iii) password management;
(iv) using the latest technology to identify and respond to vulnerabilities;
(v) protecting data in new and old systems; and
(vi) best procurement practices.
(6) A member who is not a member of the Legislature may not receive compensation
or benefits for the member's service but may receive per diem and travel expenses as provided
in:
(a) Section 
63A-3-106
;
(b) Section 
63A-3-107
; and
(c) rules made by the Division of Finance under Sections 
63A-3-106
 and 
63A-3-107
.
Section 3. Section 
63F-2-103
 is enacted to read:
 63F-2-103.
Data Security Management Council -- Report to Legislature --
Recommendations.
(1) The council chair or the council chair's designee shall report annually no later than
October 1 of each year to the Public Utilities and Technology Interim Committee.
(2) The council's annual report shall contain:
(a) a summary of topics the council studied during the year;
(b) best practice recommendations for state government; and
(c) recommendations for implementing the council's best practice recommendations.