Bill
State Technology Governance Amendments
- Number
- H.B. 80 (2017GS)
- Sponsor
- Rep. Cutler, B. R.
- Final action
- Governor Signed 3/22/2017
- Outcome
- Became law — signed by Gov. Gary R. Herbert
Summary
This bill amends provisions related to state technology governance.
What it does
- This bill:
- eliminates divisions within the Department of Technology Services;
- assigns duties formerly assigned to divisions within the Department of Technology Services to the Department of Technology Services and the chief information officer within the Department of Technology Services;
- directs the chief information officer within the Department of Technology Services to appoint a chief information security officer; and
- defines terms.
Every vote on this bill
1/30/2017House Comm - Favorable Recommendation
House Public Utilities, Energy, and Technology Committee
10 0 1not eligible / no record2/7/2017House/ passed 3rd reading
Senate Secretary
73 0 2YEA2/15/2017Senate Comm - Favorable Recommendation
Senate Transportation, Public Utilities, Energy, and Technology Committee
5 0 2not eligible / no record2/15/2017Senate Comm - Consent Calendar Recommendation
Senate Transportation, Public Utilities, Energy, and Technology Committee
5 0 2not eligible / no record2/22/2017Senate/ passed 3rd reading
Senate President
28 0 1not eligible / no recordBill text
enrolled version · official source
STATE TECHNOLOGY GOVERNANCE AMENDMENTS GENERAL SESSION STATE OF UTAH Chief Sponsor: Bruce R. Cutler Senate Sponsor: David P. Hinkins LONG TITLE General Description: This bill amends provisions related to state technology governance. Highlighted Provisions: This bill: ▸ eliminates divisions within the Department of Technology Services; ▸ assigns duties formerly assigned to divisions within the Department of Technology Services to the Department of Technology Services and the chief information officer within the Department of Technology Services; ▸ directs the chief information officer within the Department of Technology Services to appoint a chief information security officer; and ▸ defines terms. Money Appropriated in this Bill: None Other Special Clauses: None Utah Code Sections Affected: AMENDS: 63F-1-102 , as last amended by Laws of Utah 2015, Chapter 114 63F-1-104 , as last amended by Laws of Utah 2016, Chapter 13 63F-1-106 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-202 , as last amended by Laws of Utah 2014, Chapter 387 63F-1-203 , as last amended by Laws of Utah 2016, Chapter 13 63F-1-204 , as last amended by Laws of Utah 2013, Chapter 53 63F-1-205 , as last amended by Laws of Utah 2016, Chapter 355 63F-1-206 , as last amended by Laws of Utah 2015, Chapter 114 63F-1-207 , as last amended by Laws of Utah 2008, Chapter 382 63F-1-208 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-209 , as last amended by Laws of Utah 2008, Chapter 382 63F-1-210 , as enacted by Laws of Utah 2015, Chapter 114 63F-1-404 , as last amended by Laws of Utah 2016, Chapter 13 63F-1-502 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-504 , as last amended by Laws of Utah 2016, Chapter 13 63F-1-604 , as last amended by Laws of Utah 2016, Chapter 13 ENACTS: 63F-1-211 , Utah Code Annotated 1953 63F-1-212 , Utah Code Annotated 1953 REPEALS AND REENACTS: 63F-1-401 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-403 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-501 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-503 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-601 , as enacted by Laws of Utah 2005, Chapter 169 63F-1-603 , as enacted by Laws of Utah 2005, Chapter 169 REPEALS: 63F-1-602 , as enacted by Laws of Utah 2005, Chapter 169 Be it enacted by the Legislature of the state of Utah: Section 1. Section 63F-1-102 is amended to read: 63F-1-102. Definitions. As used in this title: (1) "Board" means the Technology Advisory Board created in Section 63F-1-202 . (2) "Chief information officer" means the chief information officer appointed under Section 63F-1-201 . [ (3) "Computer center" means the location at which a central data processing platform is managed to serve multiple executive branch agencies. ] [ (4) ] (3) "Data center" means a centralized repository for the storage, management, and dissemination of data. [ (5) ] (4) "Department" means the Department of Technology Services. (5) "Enterprise architecture" means: (a) information technology that can be applied across state government; and (b) support for information technology that can be applied across state government, including: (i) technical support; (ii) master software licenses; and (iii) hardware and software standards. (6) (a) Except as provided in Subsection (6)(b), "executive branch agency" means an agency or administrative subunit of state government. (b) "Executive branch agency" does not include: (i) the legislative branch; (ii) the judicial branch; (iii) the State Board of Education; (iv) the Board of Regents; (v) institutions of higher education; (vi) independent entities as defined in Section 63E-1-102 ; and (vii) elective constitutional offices of the executive department which includes: (A) the state auditor; (B) the state treasurer; and (C) the attorney general. (7) "Executive branch strategic plan" means the executive branch strategic plan created under Section 63F-1-203 . (8) "Individual with a disability" means an individual with a condition that meets the definition of "disability" in 42 U.S.C. Sec. 12102. (9) "Information technology" means all computerized and auxiliary automated information handling, including: (a) systems design and analysis; (b) acquisition, storage, and conversion of data; (c) computer programming; (d) information storage and retrieval; (e) voice, [ radio, ] video, and data communications; (f) requisite systems controls; (g) simulation; and (h) all related interactions between people and machines. (10) "State information architecture" means a logically consistent set of principles, policies, and standards that guide the engineering of state government's information technology and infrastructure in a way that ensures alignment with state government's business and service needs. [ (11) "Telecommunications" means the transmission or reception of signs, signals, writing, images, sounds, messages, data, or other information of any nature by wire, radio, light waves, or other electromagnetic means. ] Section 2. Section 63F-1-104 is amended to read: 63F-1-104. Purposes. The department shall: (1) lead state executive branch agency efforts to establish and reengineer the state's information technology architecture with the goal of coordinating central and individual agency information technology in a manner that: (a) ensures compliance with the executive branch agency strategic plan; and (b) ensures that cost-effective, efficient information and communication systems and resources are being used by agencies to: (i) reduce data, hardware, and software redundancy; (ii) improve system interoperability and data accessibility between agencies; and (iii) meet the agency's and user's business and service needs; (2) coordinate an executive branch strategic plan for all agencies; [ (3) each year, in coordination with the governor's office, convene a group of public and private sector information technology and data security experts to identify best practices from agencies and other public and private sector entities, including best practices for data and information technology system security standards; ] [ (4) ] (3) develop and implement processes to replicate information technology best practices and standards [ identified in Subsection (3), ] throughout the executive branch; [ (5) by July 1, 2015, and ] (4) at least once every [ two years thereafter ] odd-numbered year : (a) evaluate the adequacy of the department's and the executive branch agencies' data and information technology system security standards through an independent third party assessment; and (b) communicate the results of the independent third party assessment to the appropriate executive branch agencies and to the president of the Senate and the speaker of the House of Representatives; [ (6) ] (5) oversee the expanded use and implementation of project and contract management principles as they relate to information technology projects within the executive branch; [ (7) ] (6) serve as general contractor between the state's information technology users and private sector providers of information technology products and services; [ (8) ] (7) work toward building stronger partnering relationships with providers; [ (9) ] (8) develop service level agreements with executive branch departments and agencies to ensure quality products and services are delivered on schedule and within budget; [ (10) ] (9) develop standards for application development including a standard methodology and cost-benefit analysis that all agencies shall utilize for application development activities; [ (11) ] (10) determine and implement statewide efforts to standardize data elements [ and determine data ownership assignments among executive branch agencies ]; [ (12) ] (11) develop systems and methodologies to review, evaluate, and prioritize existing information technology projects within the executive branch and report to the governor and the Public Utilities, Energy, and Technology Interim Committee on a semiannual basis regarding the status of information technology projects; and [ (13) ] (12) assist the Governor's Office of Management and Budget with the development of information technology budgets for agencies. Section 3. Section 63F-1-106 is amended to read: 63F-1-106. Executive director -- Jurisdiction over office directors -- Authority. (1) The executive director of the department : (a) has administrative jurisdiction over each [ division and ] office in the department and the [ division and office directors. The executive director ] director of each office; (b) may make changes in department personnel and each office's service functions in the divisions under the director's administrative jurisdiction[ , ] ; and (c) may authorize [ designees ] a designee to perform appropriate responsibilities[ , to effectuate greater efficiency and economy in the operations of the department as permitted by this section. ] . (2) The executive director may , to facilitate department management, establish offices and bureaus to perform functions such as budgeting, planning, and personnel administration [ to facilitate management of the department. ] . (3) (a) The executive director may hire employees in the department, divisions, and offices as permitted by department resources. (b) Except as provided in Subsection (4), [ any employees ] each employee of the department [ are ] is exempt from career service or classified service status as provided in Section 67-19-15 . (4) (a) An employee of an executive branch agency who was a career service employee as of July 1, 2005 who is transferred to the Department of Technology Services continues in the employee's career service status during the employee's service to the Department of Technology Services if the duties of the position in the new department are substantially similar to those in the employee's previous position. (b) A career service employee transferred to the new department under the provisions of Subsection (4)(a), whose duties or responsibilities subsequently change, may not be converted to exempt status without the review process required by Subsection 67-19-15 (3). [ (c) The executive director shall work with executive branch agency directors, during the period of transition to the new department, in good faith, to: ] [ (i) preserve relevant career service positions; ] [ (ii) retain qualified employees in non-relevant positions through transfers to other positions in state government, with retraining as necessary; and ] [ (iii) promote greater economy and efficiencies for the department. ] [ (d) The Department of Technology Services together with the Department of Human Resource Management may develop financial and other incentives to encourage a career service employee who transfers to the department under the provisions of Subsection (4)(a) to voluntarily convert to an exempt position under Section 67-19-15 . ] [ (e) If a career service employee transfers to the department under the provisions of Subsection (4)(a) and terminates his employment with the department for any reason, the employment position shall be exempt from career service status under the provisions of Subsection (3). ] Section 4. Section 63F-1-202 is amended to read: 63F-1-202. Technology Advisory Board -- Membership -- Duties. (1) There is created the Technology Advisory Board to the chief information officer. The board shall have seven members as follows: (a) three members appointed by the governor who are individuals actively involved in business planning for state agencies; (b) one member appointed by the governor who is actively involved in business planning for higher education or public education; (c) one member appointed by the speaker of the House of Representatives and president of the Senate [ from the Legislative Automation Committee of the Legislature to represent the legislative branch ]; (d) one member appointed by the Judicial Council [ to represent the judicial branch ]; and (e) one member appointed by the governor who represents private sector business needs in the state, but who is not an information technology vendor for the state. (2) (a) The members of the advisory board shall elect a chair from the board by majority vote. (b) The department shall provide staff to the board. (c) (i) A majority of the members of the board constitutes a quorum. (ii) Action by a majority of a quorum of the board constitutes an action of the board. (3) The board shall meet as necessary to advise the chief information officer and assist the chief information officer and executive branch agencies in coming to consensus on: (a) the development and implementation of the state's information technology strategic plan; (b) critical information technology initiatives for the state; (c) the development of standards for state information architecture; (d) identification of the business and technical needs of state agencies; (e) the department's performance measures for service agreements with executive branch agencies and subscribers of services, including a process in which an executive branch agency may review the department's implementation of and compliance with an executive branch agency's data security requirements; and (f) the efficient and effective operation of the department. (4) (a) A member who is not a legislator may not receive compensation or benefits for the member's service, but may receive per diem and travel expenses as allowed in: (i) Section 63A-3-106 ; (ii) Section 63A-3-107 ; and (iii) rules made by the Division of Finance [ according to ] in accordance with Sections 63A-3-106 and 63A-3-107 . (b) Compensation and expenses of a member who is a legislator are governed by Section 36-2-2 and Legislative Joint Rules, Title 5, Legislative Compensation and Expenses. Section 5. Section 63F-1-203 is amended to read: 63F-1-203. Executive branch information technology strategic plan. (1) In accordance with this section, the chief information officer shall prepare an executive branch information technology strategic plan: (a) that complies with this chapter; and (b) [ which shall include ] that includes : (i) a strategic plan for the: (A) interchange of information related to information technology between executive branch agencies; (B) coordination between executive branch agencies in the development and maintenance of information technology and information systems, including the coordination of agency information technology plans described in Section 63F-1-204 ; and (C) protection of the privacy of individuals who use state information technology or information systems, including the implementation of industry best practices for data and system security [ that are identified in Subsection 63F-1-104 (3) ]; (ii) priorities for the development and implementation of information technology or information systems including priorities determined on the basis of: (A) the importance of the information technology or information system; and (B) the time sequencing of the information technology or information system; and (iii) maximizing the use of existing state information technology resources. (2) In the development of the executive branch strategic plan, the chief information officer shall consult with: (a) all cabinet level officials; and (b) the advisory board created in Section 63F-1-202[ ; and (c) the group convened in accordance with Subsection 63F-1-104 (3) ]. (3) (a) Unless withdrawn by the chief information officer or the governor in accordance with Subsection (3)(b), the executive branch strategic plan takes effect 30 days after the day on which the executive branch strategic plan is submitted to: (i) the governor; and (ii) the Public Utilities, Energy, and Technology Interim Committee. (b) The chief information officer or the governor may withdraw the executive branch strategic plan submitted under Subsection (3)(a) if the governor or chief information officer determines that the executive branch strategic plan: (i) should be modified; or (ii) for any other reason should not take effect. (c) The Public Utilities, Energy, and Technology Interim Committee may make recommendations to the governor and to the chief information officer if the commission determines that the executive branch strategic plan should be modified or for any other reason should not take effect. (d) Modifications adopted by the chief information officer shall be resubmitted to the governor and the Public Utilities, Energy, and Technology Interim Committee for their review or approval as provided in Subsections (3)(a) and (b). (4) (a) The chief information officer shall, on or before January 1, 2014, and each year thereafter, modify the executive branch information technology strategic plan to incorporate security standards that: (i) are identified as industry best practices in accordance with Subsections 63F-1-104 (3) and (4); and (ii) can be implemented within the budget of the department or the executive branch agencies. (b) The chief information officer shall inform the speaker of the House of Representatives and the president of the Senate on or before January 1 of each year if best practices identified in Subsection (4)(a)(i) are not adopted due to budget issues considered under Subsection (4)(a)(ii). (5) [ The ] Each executive branch agency shall implement the executive branch strategic plan [ is to be implemented by executive branch agencies through each executive branch agency ] by adopting an agency information technology plan in accordance with Section 63F-1-204 . Section 6. Section 63F-1-204 is amended to read: 63F-1-204. Agency information technology plans. (1) (a) By July 1 of each year, each executive branch agency shall submit an agency information technology plan to the chief information officer at the department level, unless the governor or the chief information officer request an information technology plan be submitted by a subunit of a department, or by an executive branch agency other than a department. (b) The information technology plans required by this section shall be in the form and level of detail required by the chief information officer, by administrative rule adopted in accordance with Section 63F-1-206 , and shall include, at least: (i) the information technology objectives of the agency; (ii) any performance measures used by the agency for implementing the agency's information technology objectives; (iii) any planned expenditures related to information technology; (iv) the agency's need for appropriations for information technology; (v) how the agency's development of information technology coordinates with other state and local governmental entities; (vi) any efforts the agency has taken to develop public and private partnerships to accomplish the information technology objectives of the agency; (vii) the efforts the executive branch agency has taken to conduct transactions electronically in compliance with Section 46-4-503 ; and (viii) the executive branch agency's plan for the timing and method of verifying the department's security standards, if an agency intends to verify the department's security standards for the data that the agency maintains or transmits through the department's servers. (2) (a) Except as provided in Subsection (2)(b), an agency information technology plan described in Subsection (1) shall comply with the executive branch strategic plan established in accordance with Section 63F-1-203 . (b) If the executive branch agency submitting the agency information technology plan justifies the need to depart from the executive branch strategic plan, an agency information technology plan may depart from the executive branch strategic plan to the extent approved by the chief information officer. [ (3) (a) On receipt of a state agency information technology plan, the chief information officer shall forward a complete copy of the agency information technology plan to the Division of Enterprise Technology created in Section 63F-1-401 and the Division of Integrated Technology created in Section 63F-1-501 . ] [ (b) The divisions shall provide the chief information officer a written analysis of each agency plan submitted in accordance with Subsections 63F-1-404 (14) and 63F-1-504 (3). ] [ (4) (a) ] (3) The chief information officer shall review each agency plan to determine: [ (i) (A) ] (a) (i) whether the agency plan complies with the executive branch strategic plan and state information architecture; or [ (B) ] (ii) to the extent that the agency plan does not comply with the executive branch strategic plan or state information architecture, whether the executive branch entity is justified in departing from the executive branch strategic plan, or state information architecture; and [ (ii) ] (b) whether the agency plan meets the information technology and other needs of: [ (A) ] (i) the executive branch agency submitting the plan; and [ (B) ] (ii) the state. [ (b) In conducting the review required by Subsection (4)(a), the chief information officer shall consider the analysis submitted by the divisions under Subsection (3). ] [ (5) ] (4) After the chief information officer conducts the review described in Subsection [ (4) ] (3) of an agency information technology plan, the chief information officer may: (a) approve the agency information technology plan; (b) disapprove the agency information technology plan; or (c) recommend modifications to the agency information technology plan. [ (6) ] (5) An executive branch agency or the department may not submit a request for appropriation related to information technology or an information technology system to the governor in accordance with Section 63J-1-201 until after the executive branch agency's information technology plan is approved by the chief information officer. Section 7. Section 63F-1-205 is amended to read: 63F-1-205. Approval of acquisitions of information technology. (1) (a) Except as provided in Title 63N, Chapter 13, Part 2, Government Procurement Private Proposal Program, in accordance with Subsection (2), the chief information officer shall approve the acquisition by an executive branch agency of: (i) information technology equipment; (ii) telecommunications equipment; (iii) software; (iv) services related to the items listed in Subsections (1)(a)(i) through (iii); and (v) data acquisition. (b) The chief information officer may negotiate the purchase, lease, or rental of private or public information technology or telecommunication services or facilities in accordance with this section. (c) Where practical, efficient, and economically beneficial, the chief information officer shall use existing private and public information technology or telecommunication resources. (d) Notwithstanding another provision of this section, an acquisition authorized by this section shall comply with rules made by the applicable rulemaking authority under Title 63G, Chapter 6a, Utah Procurement Code. (2) Before negotiating a purchase, lease, or rental under Subsection (1) for an amount that exceeds the value established by the chief information officer by rule in accordance with Section 63F-1-206 , the chief information officer shall: (a) conduct an analysis of the needs of executive branch agencies and subscribers of services and the ability of the proposed information technology or telecommunications services or supplies to meet those needs; and (b) for purchases, leases, or rentals not covered by an existing statewide contract, certify in writing to the chief procurement officer in the Division of Purchasing and General Services that: (i) the analysis required in Subsection (2)(a) was completed; and (ii) based on the analysis, the proposed purchase, lease, rental, or master contract of services, products, or supplies is practical, efficient, and economically beneficial to the state and the executive branch agency or subscriber of services. (3) In approving an acquisition described in Subsections (1) and (2), the chief information officer shall: (a) establish by administrative rule, in accordance with Section 63F-1-206 , standards under which an agency must obtain approval from the chief information officer before acquiring the items listed in Subsections (1) and (2); (b) for those acquisitions requiring approval, determine whether the acquisition is in compliance with: (i) the executive branch strategic plan; (ii) the applicable agency information technology plan; (iii) the budget for the executive branch agency or department as adopted by the Legislature; (iv) Title 63G, Chapter 6a, Utah Procurement Code; and (v) the information technology accessibility standards described in Section 63F-1-210 ; and (c) in accordance with Section 63F-1-207 , require coordination of acquisitions between two or more executive branch agencies if it is in the best interests of the state. (4) [ (a) ] Each executive branch agency shall provide the chief information officer with complete access to all information technology records, documents, and reports: [ (i) ] (a) at the request of the chief information officer; and [ (ii) ] (b) related to the executive branch agency's acquisition of any item listed in Subsection (1). [ (b) Beginning July 1, 2006 and in ] (5) (a) In accordance with administrative rules established by the department under Section 63F-1-206 , [ no new technology projects may be initiated by an executive branch agency or the department ] an executive branch agency and the department may not initiate a new technology project unless the technology project is described in a formal project plan and [ the ] a business case analysis [ has been ] is approved by the chief information officer and [ agency head ] the highest ranking executive branch agency official . (b) The project plan and business case analysis required by this Subsection [ (4) ] (5) shall [ be in the form required by the chief information officer, and shall ] include: (i) a statement of work to be done and existing work to be modified or displaced; (ii) total cost of system development and conversion effort, including system analysis and programming costs, establishment of master files, testing, documentation, special equipment cost and all other costs, including overhead; (iii) savings or added operating costs that will result after conversion; (iv) other advantages or reasons that justify the work; (v) source of funding of the work, including ongoing costs; (vi) consistency with budget submissions and planning components of budgets; and (vii) whether the work is within the scope of projects or initiatives envisioned when the current fiscal year budget was approved. (c) The chief information officer shall determine the required form of the project plan and business case analysis described in this Subsection (5). [ (5) ] (6) The chief information officer and the Division of Purchasing and General Services within the Department of Administrative Services shall work cooperatively to establish procedures under which the chief information officer shall monitor and approve acquisitions as provided in this section. Section 8. Section 63F-1-206 is amended to read: 63F-1-206. Rulemaking -- Policies. (1) (a) Except as provided in Subsection (2), the chief information officer shall, by rule made in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act[ , the chief information officer shall make rules that ]: (i) provide standards that impose requirements on executive branch agencies that: (A) are related to the security of the statewide area network; and (B) establish standards for when an agency must obtain approval before obtaining items listed in Subsection 63F-1-205 (1); (ii) specify the detail and format required in an agency information technology plan submitted in accordance with Section 63F-1-204 ; (iii) provide for standards related to the privacy policies of websites operated by or on behalf of an executive branch agency; (iv) provide for the acquisition, licensing, and sale of computer software; (v) specify the requirements for the project plan and business case analysis required by Section 63F-1-205 ; (vi) provide for project oversight of agency technology projects when required by Section 63F-1-205 ; (vii) establish, in accordance with Subsection 63F-1-205 (2), the implementation of the needs assessment for information technology purchases; (viii) establish telecommunications standards and specifications in accordance with Section 63F-1-404 ; and (ix) establish standards for accessibility of information technology by individuals with disabilities in accordance with Section 63F-1-210 . (b) The rulemaking authority [ in ] granted by this Subsection (1) is in addition to any other rulemaking authority granted by this title. (2) (a) Notwithstanding Title 63G, Chapter 3, Utah Administrative Rulemaking Act, and subject to Subsection (2)(b), the chief information officer may adopt a policy that outlines procedures to be followed by the chief information officer in facilitating the implementation of this title by executive branch agencies if the policy: (i) is consistent with the executive branch strategic plan; and (ii) is not required to be made by rule under Subsection (1) or Section 63G-3-201 . (b) (i) A policy adopted by the chief information officer under Subsection (2)(a) may not take effect until 30 days after the day on which the chief information officer submits the policy to: (A) the governor; and (B) all cabinet level officials. (ii) During the 30-day period described in Subsection (2)(b)(i), cabinet level officials may review and comment on a policy submitted under Subsection (2)(b)(i). (3) (a) Notwithstanding Subsection (1) or (2) or Title 63G, Chapter 3, Utah Administrative Rulemaking Act, without following the procedures of Subsection (1) or (2), the chief information officer may adopt a security procedure to be followed by executive branch agencies to protect the statewide area network if: (i) broad communication of the security procedure would create a significant potential for increasing the vulnerability of the statewide area network to breach or attack; and (ii) after consultation with the chief information officer, the governor agrees that broad communication of the security procedure would create a significant potential increase in the vulnerability of the statewide area network to breach or attack. (b) A security procedure described in Subsection (3)(a) is classified as a protected record under Title 63G, Chapter 2, Government Records Access and Management Act. (c) The chief information officer shall provide a copy of the security procedure as a protected record to: (i) the chief justice of the Utah Supreme Court for the judicial branch; (ii) the speaker of the House of Representatives and the president of the Senate for the legislative branch; (iii) the chair of the Board of Regents; and (iv) the chair of the State Board of Education. Section 9. Section 63F-1-207 is amended to read: 63F-1-207. Coordination within the executive branch -- Cooperation with other branches. (1) In accordance with the executive branch strategic plan and the requirements of this title, the chief information officer shall coordinate the development of information technology systems between two or more executive branch agencies subject to: (a) the budget approved by the Legislature; and (b) Title 63J, Chapter 1, Budgetary Procedures Act. (2) In addition to the coordination described in Subsection (1), the chief information officer shall promote cooperation regarding information technology [ in a manner consistent with the interbranch coordination plan created in accordance with Section 63F-1-201 . ] between branches of state government. Section 10. Section 63F-1-208 is amended to read: 63F-1-208. Delegation of department functions. (1) (a) If the conditions of Subsections (1)(b) and (2) are met and subject to the other provisions of this section, the chief information officer may delegate a function of the department to another executive branch agency or an institution of higher education by contract or other means authorized by law. (b) The chief information officer may delegate a function of the department as provided in Subsection (1)(a) if in the judgment of the director of the executive branch agency[ , the director of the division, ] and the chief information officer: (i) the executive branch agency or institution of higher education has requested that the function be delegated; (ii) the executive branch agency or institution of higher education has the necessary resources and skills to perform or control the function to be delegated; and (iii) the function to be delegated is a unique or [ mission critical ] mission-critical function of the agency or institution of higher education [ which is not appropriate to: (A) govern or manage under the Division of Enterprise Technology; or (B) govern or manage under the Division of Integrated Technology. ] . (2) The chief information officer may delegate a function of the department only when the delegation results in net cost savings or improved service delivery to the state as a whole or to the unique mission critical function of the executive branch agency. (3) The delegation of a function under this section shall: (a) be in writing; (b) contain all of the following: (i) a precise definition of each function to be delegated; (ii) a clear description of the standards to be met in performing each function delegated; (iii) a provision for periodic administrative audits by the [ Division of Agency Services in accordance with Section 63F-1-604 ] department ; (iv) a date on which the agreement shall terminate if the agreement has not been previously terminated or renewed; and (v) any delegation of department staff to the agency to support the function in-house with the agency and rates to be charged for the delegated staff; and (c) include a cost-benefit analysis justifying the delegation [ in accordance with Section 63F-1-604 ]. (4) An agreement to delegate functions to an executive branch agency or an institution of higher education may be terminated by the department if the results of an administrative audit conducted by the [ division ] department reveals a lack of compliance with the terms of the agreement by the executive branch agency or institution of higher education. Section 11. Section 63F-1-209 is amended to read: 63F-1-209. Delegation of department staff to executive branch agencies -- Prohibition against executive branch agency information technology staff. (1) (a) The chief information officer shall assign department staff to serve an agency in-house if the chief information officer and the executive branch agency director jointly determine it is appropriate to provide information technology services to: (i) the agency's unique [ mission critical ] mission-critical functions and applications; (ii) the agency's participation in and use of statewide enterprise architecture [ under the Division of Enterprise Technology ]; and (iii) the agency's use of coordinated technology services with other agencies that share similar characteristics with the agency [ under the Division of Integrated Technology ]. (b) (i) An agency may request the chief information officer to assign in-house staff support from the department. (ii) The chief information officer shall respond to the agency's request for in-house staff support in accordance with Subsection (1)(a). (c) The department shall enter into service agreements with an agency when department staff is assigned in-house to the agency under the provisions of this section. (d) An agency that receives in-house staff support assigned from the department under the provision of this section is responsible for paying the rates charged by the department for that staff as established under Section 63F-1-301 . (2) (a) [ After July 1, 2006, an ] An executive branch agency may not create a full-time equivalent position or part-time position, or request an appropriation to fund a full-time equivalent position or part-time position under the provisions of Section 63J-1-201 for the purpose of providing information technology services to the agency unless: (i) the chief information officer has approved a delegation under Section 63F-1-208 ; and (ii) the [ Division of Agency Services ] department conducts an audit under Section 63F-1-604 and finds that the delegation of information technology services to the agency meets the requirements of Section 63F-1-208 . (b) The prohibition against a request for appropriation under Subsection (2)(a) does not apply to a request for appropriation needed to pay rates imposed under Subsection (1)(d). Section 12. Section 63F-1-210 is amended to read: 63F-1-210. Accessibility standards for executive branch agency information technology. (1) The chief information officer shall establish, by rule made in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act: (a) minimum standards for accessibility of executive branch agency information technology by an individual with a disability that: (i) include accessibility criteria for: (A) agency websites; (B) hardware and software procured by an executive branch agency; and (C) information systems used by executive branch agency employees; [ and ] (ii) include a protocol to evaluate the standards via testing by individuals with a variety of access limitations; and (iii) are, at minimum, consistent with the most recent Web Content Accessibility guidelines published by the World Wide Web Consortium; and (b) grievance procedures for an individual with a disability who is unable to access executive branch agency information technology, including: (i) a process for an individual with a disability to report the access issue to the chief information officer; and (ii) a mechanism through which the chief information officer can respond to the report[ ; and (c) are, at minimum, consistent with the Web Content Accessibility 2.0 guidelines published by the World Wide Web Consortium. ] . (2) The chief information officer shall update the standards described in Subsection (1)(a) at least every three years to reflect advances in technology. Section 13. Section 63F-1-211 is enacted to read: 63F-1-211. Chief information security officer. (1) The chief information officer shall appoint a chief information security officer. (2) The chief information security officer described in Subsection (1) shall: (a) assess cybersecurity risks; (b) coordinate with executive branch agencies to assess the sensitivity of information; and (c) manage cybersecurity support for the department and executive branch agencies. Section 14. Section 63F-1-212 is enacted to read: 63F-1-212. Report to the Legislature. The department shall, before November 1 of each year, report to the Public Utilities, Energy, and Technology Interim Committee on: (1) performance measures that the department uses to assess the department's effectiveness in performing the department's duties under this chapter; and (2) the department's performance, evaluated in accordance with the performance measures described in Subsection (1). Section 15. Section 63F-1-401 is repealed and reenacted to read: Part 4. Enterprise Technology 63F-1-401. Title. This part is known as "Enterprise Technology." Section 16. Section 63F-1-403 is repealed and reenacted to read: 63F-1-403. Enterprise technology -- Chief information officer manages. The chief information officer shall manage the department's duties related to enterprise technology. Section 17. Section 63F-1-404 is amended to read: 63F-1-404. Duties of the department -- Enterprise technology. The [ division ] department shall: (1) develop and implement an effective enterprise architecture governance model for the executive branch; (2) provide oversight of information technology projects that impact statewide information technology services, assets, or functions of state government to: (a) control costs; (b) ensure business value to a project; (c) maximize resources; (d) ensure the uniform application of best practices; and (e) avoid duplication of resources; (3) develop a method of accountability to agencies for services provided by the [ division ] department through service agreements with the agencies; [ (4) beginning September 1, 2006, and each September 1 thereafter, provide the chief information officer and the Public Utilities, Energy, and Technology Interim Committee with performance measures used by the division to measure the quality of service delivered by the division and the results of the performance measures; ] [ (5) ] (4) serve as a project manager for enterprise architecture which includes the management of applications, standards, and procurement of enterprise architecture; [ (6) ] (5) coordinate the development and implementation of advanced state telecommunication systems; [ (7) ] (6) provide services including technical assistance: (a) to executive branch agencies and subscribers to the services; and (b) related to information technology or telecommunications; [ (8) ] (7) establish telecommunication system specifications and standards for use by: (a) one or more executive branch agencies; or (b) one or more entities that subscribe to the telecommunication systems in accordance with Section 63F-1-303 ; [ (9) ] (8) coordinate state telecommunication planning in cooperation with: (a) state telecommunication users; (b) executive branch agencies; and (c) other subscribers to the state's telecommunication systems; [ (10) ] (9) cooperate with the federal government, other state entities, counties, and municipalities in the development, implementation, and maintenance of: (a) (i) governmental information technology; or (ii) governmental telecommunication systems; and (b) (i) as part of a cooperative organization; or (ii) through means other than a cooperative organization; [ (11) ] (10) establish, operate, manage, and maintain: (a) one or more state data centers; and (b) one or more regional computer centers; [ (12) ] (11) design, implement, and manage all state-owned, leased, or rented land, mobile, or radio telecommunication systems that are used in the delivery of services for state government or its political subdivisions; and [ (13) ] (12) in accordance with the executive branch strategic plan, implement minimum standards to be used by the [ division ] department for purposes of compatibility of procedures, programming languages, codes, and media that facilitate the exchange of information within and among telecommunication systems[ ; and ] . [ (14) provide the chief information officer with an analysis of an executive branch agency information technology plan that includes: ] [ (a) an assessment of how the implementation of the agency information technology plan will affect the costs, operations, and services of: ] [ (i) the department; and ] [ (ii) other executive branch agencies; and ] [ (b) any recommended changes to the plan. ] Section 18. Section 63F-1-501 is repealed and reenacted to read: Part 5. Integrated Technology 63F-1-501. Title. This part is known as "Integrated Technology." Section 19. Section 63F-1-502 is amended to read: 63F-1-502. Definitions. As used in this part: (1) "Center" means the Automated Geographic Reference Center created in Section 63F-1-506 . (2) "Database" means the State Geographic Information Database created in Section 63F-1-507 . [ (3) "Director" means the director appointed in accordance with Section 63F-1-503 . ] [ (4) "Division" means the Division of Integrated Technology created in this part. ] [ (5) ] (3) "Geographic Information System" or "GIS" means a computer driven data integration and map production system that interrelates disparate layers of data to specific geographic locations. [ (6) ] (4) "State Geographic Information Database" means the database created in Section 63F-1-507 . [ (7) ] (5) "Statewide Global Positioning Reference Network" or "network" means the network created in Section 63F-1-509 . Section 20. Section 63F-1-503 is repealed and reenacted to read: 63F-1-503. Integrated technology -- Chief information officer manages. The chief information officer shall manage the department's duties related to integrated technology. Section 21. Section 63F-1-504 is amended to read: 63F-1-504. Duties of the department -- Integrated technology. The [ division ] department shall: (1) establish standards for the information technology needs of a collection of executive branch agencies or programs that share common characteristics relative to the types of stakeholders they serve, including: (a) project management; (b) application development; and (c) procurement; (2) provide oversight of information technology standards that impact multiple executive branch agency information technology services, assets, or functions to: (a) control costs; (b) ensure business value to a project; (c) maximize resources; (d) ensure the uniform application of best practices; and (e) avoid duplication of resources; and [ (3) in accordance with Section 63F-1-204 , provide the chief information officer a written analysis of any agency information technology plan provided to the division, which shall include: ] [ (a) a review of whether the agency's technology projects impact multiple agencies and if so, whether the information technology projects are appropriately designed and developed; ] [ (b) an assessment of whether the agency plan complies with the state information architecture; and ] [ (c) an assessment of whether the information technology projects included in the agency plan comply with policies, procedures, and rules adopted by the department to ensure that: ] [ (i) information technology projects are phased in; ] [ (ii) funding is released in phases; ] [ (iii) an agency's authority to proceed to the next phase of an information technology project is contingent upon the successful completion of the prior phase; and ] [ (iv) one or more specific deliverables is identified for each phase of a technology project; ] [ (4) ] (3) establish a system of accountability to user agencies through the use of service agreements[ ; ] . [ (5) each year, provide the chief information officer and the Public Utilities, Energy, and Technology Interim Committee with performance measures used by the division to measure the quality of services delivered by the division and results of those measures; and ] [ (6) establish administrative rules in accordance with Section 63F-1-206 and as required by Section 63F-1-506 . ] Section 22. Section 63F-1-601 is repealed and reenacted to read: Part 6. Agency Services 63F-1-601. Title. This part is known as "Agency Services." Section 23. Section 63F-1-603 is repealed and reenacted to read: 63F-1-603. Agency services -- Chief information officer manages. The chief information officer shall manage the department's duties related to agency services. Section 24. Section 63F-1-604 is amended to read: 63F-1-604. Duties of the department -- Agency services. The [ division ] department shall: (1) be responsible for providing support to executive branch agencies for an agency's information technology assets and functions that are unique to the executive branch agency and are mission critical functions of the agency; [ (2) conduct audits of an executive branch agency when requested under the provisions of Section 63F-1-208 ; ] [ (3) conduct cost-benefit analysis of delegating a department function to an agency in accordance with Section 63F-1-208 ; ] [ (4) ] (2) provide in-house information technology staff support to executive branch agencies; [ (5) establish accountability and performance measures for the division to assure that the division is: ] [ (a) meeting the business and service needs of the state and individual executive branch agencies; and ] [ (b) implementing security standards in accordance with Subsection 63F-1-203 (4); ] [ (6) ] (3) establish a committee composed of agency user groups for the purpose of coordinating department services with agency needs; and [ (7) ] (4) assist executive branch agencies in complying with the requirements of any rule adopted by the chief information officer[ ; and (8) by July 1, 2013, and each July 1 thereafter, report to the Public Utilities, Energy, and Technology Interim Committee on the performance measures used by the division under Subsection (5) and the results. ] . Section 25. Repealer. This bill repeals: Section 63F-1-602 , Definitions.