LEGISLATION PAM GREENBERG, NCSL | NASS 2019 SUMMER CONFERENCE | JULY - - PowerPoint PPT Presentation

legislation
SMART_READER_LITE
LIVE PREVIEW

LEGISLATION PAM GREENBERG, NCSL | NASS 2019 SUMMER CONFERENCE | JULY - - PowerPoint PPT Presentation

OVERVIEW OF STATE CYBERSECURITY LAWS & LEGISLATION PAM GREENBERG, NCSL | NASS 2019 SUMMER CONFERENCE | JULY 2019 STATE CYBERSECURITY LAWS & LEGISLATION ABOUT NCSL Serves 7,383 legislators and 25,000 legislative staff. Provides


slide-1
SLIDE 1

PAM GREENBERG, NCSL | NASS 2019 SUMMER CONFERENCE | JULY 2019

OVERVIEW OF STATE CYBERSECURITY LAWS & LEGISLATION

slide-2
SLIDE 2

STATE CYBERSECURITY LAWS & LEGISLATION

ABOUT NCSL

 Serves 7,383 legislators and 25,000 legislative staff.  Provides nonpartisan research and analysis  Links legislators with each other and with experts  Speaks on behalf of state legislatures in D.C.

slide-3
SLIDE 3

STATE CYBERSECURITY LAWS & LEGISLATION

NCSL CYBERSECURITY TASK FORCE

Mission:

 Educate and engage task force members in cybersecurity policy

discussions.

 Extend networking opportunities among legislative leaders on

cybersecurity issues.

 Engage with strategic partners and extend networks to develop and

maintain security programs.

 Provide well-defined programs on key and critical cyber policy issues.

slide-4
SLIDE 4

CYBERSECURITY LAWS & LEGISLATION: AGENDA

Cybersecurity Laws & 2019 Legislation/Trends

▪ Private sector ▪ Government

Public Records Laws & Cybersecurity

▪ Current laws ▪ 2019 legislation/trends

slide-5
SLIDE 5

STATE CYBERSECURITY LAWS & LEGISLATION

DEFINITIONS

Cybersecurity: Defending against attacks to various networks, computers and data. Data security: Protecting information from unauthorized access. Privacy: Controlling who has access to personal information.

slide-6
SLIDE 6

STATE CYBERSECURITY LAWS & LEGISLATION

CYBERSECURITY/DATA SECURITY LAWS

Private sector

 Breach notification laws=50

states

 Data security laws=25 states

slide-7
SLIDE 7

STATE CYBERSECURITY LAWS AND LEGISLATION

DATA SECURITY LAWS 2016 vs. 2018

slide-8
SLIDE 8

STATE CYBERSECURITY LAWS & LEGISLATION

CYBERSECURITY/DATA SECURITY LAWS

Government

Data security laws=29 states

 Statewide authority, oversight  “Reasonable security” practices  Specific security requirements

slide-9
SLIDE 9

STATE CYBERSECURITY LAWS & LEGISLATION

CYBERSECURITY/DATA SECURITY LAWS

Data Disposal Laws

 For private sector=34 states  For government=14 states

slide-10
SLIDE 10

STATE CYBERSECURITY LAWS & LEGISLATION

2019 CYBERSECURITY LEGISLATION

slide-11
SLIDE 11

STATE CYBERSECURITY LAWS & LEGISLATION

2019 CYBERSECURITY ENACTMENTS Key cybersecurity enactments— Private sector:

 Connected devices/IoT (OR, WA)  Insurance (AL, CT, KS, MS)  Security practices/requirements

(Ø)

slide-12
SLIDE 12

STATE CYBERSECURITY LAWS & LEGISLATION

CYBERSECURITY/DATA SECURITY LEGISLATION Top 3 cybersecurity enactments—Government:

 Security requirements for

government

 Elections security  Public records exemptions for

cybersecurity

slide-13
SLIDE 13

STATE CYBERSECURITY LAWS & LEGISLATION

2019 CYBERSECURITY ENACTMENTS Cybersecurity enactments— Government:

 Centralizing cybersecurity authority

(ND, NV, VT, WV)

 Security requirements (NV, OK, WV)  Emergency preparedness (MT, NV)  Req. govt. employee training (TX)  Explore blockchain for security (FL)

slide-14
SLIDE 14

STATE CYBERSECURITY LAWS & LEGISLATION

2019 CYBERSECURITY ENACTMENTS Cybersecurity enactments— Elections:

 Security practices (IA, IN, NV, OK,

TX, VA )

slide-15
SLIDE 15

STATE CYBERSECURITY LAWS AND LEGISLATION

PUBLIC RECORDS LAWS & CYBERSECURITY

State Laws: Confidentiality of Cybersecurity Information

 Expressly refer to cyber threats,

cybersecurity systems = 23 states

 Refers only to systems or technology in the

context of anti-terrorism or homeland security threats = 5 states

 Refers to “security systems,” plans, etc.,

without specific reference to information systems or technology = 5 states

slide-16
SLIDE 16

STATE CYBERSECURITY LAWS & LEGISLATION

2019 DATA SECURITY ENACTMENTS Public Records & Cybersecurity 2019 Enactments

 Exemption of cybersecurity

information from disclosure (IN, MS, ND, NV, WV)

slide-17
SLIDE 17

STATE LEGISLATIVE UPDATE

TRENDS IN CYBERSECURITY LEGISLATION 2018

Questions?

Additional Information

Pam Greenberg, NCSL Denver Office pam.greenberg@ncsl.org

NCSL Web Resources: www.ncsl.org

 Security Breach Laws and Legislation  Cybersecurity Legislation 2016-2018  Data Security Laws – Private Sector  Data Security Laws – Government  Data Disposal Statutes  Computer Crime Statutes  Election Security: State Policies