Texas
HB150
HB150 - Relating to the establishment of the Texas Cyber Command and the transfer to it of certain powers and duties of the Department of Information Resources.
Source: Congress.gov ·
15,369 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
      H.B. No. 150         AN ACT   relating to the establishment of the Texas Cyber Command and the   transfer to it of certain powers and duties of the Department of   Information Resources.          BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF TEXAS:          SECTION 1.  Subtitle B, Title 10, Government Code, is   amended by adding Chapter 2063 to read as follows:   CHAPTER 2063. TEXAS CYBER COMMAND   SUBCHAPTER A. GENERAL PROVISIONS           Sec. 2063.001.  DEFINITIONS. In this chapter:                 (1)     "Chief" means the chief of the Texas Cyber   Command.                 (2)     "Command" means the Texas Cyber Command   established under this chapter.                 (3)     "Covered entity" means a private entity operating   critical infrastructure or a local government that the command   contracts with in order to provide cybersecurity services under   this chapter.                 (4)     "Critical infrastructure" means infrastructure in   this state vital to the security, governance, public health and   safety, economy, or morale of the state or the nation, including:                       (A)  chemical facilities;                       (B)  commercial facilities;                       (C)  communication facilities;                       (D)  manufacturing facilities;                       (E)  dams;                       (F)  defense industrial bases;                       (G)  emergency services systems;                       (H)  energy facilities;                       (I)  financial services systems;                       (J)  food and agriculture facilities;                       (K)  government facilities;                       (L)  health care and public health facilities;                       (M)     information technology and information   technology systems;                       (N)  nuclear reactors, materials, and waste;                       (O)  transportation systems; or                       (P)  water and wastewater systems.                 (5)     "Cybersecurity" means the measures taken for a   computer, computer network, computer system, or other technology   infrastructure to protect against, respond to, and recover from   unauthorized:                       (A)     use, access, disruption, modification, or   destruction; or                       (B)     disclosure, modification, or destruction of   information.                 (6)  "Cybersecurity incident" includes:                       (A)     a breach or suspected breach of system   security as defined by Section 521.053, Business & Commerce Code;                       (B)     the introduction of ransomware, as defined by   Section 33.023, Penal Code, into a computer, computer network, or   computer system; or                       (C)     any other cybersecurity-related occurrence   that jeopardizes information or an information system designated by   command policy adopted under this chapter.                 (7)     "Department" means the Department of Information   Resources.                 (8)     "Governmental entity" means a state agency or a   local government.                 (9)     "Information resources" has the meaning assigned   by Section 2054.003.                 (10)     "Information resources technologies" has the   meaning assigned by Section 2054.003.                 (11)     "Local government" has the meaning assigned by   Section 2054.003.                 (12)     "Sensitive personal information" has the meaning   assigned by Section 521.002, Business & Commerce Code.                 (13)  "State agency" means:                       (A)     a department, commission, board, office, or   other agency that is in the executive branch of state government and   that was created by the constitution or a statute;                       (B)     the supreme court, the court of criminal   appeals, a court of appeals, a district court, or the Texas Judicial   Council or another agency in the judicial branch of state   government; or                       (C)     a university system or an institution of   higher education as defined by Section 61.003, Education Code.           Sec.   2063.002.     ORGANIZATION. (a) The Texas Cyber Command   is a state agency.           (b)     The command is governed by a chief appointed by the   governor and confirmed with the advice and consent of the senate.     The chief serves for a two-year term expiring February 1 of each   odd-numbered year and must possess professional training and   knowledge relevant to the functions and duties of the command.           (c)     The command shall employ other coordinating and   planning officers and other personnel necessary to the performance   of its functions.           (d)     The command may enter into an interagency agreement with   another state agency for the purpose of providing:                 (1)     administrative support services to the command as   necessary to carry out the purposes of this chapter and Chapter   2059; and                 (2)     a facility to the command located in San Antonio   that has a sensitive compartmented information facility for use in   carrying out the purposes of this chapter and Chapter 2059.           Sec.   2063.003.     ESTABLISHMENT AND PURPOSE. (a) The command   is established to prevent and respond to cybersecurity incidents   that affect governmental entities and critical infrastructure in   this state.           (b)     The command is responsible for cybersecurity for this   state, including:                 (1)     providing leadership, guidance, and tools to   enhance cybersecurity defenses;                 (2)     facilitating education and training of a   cybersecurity workforce;                 (3)     monitoring and coordinating cyber threat   intelligence and information systems to detect and warn entities of   cyber attacks, identifying cyber threats to critical   infrastructure and state systems, planning and executing   cybersecurity incident responses, and conducting digital forensics   of cybersecurity incidents to support law enforcement and attribute   the incidents;                 (4)     creating partnerships needed to effectively carry   out the command's functions; and                 (5)     receiving all cybersecurity incident reports from   state agencies and covered entities.           Sec.   2063.004.     GENERAL POWERS AND DUTIES. (a) The command   shall:                 (1)  promote public awareness of cybersecurity issues;                 (2)     develop cybersecurity best practices and minimum   standards for governmental entities;                 (3)     develop and provide training to state agencies and   covered entities on cybersecurity measures and awareness;                 (4)     administer the cybersecurity threat intelligence   center under Section 2063.201;                 (5)     provide support to state agencies and covered   entities experiencing a cybersecurity incident and respond to   cybersecurity reports received under Subchapter D and other reports   as appropriate;                 (6)     administer the digital forensics laboratory under   Section 2063.203;                 (7)     administer a statewide portal for enterprise   cybersecurity threat, risk, and incident management, and operate a   cybersecurity hotline available for state agencies and covered   entities 24 hours a day, seven days a week;                 (8)     collaborate with law enforcement agencies to   provide training and support related to cybersecurity incidents;                 (9)     serve as a clearinghouse for information relating   to all aspects of protecting the cybersecurity of governmental   entities, including sharing appropriate intelligence and   information with governmental entities, federal agencies, and   covered entities;                 (10)     collaborate with the department to ensure   information resources and information resources technologies   obtained by the department meet the cybersecurity standards and   requirements established under this chapter;                 (11)     offer cybersecurity resources to state agencies   and covered entities as determined by the command;                 (12)     adopt policies to ensure state agencies implement   sufficient cybersecurity measures to defend information resources,   information resources technologies, and sensitive personal   information maintained by the agencies; and                 (13)     collaborate with federal agencies to protect   against, respond to, and recover from cybersecurity incidents.           (b)  The command may:         &
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.