Bill

Bill > A00426


NY A00426

NY A00426
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.


summary

Introduced
01/08/2025
In Committee
02/03/2025
Crossed Over
02/11/2025
Passed
02/12/2025
Dead
Signed/Enacted/Adopted
02/14/2025

Introduced Session

2025-2026 General Assembly

Bill Summary

AN ACT to amend the state finance law, in relation to procurement requirements for end point device security

AI Summary

This bill modifies New York state procurement requirements for end point devices, which are defined as personal computing goods like desktops, laptops, tablets, mobile phones, printers, and multi-functional devices. Specifically, the bill requires that when state agencies and the state commissioner purchase these devices, they must align with relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework. The bill removes previous language that required devices to "meet" specific security standards and instead mandates consistency with NIST cybersecurity guidelines. It also eliminates a previous provision that would have required agencies to update their procurement requirements within one year of any amendments to the security standards. The change appears to provide more flexibility in interpretation while still emphasizing the importance of cybersecurity standards in state technology procurement.

Committee Categories

Business and Industry

Sponsors (1)

Last Action

signed chap.12 (on 02/14/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...