Bill

Bill > SB907


MD SB907

Cybersecurity - Standards, Compliance, and Audits - Alterations


summary

Introduced
02/03/2025
In Committee
02/03/2025
Crossed Over
Passed
Dead
04/08/2025

Introduced Session

2025 Regular Session

Bill Summary

Repealing the requirement that county boards of education prioritize the purchase of digital devices with certain funds; requiring each local school system to comply with, and certify compliance with, the State minimum cybersecurity standards and to conduct a cybersecurity maturity assessment every 2 years; requiring the Office of Security Management within the Department of Information Technology to annually update the State minimum cybersecurity standards; etc.

AI Summary

This bill strengthens cybersecurity requirements for local school systems in Maryland by implementing several key provisions. Starting in 2026, each local school system will be required to comply with the State minimum cybersecurity standards (SMCS) established by the Department of Information Technology and conduct a cybersecurity maturity assessment every two years. By June 30, 2026, and every two years thereafter, school systems must certify their compliance with these standards to the Office of Security Management. The bill removes the previous requirement that county boards prioritize purchasing digital devices and instead mandates that each local school system provide sufficient cybersecurity staffing as determined by the State Chief Information Security Officer. Local school systems may share services, contractors, or regional support to meet these requirements. The Department of Information Technology will assign at least three information security officers to support local school systems in achieving compliance, conducting assessments, and implementing remediation efforts. Additionally, the Office of Legislative Audits will be guided by the State minimum cybersecurity standards when conducting various types of audits. For the 2025-2026 school year, the Department will specifically focus on the Protect (PR) Controls standard, with the entire act taking effect on July 1, 2025.

Committee Categories

Education

Sponsors (1)

Last Action

Senate Education, Energy, and the Environment Hearing (13:00:00 3/5/2025 ) (on 03/05/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...