Bill

Bill > HB1309


MD HB1309

Cybersecurity – Standards, Compliance, and Audits – Alterations


summary

Introduced
02/07/2025
In Committee
02/07/2025
Crossed Over
Passed
Dead
04/08/2025

Introduced Session

2025 Regular Session

Bill Summary

Repealing the requirement that county boards of education prioritize the purchase of digital devices with certain funds; requiring each local school system to comply with, and certify compliance with, the State minimum cybersecurity standards and to conduct a cybersecurity maturity assessment every 2 years; requiring the Office of Security Management within the Department of Information Technology to annually update the State minimum cybersecurity standards; etc.

AI Summary

This bill enhances cybersecurity requirements for local school systems in Maryland by removing the existing mandate for county boards of education to prioritize digital device purchases and instead establishing comprehensive cybersecurity standards and compliance measures. Beginning in 2026, local school systems will be required to comply with State Minimum Cybersecurity Standards (SMCS) established by the Department of Information Technology and conduct a cybersecurity maturity assessment every two years. Each local school system must certify their compliance with these standards by June 30th every two years and provide detailed reports on their information technology staffing, including dedicated cybersecurity professionals. The bill also requires county boards to provide sufficient cybersecurity staffing as determined by the State Chief Information Security Officer, with the option to share services or contractors. Additionally, the Department of Information Technology will assign at least three information security officers to support local school systems in meeting these standards, conducting assessments, and implementing remediation efforts. The Office of Security Management within the Department of Information Technology will be responsible for annually reviewing and updating the State Minimum Cybersecurity Standards, ensuring that local school systems maintain robust and evolving cybersecurity practices.

Committee Categories

Health and Social Services

Sponsors (1)

Last Action

House Health and Government Operations Hearing (11:30:00 3/10/2025 ) (on 03/10/2025)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...