Bill Text: NJ A4936 | 2016-2017 | Regular Session | Amended


Bill Title: Requires State, county, and municipal employees and certain State contractors to complete cybersecurity awareness training.

Spectrum: Partisan Bill (Democrat 3-0)

Status: (Introduced - Dead) 2017-06-15 - Reported out of Assembly Comm. with Amendments, 2nd Reading [A4936 Detail]

Download: New_Jersey-2016-A4936-Amended.html

[First Reprint]

ASSEMBLY, No. 4936

STATE OF NEW JERSEY

217th LEGISLATURE

 

INTRODUCED JUNE 5, 2017

 


 

Sponsored by:

Assemblywoman  ANNETTE QUIJANO

District 20 (Union)

Assemblywoman  ANNETTE CHAPARRO

District 33 (Hudson)

 

 

 

 

SYNOPSIS

     Requires State, county, and municipal employees and certain State contractors to complete cybersecurity awareness training.

 

CURRENT VERSION OF TEXT

     As reported by the Assembly Homeland Security and State Preparedness Committee on June 15, 2017, with amendments.

  


An Act requiring State, county, and municipal employees and certain State contractors to complete cybersecurity awareness training and supplementing various parts of the statutory law. 

 

     Be It Enacted by the Senate and General Assembly of the State of New Jersey:

 

     1.    All State officers and employees in a State agency in the Executive Branch and in the Judicial Branch of State government shall complete a cybersecurity awareness training program at least once in each calendar year.  An officer and employee shall verify completion of the program in the manner specified by the Chief Technology Officer, or a designee, of the New Jersey Office of Information Technology. 

     The Chief Technology Officer, or a designee, shall approve the format and content of the program.  The program shall be provided online.  The program may include content which 1[in particular]1 addresses 1[the situations of]1certain identified groups of officers or employees, such as those who are involved in contracting processes.

     The Chief Technology Officer shall require 1[the conduct of]1 periodic audits by appropriate persons or agencies to ensure compliance with the requirement set forth in this section.

     As used in this section1[,] :1

     "State agency in the Executive Branch" means any of the principal departments in the Executive Branch of 1[the]1 State 1[Government] government1, and any division, board, bureau, office, commission, or other instrumentality within or created by 1[such] a1 department, and any independent State authority, commission, instrumentality, or agency, including any public institution of higher education1[; and] .1

     "State officer and employee" means a person employed and compensated to serve in a full time or part time capacity.

 

     2.    All county and municipal officers and employees shall complete, at least once in each calendar year, the cybersecurity awareness training program approved by the Chief Technology Officer, or a designee, pursuant to section 1 of P.L.   , c.        (C.    ) (pending before the 1[legislature] Legislature1 as this bill).  An officer and employee shall verify completion of the program to the governing body of each county and municipality, as appropriate.  The governing body of each county and municipality, as appropriate, shall report completion of the program to the Chief Technology Officer, or a designee. 

     The governing body of each county and municipality, as appropriate, shall require 1[the conduct of]1 periodic audits by appropriate persons to ensure compliance with the requirement set forth in this section 1[by officers and employees in the county and municipality, as appropriate]1.

     As used in this section1[, "county"] :

     "County"1 means any county of any class of this State, and any authority, commission, agency, or instrumentality of a county.

      1["municipality"] "Municipality"1 means any city of any class, any town, township, village, or borough of this State, other than a county or a school district, and any authority, commission, agency, or instrumentality of a municipality.

 

     3.    The members of the Legislature and the State officers and employees in the Legislative Branch of State government shall complete, at least once in each calendar year, the cybersecurity awareness training program approved by the Chief Technology Officer, or a designee, pursuant to section 1 of P.L.   , c.        (C.    ) (pending before the 1[legislature] Legislature1 as this bill).  A member, officer, and employee shall verify completion of the program to the Office of Legislative Services.  The Office of Legislative Services shall report completion of the program to the Chief Technology Officer, or a designee.  The President of the Senate, Speaker of the General Assembly, and Executive Director of the Office of Legislative Services shall require 1[the conduct of]1 periodic audits by appropriate persons to ensure compliance with the requirement set forth in this section 1[by members, officers, and employees in the Senate, in the General Assembly, and in the Office of Legislative Services, as appropriate]1.

 

     4.    Notwithstanding any other provision of law to the contrary, a State contractor and a subcontractor of 1[such]1 a  1State1 contractor, and an officer and employee of the contractor and subcontractor, who has access to a computer system of the State or a database of the State shall complete the cybersecurity awareness training program approved by the Chief Technology Officer, or a designee, pursuant to section 1 of P.L.   , c.        (C.    ) (pending before the 1[legislature] Legislature1 as this bill), except that the Chief Technology Officer, or a designee, may include content in the program which 1[in particular]1 addresses 1[the situations of such]1 contractors and their officers and employees.  The program shall be completed once by each contractor, subcontractor, officer, and employee during each contract period and each renewal period.

     The completion of the program shall be required by the terms and conditions of the contract or agreement awarded by the State.  Each contractor, subcontractor, officer, and employee shall verify completion of the program in the manner specified by the Chief Technology Officer, or a designee.  The State contract manager, or a designee, shall report completion of the program to the Chief Technology Officer, or a designee.  The State contract manager, or a designee, shall conduct periodic audits to ensure compliance 1[by contractors, subcontractors, officers, and employees]1 with the requirement set forth in this section. 

     The requirement of this section shall apply to contracts awarded or renewed after the effective date of P.L.    , c.       (pending before the Legislature as this bill).

 

     5.    This act shall take effect on the 90th day following enactment, except that the Chief Technology Officer may take such anticipatory administrative action in advance as shall be necessary for the implementation of this act. 

feedback