Plain English Breakdown
The specific list of agency exceptions and implementation dates are defined elsewhere or left unspecified in this summary text.
AB-869: State Agencies Must Use Zero Trust Security
This law requires specified state agencies to implement a cybersecurity system called Zero Trust architecture and report on their progress.
What This Bill Does
- Requires specified state agencies, with some exceptions, to use Zero Trust architecture for data, hardware, software, internal systems, and essential third-party software by set dates.
- Mandates that agencies prioritize solutions matching federal guidelines, including multifactor authentication, endpoint detection tools, and strong logging practices.
- Directs the Office of Information Security chief to create or update uniform technology policies in official state manuals for Zero Trust architecture.
- Updates annual reporting rules so agencies must share information about their progress on improving internal system defenses.
Who It Names or Affects
- Specified California state agencies, departments, and offices.
- The Office of Information Security within the Department of Technology.
- Essential third-party software used by state agencies.
Terms To Know
- Zero Trust architecture
- A security model required for all data, hardware, and systems that does not automatically trust anyone inside or outside a network.
- Multifactor authentication
- A login method requiring users to provide two or more forms of proof to access systems and data.
- CISA Maturity Model
- A set of standards from the federal Cybersecurity and Infrastructure Security Agency used to measure how advanced an agency's security is.
Limits and Unknowns
- The bill includes specified exceptions for some agencies, but does not list them in this summary.
- Specific dates for when agencies must finish implementation are mentioned as 'specified' but not listed here.
- The exact details of how federal fund requirements will be met depend on future actions.