House State Government Hearing
Room 206 at 15:00:00

HB68 would require Alabama state government entities that hold sensitive personal information to adopt cybersecurity rules modeled on the NIST Cybersecurity Framework, with incident reporting and data disposal requirements, effective January 1, 2025.
The Secretary of the Office of Information Technology would be required to create and enforce cybersecurity rules for government entities that possess or access sensitive personal information. The rules must meet or exceed standards such as NIST CSF Version 1.1 (or successor) and include access controls, incident reporting, and data disposal procedures. Incidents would have to be reported to both the OIT and the Alabama State Law Enforcement Agency. Overall, it adds formal security requirements for state government handling of sensitive data.
Pending House State Government
Read for the first time and referred to the House Committee on State Government
Prefiled
Room 206 at 15:00:00
Source: Alabama Legislature