AB 869: State agencies: information security: Zero Trust architecture.
The bill aims to improve state government's information security by implementing zero trust architecture. This architecture requires state agencies to prioritize multifactor authentication, enterprise endpoint detection and response solutions, and robust logging practices. The bill also mandates the use of solutions that comply with federal guidelines and programs. State agencies must achieve prescribed levels of maturity based on the CISA maturity model by specified dates. The Office of Information Security must develop uniform technology policies, standards, and procedures for use by all state agencies. Annual reporting activities will be updated to collect information on the progress made by state agencies in increasing their internal defenses. The bill's provisions will be implemented in a manner consistent with the state's timely compliance with federal requirements for receiving f…
| Aug. 29, 2025 | In committee: Held under submission. |
| Aug. 18, 2025 | In committee: Referred to suspense file. |
| Jul. 08, 2025 | From committee: Do pass and re-refer to Com. on APPR. with recommendation: To Consent Calendar. (Ayes 15. Noes 0.) (July 8). Re-referred to Com. on APPR. |
| Jun. 11, 2025 | Referred to Com. on G.O. |
| Jun. 03, 2025 | In Senate. Read first time. To Com. on RLS. for assignment. |