A 426: Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
The bill aims to improve the security of end point devices used by the state of New York. End point devices include personal computing goods such as desktops, laptops, and mobile phones, as well as printers and multi-functional devices. The bill requires the commissioner and state agencies to be consistent with relevant standards and guidelines developed by the National Institute of Standards and Technology (NIST) cybersecurity framework when procuring end point devices. The bill also requires state agencies to update their end point device procurement requirements within one year of any amendments to the security standards and guidelines. This ensures that the state's procurement practices align with the latest cybersecurity standards and helps to protect against potential security threats.
| Feb. 14, 2025 | signed chap.12 |
| Feb. 12, 2025 | delivered to governor |
| Feb. 11, 2025 | PASSED SENATE |
| Feb. 11, 2025 | 3RD READING CAL.154 |
| Feb. 11, 2025 | SUBSTITUTED FOR S2671 |
STATE OF NEW YORK ________________________________________________________________________ 426 2025-2026 Regular Sessions IN ASSEMBLY (Prefiled) January 8, 2025 ___________ Introduced by M. of A. OTIS -- read once and referred to the Committee on Science and Technology AN ACT to amend the state finance law, in relation to procurement requirements for end point device security The People of the State of New York, represented in Senate and Assem- bly, do enact as follows: 1 Section 1. Subdivision 9 of section 165 of the state finance law, as 2 added by a chapter of the laws of 2024 amending the state finance law 3 relating to procurement requirements for end point device security, as 4 proposed in legislative bills numbers S. 5615 and A. 2833, is amended to 5 read as follows: 6 9. End point device security. (a) For the purposes of this subdivision 7 "end point device" shall mean personal computing goods that include 8 desktops, laptops, all-in-ones, tablets, mobile or cellular telephones, 9 thin clients, and monitors of various sizes; printers; and multi-func- 10 tional devices that include imaging devices that combine operations such 11 as copying, printing, scanning and faxing into one machine. 12 (b) The commissioner and all state agencies, when procuring end point 13 devices, shall [require those devices, services and solutions to meet] 14 be consistent with any relevant standards, guidelines, or guidance 15 developed as part of the National Institute of Standards and Technology 16 (NIST) Cybersecurity Framework. 17 [(c) Within one year of adoption of any amendments to the security18standards and guidelines referenced in paragraph (b) of this subdivision19the commissioner and each state agency shall update their end point20device procurement requirements.] 21 § 2. This act shall take effect on the same date and in the same 22 manner as a chapter of the laws of 2024 amending the state finance law 23 relating to procurement requirements for end point device security, as 24 proposed in legislative bills numbers S. 5615 and A. 2833, takes effect. EXPLANATION--Matter in italics (underscored) is new; matter in brackets [] is old law to be omitted. LBD02682-01-5