Md. Code Ann., State Fin. & Proc. § 3.5-406
Redline — January 1, 2023 → current.View current text →
Current — January 1, 2026
As of January 1, 2023
(a) On or before December 1 each year, each unit of State government shall:
(1) report the results of any cybersecurity preparedness assessments performed in the prior year to the Office of Security Management in accordance with guidelines developed by the Office; and
(2) submit a report to the Governor and the Office of Security Management that includes:
(i) an inventory of all information systems and applications used or maintained by the unit;
(ii) a full data inventory of the unit;
(iii) a list of all cloud or statistical analysis system solutions used by the unit;
(iv) a list of all permanent and transient vendor interconnections that are in place;
(v) the number of unit employees who have received cybersecurity training;
(vi) the total number of unit employees who use the network;
(vii) the number of information technology staff positions, including vacancies;
(viii) the number of noninformation technology staff positions, including vacancies;
(ix) the unit’s information technology budget, itemized to include the following categories:
1. services;
2. equipment;
3. applications;
4. personnel;
5. software licensing;
6. development;
7. network projects;
8. maintenance; and
9. cybersecurity;
(x) any major information technology initiatives to modernize the unit’s information technology systems or improve customer access to State and local services;
(xi) the unit’s plans for future fiscal years to implement the unit’s information technology goals;
(xii) compliance with timelines and metrics provided in the Department’s master plan; and
(xiii) any other key performance indicators required by the Office of Security Management to track compliance or consistency with the Department’s statewide information technology master plan.
(a) This section does not apply to municipal governments.
(b) In a manner and frequency established in regulations adopted by the Department, each county government, local school system, and local health department shall:
(1) in consultation with the local emergency manager, create or update a cybersecurity preparedness and response plan; and
(2) complete a cybersecurity preparedness assessment.
(c) The assessment required under paragraph (b)(2) of this section may, in accordance with the preference of each county government, be performed by the Department or by a vendor authorized by the Department.
(d) (1) Each local government shall report a cybersecurity incident, including an attack on a State system being used by the local government, to the appropriate local emergency manager and the State Security Operations Center in the Department in accordance with paragraph (2) of this subsection.
(2) For the reporting of cybersecurity incidents under paragraph (1) of this subsection, the State Chief Information Security Officer shall determine: (i) the criteria for determining when an incident must be reported; (ii) the manner in which to report; and (iii) the time period within which a report must be made.
(2) For the reporting of cybersecurity incidents to local emergency managers under subparagraph (i) of this paragraph, the State Chief Information Security Officer shall determine: (i) the criteria for determining when an incident must be reported; (ii) the manner in which to report; and (iii) the time period within which a report must be made. (3) The State Security Operations Center shall immediately notify the appropriate agencies of a cybersecurity incident reported under this subsection through the State Security Operations Center.
Official source: Maryland General Assembly. Reproduced from public-domain Maryland statutes; confirm against the official source for the current text. Not legal advice.