|
| | 104TH GENERAL ASSEMBLY
State of Illinois
2025 and 2026 SB1363 Introduced 1/28/2025, by Sen. Sally J. Turner SYNOPSIS AS INTRODUCED: | | | Amends the State Officials and Employees Ethics Act. Requires each officer, member, and employee to complete, at least annually, a cybersecurity training program, with certain requirements. Requires each ultimate jurisdictional authority to submit to the applicable Ethics Commission, at least annually, a report regarding that training, with certain requirements. |
| |
| | A BILL FOR |
|
|
| | SB1363 | | LRB104 06502 BDA 16538 b |
|
|
1 | | AN ACT concerning government. |
2 | | Be it enacted by the People of the State of Illinois, |
3 | | represented in the General Assembly: |
4 | | Section 5. The State Officials and Employees Ethics Act is |
5 | | amended by adding Section 5-10.10 as follows: |
6 | | (5 ILCS 430/5-10.10 new) |
7 | | Sec. 5-10.10. Cybersecurity training. |
8 | | (a) Each officer, member, and employee must complete, at |
9 | | least annually, a cybersecurity training program. A person who |
10 | | fills a vacancy in an elective or appointed position that |
11 | | requires training under this Section must complete the initial |
12 | | cybersecurity training program within 30 days after |
13 | | commencement of office or employment. The training shall |
14 | | include, at a minimum, information concerning: (i) the types |
15 | | of cybersecurity threats, including malware, phishing, social |
16 | | engineering, and ransomware; (ii) the creation of strong |
17 | | passwords and the proper use of passwords and multi-factor |
18 | | authentication; (iii) the applicability of data privacy |
19 | | regulations and best practices for proper data handling, and |
20 | | secure file sharing; (iv) the recognition and avoidance of |
21 | | suspicious links, attachments, and unsafe websites; and (v) |
22 | | the actions that should be taken to secure personal and |
23 | | government devices and report lost or stolen devices. Proof of |