143B-1379. State agency cooperation and training; liaisons; county and municipal government reporting.
(a) The head of each principal department and Council of State agency shall cooperate with the State CIO in the discharge of the State CIO's duties by providing the following information to the Department:
(1) The full details of the State agency's information technology and operational requirements and of all the agency's significant cybersecurity incidents within 24 hours of confirmation.
(2) Comprehensive information concerning the information technology security employed to protect the agency's data, including documentation and reporting of remedial or corrective action plans to address any deficiencies in the information security policies, procedures, and practices of the State agency.
(3) A forecast of the parameters of the agency's projected future cybersecurity and privacy needs and capabilities.
(4) Designating an agency liaison in the information technology area to coordinate with the State CIO. The liaison shall be subject to a criminal background report from the State Repository of Criminal Histories, which shall be provided by the State Bureau of Investigation upon its receiving fingerprints from the liaison. Military personnel with a valid secret security clearance or a favorable Tier 3 security clearance investigation are exempt from this requirement. If the liaison has been a resident of this State for less than five years, the background report shall include a review of criminal information from both the State and National Repositories of Criminal Histories. The criminal background report shall be provided to the State CIO and the head of the agency. In addition, all personnel in the Office of the State Auditor who are responsible for information technology security reviews shall be subject to a criminal background report from the State Repository of Criminal Histories, which shall be provided by the State Bureau of Investigation upon receiving fingerprints from the personnel designated by the State Auditor. For designated personnel who have been residents of this State for less than five years, the background report shall include a review of criminal information from both the State and National Repositories of Criminal Histories. The criminal background reports shall be provided to the State Auditor. Criminal histories provided pursuant to this subdivision are not public records under Chapter 132 of the General Statutes.
(5) Completing mandatory annual security awareness training and reporting compliance for all personnel, including contractors and other users of State information technology systems.
(b) The information provided by State agencies to the State CIO under this section is protected from public disclosure pursuant to G.S. 132-6.1(c).
(c) Local government entities, as defined in G.S. 143-800(c)(1), shall report cybersecurity incidents to the Department. Information shared as part of this process will be protected from public disclosure under G.S. 132-6.1(c). Private sector entities are encouraged to report cybersecurity incidents to the Department. (2015-241, s. 7A.2(b); 2019-200, s. 6(e); 2021-180, s. 38.13(c).)
Structure North Carolina General Statutes
North Carolina General Statutes
Chapter 143B - Executive Organization Act of 1973
Article 15 - Department of Information Technology.
§ 143B-1320 - Definitions; scope; exemptions.
§ 143B-1321 - Powers and duties of the Department; cost-sharing with exempt entities.
§ 143B-1322 - State CIO duties; Departmental personnel and administration.
§ 143B-1323 - Departmental organization; divisions and units; education community of practice.
§ 143B-1324 - State agency information technology management; deviations for State agencies.
§ 143B-1325 - State information technology consolidated under Department of Information Technology.
§ 143B-1330 - Planning and financing State information technology resources.
§ 143B-1331 - Business continuity planning.
§ 143B-1332 - Information Technology Fund.
§ 143B-1333 - Internal Service Fund.
§ 143B-1336 - Information technology human resources.
§ 143B-1337 - Information Technology Strategy Board.
§ 143B-1340 - Project management.
§ 143B-1341 - Project management standards.
§ 143B-1342 - Dispute resolution.
§ 143B-1343 - Standardization.
§ 143B-1344 - Legacy applications.
§ 143B-1350 - Procurement of information technology.
§ 143B-1354 - Certification that information technology bid submitted without collusion.
§ 143B-1356 - Multiyear contracts; Attorney General assistance.
§ 143B-1358 - Refurbished computer equipment purchasing program.
§ 143B-1359 - Configuration and specification requirements same as for new computers.
§ 143B-1360 - Data on reliability and other issues; report.
§ 143B-1361 - Information technology procurement policy; reporting requirements.
§ 143B-1362 - Personal services contracts subject to Article.
§ 143B-1370 - Communications services.
§ 143B-1371 - Communications services for local governmental entities and other entities.
§ 143B-1372 - Statewide electronic web presence; annual report.
§ 143B-1373 - Growing Rural Economies with Access to Technology (GREAT) program.
§ 143B-1373.1 - Completing Access to Broadband program.
§ 143B-1373.2 - G.R.E.A.Tprogram fixed wireless and satellite broadband grants.
§ 143B-1373.3 - Wireless broadband grants.
§ 143B-1374 - Satellite-Based Broadband Grant Program.
§ 143B-1376 - Statewide security and privacy standards.
§ 143B-1377 - State CIO approval of security standards and risk assessments.
§ 143B-1378 - Assessment of agency compliance with cybersecurity standards.
§ 143B-1385 - Government Data Analytics Center.
§ 143B-1402 - Powers and duties of the 911 Board.
§ 143B-1403 - Service charge for 911 service.
§ 143B-1405 - Fund distribution to CMRS providers.
§ 143B-1406 - Fund distribution to PSAPs.
§ 143B-1407 - PSAP Grant and Statewide 911 Projects Account; Next Generation 911 Reserve Fund.
§ 143B-1408 - Recovery of unauthorized use of funds.
§ 143B-1409 - Conditions for providing enhanced 911 service.
§ 143B-1411 - Subscriber records.
§ 143B-1412 - Proprietary information.
§ 143B-1413 - Limitation of liability.
§ 143B-1415 - Limitation of liability, prepaid wireless.
§ 143B-1416 - Exclusivity of 911 service charge for prepaid wireless telecommunications service.
§ 143B-1420 - Council established; role of the Center for Geographic Information and Analysis.
§ 143B-1421 - Council membership; organization.
§ 143B-1422 - Compensation and expenses of Council members; travel reimbursements.