House File 601 - Introduced HOUSE FILE 601 BY COMMITTEE ON GOVERNMENT OVERSIGHT (SUCCESSOR TO HSB 185) A BILL FOR An Act providing for the confidentiality of certain cyber 1 security and critical infrastructure information developed 2 and maintained by a government body. 3 BE IT ENACTED BY THE GENERAL ASSEMBLY OF THE STATE OF IOWA: 4 TLSB 2641HV (1) 87 rh/rj
H.F. 601 Section 1. Section 22.7, subsection 50, Code 2017, is 1 amended to read as follows: 2 50. Information concerning cyber security, critical 3 infrastructure, security procedures , or emergency preparedness 4 information developed and maintained by a government body 5 for the protection of governmental employees, visitors to 6 the government body, persons in the care, custody, or under 7 the control of the government body, or property under the 8 jurisdiction of the government body, if disclosure could 9 reasonably be expected to jeopardize such employees, visitors, 10 persons, or property. 11 a. (1) Such information includes but is not limited to 12 information directly related to vulnerability assessments; 13 information contained in records relating to security measures 14 such as security and response plans, security codes and 15 combinations, passwords, restricted area passes, keys, and 16 security or response procedures; emergency response protocols; 17 and information contained in records that if disclosed would 18 significantly increase the vulnerability of critical physical 19 systems or infrastructures of a government body to attack. 20 (2) For purposes of this subsection, “information concerning 21 cyber security” includes but is not limited to information 22 relating to cyber security defenses, threats, attacks, or 23 general attempts to attack cyber system operations. 24 b. This subsection shall only apply to information held by 25 a government body that has adopted a rule or policy identifying 26 the specific records or class of records to which this 27 subsection applies and which is contained in such a record. 28 EXPLANATION 29 The inclusion of this explanation does not constitute agreement with 30 the explanation’s substance by the members of the general assembly. 31 This bill provides for the confidentiality of certain cyber 32 security and critical infrastructure information developed and 33 maintained by a government body. 34 Under current law, information concerning security 35 -1- LSB 2641HV (1) 87 rh/rj 1/ 2
H.F. 601 procedures or emergency preparedness information developed 1 and maintained by a government body for the protection of 2 governmental employees, visitors to the government body, 3 persons in the care, custody, or under the control of the 4 government body, or property under the jurisdiction of the 5 government body, if disclosure could reasonably be expected to 6 jeopardize such employees, visitors, persons, or property must 7 be kept confidential under Code section 22.7 unless otherwise 8 ordered by a court, by the lawful custodian of the records, or 9 by another person duly authorized to release such information. 10 The bill includes cyber security and critical infrastructure 11 information developed and maintained by a government body for 12 such purposes. Information concerning cyber security includes 13 but is not limited to information relating to cyber security 14 defenses, threats, attacks, or general attempts to attack cyber 15 system operations. 16 -2- LSB 2641HV (1) 87 rh/rj 2/ 2