H-0469.1
HOUSE BILL 1467
State of Washington
64th Legislature
2015 Regular Session
By Representatives Hudgins, Stanford, S. Hunt, and Ormsby
Read first time 01/21/15. Referred to Committee on Gen Govt & Info Tech.
AN ACT Relating to encryption of data on state information technology systems; and adding a new section to chapter 43.41A RCW.
BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF WASHINGTON:
NEW SECTION.  Sec. 1.  A new section is added to chapter 43.41A RCW to read as follows:
(1) The office shall adopt data encryption standards with which all state agencies must comply. These standards must include a classification schedule for ranking data sensitivity, and all state agencies must classify any data held on state networks according to the schedule. The highest sensitivity data must be encrypted while at rest on state data systems, and the chief information officer's standards must also include technical requirements for encryption that are appropriate to each other data classification.
(2) The office shall update and distribute the encryption standards to state information technology directors annually, by the end of each fiscal year, to reflect the changing state of information technology. The annual distribution must include a timeline for phase-in of any new technologies required under the updated standards.
(3) The office may grant individual waivers to the policies established under subsection (1) of this section in cases where encryption is deemed unreasonably costly.
--- END ---