Colorado § 24-37.5-404.7 - General assembly - information security plans.

Full text of Colorado Colorado Revised Statutes § 24-37.5-404.7 — General assembly - information security plans., with citation guidance and answers to common questions.

§ 24-37.5-404.7. General assembly - information security plans.

(1) The general assembly shall develop an information security plan. The information security plan shall provide information security for the communication and information resources that support the operations and assets of the general assembly.

(2) The information security plan shall include:

(a) Periodic assessments of the risk and magnitude of the harm that could result from a security incident;

(b) A process for providing adequate information security for the communication and information resources of the general assembly;

(c) Information security awareness training for regular employees of the general assembly;

(d) Periodic testing and evaluation of the effectiveness of information security for the general assembly, which shall be performed not less than annually;

(e) A process for detecting, reporting, and responding to security incidents consistent with the information security policy of the general assembly. The general assembly and the chief information security officer shall establish the terms and conditions by which the general assembly shall report information security incidents to the chief information security officer.

(f) Plans and procedures to ensure the continuity of operations for information resources that support the operations and assets of the general assembly in the event of a security incident.

(3) The legislative service agency directors shall maintain the information security plan pursuant to this section and keep the joint technology committee advised of the plan.

(4) Nothing in this section shall be construed to require the general assembly to adopt policies or standards that conflict with federal law, rules, or regulations or with contractual arrangements governed by federal laws, rules, or regulations.

(5) The general assembly shall provide regularized security awareness training to inform the regular legislative employees, administrators, and users about the information security risks and the responsibility of employees, administrators, and users to comply with the general assembly's information security plan and the policies, standards, and procedures designed to reduce those risks.

Source: L. 2011: Entire section added, (SB 11-062), ch. 128, p. 431, § 9, effective April 22. L. 2013: (3) amended, (HB 13-1079), ch. 246, p. 1193, § 8, effective May 18.

Frequently Asked Questions About Colorado § 24-37.5-404.7

What does Colorado Revised Statutes § 24-37.5-404.7 cover?

Section 24-37.5-404.7 ("General assembly - information security plans.") is part of the Colorado Revised Statutes, the codified statutory law of Colorado. It sets out the legal rule or procedure described in the text above. Statutes are amended regularly, so always verify against the official source.

How do I cite Colorado § 24-37.5-404.7?

A common citation format is "Colorado Revised Statutes § 24-37.5-404.7" (Colorado). Legal writing may require the code abbreviation, section number, and year or edition. Match the style required by your court, professor, or publisher.

Is this the official text of Colorado law?

No. This page is for research and education and may not include the most recent amendments. For official current law, check the Colorado official source linked on this page or consult a licensed Colorado attorney.

How does Colorado § 24-37.5-404.7 apply to my situation?

Statutes are interpreted in context, and application depends on your specific facts. Only a licensed attorney in Colorado can advise on how this section applies to you. Contact your state or local bar association for a referral.

Sources & Verification

Not legal advice. Verify against the official source and consult a licensed attorney in Colorado.