Md. Code, State Fin. & Proc. § 3.5-2A-05

Current with changes from the 2024 Legislative Session effective on or before 7/1/2024, from Chs.. 2 through 1049
Section 3.5-2A-05 - Cybersecurity Coordinating Council
(a) There is a Maryland Cybersecurity Coordinating Council.
(b)
(1) The Council consists of the following members:
(i) the secretary of each of the principal departments listed in § 8-201 of the State Government Article, or a secretary's designee;
(ii) the State Chief Information Security Officer;
(iii) the Adjutant General of the Maryland National Guard, or the Adjutant General's designee;
(iv) the Superintendent of State Police, or the Superintendent's designee;
(v) the Director of the Governor's Office of Homeland Security, or the Director's designee;
(vi) the Executive Director of the Department of Legislative Services, or the Executive Director's designee;
(vii) one representative of the Administrative Office of the Courts;
(viii) the Chancellor of the University System of Maryland, or the Chancellor's designee; and
(ix) any other stakeholder that the State Chief Information Security Officer deems appropriate.
(2) If a designee serves on the Council in place of an official listed in paragraph (1) of this subsection, the designee shall report information from the Council meetings and other communications to the official.
(c) In addition to the members listed under subsection (b) of this section, the following representatives may serve as nonvoting members of the Council:
(1) one member of the Senate of Maryland, appointed by the President of the Senate;
(2) one member of the House of Delegates, appointed by the Speaker of the House; and
(3) one representative of the judiciary, appointed by the Chief Justice of the Supreme Court of Maryland.
(d) The chair of the Council is the State Chief Information Security Officer.
(e) The Council shall meet at least quarterly at the request of the chair.
(f) The Council shall:
(1) provide advice and recommendations to the State Chief Information Security Officer regarding:
(i) the strategy and implementation of cybersecurity initiatives and recommendations; and
(ii) building and sustaining the capability of the State to identify and mitigate cybersecurity risk and respond to and recover from cybersecurity-related incidents.
(2) use the analysis compiled by the Office under § 3.5-2 A-04(e)(1)(ii) of this subtitle to prioritize cybersecurity risk across the Executive Branch of State government and make corresponding recommendations for security investments in the Governor's annual budget.
(g) In carrying out the duties of the Council, the Council shall consult with outside experts, including experts in the private sector, government agencies, and institutions of higher education.

Md. Code, SF § 3.5-2A-05

Added by 2022 Md. Laws, Ch. 242, Sec. 2, eff. 7/1/2022.