A00426 Summary:

BILL NOA00426
 
SAME ASSAME AS S02671
 
SPONSOROtis
 
COSPNSR
 
MLTSPNSR
 
Amd §165, St Fin L (as proposed in S.5615 & A.2833)
 
Directs that state agencies require that procurement of end point devices be consistent with any relevant standards, guidelines, or guidance developed as part of the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Go to top    

A00426 Actions:

BILL NOA00426
 
01/08/2025referred to science and technology
01/22/2025reported referred to rules
01/28/2025reported
01/28/2025rules report cal.67
01/28/2025ordered to third reading rules cal.67
02/03/2025passed assembly
02/03/2025delivered to senate
02/03/2025REFERRED TO RULES
02/11/2025SUBSTITUTED FOR S2671
02/11/20253RD READING CAL.154
02/11/2025PASSED SENATE
02/11/2025RETURNED TO ASSEMBLY
02/12/2025delivered to governor
02/14/2025signed chap.12
Go to top

A00426 Committee Votes:

SCIENCE AND TECHNOLOGY Chair:Otis DATE:01/22/2025AYE/NAY:8/0 Action: Favorable refer to committee Rules
OtisAyeBlumencranzAye
VanelAyeDursoAye
BurkeAye
ConradAye
GibbsExcused
BoresAye
HooksAye

RULES Chair:Heastie DATE:01/28/2025AYE/NAY:31/0 Action: Favorable
HeastieAyeBarclayAye
PretlowAyeHawleyAye
CookAyeBlankenbushAye
GlickAyeRaAye
DinowitzAyeBrabenecAye
ColtonAyePalmesanoAye
MagnarelliAyeReillyAye
PaulinAyeSmithAye
Peoples-StokesAyeJensenAye
BenedettoAye
LavineAye
LupardoAye
BraunsteinAye
DavilaAye
HyndmanAye
RozicAye
BronsonAye
HevesiAye
HunterAye
TaylorAye
CruzAye
VanelAye

Go to top

A00426 Floor Votes:

DATE:02/03/2025Assembly Vote  YEA/NAY: 147/0
Yes
Alvarez
Yes
Carroll P
Yes
Friend
Yes
Lee
Yes
Peoples-Stokes
Yes
Slater
Yes
Anderson
Yes
Carroll RC
Yes
Gallagher
Yes
Lemondes
Yes
Pheffer Amato
Yes
Smith
Yes
Angelino
Yes
Chandler-Waterm
Yes
Gallahan
Yes
Levenberg
Yes
Pirozzolo
Yes
Smullen
Yes
Bailey
Yes
Chang
Yes
Gandolfo
Yes
Lucas
Yes
Pretlow
Yes
Solages
Yes
Barclay
Yes
Chludzinski
Yes
Gibbs
Yes
Lunsford
Yes
Ra
Yes
Steck
Yes
Barrett
Yes
Clark
Yes
Giglio
Yes
Lupardo
Yes
Raga
Yes
Stern
Yes
Beephan
Yes
Colton
Yes
Glick
Yes
Magnarelli
Yes
Rajkumar
Yes
Stirpe
Yes
Bendett
Yes
Conrad
Yes
Gonzalez-Rojas
Yes
Maher
Yes
Ramos
Yes
Tague
Yes
Benedetto
Yes
Cook
Yes
Gray
Yes
Mamdani
Yes
Reilly
Yes
Tannousis
Yes
Berger
Yes
Cruz
Yes
Griffin
Yes
Manktelow
Yes
Reyes
Yes
Tapia
Yes
Bichotte Hermel
Yes
Cunningham
Yes
Hawley
Yes
McDonald
Yes
Rivera
Yes
Taylor
ER
Blankenbush
Yes
Dais
ER
Hevesi
ER
McDonough
Yes
Romero
Yes
Torres
Yes
Blumencranz
Yes
Davila
Yes
Hooks
Yes
McMahon
Yes
Rosenthal
Yes
Valdez
Yes
Bologna
Yes
De Los Santos
Yes
Hunter
Yes
Meeks
Yes
Rozic
Yes
Vanel
Yes
Bores
Yes
DeStefano
Yes
Hyndman
Yes
Mikulin
Yes
Santabarbara
Yes
Walker
Yes
Brabenec
Yes
Dilan
Yes
Jackson
Yes
Miller
Yes
Sayegh
Yes
Walsh
Yes
Braunstein
Yes
Dinowitz
Yes
Jacobson
Yes
Mitaynes
Yes
Schiavoni
Yes
Weprin
Yes
Bronson
Yes ‡
DiPietro
Yes
Jensen
Yes
Molitor
Yes
Seawright
Yes
Wieder
Yes
Brook-Krasny
Yes
Durso
Yes
Jones
Yes
Morinello
Yes
Sempolinski
Yes
Williams
Yes
Brown EA
Yes
Eachus
Yes
Kassay
Yes
Norber
Yes
Septimo
Yes
Woerner
Yes
Brown K
Yes
Eichenstein
Yes
Kay
Yes
Novakhov
Yes
Shimsky
Yes
Wright
Yes
Burdick
Yes
Epstein
Yes
Kelles
Yes
O'Pharrow
Yes
Shrestha
Yes
Yeger
Yes
Burke
Yes
Fall
Yes
Kim
Yes
Otis
Yes
Simon
Yes
Zaccaro
Yes
Burroughs
Yes
Fitzpatrick
Yes
Lasher
Yes
Palmesano
Yes
Simone
Yes
Zinerman
Yes
Buttenschon
Yes
Forrest
Yes
Lavine
Yes
Paulin
Yes
Simpson
Yes
Mr. Speaker

‡ Indicates voting via videoconference
Go to top

A00426 Memo:

NEW YORK STATE ASSEMBLY
MEMORANDUM IN SUPPORT OF LEGISLATION
submitted in accordance with Assembly Rule III, Sec 1(f)
 
BILL NUMBER: A426
 
SPONSOR: Otis
  TITLE OF BILL: An act to amend the state finance law, in relation to procurement requirements for end point device security   PURPOSE OR GENERAL IDEA OF BILL: The purpose of this bill is to effectuate an amendment to Chapter 608 (approval memo 50) relating to procurement requirements for end point device security to manage cybersecurity related risks.   SUMMARY OF PROVISIONS:. Section one makes technical amendments requiring utilization of end point devices be consistent with relevant guidelines developed by the National Institute of Standards and Technology Cybersecurity Framework. Section two is the effective date.   JUSTIFICATION: This chapter makes technical amendments to clarify Chapter 608 of the laws of 2024.   PRIOR LEGISLATIVE HISTORY: This bill is a chapter amendment to Chapter 608 of the laws of 2024.   FISCAL IMPLICATIONS FOR STATE AND LOCAL GOVERNMENTS: None.   EFFECTIVE DATE: This act shall take effect on the same date and in the same manner as a Chapter of the laws of 2024 amending the state finance law relating to procurement requirements for end point device security, as proposed in legislative bills numbers S. 5615 and A. 2833, takes effect.
Go to top

A00426 Text:



 
                STATE OF NEW YORK
        ________________________________________________________________________
 
                                           426
 
                               2025-2026 Regular Sessions
 
                   IN ASSEMBLY
 
                                       (Prefiled)
 
                                     January 8, 2025
                                       ___________
 
        Introduced  by  M. of A. OTIS -- read once and referred to the Committee
          on Science and Technology
 
        AN ACT to amend the  state  finance  law,  in  relation  to  procurement
          requirements for end point device security

          The  People of the State of New York, represented in Senate and Assem-
        bly, do enact as follows:
 
     1    Section 1. Subdivision 9 of section 165 of the state finance  law,  as
     2  added  by  a  chapter of the laws of 2024 amending the state finance law
     3  relating to procurement requirements for end point device  security,  as
     4  proposed in legislative bills numbers S. 5615 and A. 2833, is amended to
     5  read as follows:
     6    9. End point device security. (a) For the purposes of this subdivision
     7  "end  point  device"  shall  mean  personal computing goods that include
     8  desktops, laptops, all-in-ones, tablets, mobile or cellular  telephones,
     9  thin  clients,  and monitors of various sizes; printers; and multi-func-
    10  tional devices that include imaging devices that combine operations such
    11  as copying, printing, scanning and faxing into one machine.
    12    (b) The commissioner and all state agencies, when procuring end  point
    13  devices,  shall  [require those devices, services and solutions to meet]
    14  be consistent with  any  relevant  standards,  guidelines,  or  guidance
    15  developed  as part of the National Institute of Standards and Technology
    16  (NIST) Cybersecurity Framework.
    17    [(c) Within one year of adoption of any  amendments  to  the  security
    18  standards and guidelines referenced in paragraph (b) of this subdivision
    19  the  commissioner  and  each  state  agency shall update their end point
    20  device procurement requirements.]
    21    § 2. This act shall take effect on the  same  date  and  in  the  same
    22  manner  as  a chapter of the laws of 2024 amending the state finance law
    23  relating to procurement requirements for end point device  security,  as
    24  proposed in legislative bills numbers S. 5615 and A. 2833, takes effect.
 
         EXPLANATION--Matter in italics (underscored) is new; matter in brackets
                              [ ] is old law to be omitted.
                                                                   LBD02682-01-5
Go to top

A00426 LFIN:

 NO LFIN
Go to top

A00426 Chamber Video/Transcript:

2-3-25Video (@ 01:03:59)Transcript pdf Transcript html
Go to top