No. CS/CS/SB 480
Filed under Education.
Information Technology; Providing for a type two transfer of the duties and functions of the Florida Digital Service from the Department of Management Services to the Division of Integrated Government Innovation and Technology; creating the Division of Integrated Government Innovation and Technology (DIGIT) within the Executive Office of the Governor; requiring DIGIT to operate as the state enterprise organization for information technology governance and as the lead entity responsible for understanding needs and environments, creating standards and strategy, supporting state agency technology efforts, and reporting on the state of information technology in this state, etc.
Plain English Summary
AI-GENERATEDThe bill moves the Florida Digital Service from the Department of Management Services to a new division, DIGIT, within the Governor's office. This transfer includes all existing duties, records, contracts, and funds. DIGIT becomes the state's central body for IT governance.
State agencies must now follow DIGIT's policies, standards, and guidelines for IT planning, procurement, and operations. DIGIT is required to conduct baseline needs assessments of every agency by 2029. It must also oversee all IT projects costing $10 million or more.
Inspectors general must annually audit agency IT practices against DIGIT standards. DIGIT gains authority to define and list prohibited foreign applications that present security risks. Agencies must align risk assessments with the NIST Cybersecurity Framework.
The bill creates a new regulatory and oversight structure for state information technology. It shifts decision-making power from a cabinet-level department to the Governor's office. Agencies lose some autonomy in favor of centralized state standards and reporting requirements.
AIMoves all Florida Digital Service duties, records, contracts, and funds to a new division under the Governor, making it the state's central IT governance body.
AIRequires every agency inspector general to annually audit IT practices against DIGIT standards and submit a compliance report to the Auditor General and legislature.
AIGives DIGIT the power to define, list, and update prohibited foreign applications, replacing the Department of Management Services in this role.
AIState agencies must follow DIGIT’s policies, standards, and guidelines for IT planning, procurement, and operations.
AIDIGIT must assess every state agency’s technical environment, technical debt, and security risks using the Capability Maturity Model Integration.
AIDIGIT must perform project oversight on all state agency IT projects costing $10 million or more and report high-risk projects quarterly to the Governor and legislative leaders.
AIDIGIT must establish a policy for all IT-related solicitations and contracts, including state term contracts, sole source, and emergency procurements.
AIState agencies must now align their risk assessment methodologies with the National Institute of Standards and Technology Cybersecurity Framework.