Files
2026-07-06 17:26:56 -04:00

12 KiB

type, title, description, jurisdiction, legislature, session, identifier, citation, classification, subjects, status, primary_sponsors, version_count, action_count, vote_count, first_action, last_action, source, source_identifier, source_url, source_hash, vintage, source_snapshot, retrieved_at, confidence, tags
type title description jurisdiction legislature session identifier citation classification subjects status primary_sponsors version_count action_count vote_count first_action last_action source source_identifier source_url source_hash vintage source_snapshot retrieved_at confidence tags
Bill Enhance Security of Office of Information Technology The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.) us/states/co Colorado General Assembly 2026A SB 185 Colorado SB 185 (2026A)
bill
Telecommunications & Information Technology
enacted
A. Paschal
B. Titone
J. Marchman
M. Baisley
R. Keltie
7 14 6 2026-05-01 2026-06-02 openstates ocd-bill/e6750d61-7aec-4848-89f8-b8f26d5b5af1 https://leg.colorado.gov/bills/SB26-185 d83894a47cccd09fa63fc4be52ed81488994db3a1b022f6f493a4c22a7282190 2026-07-01 https://data.openstates.org/daily/2026-07-01/public.pgdump 2026-07-06 reported
legislation
bill
us-co

Colorado SB 185 (2026A) — Enhance Security of Office of Information Technology

The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)

Version chain

The bill's text revisions, in order — the diff chain from filing to enrollment.

  1. Introduced (filed) — source
  2. Engrossed (committee substitute) — source
  3. Final Act (committee substitute) — source
  4. Reengrossed (committee substitute) — source
  5. Rerevised (committee substitute) — source
  6. Revised (committee substitute) — source
  7. Signed Act (committee substitute) — source

Votes

  • Refer Senate Bill 26-185, as amended, to the Committee on Appropriations. — pass (pass) · upper
  • Refer Senate Bill 26-185 to the Committee of the Whole and with a recommendation that it be placed on the consent calendar. — pass (pass) · upper
  • Adopt amendment L.001 — pass (pass) · upper
  • BILL — pass (pass) · lower
  • Refer Senate Bill 26-185 to the Committee on Appropriations. — pass (pass) · upper
  • Refer Senate Bill 26-185 to the Committee of the Whole. — pass (pass) · upper

Sponsors

  • A. Paschal — primary (person)
  • B. Titone — primary (person)
  • J. Marchman — primary (person)
  • M. Baisley — primary (person)
  • R. Keltie — primary (person)
  • B. Marshall — cosponsor (person)
  • C. Clifford — cosponsor (person)
  • J. Bacon — cosponsor (person)
  • J. Coleman — cosponsor (person)
  • J. Jackson — cosponsor (person)
  • M. Carter — cosponsor (person)
  • M. Rutinel — cosponsor (person)

Timeline

The legislative action history — every referral, reading, and vote.

  • 2026-06-02 Governor Signed executive-signature
  • 2026-05-22 Sent to the Governor executive-receipt
  • 2026-05-22 Signed by the Speaker of the House passage
  • 2026-05-22 Signed by the President of the Senate passage
  • 2026-05-13 House Third Reading Passed - No Amendments passage, reading-3
  • 2026-05-12 House Second Reading Special Order - Passed - No Amendments
  • 2026-05-12 House Committee on Appropriations Refer Unamended to House Committee of the Whole committee-passage, referral-committee
  • 2026-05-09 House Committee on State, Civic, Military, & Veterans Affairs Refer Unamended to Appropriations referral-committee
  • 2026-05-08 Introduced In House - Assigned to State, Civic, Military, & Veterans Affairs introduction
  • 2026-05-08 Senate Third Reading Passed - No Amendments passage, reading-3
  • 2026-05-07 Senate Second Reading Special Order - Passed with Amendments - Committee
  • 2026-05-07 Senate Committee on Appropriations Refer Unamended - Consent Calendar to Senate Committee of the Whole committee-passage
  • 2026-05-05 Senate Committee on Business, Labor, & Technology Refer Amended to Appropriations referral-committee
  • 2026-05-01 Introduced In Senate - Assigned to Business, Labor, & Technology introduction

Source

OpenStates / OpenCivicData bulk snapshot 2026-07-01; origin ocd-bill/e6750d61-7aec-4848-89f8-b8f26d5b5af1. Confidence: reported (aggregated from official Colorado legislature records).