{"data":{"id":"us-ut/utah-code-63c-27-202","jurisdiction":"us-ut","citation":"Utah Code § 63C-27-202","heading":"Commission duties.","body":"The commission shall:\n(1) identify and inform the governor of:\n(a) cyber threats and vulnerabilities towards Utah's critical infrastructure;\n(b) cybersecurity assets and resources; and\n(c) an analysis of:\n(i) current cyber incident response capabilities;\n(ii) potential cyber threats; and\n(iii) areas of significant concern with respect to:\n(A) vulnerability to cyber attack; or\n(B) seriousness of consequences in the event of a cyber attack;\n(2) provide resources with respect to cyber attacks in both the public and private sector, including:\n(a) best practices;\n(b) education; and\n(c) mitigation;\n(3) promote cyber security awareness;\n(4) share information;\n(5) promote best practices to prevent and mitigate cyber attacks;\n(6) enhance cyber capabilities and response for all Utahns;\n(7) provide consistent outreach and collaboration with private and public sector organizations;\n(8) share cyber threat intelligence to operators and overseers of Utah's critical infrastructure; and\n(9) in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, make rules establishing minimum cybersecurity standards for a local education agency, as that term is defined in Section 53G-3-402, that:\n(a) align with industry recognized cybersecurity frameworks and standards, including frameworks developed by the National Institute of Standards and Technology, the Center for Internet Security, or a successor organization;\n(b) take into account varying local education agency resources, capacity, and needs;\n(c) establish phased implementation timelines based on local education agency size, existing cybersecurity infrastructure, and available resources; and\n(d) as appropriate based on the local education agency's size, risk profile, and available resources, shall address:\n(i) identity and access management;\n(ii) asset management and inventory of hardware, software, and data systems;\n(iii) data protection;\n(iv) security monitoring and logging capabilities;\n(v) vulnerability management, including regular security assessments and patching procedures;\n(vi) incident response and recovery planning;\n(vii) security awareness training requirements for staff and administrators;\n(viii) third-party risk management for vendors with access to local education agency systems or data;\n(ix) network security controls;\n(x) backup and disaster recovery procedures; and\n(xi) governance structures for cybersecurity oversight within a local education agency.","path":["Title 63C State Commissions and Councils Code","Chapter 63C-27 Cybersecurity Commission","Part 63C-27-2 Cybersecurity Commission"],"source_url":"https://le.utah.gov/xcode/Title63C/Chapter27/63C-27-S202.html","current_through":"2026 General Session","vintage":"","retrieved_at":"2026-09-03T11:34:33Z","sha256":"19467f66cd899b319a999453963d4bbc4d80b7755e892b87c5d2e9df7ffd1ee2","source_id":"us-ut","stale":false,"prev":"us-ut/utah-code-63c-27-201","next":"us-ut/utah-code-63c-27-203"},"notice":"GroundRules: Original legal text. Not legal advice."}
