Ark. Code § 10-4-429

Current with legislation from 2024 Fiscal and Special Sessions.
Section 10-4-429 - Report of security incident - Definitions
(a) As used in this section:
(1) "Public entity" means an entity of the state, political subdivision of the state, or school; and
(2) "Security incident" means any compromise of the security, confidentiality, or integrity of an information system maintained by a public entity, a contractual provider of an information system that contracts with a public entity, or other computer-related services of a public entity, that is caused by any unauthorized:
(A) Access to an information system of a public entity;
(B) Destruction of an information system of a public entity or the data of an information system of a public entity; or
(C) Acquisition of data from an information system of a public entity.
(b)
(1) A public entity that experiences a security incident shall disclose, in writing, an initial report of the known facts of the security incident to the Legislative Auditor within five (5) business days after learning of the security incident.
(2) A public entity shall provide regular updates of the security incident to the Legislative Auditor until the investigation of the security incident is closed.
(c) The Legislative Auditor shall:
(1) Maintain a list of all security incidents reported by a public entity; and
(2) Annually on or before December 15, report the information required by subdivision (c)(1) of this section to the Legislative Council, Legislative Joint Auditing Committee, and Joint Committee on Advanced Communications and Information Technology.
(d) If the Legislative Auditor believes the security incident significantly compromises citizens' data, creates a significant security concern, or involves significant theft, then the Legislative Auditor shall notify:
(1) The Governor;
(2) The President Pro Tempore of the Senate;
(3) The Speaker of the House of Representatives;
(4) The House and Senate cochairs of the Legislative Council;
(5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and
(6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
(e) A report, update, notification, or list created or maintained under this section is exempt from disclosure under the Freedom of Information Act of 1967, § 25-19-101 et seq., as a security function under § 25-19-105(b)(11).

Ark. Code § 10-4-429

Amended by Act 2023, No. 175,§ 2, eff. 8/1/2023.
Added by Act 2021, No. 260,§ 1, eff. 7/28/2021.