← California State Legislature · All bills
AB 869
State agencies: information security: Zero Trust architecture.
Assembly · Other
What this bill does
This bill would require every state agency, as specified, and subject to specified exceptions, to implement Zero Trust architecture for all data, hardware, software, internal systems, and essential third-party software, including for on-premises, cloud, and hybrid environments, to achieve prescribed levels of maturity based on the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model, as defined, by specified dates. In implementing Zero Trust architecture, the bill would require state agencies to prioritize the use of solutions that comply with, are authorized by, or align to federal guidelines, programs, and frameworks and, at a minimum, prioritize multifactor authentication for access to all systems and data, enterprise endpoint detection and response solutions, and robust logging practices, as specified. …
Read the full official summary
Existing law establishes the Office of Information Security within the Department of Technology for the purpose of ensuring the confidentiality, integrity, and availability of state systems and applications and to promote and protect privacy as part of the development and operations of state systems and applications to ensure the trust of the residents of this state. Existing law requires specified state entities to implement the policies and procedures issued by the office. Existing law additionally authorizes the office to conduct, or require to be conducted, an independent security assessment of every state agency, department, or office, as specified. Existing law requires every state agency, as specified, to certify, by February 1 annually, to the office that the agency is in compliance with all adopted policies, standards, and procedures and to include a plan of action and milestones, as specified.
This bill would require every state agency, as specified, and subject to specified exceptions, to implement Zero Trust architecture for all data, hardware, software, internal systems, and essential third-party software, including for on-premises, cloud, and hybrid environments, to achieve prescribed levels of maturity based on the Cybersecurity and Infrastructure Security Agency (CISA) Maturity Model, as defined, by specified dates. In implementing Zero Trust architecture, the bill would require state agencies to prioritize the use of solutions that comply with, are authorized by, or align to federal guidelines, programs, and frameworks and, at a minimum, prioritize multifactor authentication for access to all systems and data, enterprise endpoint detection and response solutions, and robust logging practices, as specified. The bill would require the office's chief to develop or revise uniform technology policies, standards, and procedures for use by all state agencies in Zero Trust architecture to achieve specified maturity levels on all systems in the State Administrative Manual and Statewide Information Management Manual. The bill would require the chief to update requirements for existing annual reporting activities to collect information relating to the progress state agencies are making to increase internal defenses of agency systems. The bill would authorize the chief to update existing annual reporting activities to include how a state agency is progressing with respect to specified goals. The bill would also state the Legislature's intent that the bill's provisions be implemented in a manner consistent with the state's timely compliance with requirements that are conditions to receipt of federal funds. The bill would also make related legislative findings and declarations.
Official summary from the Legislative Counsel’s office, via OpenStates.
Floor votes (1)
June 2, 2025 — Third reading vote
Passed · 78 yes · 0 no · 1 other
Yes (78): Dawn Addis, Cecilia Aguiar-Curry, Patrick Ahrens, Juan Alanis, David Alvarez, Joaquin Arambula, Jasmeet Bains, Rebecca Bauer-Kahan, Steve Bennett, Marc Berman, Blanca Rubio, Tasha Boerner, Mia Bonta, Isaac Bryan, Lisa Calderon, Jessica Caloza, Juan Carrillo, Leticia Castillo, Celeste Rodriguez, Phillip Chen, Damon Connolly, Laurie Davies, Carl DeMaio, Diane Dixon, Sade Elhawary, Heath Flora, Mike Fong, Jesse Gabriel, James Gallagher, Robert Garcia, Mike Gipson, Heather Hadwick, Matt Haney, John Harabedian, Gregg Hart, Joshua Hoover, Jacqui Irwin, Corey Jackson, Jeff Gonzalez, Ash Kalra, Maggy Krell, Tom Lackey, Alex Lee, Josh Lowenthal, Ali Macedo, Mark González, Tina McKinnor, Michelle Rodriguez, Al Muratsuchi, Stephanie Nguyen, Liz Ortega, Blanca Pacheco, Diane Papan, Darsh Patel, Joe Patterson, Gail Pellerin, Cottie Petrie-Norris, Sharon Quirk-Silva, James Ramos, Rhodesia Ransom, Robert Rivas, Chris Rogers, Kate Sanchez, Pilar Schiavo, Nick Schultz, LaShae Sharp-Collins, José Solache, Esmeralda Soria, Catherine Stefani, Tri Ta, David Tangipa, Avelino Valencia, Greg Wallis, Chris Ward, Buffy Wicks, Lori Wilson, Rick Zbur, Anamarie Ávila Farías
Other / no vote recorded (1): Stan Ellis
Official motion wording
AB 869 Irwin Assembly Third Reading
Official record: leginfo.legislature.ca.gov