govt.fyi
Back to HB 1549
Arkansas General Assembly· HB 1549Notification that HB1549 is now Act 489

An act TO CREATE THE ARKANSAS CYBERSECURITY ACT OF 10 2025, the official text

Shown verbatim: the complete text as captured from the official PDF posted by the Arkansas General Assembly, fetched 2026-07-23. Page and line markers are part of the official record; nothing is edited or removed. The official bill page.
Stricken language would be deleted from and underlined language would be added to present law.

1 State of Arkansas      As Engrossed: H2/25/25 H3/11/25
2 95th General Assembly
                                  A Bill

3 Regular Session, 2025                                            HOUSE BILL 1549

4

5 By: Representative R. Scott Richardson

6 By: Senator J. Bryant

7

8                                  For An Act To Be Entitled

9   AN ACT TO CREATE THE ARKANSAS CYBERSECURITY ACT OF

10  2025; AND FOR OTHER PURPOSES.

11

12

13                                        Subtitle

14                       TO CREATE THE ARKANSAS CYBERSECURITY ACT

15                       OF 2025.

16

17 BE IT ENACTED BY THE GENERAL ASSEMBLY OF THE STATE OF ARKANSAS:

18

19  SECTION 1. DO NOT CODIFY. Title.

20  This act shall be known and may be cited as the "Arkansas Cybersecurity

21 Act of 2025".

22

23  SECTION 2. Arkansas Code Title 25, Chapter 4, is amended to add an

24 additional section to read as follows:

25  25-4-130. State Cybersecurity Office -- Duties and powers --

26 Definitions.

27  (a) As used in this section:

28  (1) "Cybersecurity":

29                       (A) Means the practice of protecting a system, network,

30 device, and data from cyber threats, unauthorized access, and malicious

31 activities; and

32                       (B) Involves a combination of technologies, processes,

33 policies, and practices designed to safeguard and ensure the confidentiality,

34 integrity, and availability of digital assets;

35  (2) "Functional report" means the practice of aligning employees

36 based on function, including without limitation cybersecurity function and

    *LJH063*                                                       03-11-2025 09:57:13 LJH063
    As Engrossed: H2/25/25 H3/11/25                                        HB1549

1 information security function, and including without limitation the following

2 factors:

3               (A) Monitoring and responding to threats;

4               (B) Incident response and recovery;

5               (C) Vulnerability management;

6               (D) Security awareness training;

7               (E) Compliance and risk management; and

8               (F) Implementation and adherence to cybersecurity

9 governance and standards;

10              (3) "Information security" means a practice or system that

11 eliminates or reduces the risk of state information being maliciously or

12 improperly accessed through physical or electronic means; and

13              (4) "State agency" means a department, agency, division, board,

14 or commission within the executive branch of the state government.

15  (b) The State Cybersecurity Office shall:

16              (1) Be managed by the State Information Security Officer;

17              (2) Be responsible for directing and managing all functions related

18 to state cybersecurity and information security for each state agency;

19              (3) Maximize state cybersecurity resources, including without

20 limitation cybersecurity personnel;

21              (4) Establish cybersecurity governance policies, procedures, and

22 standards to protect state information technology systems and infrastructure,

23 including without limitation:

24              (A) Data classification and design controls;

25              (B) Cybersecurity and data breach notification;

26              (C) Detection, mitigation, and monitoring of cybersecurity

27 threats;

28              (D) A cyber assessment program and remediation actions;

29              (E) Cybersecurity awareness and training;

30              (F) Enforcement and compliance, including without

31 limitation:

32              (i) Creation of a procedure for auditing;

33              (ii) Implementation of a state incident response

34 plan and incident response team;

35              (iii) Coordination with state and federal agencies,

36 including without limitation service as the incident response coordinator;

                                        2         03-11-2025 09:57:13 LJH063
    As Engrossed: H2/25/25 H3/11/25                                       HB1549

1                  (iv) Service as a cybersecurity resource for local,

2 state, and federal agencies, utilities and other service providers, academic

3 institutions, and nongovernmental organizations; and

4                  (v) Audit of the compliance of each state agency

5 with state and federal cybersecurity governance standards, policies, and

6 procedures; and

7               (5)(A) Report the audit and enforcement findings of the State

8 Cybersecurity Office in a closed meeting to the Joint Committee on Advanced

9 Communications and Information Technology at least two (2) times per calendar

10 year and at the call of the chair, as appropriate.

11                 (B) The report under subdivision (b)(5)(A) of this section

12 shall detail cyber assessment and remediation actions, department

13 noncompliance, and other cybersecurity efforts that the State Cybersecurity

14 Office determines are relevant.

15  (c) A state agency shall comply with the governance standards,

16 policies, and procedures established by the State Cybersecurity Office under

17 subdivision

18  (b)(4) of this section, except:

19              (1) The standards of a state agency may be more stringent than

20 the statewide minimum standards, but in no case less than the minimum

21 standards; and

22              (2) When federal standards apply that are stricter than the

23 statewide minimums, the federal standards shall apply.

24  (d) The State Information Security Officer may create a Cybersecurity

25 Governance Team to assist the State Cybersecurity Office in the development and

26 administration of the State Cybersecurity Office's cybersecurity plan,

27 standards, policies, and procedures.

28  (e)(1) Except as provided under subdivision (e)(2) of this section,

29 cybersecurity personnel and personnel with job functions that relate to

30 information security within each state agency shall functionally report to the

31 State Cybersecurity Office for the purpose of implementing this section.

32              (2) The positions, funding, and daily management of

33 cybersecurity personnel and personnel with job functions related to

34 information security under subdivision (e)(1) of this section shall remain

35 with each respective state agency.

36  (f) This section shall not be construed as requiring access to data that

                                       3               03-11-2025 09:57:13 LJH063
    As Engrossed: H2/25/25 H3/11/25      HB1549

1 is protected by state or federal law.

2

3   /s/R. Scott Richardson

4

5

6

7

8

9

10

11

12

13

14

15

16

17

18

19

20

21

22

23

24

25

26

27

28

29

30

31

32

33

34

35

36

                                     4   03-11-2025 09:57:13 LJH063
Every fact on this page links to its source, starting with the official bill record.