|
|
|
93RD GENERAL ASSEMBLY
State of Illinois
2003 and 2004 HB6573
Introduced 2/6/2004, by Naomi D. Jakobsson SYNOPSIS AS INTRODUCED: |
|
|
Amends the Data Security on State Computers Act. Provides that drives or disks on State-owned electronic data processing equipment that is to be disposed of must be cleared of all data and software before being prepared for sale, donation, or transfer by following standards established by the Department of Central Management Services by rule (now, must be cleared of all data and software by (i) overwriting the previously stored data at least 10 times and (ii) certifying in writing that the overwriting process has been completed). Effective immediately.
|
| |
|
|
| FISCAL NOTE ACT MAY APPLY | |
|
|
A BILL FOR
|
|
|
|
|
HB6573 |
|
LRB093 19766 MKM 47267 b |
|
|
1 |
| AN ACT concerning data security.
|
2 |
| Be it enacted by the People of the State of Illinois,
|
3 |
| represented in the General Assembly:
|
4 |
| Section 5. The Data Security on State Computers Act is |
5 |
| amended by changing Section 20 as follows:
|
6 |
| (20 ILCS 450/20)
|
7 |
| Sec. 20. Establishment and implementation. The Data |
8 |
| Security on
State Computers Act is established to protect |
9 |
| sensitive data stored on
State-owned electronic data |
10 |
| processing equipment to be (i) disposed of by
sale, donation, |
11 |
| or
transfer or (ii) relinquished to a successor executive |
12 |
| administration. This Act
shall be administered by the |
13 |
| Department or an authorized
agency. The Department or an |
14 |
| authorized agency shall
implement a policy
to mandate that all |
15 |
| hard drives of surplus electronic data processing equipment
be |
16 |
| cleared of all data and software before being prepared for |
17 |
| sale, donation,
or transfer
by
following standards established |
18 |
| by the Department by rule
(i) overwriting the previously stored |
19 |
| data on a drive or a disk at least
10
times
and (ii)
certifying |
20 |
| in writing that the overwriting process has been completed by
|
21 |
| providing
the following information: (1) the serial number of |
22 |
| the computer or other
surplus
electronic data processing |
23 |
| equipment; (2) the name of the overwriting software
used; and |
24 |
| (3) the name, date, and signature of the person performing the
|
25 |
| overwriting process .
The head of each State agency shall
|
26 |
| establish a system for the protection and preservation of State
|
27 |
| data on State-owned electronic data processing equipment |
28 |
| necessary for the
continuity of
government functions upon it |
29 |
| being relinquished to a successor executive
administration.
|
30 |
| (Source: P.A. 93-306, eff. 7-23-03.)
|
31 |
| Section 99. Effective date. This Act takes effect upon |
32 |
| becoming law.
|