Data breach reporting -- Coordination with Utah Cyber Center.

Utah Code § 53G-8-903, under Part 53G-8-9: LEA Cybersecurity Standards.

Utah Code § 53G-8-903

53G-8-903. Data breach reporting -- Coordination with Utah Cyber Center.

(1) An LEA shall report a data breach to the Cyber Center: in accordance with Section; and 63A-19-405 consistent with standards and procedures established in rule under Subsection. 63C-27-202(9)

(2) In addition to the requirements in Section, an LEA shall: 63A-19-405 notify the state board within 24 hours of discovering the data breach; coordinate with UETN if the data breach involves network infrastructure or services provided by UETN; and cooperate with the Cyber Center's investigation and response efforts.

(3) The Cyber Center shall provide assistance to an LEA in responding to a data breach in the same manner the Cyber Center provides assistance to a governmental entity as described in Title 63A, Chapter 16, Part 11, Utah Cyber Center.

(4) An LEA shall: participate in cybersecurity information sharing initiatives coordinated by the Cyber Center; designate a primary point of contact for cybersecurity matters who shall interface with the Cyber Center, the state board, and UETN; and cooperate with statewide cybersecurity assessments and improvement initiatives.

(5) A regional education service agency, as that term is defined in Section, may serve as the designated primary cybersecurity contact for multiple LEAs within the service area. 53G-4-410 If a regional education service agency serves as the primary contact under Subsection, the agency shall: (5)(a) coordinate with the Cyber Center, the state board, and UETN on behalf of the participating LEAs; ensure each participating LEA meets the minimum cybersecurity standards established under Subsection; and 63C-27-202(9) maintain documentation of cybersecurity services provided to each LEA.