63C-27-202. Commission duties.
The commission shall:
(1) identify and inform the governor of: cyber threats and vulnerabilities towards Utah's critical infrastructure; cybersecurity assets and resources; and an analysis of: current cyber incident response capabilities; potential cyber threats; and areas of significant concern with respect to: vulnerability to cyber attack; or seriousness of consequences in the event of a cyber attack;
(2) provide resources with respect to cyber attacks in both the public and private sector, including: best practices; education; and mitigation;
(3) promote cyber security awareness;
(4) share information;
(5) promote best practices to prevent and mitigate cyber attacks;
(6) enhance cyber capabilities and response for all Utahns;
(7) provide consistent outreach and collaboration with private and public sector organizations;
(8) share cyber threat intelligence to operators and overseers of Utah's critical infrastructure; and
(9) in accordance with Title 63G, Chapter 3, Utah Administrative Rulemaking Act, make rules establishing minimum cybersecurity standards for a local education agency, as that term is defined in Section, that: 53G-3-402 align with industry recognized cybersecurity frameworks and standards, including frameworks developed by the National Institute of Standards and Technology, the Center for Internet Security, or a successor organization; take into account varying local education agency resources, capacity, and needs; establish phased implementation timelines based on local education agency size, existing cybersecurity infrastructure, and available resources; and as appropriate based on the local education agency's size, risk profile, and available resources, shall address: identity and access management; asset management and inventory of hardware, software, and data systems; data protection; security monitoring and logging capabilities; vulnerability management, including regular security assessments and patching procedures; incident response and recovery planning; security awareness training requirements for staff and administrators; third-party risk management for vendors with access to local education agency systems or data; network security controls; backup and disaster recovery procedures; and governance structures for cybersecurity oversight within a local education agency.