Sec. 2054.077. VULNERABILITY REPORTS  


Latest version.
  • (a) In this section, a term defined by Section 33.01, Penal Code, has the meaning assigned by that section.

    (b) The information resources manager of a state agency may prepare or have prepared a report, including an executive summary of the findings of the report, assessing the extent to which a computer, a computer program, a computer network, a computer system, an interface to a computer system, computer software, or data processing of the agency or of a contractor of the agency is vulnerable to unauthorized access or harm, including the extent to which the agency's or contractor's electronically stored information is vulnerable to alteration, damage, erasure, or inappropriate use.

    (c) Except as provided by this section, a vulnerability report and any information or communication prepared or maintained for use in the preparation of a vulnerability report is confidential and is not subject to disclosure under Chapter 552.

    (d) The information resources manager shall provide an electronic copy of the vulnerability report on its completion to:

    (1) the department;

    (2) the state auditor;

    (3) the agency's executive director; and

    (4) any other information technology security oversight group specifically authorized by the legislature to receive the report.

    (e) Separate from the executive summary described by Subsection (b), a state agency whose information resources manager has prepared or has had prepared a vulnerability report shall prepare a summary of the report that does not contain any information the release of which might compromise the security of the state agency's or state agency contractor's computers, computer programs, computer networks, computer systems, computer software, data processing, or electronically stored information. The summary is available to the public on request.

Added by Acts 2001, 77th Leg., ch. 792, Sec. 1, eff. June 14, 2001. Amended by: Acts 2009, 81st Leg., R.S., Ch. 183 , Sec. 5, eff. September 1, 2009.