Amend CSHB 8 (house committee report) as follows:
(1)  On page 8, line 8, strike "Sections 2054.0593 and" and substitute "Section".
(2)  Strike page 8, line 10, through page 9, line 16.
(3)  On page 9, line 10 strike "; and" and substitute ";".
(4)  On page 9, line 11, between "(6)" and "provide", insert the following:
consider the costs and benefits of establishing a computer emergency readiness team to address cyber attacks occurring in this state during routine and emergency situations;
(7)  establish criteria and priorities for addressing cybersecurity threats to critical state installations, including energy infrastructures and communication providers; and
(8)
(5)  On page 12, line 8, between "breaches." and "If" insert the following:
The plan at a minimum must include solutions that isolate and segment sensitive information and maintain architecturally sound and secured separation among networks.
(6)  On page 13, line 7, strike "demonstrate" and substitute "contractually warrant".
(7)  On page 17, strike lines 9 and 10 and substitute the following:
resources technology for a state agency is responsible for addressing known cybersecurity risks associated with the technology and is responsible for any cost associated with addressing the identified cybersecurity risks. For a major information resources project, the vendor shall provide to state agency contracting personnel:
(8)  On page 17, on both lines 14 and 21, between "2054.516" and the underlined semicolon, insert "or 2054.517".
(9)  Strike page 19, line 26, through page 20, line 1, and substitute the following:
other information identifies an individual in connection with the agency's networks, computers, software, or data storage if the agency is otherwise prohibited by law from retaining the information for a period of years.
(10)  Add the following appropriately numbered SECTIONS to the bill and renumber the SECTIONS of the bill accordingly:
SECTION ____.  Section 2054.512, Government Coe, is amended to read as follows:
SECTION ____.  Section 552.139, Government Code, is amended by adding Subsection (d) to read as follows:
(d)  When posting a contract on an Internet website as required by  2261.253, a state agency shall redact information made confidential by this section or excepted from public disclosure by this section. Redaction under this subsection does not except information from the requirements of Section 552.021.
Sec. 2054.512.  CYBERSECURITY [PRIVATE INDUSTRY-GOVERNMENT] COUNCIL. (a)  The state cybersecurity coordinator shall [may] establish and lead a cybersecurity council that includes public and private sector leaders and cybersecurity practitioners to collaborate on matters of cybersecurity concerning this state.
(b)  The cybersecurity council must include:
(1)  one member appointed by the governor;
(2)  one member of the senate appointed by the lieutenant governor;
(3)  one member of the house of representatives appointed by the speaker of the house of representatives; and
(4)  additional members appointed by the state cybersecurity coordinator, including representatives of institutions of higher education and private sector leaders.
(c)  In appointing representatives from institutions of higher education to the cybersecurity council, the state cybersecurity coordinator shall consider appointing members of the Information Technology Council for Higher Education.
(d)  The cybersecurity council shall provide recommendations to the legislature on any legislation necessary to implement cybersecurity best practices and remediation strategies for this state.