SENATE DOCKET, NO. 805        FILED ON: 1/18/2023

SENATE  .  .  .  .  .  .  .  .  .  .  .  .  .  .  No. 26

 

The Commonwealth of Massachusetts

_________________

PRESENTED BY:

Brendan P. Crighton

_________________

To the Honorable Senate and House of Representatives of the Commonwealth of Massachusetts in General
Court assembled:

The undersigned legislators and/or citizens respectfully petition for the adoption of the accompanying bill:

An Act relative to the modernization of state agency information technology systems.

_______________

PETITION OF:

 

Name:

District/Address:

Brendan P. Crighton

Third Essex


SENATE DOCKET, NO. 805        FILED ON: 1/18/2023

SENATE  .  .  .  .  .  .  .  .  .  .  .  .  .  .  No. 26

By Mr. Crighton, a petition (accompanied by bill, Senate, No. 26) of Brendan P. Crighton for legislation to modernize state agency information technology systems.  Advanced Information Technology, the Internet and Cybersecurity.

 

The Commonwealth of Massachusetts

 

_______________

In the One Hundred and Ninety-Third General Court
(2023-2024)

_______________

 

An Act relative to the modernization of state agency information technology systems.

 

Be it enacted by the Senate and House of Representatives in General Court assembled, and by the authority of the same, as follows:
 

SECTION 1. Chapter 7D of the General Laws, as appearing in the Official 2018 Edition, is hereby amended by inserting the following section:-

“SECTION 11. Massachusetts Innovation Fund and State Agency Technology Upgrades Account

(a) As used in this section, the following terms shall have the following meanings:-

"Account," the state agency technology upgrades account.

"Board," the Massachusetts innovation fund board.

"Cloud computing service" has the meaning given the term by the National Institute of Standards and Technology in NIST Special Publication 800-145 and any amendatory or superseding document thereto.

"Device-as-a-service," a managed service in which hardware that belongs to a managed service provider is installed at a state agency and a service level agreement defines the responsibilities of each party to the agreement.

"Fund," means the Massachusetts Innovation Fund.

"Information technology system," any equipment or interconnected system or subsystem of equipment used by a state agency, or a person under a contract with a state agency if the contract requires use of the equipment, to acquire, store, analyze, evaluate, manipulate, manage, move, control, display, switch, interchange, transmit, print, copy, scan, or receive data or other information. “Information technology system” shall include a computer, a device-as-a-service solution, ancillary computer equipment such as imaging, printing, scanning, and copying peripherals and input, output, and storage devices necessary for security and surveillance, peripheral equipment designed to be controlled by the central processing unit of a computer, software and firmware and similar procedures, and services, including support services, and related resources. “Information technology system” shall not include equipment acquired by a contractor incidental to a state contract.

"Legacy information technology system," is an information technology system that is operated with outdated or obsolete, or inefficient hardware or software system of information technology.

"Qualifying information technology modernization project," a project by a state agency to (i) replace the agency's information technology systems;(ii) transition the agency's legacy information technology systems to a cloud computing service or other innovative commercial platform or technology; or (iii) develop and implement a method to provide adequate, risk-based, and cost-effective information technology responses to threats to the agency's information security.

(b) The Massachusetts innovation fund board is established to administer the Massachusetts innovation fund and the state agency technology upgrades account and to make awards of financial assistance to state agencies from the fund or account for qualifying information technology modernization projects. The board shall consist of: (i) the comptroller or a designee (ii) the secretary of the executive office of technology services and security or a designee (iii) the governor or a designee (iv) two members of the senate appointed by the president of the senate;(v) two members of the house of representatives appointed by the speaker of the house of representatives; (vi) one member of the public with relevant subject matter expertise appointed by the governor; and (vii) three state employees primarily having technical expertise information technology development, financial management, cybersecurity and privacy, and acquisition, appointed by the secretary of the executive office of technology services and security.

(c) Members of the board shall serve six two-year terms. A board member is not entitled to compensation for service on the board but is entitled to reimbursement of expenses incurred while performing duties as a board member.

(d) The Massachusetts innovation fund and the state agency technology upgrades account are special funds outside the state treasury to be used by the board, without further legislative appropriation, as provided by this section.

(e) The fund consists of:

(1) money appropriated, credited, or transferred to the fund by the legislature;

(2) money received by the board for the repayment of a loan made from the fund; and

(3) interest and other earnings earned on deposits and investments of money in the fund.

(f) The account consists of:

(1) money deposited to the account by the comptroller in the manner prescribed by subsection (h); and

(2) interest and other earnings earned on deposits and investments of money in the account.

(g) The comptroller, in consultation with the executive office of technology services and security, shall establish a loan program to authorize the board to use money from the fund to provide loans to state agencies for qualifying information technology modernization projects. A state agency must apply to the board for a loan from the fund. The application must include a description of the qualifying information technology modernization project for which the state agency is requesting a loan. A loan agreement entered into under this subsection must require the state agency to:

(1) repay the loan to the board within seven years of the date the loan is made to the agency; and

(2) make annual reports to the board identifying cost savings realized by the agency as a result of the project for which the agency received the loan.

(h) At the end of each state fiscal year, on the written request of a state agency, the comptroller shall deposit to the account the unexpended balance of any money appropriated to the agency for that state fiscal year that is budgeted by the agency for information technology services or cybersecurity purposes. A state agency may request money from the account from the board at any time for a qualifying information technology modernization project.

(i) The comptroller shall separately account for the amount of money deposited to the account at the request of each state agency under Subsection (h). Money deposited to the account under subsection (h) and any interest and other earnings on that money may be provided only to the state agency for which the comptroller deposited the money to the account and may be used by the agency only for a qualifying information technology modernization project.

(j) Any money deposited to the account at the request of a state agency under subsection (h) that is not requested by the agency within three years from the date the money is deposited shall be transferred by the comptroller to the general revenue fund to be used in accordance with legislative appropriation.

(k) A state agency that receives money from the fund or the account may collaborate with one or more other state agencies that also receive money from the fund or the account to purchase information technology systems that may be shared between the agencies.

(l) The comptroller may adopt rules to implement and administer this section.”

SECTION 2. This Act shall take effect upon its passage.