SB 185 — Enhance Security of Office of Information Technology
Last action — Governor Signed
-
✓Introduced
-
✓In Committee
-
✓Passed Senate
-
✓Passed House
-
✓To Executive
-
6Enacted
This bill has been enacted into law. Introduced May 01, 2026. Enacted.
Signed by Governor Jared Polis (Democratic) on June 02, 2026.
Odds of enactment
High chanceBased on the sponsor, cosponsors, and committee posture, this bill has a high chance of becoming law.
Upgrade to see the exact probability and what's driving it.
A statistical estimate from our own model of past outcomes — an insight, not a guarantee. Policymaking is volatile.
Prognosis
-
Enacted
Current position in the legislative process.
-
12 sponsors
5 primary, 7 co-sponsors signed on.
-
Bipartisan support
Sponsored across 2 parties (2 D · 1 R) — cross-party backing.
-
Cleared a recorded vote
Passed 6 recorded votes so far.
Based on stage, sponsorship breadth, committee status, recorded votes, and cross-state momentum — a description of the observable signals, not a prediction.
In plain language
The bill enhances the security oversight of Colorado's Office of Information Technology.
This legislation allows for additional audits of the Office of Information Technology if security compliance issues persist. It also mandates that the office maintain updated vendor contracts and submit annual reports on security compliance and risks.
What this means for you
- Workers: This means workers will benefit from improved security measures protecting the state's information technology systems.
Summary
The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
Bill Text
What changed in the latest version
265 added · 354 removedPlain-language change summary
The recent amendment to SB 185 added a note indicating that the bill is ready for the signatures of legislative officers and the Governor, and provided guidance on how to check the bill's status. Additionally, the bill now allows the Joint Technology Committee to call the Chief Information Security Officer to provide testimony regarding compliance reports on information technology security. These changes aim to improve oversight and accountability in information security procedures, ensuring that security measures are adequately addressed and followed.
SecondNOTE: Regular Session Seventy-fifth General Assembly STATE OF COLORADO REREVISED This Version Includes All Amendments Adopted in the Second House LLS NO.
26-0979.02This Nicolebill Myershas x4326been SENATEprepared BILLfor 26-185the SENATEsignatures SPONSORSHIPof Marchmanthe andappropriate Baisley,legislative Colemanofficers HOUSE SPONSORSHIP Titone and Keltie,the Paschal,Governor. Bacon, Carter, Clifford, Jackson, Marshall, Rutinel e n m 2 E n 2 U U 3 O i 1 H a a Senate Committees House Committees R M Business, Labor, & Technology State, Civic, Military, & Veterans Affairs r Appropriations Appropriations 3 d A BILL FOR AN ACT d e 2 C ONCERNING MEASURES TO ENHANCE THE OFFICE OF INFORMATION S a 2 U U 1 TECHNOLOGY S SECURITY PROCEDURES .
HTo gdetermine ywhether dthe MGovernor ehas Billsigned Summarythe dbill (Note:or taken other action on it, please consult the legislative status sheet, the legislative history, or the Session Laws.
ThisSENATE summaryBILL applies26-185 toBY thisSENATOR(S) billMarchman as introduced and doesBaisley, notreflectanyamendmentsthatmaybesubsequentlyadopted.IfthisbillColeman; d passes third reading in the house of introduction, a bill summary that e m 2 applies to the reengrossed version of this bill will be available at T n 2 http://leg.colorado.gov/.) N g 8 E i y S e M Joint Technology Committee.
Thealso billREPRESENTATIVE(S) allowsTitone theand jointKeltie, RPaschal, rBacon, technologyCarter, committeeClifford, (JTC),Jackson, withinMarshall, 90Rutinel. days after the day that the chief 3 information security officer of the office of information technology (securityofficer)filesawritteninformationtechnologycompliancereport (compliancereport)withtheJTCasrequiredbythebill,tovotetorequest i a that the legislative audit committee direct the state auditor to conduct a e 2 T d 0 A n , E d y Shading denotes HOUSE amendment.
DoubleCONCERNING underliningMEASURES denotesTO SENATEENHANCE amendment.THE OFFICE OF INFORMATION TECHNOLOGY S SECURITY PROCEDURES .
S d a Capital letters or bold & italic numbers indicate new material to be added to existing law.n M Dashes through the words or numbers indicate deletions from existing law.
m A special information technology security audit (IT security audit) of the officeofinformationtechnology(OIT)ifthecompliancereportindicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding.
If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the bill requires:
! The state auditor to conduct the IT security audit;
! The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;
! The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor;
and ! OIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit.
The bill requires OIT to establish, maintain, keep, update, and makeavailabletostateagencyinformationtechnologyleadershipandthe members of the JTC, a list of all active information technology vendor contracts for state agencies.
The bill specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technologystandard, and that the standard is void, unless the standard:
! Was publicly posted;
and ! Received approval fromthe securityofficerif the standard relates to security, access controls, or the handling of data.
The bill requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, that the contract maintains current architecture diagrams that are updated at least annually.
The bill prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer.
The bill requires the securityofficer to submit 2 annual reports to theJTC.ThefirstreportisawrittencompliancereportthatincludesOIT's current compliance status with applicable security standards;
all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made;
and a timeline for remediationandamitigationplanorcompensationcontrolsforeachopen audit recommendation made by the state auditor.
The second report is a written statewide information technology securityriskreport(securityriskreport)thatassesses the overall security risk posture of state agencyinformation technology systems.
To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, -2- 185 including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews.
Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information.
The bill requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.
Powersanddutiesofthejointtechnologycommittee.Powers and duties of the joint technology committee.
(13) THETHECOMMITTEEMAYCALLTHECHIEFINFORMATIONSECURITY COMMITTEE MAY CALL THE CHIEF INFORMATION SECURITY OFFICER TO TESTIFY BEFORE THE COMMITTEE REGARDING THE WRITTEN INFORMATIONTECHNOLOGYSECURITYCOMPLIANCEREPORTTHATTHECHIEF INFORMATION TECHNOLOGY SECURITY COMPLIANCEOFFICER REPORTIS THATTHECHIEFINFORMATIONSECURITYOFFICERISREQUIREDTOSUBMITREQUIRED TO SUBMIT TO THE COMMITTEE PURSUANT TO SECTION 24-37.5-403 (2)(j).
(14) W ITHIN NINETY DAYS AFTER THE DAY THAT THE CHIEF INFORMATION SECURITY OFFICER OF THE OFFICE OF INFORMATION TECHNOLOGY________ FILESCapital Aletters WRITTENor INFORMATIONbold TECHNOLOGY& SECURITYitalic COMPLIANCEnumbers REPORTindicate ASnew REQUIREDmaterial BYadded SECTIONto 24-37.5-403existing (2)(jTHElaw; COMMITTEE MAY VOTE TO FORMALLY REQUEST THAT THE LEGISLATIVE AUDIT COMMITTEE ,PURSUANT TO SECTION 2-3-108,VOTE TO DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT OF THE OFFICE IN ACCORDANCE WITH THE STATE AUDITOR 'S AUTHORITY RELATED TO INFORMATION TECHNOLOGY SYSTEMS AS DESCRIBED IN SECTION 2-3-103 (1.5),F:
(a)dashes Tthrough HEwords WRITTENor INFORMATIONnumbers TECHNOLOGYindicate SECURITYdeletions -3-from 185existing COMPLIANCEREPORTREQUIREDBYSECTIONlaw 24-37.5-403(2)(INDICATESand THATsuch ONEmaterial ORis MOREnot AUDITpart RECOMMENDATIONSof MADEthe BYact. THE STATE AUDITOR IS UNRESOLVED TWO OR MORE YEARS PAST THE IMPLEMENTATIONDATEFORTHEAUDITRECOMMENDATIONTOWHICHTHE OFFICE COMMITTED IN A PRIOR COMPLIANCE REPOR;OR (b) A MATERIAL DISCREPANCY EXISTS BETWEEN A REPRESENTATION MADE IN THE WRITTEN INFORMATION TECHNOLOGY SECURITYCOMPLIANCEREPORTREQUIREDBYSECTION 24-37.5-403(2)(j) AND A FINDING MADE IN A PREVIOUS AUDIT BY THE STATE AUDI.OR (15) (a) IA MAJORITY OF THE COMMITTEE VOTES TO REQUEST THAT THE LEGISLATIVE AUDIT COMMITTEE DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT PURSUANT TO SUBSECTION (14)OF THIS SECTION AND IF A MAJORITY OF THE LEGISLATIVE AUDIT COMMITTEEVOTESTOAPPROVEANAUDITPURSUANTTOSECTION 2-3-108, THE STATE AUDITOR SHALL CONDUCT THE INFORMATION TECHNOLOGY SECURITY AUDIT AND MAY CONTRACT WITH A QUALIFIED THIRD-PARTY INFORMATIONTECHNOLOGYSECURITYFIRMTOCONDUCTTHEAUDIT .THE STATE AUDITOR SHALL OBTAIN INPUT FROM THE OFFICE OF INFORMATION TECHNOLOGY WHEN THE STATE AUDITOR DETERMINES THE SCOPE AND BOUNDARIESOFTHEAUDIT ,TAKINGINTOCONSIDERATIONTHERESOURCES AVAILABLE TO THE OFFICE TO REIMBURSE THE AUDITOR FOR THE COST OF THE AUDIT PURSUANT TO SUBSECTION(15)(b)OF THIS SECTI.N (b) THE STATE AUDITOR SHAL,WITHIN TWELVE MONTHS OF THE AFFIRMATIVE VOTE OF A MAJORITY OF THE LEGISLATIVE AUDIT COMMITTEE ,PRODUCE AN INFORMATION TECHNOLOGY SECURITY AUDIT REPORT AND SUBMIT THE AUDIT REPORT TO THE LEGISLATIVE AUDIT COMMITTEE , AFTER WHICH THE STATE AUDITOR SHALL SUBMIT THE -4- 185 REPORT TO THE COMMITTEE ,THE JOINT BUDGET COMMITTEE ,AND THE GOVERNOR .
TECHNOLOGY FILES A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT AS REQUIRED BY SECTION 24-37.5-403 (2)(jTHE COMMITTEE MAY VOTE TO FORMALLY REQUEST THAT THE LEGISLATIVE AUDIT COMMITTEE , PURSUANT TO SECTION 2-3-110,THE2-3-108,VOTE TO DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT OF THE OFFICE SHALLIN REIMBURSETHESTATEAUDITORFORANAUDITCONDUCTEDPURSUANTTOACCORDANCE SUBSECTIONWITH (14)OFTHE THISSTATE SECTIO.AUDITOR S AUTHORITY RELATED TO INFORMATION TECHNOLOGY SYSTEMS AS DESCRIBED IN SECTION 2-3-103 (1.5),F:
(a) T HE WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT REQUIRED BY SECTION 24-37.5-403 (2)(jINDICATES THAT ONE OR MORE AUDIT RECOMMENDATIONS MADE BY THE REIMBURSEMENTSTATE MAYAUDITOR BEIS PAIDUNRESOLVED FROMTHETECHNOLOGYRISKPREVENTIONANDRESPONSEFUNDCREATEDTWOORMORE YEARSPAST THE IMPLEMENTATION DATEFORTHEAUDITRECOMMENDATIONTOWHICHTHEOFFICECOMMITTED IN SECTION24-37.5-120.A PRIOR COMPLIANCE REPORT;OR (b) AMATERIALDISCREPANCYEXISTSBETWEENAREPRESENTATION MADE IN THEWRITTENINFORMATIONTECHNOLOGYSECURITY COMPLIANCE REPORT REQUIRED BY SECTION 24-37.5-403 (2)(AND A FINDING MADE IN A PREVIOUS AUDIT BY THE STATE AUDITOR (15)(a) IAMAJORITYOFTHECOMMITTEEVOTESTOREQUESTTHAT THE LEGISLATIVE AUDIT COMMITTEE DIRECT A SPECIAL INFORMATION TECHNOLOGY SECURITY AUDIT PURSUANT TO SUBSECTION (14) OF THIS SECTION AND IFA MAJORITYOFTHELEGISLATIVEAUDIT COMMITTEE VOTES TOAPPROVEANAUDITPURSUANTTOSECTION 2-3-108,THESTATEAUDITOR SHALLCONDUCTTHEINFORMATIONTECHNOLOGYSECURITYAUDITANDMAY CONTRACT WITH A QUALIFIED THIRD -PARTY INFORMATION TECHNOLOGY SECURITYFIRMTOCONDUCTTHEAUDIT .THESTATEAUDITORSHALLOBTAIN INPUT FROM THE OFFICE OF INFORMATION TECHNOLOGY WHEN THE STATE AUDITOR DETERMINES THE SCOPE AND BOUNDARIES OF THE AUDIT,TAKING INTO CONSIDERATION THE RESOURCES AVAILABLE TO THE OFFICE TO REIMBURSE THE AUDITOR FOR THE COST OF THE AUDIT PURSUANT TO SUBSECTION (15)(b)OF THIS SECTIO.
SECTION2.(b) THE STATE AUDITOR SHALL ,WITHIN TWELVE MONTHS OF THE AFFIRMATIVEVOTEOFAMAJORITYOFTHELEGISLATIVEAUDITCOMMITTEE , PRODUCE AN INFORMATION TECHNOLOGY SECURITY AUDIT REPORT AND SUBMIT THE AUDIT REPORT TO THE LEGISLATIVE AUDIT COMMITTEEAFTER WHICHTHESTATEAUDITORSHALLSUBMITTHEREPORTTOTHECOMMITTEE , PAGE 2-SENATE BILL 26-185 THEJOINTBUDGETCOMMITTEE ,ANDTHEGOVERNOR .PURSUANTTOSECTION 2-3-110,THE OFFICE SHALL REIMBURSE THE STATE AUDITOR FOR AN AUDIT CONDUCTED PURSUANT TO SUBSECTION (14) OF THIS SECTION .
InColoradoRevisedStatutes,24-37.5-105,amendTHE (3)(c),REIMBURSEMENT (3)(d),MAY (6)(c),BE andPAID (6)(d);FROM THE TECHNOLOGY RISK PREVENTION AND RESPONSE FUND CREATED IN SECTION 24-37.5-120.
andSECTION add2. (3)(e), (4.5), and (6)(e) as follows:
In Colorado Revised Statutes, 24-37.5-105, amend (3)(c),(3)(d),(6)(c),and(6)(d);andadd(3)(f),(4.5),and(6)(e)asfollows:
(c) AssistthejointtechnologycommitteeasnecessarytofacilitateAssist the joint technology committee as necessary to facilitate the committee's oversight of the office;
(e)(f)(I)ESTABLISH (I),MAINTAIN ETABLISH,MAINTAINKEEP ,KEEP,,QUARTERLYUPDATE QUARTERLY,ANDMAKE UPDATEAVAILABLETOSTATEAGENCYINFORMATIONTECHNOLOGYLEADERSHIPAND ,THEMEMBERSOFTHEJOINTTECHNOLOGYCOMMITTEE ANDALISTOFALLACTIVE MAKE AVAILABLE TO STATE AGENCY INFORMATION TECHNOLOGY LEADERSHIP AND THE MEMBERS OF THE JOINT TECHNOLOGY COMMITTEE , A LIST OF ALL ACTIVE INFORMATION TECHNOLOGY VENDOR CONTRACTS FOR STATE AGENCIES AS DESCRIBED IN SUBSECTIO(6)OFSUBSECTION (6)OF THIS SECTIO.SECTION.
FOREACHINFORMATIONTECHNOLOGYVENDORCONTRACTFOR THELISTMUSTEACH INFORMATION TECHNOLOGY VENDOR CONTRACT ,THE LIST MUST INCLUDE :
(A) THET HE NAME OF THE VENDOR ;
Show all 83 changed lines (43 more)
(B) THET HE VALUE OF THE CONTRACT;CONTRACT ;
(C) THET HE DATE ON WHICH THE CONTRACT EXPIRES;ANDEXPIRES ;AND (D) T HEHEDATACLASSIFICATION DATA-BUSINESSCRITICALITYTIEROFTHE CLASSIFICATION-BUSINESS CRITICALITY TIER OF -5- 185 THE CONTRACT .
(II) IASTATEAGENCYINITIATESSOLICITATIONSANDCONTRACTSI A STATE AGENCY INITIATES SOLICITATIONS AND CONTRACTS FORINFORMATIONTECHNOLOGYRESOURCESWITHPRIORAPPROVALOFTHE PROCUREMENTOFFICIALFORTHEOFFICEPURSUANTTOSUBSECTIONPROCUREMENT OFFICIAL FOR THE OFFICE PURSUANT TO SUBSECTION (6)OF THIS SECTION, THE STATE AGENCY SHALL PROVIDE TO THE OFFICE THE INFORMATIONPAGE SPECIFIED3-SENATE INBILL SUBSECTION26-185 (3)(e)(IOFINFORMATIONSPECIFIEDINSUBSECTION THIS(3)(f)(OFTHISSECTIONFOREACH SECTION FOR EACH INFORMATION TECHNOLOGY VENDOR CONTRACT ,AND THE OFFICE SHALL INCLUDE THE INFORMATION IN THE LIST REQUIRED BY THIS SUBSECTION (3)(e).(3)(f).
(III) THE OFFICE SHALL SUBMIT A ONE -TIMETIME INFORMATION TECHNOLOGYTECHNOLOGYBUDGETREQUESTTOTHEJOINTTECHNOLOGYCOMMITTEEFOR BUDGET REQUEST TO THE JOINT TECHNOLOGY COMMITTEE FOR THE COST OF BUILDING AND IMPLEMENTING THE LIST REQUIRED BY THIS SUBSECTION (3)(e).F,AFTER(3)(f).F,AFTER THE BUDGET REQUEST IS APPROVED ,,THE THE OFFICE DETERMINES THAT MORE MONEY IS NEEDED TO IMPLEMENT AND MAINTAIN THE LIST ,THE, THE OFFICE MAY REQUEST THAT THE GENERAL ASSEMBLY ALLOCATE ADDITIONAL MONEY FROM THE TECHNOLOGY RISK PREVENTION AND RESPONSE FUND CREATED IN SECTION 24-37.5-120.
(4.5) TechnicalinformationtechnologyTechnical standards.(a)information EXCEPTtechnology ASstandards. OTHERWISE PROVIDED IN SUBSECTION (4.5)(bOF THIS SECTION,THE OFFICE SHALL NOT PUBLISH OR IMPLEMENT A TECHNICAL INFORMATION TECHNOLOGYSTANDARDTHATISESTABLISHEDPURSUANTTOSUBSECTION (4)OF THIS SECTION,AND THE STANDARD IS VOID,UNLESS:
(I)(a) THEEXCEPTASOTHERWISEPROVIDEDINSUBSECTION OFFICE(4.5)(bOFTHIS HASSECTION, PUBLICLY POSTED THE STANDARD;ANDOFFICE (II)SHALL THENOT CHIEFPUBLISH INFORMATIONOR SECURITYIMPLEMENT OFFICERA HASTECHNICAL APPROVEDINFORMATIONTECHNOLOGYSTANDARDTHATISESTABLISHEDPURSUANTTO THESUBSECTION STANDARD(4)OF ,THIS IFSECTION,AND THE STANDARD RELATESIS TOVOID SECURITY,UNLESS: , ACCESS CONTROLS ,OR THE HANDLING OF DATA.
(b)(I) THE PROVISIONSOFFICE OFHAS SUBSECTIONPUBLICLY (4.5)(aOFPOSTED THISTHE SECTIONSTANDARD DO;AND -6-(II) 185HECHIEFINFORMATIONSECURITYOFFICERHASAPPROVEDTHE NOTAPPLYWHENTHECHIEFINFORMATIONSECURITYOFFICERDETERMINESSTANDARD INIFTHESTANDARDRELATESTOSECURITY WRITING,ACCESSCONTROLS THAT,OR ANTHE INFORMATIONHANDLING TECHNOLOGYOF SECURITYDATA EMERGENCY. EXISTS.
FOR(b) PURPOSESTHEPROVISIONSOFSUBSECTION OF(4.5)(aOFTHISSECTIONDONOT THISAPPLY SUBSECTIONWHEN (4.5),ANTHE CHIEF INFORMATION TECHNOLOGY SECURITY EMERGENCYOFFICER MEANSDETERMINES A SITUATION IN WHICHWRITING THAT AN IMMINENT OR ACTIVE THREAT TO STATE INFORMATION TECHNOLOGY SYSTEMS REQUIRES THE IMMEDIATE IMPLEMENTATION OF A SECURITY STANDARDEMERGENCY TOEXISTS. PREVENT OR MITIGATE SIGNIFICANT HARM TO STATE DAT, SYSTEMS ,OR OPERATIONS.
(c)FOR ITHEOFFICEIMPLEMENTSASECURITYSTANDARDINRESPONSEPURPOSES TOOF ANTHIS SUBSECTION (4.5),AN INFORMATION TECHNOLOGY SECURITY EMERGENCY PURSUANTMEANS TOA SUBSECTIONSITUATION (4.5)(bOFIN THISWHICH SECTION,AN THEIMMINENT OFFICEOR SHALLACTIVE POSTTHREAT THETO STANDARDONTHEOFFICESTATE SWEBSITEWITHINSEVENTYINFORMATION -TWOHOURSOFTHETECHNOLOGY SYSTEMS REQUIRES THE IMMEDIATE IMPLEMENTATION OF THEA SECURITY STANDARD TO PREVENT OR MITIGATE SIGNIFICANT HARM TO STATE DATA , SYSTEMS ,OR OPERATIONS .
ASECURITY(c) ITHE OFFICE IMPLEMENTS A SECURITY STANDARD IMPLEMENTEDIN RESPONSE TO AN INFORMATION TECHNOLOGY SECURITY EMERGENCY PURSUANT TO SUBSECTION (4.5)(b)OF THIS SECTION EXPIRES, NINETYTHE DAYSOFFICE AFTERSHALL IMPLEMENTATIONPOST UNLESSTHE ,PRIORPAGE TO4-SENATE EXPIRATION,BILL 26-185 STANDARD ON THE OFFICE COMPLIESS WITHWEBSITE WITHIN SEVENTY -TWO HOURS OF THE REQUIREMENTSIMPLEMENTATION OF SUBSECTIONTHE (4.5)(aOFSECURITY THISSTANDARD SECTIO..
A SECURITY STANDARD IMPLEMENTEDPURSUANTTOSUBSECTION (4.5)(b) OFTHISSECTIONEXPIRES NINETY DAYS AFTER IMPLEMENTATION UNLESS ,PRIOR TO EXPIRATION ,THE OFFICECOMPLIESWITHTHEREQUIREMENTSOFSUBSECTION (4.5)(a)OFTHIS SECTION .
A state agency may initiate solicitations and contracts for information technologytechnologyresources resourcesonlywith only with prior approval of the procurement official for the office, and must include provisions allowingallowingtheofficetoenforcetechnologyandsecuritystandardsorconduct thedue officediligence to enforce technology and security standards or conductduediligenceorauditsofthecontractors.Ifthestateagencydoesaudits notreceivewrittenapprovalordisapprovalfromtheprocurementofficialof -7- 185 fortheofficewithinthirtybusinessdaysaftersubmittingtheprocurement request to the officecontractors. for review, the state agency may assume that it has receivedthepriorapprovaloftheoffice,asrequiredbythissubsection(6), and is authorized to initiate the procurement or solicitation process.
InIf connectionwiththeprocurementofinformationtechnologyresources,thethe state agency does not receive written approval or disapproval from the procurement official for the office shall:within thirty business days after submitting the procurement request to the office for review, the state agency may assume that it has received the prior approval of the office, as required bythis subsection (6), and is authorized to initiate the procurement or solicitation process.
(c)In Overseeinformationtechnologyvendorsonbehalfconnection ofwith thestatethe andprocurement stateof agenciesinformation excepttechnologyresources, whenthe delegatedoffice toshall: a state agency pursuant to section 24-37.5-105.4;
and(c) (d)Oversee Ifinformation thetechnology officevendors doeson notbehalf have oversight of anthe informationstate technologyorservicescontract,ensurethatthestateagencywithoversightand ofstate theagencies contractexcept operateswhen pursuantdelegated to sectiona 24-37.5-105.4state regardingagency thepursuant delegationto ofsection authority;24-37.5-105.4;
and (d) If the office does not have oversight of an information technologyor services contract, ensure that thestate agencywith oversight of the contract operates pursuant to section 24-37.5-105.4 regarding the delegation of authority;AND (e) IACONTRACTIF PROVIDESONGOINGSERVICEANDDELIVERYTOA CONTRACT PROVIDES ONGOING SERVICE AND DELIVERY TO C OLORADANS , ENSURE THAT THE CONTRACT MAINTAINS CURRENT ARCHITECTURE DIAGRAMS THAT ARE UPDATED AT LEAST ANNUALLY .
SECTIONSECTION3. 3.
InInColoradoRevisedStatutes,24-37.5-105.4,amend Colorado Revised Statutes, 24-37.5-105.4, amend (1) introductory portion as follows:
PAGE 5-SENATE BILL 26-185 24-37.5-105.4.
(1) The chief information officer may delegate an information technologyfunctiontechnology function of the office to another state agencybyagreementagency by agreement or other means authorized by law,CEPTlaw, EXCEPT THAT THE CHIEF INFORMATION OFFICERSHALLNOTDELEGATEADUTYOFFICER RESPONSIBILITYORPOWEROFTHESHALL CHIEFINFORMATIONSECURITYOFFICERNOT .ThechiefinformationofficermayDELEGATE delegateA anDUTY information,RESPONSIBILITY technology,OR functionPOWER ofOF theTHE officeCHIEFINFORMATION ifSECURITY inOFFICER the. judgment of the director of the state agency and the chief information officer:
-8-The 185chief SECTION4.information officer may delegateaninformationtechnologyfunctionoftheofficeifinthejudgment of the director of the state agency and the chief information officer:
InColoradoRevisedStatutes,24-37.5-403,amendSECTION (1),4. (2)(h), and (2)(i);
In Colorado Revised Statutes, 24-37.5-403, amend (1), (2)(h), and (2)(i);
(1) ThechiefinformationofficershallappointachiefinformationThe chief information officer shall appoint a chief information security officer who shall serve at the pleasure of the chief information officer.
The security officer shall exhibit a background and expertise in security and risk management for communicationsandcommunications informatioTECHNOLOGY resources.Intheeventthe security officer is unavailable to perform the duties and responsibilities under this part 4, all powers and authority granted to the security officer may MUST be exercised by the chief information officer.TECHNOLOGY resources.
In the event the security officer is unavailable to perform the duties and responsibilities under this part 4, all powers and authority granted to the security officer may MUST be exercised by the chief information officer.
(h) InIncoordinationandconsultationwiththeofficeofstateplanning coordination and consultation with the office of state planning and budgeting and the chief information officer, review public agency budget requests related to information security systems and approve such budgetbudgetrequestsforstateagenciesotherthanthelegislativedepartment;and requests(i) Coordinate with the Colorado commission on higher education for statepurposes agenciesof otherreviewing thanand thecommenting legislativeTO department;REVIEW AND COMMENT on information security plans adopted by institutions of higher education that are submitted pursuant to section 24-37.5-404.5 (3);
and(j) (i)SBMIT CoordinatewiththeColoradocommissiononhighereducationTO forTHE purposesJOINT ofTECHNOLOGY reviewingCOMMITTEE and,ON commentingVIEWANDCOMMENTOR onBEFORE informationsecurityplansadoptedbyinstitutionsofhighereducationthatN areOVEMBER submitted1, pursuant2027, toAND sectionON 24-37.5-404.5OR (3);BEFORE NOVEMBER 1 OF EACH YEAR PAGE 6-SENATE BILL 26-185 THEREAFTER , A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCE REPORT THAT INCLUDES THE FOLLOWING INFORMATION :
(j)(I) SBMITTOTHEJOINTTECHNOLOGYCOMMITTEETHE ,ONORBEFOREOFFICS NCURRENT OVEMBERCOMPLIANCE 1,STATUS 2027ANDWITH ONAPPLICABLE OR BEFORE NOVEMBER 1 OF EACH YEAR THEREAFTER , A WRITTEN INFORMATION TECHNOLOGY SECURITY COMPLIANCESTANDARDS REPORT; THAT INCLUDES THE FOLLOWING INFORMATION:
-9-(II) 185ALL (I)OPEN HEOFFICE'SCURRENTAUDIT COMPLIANCESTATUSWITHAPPLICABLERECOMMENDATIONS SECURITYMADE STANDARDSBY THE OFFICE OF THESTATEAUDITORANDTHEDATEONWHICHEACHRECOMMENDATIONWAS MADE ;
(II)(III) ALOPENAUDITA RECOMMENDATIONSMADETIMELINE BYTHEFOR REMEDIATION FOR EACH OPEN RECOMMENDATION MADE BY THE OFFICE OF THE STATE AUDITOR AND;AND THE(IV) DATEA ONMITIGATION WHICHPLAN OR COMPENSATING CONTROLS FOR THE REMEDIATION OF EACH OPEN RECOMMENDATION WAS MADE ;BY THE OFFICE OF THE STATE AUDITOR;AND (k) (I) UBMIT TO THE JOINT TECHNOLOGY COMMITTEE ,ON OR BEFORE NOVEMBER 1,2027,ANDONORBEFORE NOVEMBER 1OFEACHYEAR THEREAFTER ,A WRITTEN STATEWIDE INFORMATION TECHNOLOGY SECURITY RISK REPORT THAT ASSESSES THE OVERALL SECURITY RISK POSTURE OF STATE AGENCY INFORMATION TECHNOLOGY SYSTEMS .
(III)(II) AT TIMELINESUPPORT FOR REMEDIATION FOR EACH OPEN RECOMMENDATION MADE BY THE OFFICEPREPARATION OF THE STATESECURITY AUDITOR;ANDRISK (IV)REPORT AREQUIRED MITIGATIONBY PLANSUBSECTION OR(2)(k)(I)OF COMPENSATINGTHIS CONTROLSSECTION FOR, THE REMEDIATIONCHIEF OFINFORMATION EACHSECURITY OPENOFFICER RECOMMENDATIONMAY MADECONDUCT BYEVALUATIONS THE OFFICE OF THE STATE AUDITOR;ANDAGENCY (k)INFORMATION (I)TECHNOLOGY SBMITSYSTEMS TOAS THE JOINTCHIEFINFORMATION TECHNOLOGY COMMITTEE ,ON OR BEFORE N OVEMBER 1, 2027,AND ON OR BEFORE NOVEMBER 1OF EACH YEAR THEREAFTER ,A WRITTEN STATEWIDE INFORMATION TECHNOLOGY SECURITY RISKOFFICER REPORTDEEMS THATNECESSARY,INCLUDING ASSESSESPENETRATION THETESTING, OVERALLVULNERABILITY SECURITYSCANNING RISK,CONFIGURATION POSTUREEVALUATIONS OF,AND STATEVENDOR AGENCYAND INFORMATIONSYSTEM TECHNOLOGYREVIEWS SYSTEMS .
(II)(III) TSUPPORTEACH THEPREPARATIONOFTHESECURITYRISKREPORTSTATE REQUIREDAGENCY BYSHALL SUBSECTIONPROVIDE (2)(k)(I)OFTO THIS SECTION, THE CHIEF INFORMATION SECURITY OFFICER MAY, UPON REQUEST , THE ACCESS AND INFORMATION NECESSARY TO CONDUCT EVALUATIONS OFPURSUANT STATETO AGENCYINFORMATIONTECHNOLOGYSYSTEMSASTHECHIEFINFORMATIONSUBSECTION SECURITYOFFICERDEEMSNECESSARY(2)(k)(IIOF ,INCLUDINGPENETRATIONTESTINGTHIS ,SECTION, VULNERABILITYSCANNINGINCLUDING ,CONFIGURATIONEVALUATIONSSYSTEM ,ANDVENDORACCESS AND, SYSTEMPRODUCT REVIEWSINFORMATION ,AND ARCHITECTURE INFORMATION .
(III)(4) EACHT STATEHE AGENCYCHIEF SHALLINFORMATION PROVIDESECURITY TOOFFICER, OR THE CHIEF INFORMATION OFFICER IF THE SECURITY OFFICER ,IS UPONUNAVAILABLESHALL REQUESTPERFORMTHEDUTIESANDUPHOLDTHERESPONSIBILITIESASSIGNEDTOTHE ,THEPAGE ACCESS7-SENATE ANDBILL INFORMATION26-185 NECESSARYCHIEF TOINFORMATION CONDUCTSECURITY EVALUATIONSOFFICER PURSUANT TO SUBSECTION (2)(k)(IIOF THIS SECTION,INCLUDINGPART SYSTEM4. ACCESS , PRODUCT INFORMATION ,AND ARCHITECTURE INFORMATION .
-10-THE 185CHIEF (4)INFORMATION TOFFICER HESHALL CHIEFNOT INFORMATIONDELEGATE SECURITYTHE OFFICER,DUTIES OR, RESPONSIBILITIES,OR POWERS OF THE CHIEF INFORMATION SECURITY OFFICER IFTO THEANY SECURITYPERSON OFFICEROTHER ISTHAN UNAVAILAB,SHALLTHE PERFORMTHEDUTIESANDUPHOLDTHERESPONSIBILITIESASSIGNEDTOTHE CHIEF INFORMATION SECURITY OFFICEROFFICER. PURSUANT TO THIS PART 4.
HENOTHING IN THIS SECTION PREVENTS THE CHIEF INFORMATION SECURITY OFFICER SHALLFROM NOTDIRECTING DELEGATEPERSONNEL WITHIN THE DUTIESINFORMATION ,SECURITY RESPONSIBILITIE,OFFICE ORTO POWERSCARRY OFOUT SECURITY FUNCTIONS UNDER THE CHIEF INFORMATIONINFORMATIONSECURITYOFFICER SECURITYSSUPERVISIONANDACCOUNTABILITY OFFICER.THE TOCHIEFINFORMATIONSECURITYOFFICERISRESPONSIBLEFORTHEACCURACY ANYOF PERSONTHE OTHERCOMPLIANCE THANREPORT THEREQUIRED CHIEFIN INFORMATIONSUBSECTION (2)(jOF THIS SECTION AND THE SECURITY OFFICER.RISK REPORT REQUIRED IN SUBSECTION (2)(k) OFTHISSECTION ,REGARDLESSOFWHICHPERSONNELCONTRIBUTEDTOTHE PREPARATION OF THE REPORTS .
NOTHING IN THIS SECTION PREVENTS THE CHIEF INFORMATION SECURITYOFFICERFROMDIRECTINGPERSONNELWITHINTHEINFORMATION SECURITY OFFICE TO CARRY OUT SECURITY FUNCTIONS UNDER THE CHIEF INFORMATION SECURITY OFFICER S SUPERVISION AND ACCOUNTABILITY .
T HE CHIEF INFORMATION SECURITY OFFICER IS RESPONSIBLE FOR THE ACCURACY OF THE COMPLIANCE REPORT REQUIRED IN SUBSECTION (2)(j) OF THIS SECTION AND THE SECURITY RISK REPORT REQUIRED IN SUBSECTION (2)(k)OF THIS SECTIO,REGARDLESS OF WHICH PERSONNEL CONTRIBUTED TO THE PREPARATION OF THE REPORTS .
on the day following the expiration of the ninety-dayperiodafterfinaladjournmentofthegeneralassembly(Augustninety-dayperiod after final adjournment of the general assembly(August 12, 2026, if adjournment sine die is on May 13, 2026);
except that, if a referendumreferendumpetitionisfiledpursuanttosection1(3)ofarticleVofthestate petition is filed pursuant to section 1 (3) of article V of the state constitution against this act or an item, section, or part of this act within such period, then the act, item, section, or part will not take effect unless approvedPAGE by8-SENATE theBILL people26-185 atapprovedbythepeopleatthegeneralelectiontobeheldinNovember2026 the general election to be held in November 2026 and, in such case, will take effect on the date of the official declaration of the vote thereon by the governor.
-11-____________________________ 185____________________________ James Rashad Coleman, Sr.
Julie McCluskie PRESIDENT OF SPEAKER OF THE HOUSE THE SENATE OF REPRESENTATIVES ____________________________ ____________________________ Esther van Mourik Vanessa Reilly SECRETARY OF CHIEF CLERK OF THE HOUSE THE SENATE OF REPRESENTATIVES APPROVED________________________________________ (Date and Time) _________________________________________ Jared S.
Polis GOVERNOR OF THE STATE OF COLORADO PAGE 9-SENATE BILL 26-185
Show all 83 changed rows (43 more)
Action History
-
Governor Signed
-
Signed by the President of the Senate
-
Signed by the Speaker of the House
-
Sent to the Governor
-
House Third Reading Passed - No Amendments
-
House Committee on Appropriations Refer Unamended to House Committee of the Whole
-
House Second Reading Special Order - Passed - No Amendments
-
House Committee on State, Civic, Military, & Veterans Affairs Refer Unamended to Appropriations
-
Senate Third Reading Passed - No Amendments
-
Introduced In House - Assigned to State, Civic, Military, & Veterans Affairs
-
Senate Committee on Appropriations Refer Unamended - Consent Calendar to Senate Committee of the Whole
-
Senate Second Reading Special Order - Passed with Amendments - Committee
-
Senate Committee on Business, Labor, & Technology Refer Amended to Appropriations
-
Introduced In Senate - Assigned to Business, Labor, & Technology
Sponsors
- M. Rutinel · Cosponsor
- B. Marshall · Cosponsor
- J. Jackson · Cosponsor
- C. Clifford · Cosponsor
- M. Carter · Cosponsor
- J. Bacon · Cosponsor
- A. Paschal · Primary
- B. Titone · Primary
- R. Keltie · Primary
- Mark Baisley · Primary
- Janice Marchman · Primary
- James Coleman · Cosponsor
Sponsorship breakdown
Export CSV (upgrade) →5 sponsors · 7 co-sponsors · 89 not signed on
Sponsors (5)
- A. Paschal
- B. Titone
- R. Keltie
- Mark Baisley Republican
- Janice Marchman Democrat
Co-sponsors (7)
- M. Rutinel
- B. Marshall
- J. Jackson
- C. Clifford
- M. Carter
- J. Bacon
- James Coleman Democrat
Not signed on (89)
89 members have not signed on to this bill.
Show all 89 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Votes
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Democrat | 41 | 0 | 0 | 0 |
| Republican | 19 | 0 | 0 | 0 |
| Unaffiliated | 4 | 1 | 0 | 0 |
| Total | 64 | 1 | 0 | 0 |
| % of votes cast | 98% | 2% | 0% | 0% |
How each member voted (65)
| Member | Party | Vote |
|---|---|---|
| Gonzalez R. | — | Nay |
| Stewart K. | — | Yea |
| Stewart R. | — | Yea |
| Winter T. | — | Yea |
| Garcia Sander | — | Yea |
| Alex Valdez | Democrat | Yea |
| Amy Paschal | Democrat | Yea |
| Andrew Boesenecker | Democrat | Yea |
| Bob Marshall | Democrat | Yea |
| Brianna Titone | Democrat | Yea |
| Cecelia Espenoza | Democrat | Yea |
| Chad Clifford | Democrat | Yea |
| Eliza Hamrick | Democrat | Yea |
| Elizabeth Velasco | Democrat | Yea |
| Emily Sirota | Democrat | Yea |
| Gretchen Rydin | Democrat | Yea |
| Jacque Phillips | Democrat | Yea |
| Jamie Jackson | Democrat | Yea |
| Javier Mabrey | Democrat | Yea |
| Jennifer Bacon | Democrat | Yea |
| Jenny Willford | Democrat | Yea |
| Julie McCluskie | Democrat | Yea |
| Junie Joseph | Democrat | Yea |
| Karen McCormick | Democrat | Yea |
| Kenny Nguyen | Democrat | Yea |
| Kyle Brown | Democrat | Yea |
| Lesley Smith | Democrat | Yea |
| Lindsay Gilchrist | Democrat | Yea |
| Lisa Feret | Democrat | Yea |
| Lorena Garcia | Democrat | Yea |
| Lori Goldstein | Democrat | Yea |
| Mandy Lindsay | Democrat | Yea |
| Manny Rutinel | Democrat | Yea |
| Matthew Martinez | Democrat | Yea |
| Meg Froelich | Democrat | Yea |
| Meghan Lukens | Democrat | Yea |
| Michael Carter | Democrat | Yea |
| Monica Duran | Democrat | Yea |
| Naquetta Ricks | Democrat | Yea |
| Regina English | Democrat | Yea |
| Sean Camacho | Democrat | Yea |
| Sheila Lieder | Democrat | Yea |
| Steven Woodrow | Democrat | Yea |
| Tammy Story | Democrat | Yea |
| Tisha Mauro | Democrat | Yea |
| Yara Zokaie | Democrat | Yea |
| Anthony Hartsook | Republican | Yea |
| Ava Flanell | Republican | Yea |
| Brandi Bradley | Republican | Yea |
| Carlos Barron | Republican | Yea |
| Chris Richardson | Republican | Yea |
| Dan Woog | Republican | Yea |
| Dusty Johnson | Republican | Yea |
| Jarvis Caldwell | Republican | Yea |
| Ken DeGraaf | Republican | Yea |
| Larry Don Suckla | Republican | Yea |
| Mary Bradfield | Republican | Yea |
| Matt Soper | Republican | Yea |
| Max Brooks | Republican | Yea |
| Rebecca Keltie | Republican | Yea |
| Rick Taggart | Republican | Yea |
| Ron Weinberg | Republican | Yea |
| Scott Bottoms | Republican | Yea |
| Scott Slaugh | Republican | Yea |
| Stephanie Luck | Republican | Yea |
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Democrat | 7 | 0 | 0 | 1 |
| Republican | 3 | 0 | 0 | 0 |
| Total | 10 | 0 | 0 | 1 |
| % of votes cast | 91% | 0% | 0% | 9% |
How each member voted (11)
| Member | Party | Vote |
|---|---|---|
| Andrew Boesenecker | Democrat | Yea |
| Brianna Titone | Democrat | Yea |
| Elizabeth Velasco | Democrat | Yea |
| Emily Sirota | Democrat | Yea |
| Junie Joseph | Democrat | Yea |
| Karen McCormick | Democrat | Yea |
| Kyle Brown | Democrat | Yea |
| Yara Zokaie | Democrat | Not Voting |
| Matt Soper | Republican | Yea |
| Rick Taggart | Republican | Yea |
| Scott Bottoms | Republican | Yea |
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Republican | 3 | 0 | 0 | 0 |
| Democrat | 8 | 0 | 0 | 0 |
| Total | 11 | 0 | 0 | 0 |
| % of votes cast | 100% | 0% | 0% | 0% |
How each member voted (11)
| Member | Party | Vote |
|---|---|---|
| Cecelia Espenoza | Democrat | Yea |
| Chad Clifford | Democrat | Yea |
| Jenny Willford | Democrat | Yea |
| Kenny Nguyen | Democrat | Yea |
| Lisa Feret | Democrat | Yea |
| Meg Froelich | Democrat | Yea |
| Michael Carter | Democrat | Yea |
| Naquetta Ricks | Democrat | Yea |
| Brandi Bradley | Republican | Yea |
| Ken DeGraaf | Republican | Yea |
| Stephanie Luck | Republican | Yea |
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Democrat | 4 | 0 | 0 | 0 |
| Republican | 3 | 0 | 0 | 0 |
| Total | 7 | 0 | 0 | 0 |
| % of votes cast | 100% | 0% | 0% | 0% |
How each member voted (7)
| Member | Party | Vote |
|---|---|---|
| Chris Kolker | Democrat | Yea |
| Jeff Bridges | Democrat | Yea |
| Judy Amabile | Democrat | Yea |
| Julie Gonzales | Democrat | Yea |
| Barbara Kirkmeyer | Republican | Yea |
| Byron Pelton | Republican | Yea |
| Larry Liston | Republican | Yea |
Roll call published as PDF — view source.
| Party | Yea | Nay | Present | Not Voting |
|---|---|---|---|---|
| Republican | 2 | 0 | 0 | 0 |
| Democrat | 3 | 0 | 0 | 0 |
| Total | 5 | 0 | 0 | 0 |
| % of votes cast | 100% | 0% | 0% | 0% |
How each member voted (5)
| Member | Party | Vote |
|---|---|---|
| Iman Jodeh | Democrat | Yea |
| Jessie Danielson | Democrat | Yea |
| Nick Hinrichsen | Democrat | Yea |
| Larry Liston | Republican | Yea |
| Marc Catlin | Republican | Yea |
Subjects
Frequently asked questions
- What does SB 185 do?
- The act allows the joint technology committee (JTC), within 90 days after the day that the chief information security officer of the office of information technology (security officer) files a written information technology security compliance report (compliance report) with the JTC as required by the act, to vote to request that the legislative audit committee direct the state auditor to conduct a special information technology security audit (IT security audit) of the office of information technology (OIT) if the compliance report indicates that one or more audit recommendations made by the state auditor is unresolved 2 or more years past the implementation date for the audit recommendation or if a material discrepancy exists between a representation in the compliance report and a previous audit finding. If the JTC votes to request an IT security audit and if the legislative audit committee votes to direct the audit, the act requires:The state auditor to conduct the IT security audit;The state auditor to obtain input from OIT when the state auditor determines the scope and boundaries of the audit;The state auditor to submit the IT security audit report to the legislative audit committee, the JTC, the joint budget committee, and the governor; andOIT to reimburse the state auditor for the auditor's costs incurred in completing the IT security audit. The act requires OIT to establish, maintain, keep, update, and make available to state agency information technology leadership and the members of the JTC a list of all active information technology vendor contracts for state agencies. The act specifies that, except in the case of an information technology security emergency, OIT shall not publish or implement a technical information technology standard, and that the standard is void, unless the standard:Was publicly posted; andReceived approval from the security officer if the standard relates to security, access controls, or the handling of data. The act requires OIT to ensure that, if an information technology contract provides ongoing service and delivery to Coloradans, the contract maintains current architecture diagrams that are updated at least annually. The act prohibits the chief information officer from delegating a duty, responsibility, or power of the security officer. The act requires the security officer to submit 2 annual reports to the JTC. The first report is a written compliance report that includes OIT's current compliance status with applicable security standards; all open audit recommendations regarding OIT made by the state auditor and the date on which each recommendation was made; and a timeline for remediation and a mitigation plan or compensation controls for each open audit recommendation made by the state auditor. The second report is a written statewide information technology security risk report (security risk report) that assesses the overall security risk posture of state agency information technology systems. To support the preparation of the security risk report, the security officer may conduct evaluations of state agency information technology systems, including penetration testing, vulnerability scanning, configuration evaluations, and vendor and system reviews. Each state agency shall provide to the security officer, upon request, the access and information necessary to conduct evaluations of state agency technology systems, including system access, product information, and architecture information. The act requires the security officer, or the chief information officer if the security officer is unavailable, to perform the duties and uphold the responsibilities assigned to the security officer pursuant to law.(Note: This summary applies to this bill as enacted.)
- Who sponsors SB 185?
- SB 185 is sponsored by M. Rutinel, B. Marshall, J. Jackson, C. Clifford, M. Carter, J. Bacon, A. Paschal, B. Titone, R. Keltie, Mark Baisley (Republican), Janice Marchman (Democrat), and James Coleman (Democrat).
- What is the current status of SB 185?
- This bill has been enacted into law. Introduced May 01, 2026. Enacted.
- Where can I track SB 185?
- Track SB 185 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on SB 185
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of SB 185
Last checked for changes 3 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →