yourstate.us
Nev. Rev. Stat. § 242.1285

Statewide strategic plan: Requirements; biannual updates; use by private entity; testing of adherence to cybersecurity policy

Nevada · Nevada Revised Statutes Chapter 242 — Information Services · Status: effective

Get this as JSONEmbed this
Cite this
Citation
Nev. Rev. Stat. § 242.1285, Statewide strategic plan: Requirements; biannual updates; use by private entity; testing of adherence to cybersecurity policy, Nevada, version 1 as recorded 2026-10-03, yourstate.us, https://yourstate.us/provision/2094428
Permanent ID
ys:prov:2094428@1
SHA-256
bf2faeb93ce356e8aa98d83419e1654cbbe26462241421f1926582b240b780e7

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

1. The Office of Information Security and Cyber Defense shall prepare and make publicly available a statewide strategic plan that outlines policies, procedures, best practices and recommendations for preparing for and mitigating risks to, and otherwise protecting, the security of information systems in this State and for recovering from and otherwise responding to threats to or attacks on the security of information systems in this State. The statewide strategic plan prepared and made available pursuant to this subsection must not identify or include information which allows for the identification of specific vulnerabilities in the information systems in this State. 2. The statewide strategic plan must include, without limitation, policies, procedures, best practices and recommendations for: (a) Identifying, preventing and responding to threats to and attacks on the security of information systems in this State; (b) Ensuring the safety of, and the continued delivery of essential services to, the people of this State in the event of a threat to or attack on the security of an information system in this State; (c) Protecting the confidentiality of personal information that is stored on, transmitted to, from or through or generated by an information system in this State; (d) Investing in technologies, infrastructure and personnel for protecting the security of information systems; and (e) Enhancing the voluntary sharing of information and any other collaboration among state agencies, local governments, agencies of the Federal Government and appropriate private entities regarding protecting the security of information systems. 3. The statewide strategic plan prepared pursuant to this section must be updated at least every 2 years. 4. A private entity may, in its discretion, make use of the information set forth in the statewide strategic plan. 5. Each agency of the State Government that has adopted a cybersecurity policy shall test the adherence of its employees to that policy on a periodic basis. Such an agency shall submit the results of the testing to the Office of Information Security and Cyber Defense annually for consideration in the update of the statewide strategic plan.