Michigan Laws 388.1697g – Statewide Security Operations Center; Managed Detection and Response solution cybersecurity risk assessments
Current as of: 2024 | Check for updates
|
Other versions
Terms Used In Michigan Laws 388.1697g
- Appropriation: The provision of funds, through an annual appropriations act or a permanent law, for federal agencies to make payments out of the Treasury for specified purposes. The formal federal spending process consists of two sequential steps: authorization
- Contract: A legal written agreement that becomes binding when signed.
- Fiscal year: The fiscal year is the accounting period for the government. For the federal government, this begins on October 1 and ends on September 30. The fiscal year is designated by the calendar year in which it ends; for example, fiscal year 2006 begins on October 1, 2005 and ends on September 30, 2006.
- Partnership: A voluntary contract between two or more persons to pool some or all of their assets into a business, with the agreement that there will be a proportional sharing of profits and losses.
- state: when applied to the different parts of the United States, shall be construed to extend to and include the District of Columbia and the several territories belonging to the United States; and the words "United States" shall be construed to include the district and territories. See Michigan Laws 8.3o
(1) From the state school aid fund money appropriated in section 11, there is allocated for 2023-2024 only, $9,000,000.00 to an intermediate district with K to 12 pupil membership between 37,500 and 42,500, as reported in the 2021-2022 MI School Data Student Enrollment Counts Report school year final student count, to establish and operate a statewide Security Operations Center (SOC) in partnership with a statewide educational organization. The SOC will provide a Managed Detection and Response (MDR) solution, including SOC staff, to monitor and assist in responding to threats and attacks on critical technology infrastructure for districts and intermediate districts.
(2) The intermediate district receiving funds under this section shall contract with a nonprofit educational organization that maintains a statewide educational technology collaborative to establish the statewide SOC. This statewide SOC will operate under the guidance of an advisory board, comprising educational technology leaders, with regional statewide representation. Other K to 12 stakeholders may be invited to participate in the advisory.
(3) The nonprofit educational organization that the intermediate district contracted with in subsection (2) shall use the funds to do all of the following:
(a) Establish a statewide advisory.
(b) Establish a statewide SOC security team.
(c) Establish statewide MDR service.
(d) Train district technology staff in the deployment and use of MDR software and services.
(e) Purchase and distribute MDR licensing to districts and intermediate districts for installation on critical technology infrastructure.
(f) Train, monitor, and track district utilization of a toolkit to be identified by the SOC such as MISecure Quick Self-Assessment.
(g) Not later than January 1, 2025 and each subsequent fiscal year, prepare a summary report that includes measurable outcomes including participation, detection, prevention, and response to cybersecurity incidents in order to evaluate the effectiveness of the project. The report must be submitted to the house and senate appropriations subcommittees on school aid and to the house and senate fiscal agencies.
(4) After the nonprofit educational organization that the intermediate district contracted with in subsection (2) uses funds as required under subsection (3), the nonprofit educational organization may use any remaining funds to do any of the following:
(a) Supply additional cybersecurity services as technologies evolve and budget allows.
(b) Partner with K to 12 statewide connectivity partners to install and monitor intrusion detection systems.
(5) Districts receiving software and service under this project shall do both of the following:
(a) Complete the assessment identified in subsection (3)(f) annually.
(b) Install and maintain statewide SOC MDR software on critical infrastructure as described in this section, provide access to the software to the statewide SOC, and coordinate responses with the statewide SOC and the district’s intermediate district.
(6) For districts that have MDR solutions in place as of October 1, 2023, a licensing cost allocation equal to the cost of the statewide SOC provided license may be provided until the end of the local contract or the end of the funding period, whichever comes first. Funds allocated under this subsection must be used to offset local MDR costs, cybersecurity assessment, or further cybersecurity investment.
(7) The funds allocated under this section for 2023-2024 are a work project appropriation, and any unexpended funds for 2023-2024 are carried forward and may be expended in subsequent years until the end of the 2027-2028 state fiscal year. The purpose of the work project is to increase stable and reliable cybersecurity in districts and intermediate districts. The estimated completion date of the work project is September 30, 2028.
(8) Notwithstanding section 17b, the department shall make payments under this section on a schedule determined by the department.
