<?xml version='1.0' encoding='ISO-8859-1'?>
<xml>
<title>Illinois General Assembly - Bill Status for SB 3204         </title>
<shortdesc>CREDIT REPORT AGENCY-SECURITY</shortdesc>
<sponsor>
<sponsorhead1>Senate Sponsors</sponsorhead1><sponsors>Sen. Michael E. Hastings and Chris Nybo</sponsors>
</sponsor>
<lastaction>
<statusdate>1/9/2019</statusdate><chamber>Senate</chamber><action>Session Sine Die</action>
</lastaction>
<synopsis>
<synopsistitle></synopsistitle>
<reference>New Act</reference><aliasreference></aliasreference><SynopsisText>Creates the Consumer Credit Reporting Agency Registration and Cybersecurity Program Act. Provides for requirements for consumer credit reporting agency registration. Contains provisions regarding grounds for revocation and suspension of a registration. Provides that by January 1, 2019, a consumer credit reporting agency must have a cybersecurity program documented in writing and designed to protect the confidentiality, integrity and availability of its information systems. Provides that a consumer credit reporting agency shall implement and maintain a written cybersecurity policy setting forth its policies and procedures for the protection of its information systems and nonpublic information stored on those information systems. Provides that a consumer credit reporting agency shall designated a qualified individual as a chief information security officer to oversee and implement its cybersecurity policy. Contains provisions concerning penetration testing and vulnerability assessments, audit trail, access privileges, and application security. Provides that a consumer credit reporting agency shall conduct periodic risk assessments of its information systems. Provides requirements for cybersecurity personnel and third-party service provider security policy. Provides that a consumer credit reporting agency shall establish a written incident response plan designed to promptly respond to a cybersecurity event. Provides that the consumer credit reporting agency shall notify the Department of Financial and Professional Regulation of the existence of a cybersecurity event no later than 72 hours after the event occurred. Makes other changes. Effective immediately.</SynopsisText></synopsis>
<actions>
<statusdate>2/16/2018</statusdate><chamber>Senate</chamber><action>Filed with Secretary by Sen. Michael E. Hastings</action>
<statusdate>2/16/2018</statusdate><chamber>Senate</chamber><action>First Reading</action>
<statusdate>2/16/2018</statusdate><chamber>Senate</chamber><action>Referred to Assignments</action>
<statusdate>3/1/2018</statusdate><chamber>Senate</chamber><action>Assigned to Financial Institutions</action>
<statusdate>4/11/2018</statusdate><chamber>Senate</chamber><action>Postponed - Financial Institutions</action>
<statusdate>4/13/2018</statusdate><chamber>Senate</chamber><action>Rule 2-10 Committee Deadline Established As April 27, 2018</action>
<statusdate>4/19/2018</statusdate><chamber>Senate</chamber><action>Added as Co-Sponsor Sen. Chris Nybo</action>
<statusdate>4/27/2018</statusdate><chamber>Senate</chamber><action>Rule 3-9(a) / Re-referred to Assignments</action>
<statusdate>1/9/2019</statusdate><chamber>Senate</chamber><action>Session Sine Die</action>
</actions>
</xml>

