<?xml version='1.0' encoding='ISO-8859-1'?>
<xml>
<title>Illinois General Assembly - Bill Status for SB 240          </title>
<shortdesc>CREDIT REPORT AGENCY-SECURITY</shortdesc>
<sponsor>
<sponsorhead1>Senate Sponsors</sponsorhead1><sponsors>Sen. Michael E. Hastings, Christopher Belt and Laura Ellman</sponsors>
</sponsor>
<lastaction>
<statusdate>1/13/2021</statusdate><chamber>Senate</chamber><action>Session Sine Die</action>
</lastaction>
<synopsis>
<synopsistitle></synopsistitle>
<reference>New Act</reference><aliasreference></aliasreference><SynopsisText>Creates the Consumer Credit Reporting Agency Registration and Cybersecurity Program Act. Provides for requirements for consumer credit reporting agency registration. Contains provisions regarding grounds for revocation and suspension of a registration. Provides that by January 1, 2020, a consumer credit reporting agency must have a cybersecurity program documented in writing and designed to protect the confidentiality, integrity and availability of its information systems. Provides that a consumer credit reporting agency shall implement and maintain a written cybersecurity policy setting forth its policies and procedures for the protection of its information systems and nonpublic information stored on those information systems. Provides that a consumer credit reporting agency shall designated a qualified individual as a chief information security officer to oversee and implement its cybersecurity policy. Contains provisions concerning penetration testing and vulnerability assessments, audit trail, access privileges, and application security. Provides that a consumer credit reporting agency shall conduct periodic risk assessments of its information systems. Provides requirements for cybersecurity personnel and third-party service provider security policy. Provides that a consumer credit reporting agency shall establish a written incident response plan designed to promptly respond to a cybersecurity event. Provides that the consumer credit reporting agency shall notify the Department of Financial and Professional Regulation of the existence of a cybersecurity event no later than 72 hours after the event occurred. Makes other changes. Effective immediately.</SynopsisText></synopsis>
<actions>
<statusdate>1/31/2019</statusdate><chamber>Senate</chamber><action>Filed with Secretary by Sen. Michael E. Hastings</action>
<statusdate>1/31/2019</statusdate><chamber>Senate</chamber><action>First Reading</action>
<statusdate>1/31/2019</statusdate><chamber>Senate</chamber><action>Referred to Assignments</action>
<statusdate>2/6/2019</statusdate><chamber>Senate</chamber><action>Assigned to Financial Institutions</action>
<statusdate>2/20/2019</statusdate><chamber>Senate</chamber><action>Postponed - Financial Institutions</action>
<statusdate>2/21/2019</statusdate><chamber>Senate</chamber><action>Added as Co-Sponsor Sen. Christopher Belt</action>
<statusdate>2/21/2019</statusdate><chamber>Senate</chamber><action>Added as Co-Sponsor Sen. Laura Ellman</action>
<statusdate>3/6/2019</statusdate><chamber>Senate</chamber><action>Postponed - Financial Institutions</action>
<statusdate>3/22/2019</statusdate><chamber>Senate</chamber><action>Rule 2-10 Committee Deadline Established As March 28, 2019</action>
<statusdate>3/28/2019</statusdate><chamber>Senate</chamber><action>Rule 3-9(a) / Re-referred to Assignments</action>
<statusdate>1/13/2021</statusdate><chamber>Senate</chamber><action>Session Sine Die</action>
</actions>
</xml>

