← Back to search

HRS §27-43.5

State IT chief must check security of government data

The state's top technology officer must regularly check how well executive branch agencies protect government information and computer systems. These checks can include on-site visits and reviews of written security rules. Agencies must cooperate, and the officer can order fixes for any problems found.

state agencies

The statute, as written — Additional duties of the chief information officer relating to security of government information

(a) The chief information officer shall provide for periodic security audits of all executive branch departments and agencies regarding the protection of government information and data communication infrastructure. (b) Security audits may include on-site audits as well as reviews of all written security procedures and documented practices. The chief information officer may contract with a private firm or firms that specialize in conducting security audits; provided that information protected from disclosure by federal or state law, including confidential tax information, shall not be disclosed. All executive branch departments, agencies, boards, or commissions subject to the security audits authorized by this section shall fully cooperate with the entity designated to perform the audit. The chief information officer may direct specific remedial actions to mitigate findings of insufficient administrative, technical, and physical controls necessary to protect state government information or data communication infrastructure. (c) This section shall not infringe upon responsibilities assigned to the comptroller or the auditor by any state or federal law.
Read the official text at capitol.hawaii.gov ↗as published Jan 6, 2026our copy taken Aug 20, 2026

LawTrove is not legal advice. The summary above is a computer-generated restatement — the authoritative text is the official version linked above.