LD 1882
pg. 4
Page 3 of 5 An Act To Expand the Auditing Powers of the Department of Audit and To Clarify ... Page 5 of 5
Download Bill Text
LR 2844
Item 1

 
Sec. 7. 5 MRSA §244-D is enacted to read:

 
§244-D.__Confidentiality of audits of information security
systems

 
In the event a review by the State Auditor indicates a
computer system is vulnerable or security over the system is
lacking, those findings may not be disclosed publicly and are not
considered public records.__Notwithstanding Title 1, section 402
or any other provision of law to the contrary, the work papers
developed in connection with the review of the computer system
and the security over the system are deemed nonpublic records and
are not subject to disclosure.__The State Auditor's findings may
be disclosed at the discretion of the State Auditor to the Chief
Information Officer within the Department of Administrative and
Financial Services as well as the joint standing committee of the
Legislature having jurisdiction over appropriations and financial
affairs.__Unless the State Auditor authorizes the release of
information or findings gathered in the conduct of a review of
computer system security, that information is deemed classified,
confidential, secret and nonpublic.

 
Sec. 8. 5 MRSA §244-E is enacted to read:

 
§244-E.__Power to compel production of evidence

 
The State Auditor may conduct hearings, summon witnesses,
administer oaths, take the testimony of such witnesses and compel
the production, inspection and copying of documentary evidence,
including without limitation evidence in electronic form, all
software and hardware that hold data, are part of the technical
processes leading up to retention of data or are part of the
security system and documentary evidence that is confidential or
not available to the general public, at such time and place as
the State Auditor may designate for the purpose of investigating
and determining the status of accounts and records of any
department of State Government.__Notwithstanding any other
provision of law, the State Auditor may inspect, compel
production of and copy confidential information in any form
unless the law making such information confidential expressly
refers to this section and qualifies or supersedes it in that
particular instance.

 
The confidentiality of information obtained pursuant to this
section is as described in section 244-D.


Page 3 of 5 Top of Page Page 5 of 5