Ark. Code Ann. § 10-4-429
This is the official text of Ark. Code Ann. § 10-4-429, part of Arkansas’s Code Ann — part of the compiled statutory law of Arkansas, published by the state as "Code Ann." Browse the sections below, each linked to its official government source.
Not legal advice. This page reproduces the official text of a government statute for reference only. Laws change, and how a statute applies depends on your specific facts. For advice about your situation, consult a licensed attorney in your state.
Report of security incident - Definitions
Official statutory text
(a) As used in this section: (1) "Public entity" means an entity of the state, political subdivision of the state, or school; and (2) "Security incident" means any compromise of the security, confidentiality, or integrity of an information system maintained by a public entity, a contractual provider of an information system that contracts with a public entity, or other computer-related services of a public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity. (b) (1) A public entity that experiences a security incident shall disclose, in writing, an initial report of the known facts of the security incident to the Legislative Auditor within five (5) business days after learning of the security incident. (2) A public entity shall provide regular updates of the security incident to the Legislative Auditor until the investigation of the security incident is closed. (c) The Legislative Auditor shall: (1) Maintain a list of all security incidents reported by a public entity; and (2) Annually on or before December 15, report the information required by subdivision (c)(1) of this section to the Legislative Council, Legislative Joint Auditing Committee, and Joint Committee on Advanced Communications and Information Technology. (d) If the Legislative Auditor believes the security incident significantly compromises citizens' data, creates a significant security concern, or involves significant theft, then the Legislative Auditor shall notify: (1) The Governor; (2) The President Pro Tempore of the Senate; (3) The Speaker of the House of Representatives; (4) The House and Senate cochairs of the Legislative Council; (5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and (6) The cochairs of the Joint Committee on Advanced Communications and Information Technology. (e) A report, update, notification, or list created or maintained under this section is exempt from disclosure under the Freedom of Information Act of 1967, § 25-19-101 et seq., as a security function under § 25-19-105(b)(11) . Amended by Act 2023, No. 175,§ 2, eff. 8/1/2023. Added by Act 2021, No. 260,§ 1, eff. 7/28/2021.
(a) As used in this section: (1) "Public entity" means an entity of the state, political subdivision of the state, or school; and (2) "Security incident" means any compromise of the security, confidentiality, or integrity of an information system maintained by a public entity, a contractual provider of an information system that contracts with a public entity, or other computer-related services of a public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity.
(1) "Public entity" means an entity of the state, political subdivision of the state, or school; and
public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity.
(1) "Public entity" means an entity of the state, political subdivision of the state, or school; and
(2) "Security incident" means any compromise of the security, confidentiality, or integrity of an information system maintained by a public entity, a contractual provider of an information system that contracts with a public entity, or other computer-related services of a public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity.
(A) Access to an information system of a public entity;
(B) Destruction of an information system of a public entity or the data of an information system of a public entity; or
(C) Acquisition of data from an information system of a public entity.
(b) (1) A public entity that experiences a security incident shall disclose, in writing, an initial report of the known facts of the security incident to the Legislative Auditor within five (5) business days after learning of the security incident. (2) A public entity shall provide regular updates of the security incident to the Legislative Auditor until the investigation of the security incident is closed.
(1) A public entity that experiences a security incident shall disclose, in writing, an initial report of the known facts of the security incident to the Legislative Auditor within five (5) business days after learning of the security incident.
(2) A public entity shall provide regular updates of the security incident to the Legislative Auditor until the investigation of the security incident is closed.
(c) The Legislative Auditor shall: (1) Maintain a list of all security incidents reported by a public entity; and (2) Annually on or before December 15, report the information required by subdivision (c)(1) of this section to the Legislative Council, Legislative Joint Auditing Committee, and Joint Committee on Advanced Communications and Information Technology.
(1) Maintain a list of all security incidents reported by a public entity; and
(2) Annually on or before December 15, report the information required by subdivision (c)(1) of this section to the Legislative Council, Legislative Joint Auditing Committee, and Joint Committee on Advanced Communications and Information Technology.
(d) If the Legislative Auditor believes the security incident significantly compromises citizens' data, creates a significant security concern, or involves significant theft, then the Legislative Auditor shall notify: (1) The Governor; (2) The President Pro Tempore of the Senate; (3) The Speaker of the House of Representatives; (4) The House and Senate cochairs of the Legislative Council; (5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and (6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
(1) The Governor;
(2) The President Pro Tempore of the Senate;
(3) The Speaker of the House of Representatives;
(4) The House and Senate cochairs of the Legislative Council;
(5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and
(6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
ications and Information Technology.
(1) The Governor;
(2) The President Pro Tempore of the Senate;
(3) The Speaker of the House of Representatives;
(4) The House and Senate cochairs of the Legislative Council;
(5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and
(6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
(e) A report, update, notification, or list created or maintained under this section is exempt from disclosure under the Freedom of Information Act of 1967, § 25-19-101 et seq., as a security function under § 25-19-105(b)(11) .
Amended by Act 2023, No. 175,§ 2, eff. 8/1/2023.
Added by Act 2021, No. 260,§ 1, eff. 7/28/2021.
(a) As used in this section: (1) "Public entity" means an entity of the state, political subdivision of the state, or school; and (2) "Security incident" means any compromise of the security, confidentiality, or integrity of an information system maintained by a public entity, a contractual provider of an information system that contracts with a public entity, or other computer-related services of a public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity.
(1) "Public entity" means an entity of the state, political subdivision of the state, or school; and
public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity.
(1) "Public entity" means an entity of the state, political subdivision of the state, or school; and
(2) "Security incident" means any compromise of the security, confidentiality, or integrity of an information system maintained by a public entity, a contractual provider of an information system that contracts with a public entity, or other computer-related services of a public entity, that is caused by any unauthorized: (A) Access to an information system of a public entity; (B) Destruction of an information system of a public entity or the data of an information system of a public entity; or (C) Acquisition of data from an information system of a public entity.
(A) Access to an information system of a public entity;
(B) Destruction of an information system of a public entity or the data of an information system of a public entity; or
(C) Acquisition of data from an information system of a public entity.
(b) (1) A public entity that experiences a security incident shall disclose, in writing, an initial report of the known facts of the security incident to the Legislative Auditor within five (5) business days after learning of the security incident. (2) A public entity shall provide regular updates of the security incident to the Legislative Auditor until the investigation of the security incident is closed.
(1) A public entity that experiences a security incident shall disclose, in writing, an initial report of the known facts of the security incident to the Legislative Auditor within five (5) business days after learning of the security incident.
(2) A public entity shall provide regular updates of the security incident to the Legislative Auditor until the investigation of the security incident is closed.
(c) The Legislative Auditor shall: (1) Maintain a list of all security incidents reported by a public entity; and (2) Annually on or before December 15, report the information required by subdivision (c)(1) of this section to the Legislative Council, Legislative Joint Auditing Committee, and Joint Committee on Advanced Communications and Information Technology.
(1) Maintain a list of all security incidents reported by a public entity; and
(2) Annually on or before December 15, report the information required by subdivision (c)(1) of this section to the Legislative Council, Legislative Joint Auditing Committee, and Joint Committee on Advanced Communications and Information Technology.
(d) If the Legislative Auditor believes the security incident significantly compromises citizens' data, creates a significant security concern, or involves significant theft, then the Legislative Auditor shall notify: (1) The Governor; (2) The President Pro Tempore of the Senate; (3) The Speaker of the House of Representatives; (4) The House and Senate cochairs of the Legislative Council; (5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and (6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
(1) The Governor;
(2) The President Pro Tempore of the Senate;
(3) The Speaker of the House of Representatives;
(4) The House and Senate cochairs of the Legislative Council;
(5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and
(6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
ications and Information Technology.
(1) The Governor;
(2) The President Pro Tempore of the Senate;
(3) The Speaker of the House of Representatives;
(4) The House and Senate cochairs of the Legislative Council;
(5) The cochairs and the co-vice chairs of the Legislative Joint Auditing Committee; and
(6) The cochairs of the Joint Committee on Advanced Communications and Information Technology.
(e) A report, update, notification, or list created or maintained under this section is exempt from disclosure under the Freedom of Information Act of 1967, § 25-19-101 et seq., as a security function under § 25-19-105(b)(11) .
Amended by Act 2023, No. 175,§ 2, eff. 8/1/2023.
Added by Act 2021, No. 260,§ 1, eff. 7/28/2021.
Status: in_force
Need a lawyer in Arkansas?
Find a Arkansas lawyer
About this page: Statute text is reproduced from official government publishers via the
Open US Law dataset
(Vaquill AI, snapshot v2026.08, CC BY 4.0). Primary legislative text like this is public domain under the government-edicts doctrine
(Georgia v. Public.Resource.Org, 2020). We link every section back to its official source so you can verify it independently.