Description: This report satisfies supplemental report language adopted by the Legislature in 2022 on nonreporting entities’ information security (IS) compliance. Among other considerations, this report (1) identifies each of the nonreporting entities based on one statutory interpretation, (2) considers whether some of them could benefit from compliance with and reporting on IS policies and procedures similar to those set by the California Department of Technology, and (3) provides options for the Legislature to consider to improve nonreporting entities’ IS compliance and achieve a certain IS maturity level.