<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H18501C8646304759BB6EC395E8485BE1" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 3107 IH: Homeland Security Cybersecurity Boots-on-the-Ground Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2013-09-17</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress>113th CONGRESS</congress><session>1st Session</session><legis-num>H. R. 3107</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action><action-date date="20130917">September 17, 2013</action-date><action-desc><sponsor name-id="C001067">Ms. Clarke</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Homeland Security to establish cybersecurity occupation classifications, assess the cybersecurity workforce, develop a strategy to address identified gaps in the cybersecurity workforce, and for other purposes.</official-title></form><legis-body id="H35653070C740454184A7B6EEC9221505" style="OLC"><section id="H2A394927598B443E84082BC2DC3CB9EF" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Homeland Security Cybersecurity Boots-on-the-Ground Act</short-title></quote>.</text></section><section id="H1D490DD1C5D743EDB85E2B8CAB742C9A"><enum>2.</enum><header>Cybersecurity occupation classifications, workforce assessment, and strategy</header><subsection id="H209163D515F247A892D8E3AD7220A206"><enum>(a)</enum><header>Cybersecurity occupation classifications</header><paragraph id="H0D1F0C594ABE4BC8886DE8A8AD1B407E"><enum>(1)</enum><header>In general</header><text>Not later than 90 days after the date of the enactment of this Act, the Secretary of Homeland Security shall develop and issue comprehensive occupation classifications for individuals performing activities in furtherance of the cybersecurity mission of the Department of Homeland Security.</text></paragraph><paragraph id="H0C4B30BD7E914611907E46919107D033"><enum>(2)</enum><header>Applicability</header><text>The Secretary of Homeland Security shall ensure that the comprehensive occupation classifications issued under subsection (a) may be used throughout the Department of Homeland Security and are made available to other Federal agencies.</text></paragraph></subsection><subsection id="H483A5BF5A0A64B79A2FCE6BECD50017B"><enum>(b)</enum><header>Cybersecurity workforce assessment</header><paragraph id="H3B4275571B89424D85EA2C6FCECCDF04"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security, acting through the Chief Human Capital Officer and Chief Information Officer of the Department of Homeland Security, shall assess the readiness and capacity of the Department to meet its cybersecurity mission.</text></paragraph><paragraph id="HBAD36B70EC3D44BBB97F6C47C30A38EF"><enum>(2)</enum><header>Contents</header><text>The assessment required under paragraph (1) shall, at a minimum, include the following:</text><subparagraph id="H22461DEFE7A14C0985A74B416064934F"><enum>(A)</enum><text>Information where cybersecurity positions are located within the Department of Homeland Security, specified in accordance with the cybersecurity occupation classifications issued under subsection (a).</text></subparagraph><subparagraph id="HC0ACC00187FA43F49B7DD2FC52915475"><enum>(B)</enum><text>Information on which cybersecurity positions are—</text><clause id="H530CAFB052054FC88F578AE7ECA1E3C6"><enum>(i)</enum><text>performed by—</text><subclause id="HE158F3A5E5F04E6D965FD8AEED32BF43"><enum>(I)</enum><text>permanent full time departmental employees;</text></subclause><subclause id="H82FA30B20B474DDBBDBA705CC00146F0"><enum>(II)</enum><text>individuals employed by independent contractors; and</text></subclause><subclause id="HF83957A71BF7402D9B5EBA624DC2A901"><enum>(III)</enum><text>individuals employed by other Federal agencies, including the National Security Agency; and</text></subclause></clause><clause id="H8B4D9B4B2D0D4365BF18C02312F05265"><enum>(ii)</enum><text>vacant.</text></clause></subparagraph><subparagraph id="H323B7F0745024D658EA53A4C0F9A9468"><enum>(C)</enum><text>The number of individuals hired by the Department pursuant to the authority granted to the Secretary of Homeland Security in 2009 to permit the Secretary to fill 1,000 cybersecurity positions across the Department over a three-year period, and information on what challenges, if any, were encountered with respect to the implementation of such authority.</text></subparagraph><subparagraph id="H9C701A7E90374B308AC85F561226D743"><enum>(D)</enum><text>Information on vacancies within the Department’s cybersecurity supervisory workforce, from first line supervisory positions through senior departmental cybersecurity positions.</text></subparagraph><subparagraph id="H85741AAA17DD41BBACF39B72F1DFAF57"><enum>(E)</enum><text>Information on the percentage of individuals within each cybersecurity occupation classification who received essential training to perform their jobs, and in cases in which such training is not received, information on what challenges, if any, were encountered with respect to the provision of such training.</text></subparagraph></paragraph></subsection><subsection id="HA35C013447F44F7EB6549F6700A43901"><enum>(c)</enum><header>Workforce strategy</header><paragraph id="H37D5E9942E6F477098C8DEA2CEB6EE6F"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security shall develop a comprehensive workforce strategy that enhances the readiness, capacity, training, and recruitment and retention of the cybersecurity workforce of the Department of Homeland Security.</text></paragraph><paragraph id="H04A7C0E9E51E43B8872E1216839D1D8F"><enum>(2)</enum><header>Contents</header><text>The comprehensive workforce strategy developed under paragraph (1) shall include—</text><subparagraph id="H2F67E6BC096446828499FFC7DD4AD498"><enum>(A)</enum><text>a multiphased recruitment plan; and</text></subparagraph><subparagraph id="H65F82863489949FB98154FEF173E574F"><enum>(B)</enum><text>a 10-year projection of Federal workforce needs.</text></subparagraph></paragraph></subsection><subsection id="H109BEBF0FEA246D4B1696120C8A9A7DA"><enum>(d)</enum><header>Information security training</header><text display-inline="yes-display-inline">Not later than 270 days after the date of the enactment of this Act, the Secretary of Homeland Security shall establish and maintain a process to verify on an ongoing basis that individuals employed by independent contractors who serve in cybersecurity positions at the Department of Homeland Security receive initial and recurrent information security training comprised of general security awareness training necessary to perform their job functions, and role-based security training that is commensurate with assigned responsibilities. The Secretary shall monitor and maintain documentation to ensure that training provided to an individual under this subsection meets or exceeds requirements for such individual’s job function.</text></subsection><subsection commented="no" id="HDFE5901F5FBB4C65810EF7BBFFF2B5ED"><enum>(e)</enum><header>Updates</header><text>Together with the submission to Congress of annual budget requests, the Secretary of Homeland Security shall provide updates regarding the cybersecurity workforce assessment required under subsection (b), information on the progress of carrying out the comprehensive workforce strategy developed under subsection (c), and information on the status of the implementation of the information security training required under subsection (d).</text></subsection></section><section id="H4150D5CB9CF1463789F1D6631330639E"><enum>3.</enum><header>Definition</header><text display-inline="no-display-inline">In this Act, the term <term>cybersecurity mission</term> means activities that encompass the full range of threat reduction, vulnerability reduction, deterrence, incident response, resiliency, and recovery activities to foster the security and stability of cyberspace.</text></section></legis-body></bill>


