<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HA46112F61C00445FA7C700A52064D0EE" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 3635 IH: Safe and Secure Federal Websites Act of 2013</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2013-12-03</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress>113th CONGRESS</congress><session>1st Session</session><legis-num>H. R. 3635</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action><action-date date="20131203">December 3, 2013</action-date><action-desc><sponsor name-id="B001280">Mr. Bentivolio</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HGO00">Committee on Oversight and Government Reform</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To ensure the functionality and security of new Federal websites that collect personally identifiable information, and for other purposes.</official-title></form><legis-body id="H71141F8CEB3247E6A9E4DE1538964743" style="OLC"><section id="H4922C8AF3CD24617B39EEEF497B9D500" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Safe and Secure Federal Websites Act of 2013</short-title></quote>.</text></section><section id="H9902B7EBE8694C1E8D2D4C5625E95D84"><enum>2.</enum><header>Ensuring functionality and security of new Federal websites that collect personally identifiable information</header><subsection id="HF2FEBBD874C64F56872BA9CDE016D7CC"><enum>(a)</enum><header>Certification requirement</header><paragraph id="H8279947AF12B48728580AF78A51917A8"><enum>(1)</enum><header>In general</header><text>Except as otherwise provided under this subsection, an agency may not deploy or make available to the public a new Federal PII website until the date on which a certification under subsection (b)(2) is submitted to Congress that the website is fully functional and secure.</text></paragraph><paragraph id="H7F1F7F52703C46C8919AA526667B6930"><enum>(2)</enum><header>Transition</header><text display-inline="yes-display-inline">In the case of a new Federal PII website that is operational on the date of the enactment of this Act, paragraph (1) shall not apply until the end of the 30-day period beginning on such date of enactment. If the certification under subsection (b)(2) for such website has not been submitted to Congress before the end of such period, the head of the responsible agency shall render the website inaccessible to the public until such certification is submitted to Congress.</text></paragraph><paragraph id="HB29DD1996E4F4B58AF780297AFCB0448"><enum>(3)</enum><header>Exception for beta website with explicit permission</header><text>Paragraph (1) shall not apply to a website (or portion thereof) that is designed for testing and development purposes, if the following conditions are met:</text><subparagraph id="HEA87F079741C4BBB980D9BBEDE9C2785"><enum>(A)</enum><text>A member of the public may access PII-related portions of the website only after executing an agreement that acknowledges the risks involved.</text></subparagraph><subparagraph id="HD9B7AE71687B48D7A8CE6E450BA338BC"><enum>(B)</enum><text>No agency compelled, enjoined, or otherwise provided incentives for such a member to access the website for such purposes.</text></subparagraph></paragraph><paragraph id="H06E2FF2E47E1465DB9AB64F4FA9D917B"><enum>(4)</enum><header>Construction</header><text>Nothing in this section shall be construed as applying to a website that is operated entirely by an entity (such as a State or locality) that is independent of the Federal Government, regardless of the receipt of funding in support of such website from the Federal Government.</text></paragraph></subsection><subsection id="H90204A289BB7444F88D716E4EE6ABBD0"><enum>(b)</enum><header>Process for study and certification of functionality and security of new Federal PII websites</header><paragraph id="H559316C71248468CAA29967BD7FF4661"><enum>(1)</enum><header>GAO study and report</header><subparagraph id="H47897139FB6946DDA9A7B838D73B5546"><enum>(A)</enum><header>Study</header><clause id="H1DFDEFC2AC904F079A447DBD544CFE2C"><enum>(i)</enum><header>Current websites</header><text>Not later than 30 days after the date of the enactment of this Act, the Comptroller General of the United States shall conduct a study of each new Federal PII website that is operational as of such date of enactment to determine whether such website is fully functional and secure.</text></clause><clause id="HFA9F06C7B3554252B66FDA6291F950F9"><enum>(ii)</enum><header>Future websites</header><text>Not later than 30 days after the date on which an advance notification is received under paragraph (3) for a new Federal PII website that is not operational as of such date of enactment, the Comptroller General shall conduct a study of such website to determine whether such website is fully functional and secure.</text></clause></subparagraph><subparagraph id="HDF38C55C7CB74E3AB858A6F05A97184A"><enum>(B)</enum><header>Report to appropriate congressional committees</header><text>Upon the completion of a study of a website under subparagraph (A) or (C), the Comptroller General shall submit to the appropriate committees of Congress and the Chief Information Officer for the responsible agency a report on the results of the study. Such report shall include a determination of whether the website is fully functional and secure.</text></subparagraph><subparagraph id="H2FCB211E12C74BB78AA4DC3384BAE8D0"><enum>(C)</enum><header>Followup studies and report</header><text>If, based on the results of the most recent study under subparagraph (A) or this subparagraph, the Comptroller General determines that the website is not fully functional or not secure, the Comptroller General shall conduct an additional study (and submit a report described in subparagraph (B) on the results of such study) until the Comptroller General determines that the website is determined to be fully functional and secure.</text></subparagraph></paragraph><paragraph id="H25EAC8D941A84F45B2C603459FAAF33F"><enum>(2)</enum><header>Certification by CIO of responsible agency</header><text>Upon the submission of a report under paragraph (1) that determines that a website operated by a responsible agency is fully functional and secure, the Chief Information Officer for such agency shall submit to Congress a certification of the results of such report and a certification as to whether the website is fully functional and secure.</text></paragraph><paragraph id="H5387B5A464674581AECE3AB7C0B9D9A1"><enum>(3)</enum><header>Advance notification for operation of future websites</header><text>Each agency that intends to operate a new Federal PII website on or after the date of the enactment of this Act shall notify the Comptroller General of such intention and provide to the Comptroller General, in advance of the website becoming operational, such information as the Comptroller General may require to conduct a study and perform an evaluation under this subsection.</text></paragraph></subsection><subsection id="H9606ADBA26A64084B18564847E1A7B51"><enum>(c)</enum><header>Definitions</header><text>In this section:</text><paragraph id="HC9874415298E4CC8A67C863344A5A36A"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given that term under <external-xref legal-doc="usc" parsable-cite="usc/5/551">section 551</external-xref> of title 5, United States Code.</text></paragraph><paragraph id="HEB2C99F4153D4C74B2B797924ED8414F"><enum>(2)</enum><header>Fully functional</header><text>The term <term>fully functional</term> means, with respect to a new Federal PII website, that the website can fully support the activities for which it is designed or intended with regard to the eliciting, collection, or storage of personally identifiable information, including handling a volume of queries relating to such information commensurate with the purpose for which the website is designed.</text></paragraph><paragraph id="HBC17D1C1FEBE4A8F8E515EA8E47BE60E"><enum>(3)</enum><header>New Federal PII website</header><text display-inline="yes-display-inline">The term <term>new Federal PII website</term> means a website that—</text><subparagraph id="H8CDB3CC4B20A43A3AD2F8DCD65CE1F86"><enum>(A)</enum><text display-inline="yes-display-inline">is operated by (or under a contract with) an agency;</text></subparagraph><subparagraph id="H164F6681186D43498B98A44540E8145F"><enum>(B)</enum><text display-inline="yes-display-inline">elicits, collects, or stores personally identifiable information of individuals and is accessible to the public; and</text></subparagraph><subparagraph id="HDB320D6C16DB43E4B32456F7EAEE40DD"><enum>(C)</enum><text display-inline="yes-display-inline">is first made accessible to the public and collects or stores personally identifiable information of individuals, on or after July 1, 2013.</text></subparagraph></paragraph><paragraph id="H809403E5B4D541C7A229B32CB205FB68"><enum>(4)</enum><header>Operational</header><text>The term <term>operational</term> means, with respect to a website, that such website elicits, collects, or stores personally identifiable information of members of the public and is accessible to the public.</text></paragraph><paragraph id="H89B9EE8392584B118D353D9EC7192864"><enum>(5)</enum><header>Personally identifiable information (PII)</header><text>The terms <term>personally identifiable information</term> and <term>PII</term> mean any information that can be associated with one individual through a social security account number, taxpayer identification number, state identification number or other identifer, but does not include information (such as name, mailing or email address, telephone number, or similar contact information) necessary to contact an individual.</text></paragraph><paragraph id="HD83E0C946F1A40438ED42E9028511EDA"><enum>(6)</enum><header>Responsible agency</header><text>The term <term>responsible agency</term> means, with respect to a new Federal PII website, the agency that is responsible for the operation (whether directly or through contracts with other entities) of the website.</text></paragraph><paragraph id="H4C348490E0EC411B937125BDD2787827"><enum>(7)</enum><header>Secure</header><text>The term <term>secure</term> means, with respect to a new Federal PII website, that the following requirements are met:</text><subparagraph id="HEF2A3B987FD5423FBB0E7A6D549F3278"><enum>(A)</enum><text>The website has security features that meet a standard acceptable for banking purposes and the responsible agency has a named overall security leader with a comprehensive, top-down view of the security posture for the website who has supervised a complete end-to-end security test.</text></subparagraph><subparagraph id="HE4C0A1CD580142B49D2BD87BF590D11B"><enum>(B)</enum><text>The website ensures that personally identifiable information elicited, collected, or stored in connection with the website is captured at the latest possible step in a user input sequence.</text></subparagraph><subparagraph id="H6112B7A7BD92410B9D288A2764B1C2DB"><enum>(C)</enum><text display-inline="yes-display-inline">The responsible agency for the website has taken reasonable efforts to minimize domain name confusion, including through additional domain registrations and a program to educate consumers how to spot fraudulent websites.</text></subparagraph><subparagraph id="H3386BEE5BAEE4476A8037A51063A1B33"><enum>(D)</enum><text>The responsible agency requires all personnel who have access to personally identifiable information in connection with the website to have completed a Standard Form 85P and signed a non-disclosure agreement with respect to personally identifiable information, and the agency takes proper precautions to ensure only trustworthy persons may access such information.</text></subparagraph><subparagraph id="H1081B3CD743B485488FE0F5F4DB6FF2A"><enum>(E)</enum><text>The responsible agency maintains (either directly or through contract) ample personnel to respond in a timely manner to issues relating to the proper functioning and security of the website, and to monitor on an ongoing basis existing and emerging security threats to the website.</text></subparagraph></paragraph><paragraph id="HCD467B998AF141D8B896E94E583DBB22"><enum>(8)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each State of the United States, the District of Columbia, each territory or possession of the United States, and each federally recognized Indian tribe.</text></paragraph></subsection></section></legis-body></bill>


