<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE amendment-doc PUBLIC "-//US Congress//DTDs/amend.dtd//EN" "amend.dtd">
<amendment-doc amend-degree="first" amend-type="engrossed-amendment"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 2952 EAS: Cybersecurity Workforce Assessment Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-12-10</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<engrossed-amendment-form>
<congress display="no">113th CONGRESS</congress><session display="no">2d Session</session><legis-num display="no">H.R. 2952</legis-num><current-chamber display="yes">In the Senate of the United States,</current-chamber><action><action-date date="20141210">December 10, 2014.</action-date></action><legis-type display="yes">Amendments:</legis-type></engrossed-amendment-form><engrossed-amendment-body><section id="id9a7985dcfbf54da7a940f7b05d844a39" section-type="resolved"><text>That the bill from the House of Representatives (H.R. 2952) entitled <quote>An Act to amend the Homeland Security Act of 2002 to make certain improvements in the laws relating
			 to the advancement of security technologies for critical infrastructure
			 protection, and for other purposes.</quote>, do pass with the following</text></section><amendment><amendment-instruction blank-lines-after="0"><text>Strike all after the enacting clause and insert the following:</text></amendment-instruction><amendment-block blank-lines-after="1" changed="added" reported-display-style="italic"><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
		  <quote><short-title>Cybersecurity Workforce Assessment Act</short-title></quote>.</text></section><section id="idB124CF8368414ED4B686B09CDE0B8817"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act—</text><paragraph id="id9110228E99014C56BCE945238EC81B62"><enum>(1)</enum><text>the term <term>Cybersecurity Category</term> means a  position’s or incumbent’s primary work function involving cybersecurity, which is further
			 defined by Specialty Area;</text></paragraph><paragraph id="id520E1465740F40BDA06E1A33F9A8AD7F"><enum>(2)</enum><text>the term <term>Department</term> means the Department of Homeland Security;</text></paragraph><paragraph id="id3C6F4645F4F241E4B591208BC0AD5BF3"><enum>(3)</enum><text>the term <term>Secretary</term> means the Secretary of Homeland Security; and</text></paragraph><paragraph id="id306B2CA3369546AE845E0F3E6F423E33"><enum>(4)</enum><text>the term <term>Specialty Area</term> means any of the common types of cybersecurity work as recognized by the National
			 Initiative for Cybersecurity Education’s National Cybersecurity Workforce
			 Framework report.</text></paragraph></section><section id="id3A9D4D76808B489F8D3F533F9EA94BBA"><enum>3.</enum><header>Cybersecurity workforce assessment and strategy</header><subsection id="ide8efcc656c64463fa3cd4342a89539bd"><enum>(a)</enum><header>Workforce assessment</header><paragraph id="idCC075C8DACC548ABA5EE67AD5A8A19FA"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, and annually thereafter for 3
			 years, the Secretary shall assess the cybersecurity workforce of the
			 Department.</text></paragraph><paragraph id="idead6391bace74c0a8574e14f56b34404"><enum>(2)</enum><header>Contents</header><text>The assessment required under paragraph (1) shall include, at a minimum—</text><subparagraph id="id544d2d9723794ccdadf4026737506241"><enum>(A)</enum><text>an assessment of the readiness and capacity of the workforce of the Department to meet its
			 cybersecurity mission;</text></subparagraph><subparagraph id="idf79f37d50955494b9bc60da81178bda5"><enum>(B)</enum><text>information on where cybersecurity workforce positions are located within the Department;</text></subparagraph><subparagraph id="id5f616218ca604e3faba37f1f15183554"><enum>(C)</enum><text>information on which cybersecurity workforce positions are—</text><clause id="id68bb343bb39547a7ac9efa5bab557f80"><enum>(i)</enum><text>performed by—</text><subclause id="id452011d0c7424062beaec786b503a37d"><enum>(I)</enum><text>permanent full-time equivalent employees of the Department, including, to the greatest extent
			 practicable, demographic information about such employees;</text></subclause><subclause id="id61ffabfe6fca4b0cb127142a7a23cbac"><enum>(II)</enum><text>independent contractors; and</text></subclause><subclause id="ide0a979b4467e4786824e9e470678761d"><enum>(III)</enum><text>individuals employed by other Federal agencies, including the National Security Agency; or</text></subclause></clause><clause id="idd52e246643a3416ebd99fe86c4bb65a7"><enum>(ii)</enum><text>vacant; and</text></clause></subparagraph><subparagraph id="id5756a6548dbd43c6bab2bee14d711d54"><enum>(D)</enum><text>information on—</text><clause id="id66BD6889622248F581BBA0F4B4A67C9F"><enum>(i)</enum><text>the percentage of individuals within each Cybersecurity Category and Specialty Area who
			 received essential training to perform their jobs; and</text></clause><clause id="id5C8D6E19375A4006824E338B3DC50A72"><enum>(ii)</enum><text>in cases in which such essential training was not received, what challenges, if any, were
			 encountered with respect to the provision of such essential training.</text></clause></subparagraph></paragraph></subsection><subsection id="idbaa7fa8a762749aa8fa2c7cbd0ef08a6"><enum>(b)</enum><header>Workforce strategy</header><paragraph id="idf47bc679b8ff4652b3d16dd3b4c6a0d3"><enum>(1)</enum><header>In general</header><text>The Secretary shall—</text><subparagraph id="id284D49198930413782B655B2E69529EE"><enum>(A)</enum><text>not later than 1 year after the date of enactment of this Act, develop a
			 comprehensive workforce strategy to enhance the readiness, capacity,
			 training, recruitment, and retention of the cybersecurity workforce of the
			 Department; and</text></subparagraph><subparagraph id="id376B18AEA29A464A9AE350DD3AD3073A"><enum>(B)</enum><text>maintain and, as necessary, update the comprehensive workforce strategy developed under
			 subparagraph (A).</text></subparagraph></paragraph><paragraph id="idffa3f5ca7fc640dfacf6763240b43959"><enum>(2)</enum><header>Contents</header><text>The comprehensive workforce strategy developed under paragraph (1) shall include a description of—</text><subparagraph id="id16138c7e2b16449f8bace96fac0526e6"><enum>(A)</enum><text>a multi-phased recruitment plan, including with respect to experienced professionals, members of
			 disadvantaged or underserved communities, the unemployed, and veterans;</text></subparagraph><subparagraph id="id094160dc774942c58f3437e78265cd8f"><enum>(B)</enum><text>a 5-year implementation plan;</text></subparagraph><subparagraph id="id3f1f5956520b43f9b90fa0e01f979041"><enum>(C)</enum><text>a 10-year projection of the cybersecurity workforce needs of the Department;</text></subparagraph><subparagraph id="idf6bb15e23443490aa2b16ac40e2c8335"><enum>(D)</enum><text>any obstacle impeding the hiring and development of a cybersecurity workforce in the Department;
			 and</text></subparagraph><subparagraph id="id5489b2e7bde049dab0a2966dac7532f7"><enum>(E)</enum><text>any gap in the existing cybersecurity workforce of the Department and a plan to fill any such gap.</text></subparagraph></paragraph></subsection><subsection id="id34efe9d513ea433996dd3532e7cc2f6c"><enum>(c)</enum><header>Updates</header><text>The Secretary submit to the appropriate congressional committees annual updates on—</text><paragraph id="id38893E5F94C34CF1944ADFE5EF25319F"><enum>(1)</enum><text>the cybersecurity workforce assessment required under subsection (a); and</text></paragraph><paragraph id="idBAADE950174E473CA23C54629853D13D"><enum>(2)</enum><text>the progress of the Secretary in carrying out the comprehensive workforce strategy required to be
			 developed under subsection (b).</text></paragraph></subsection></section><section id="id1905e6043741432d88b51a769ea20534"><enum>4.</enum><header>Cybersecurity Fellowship Program</header><text display-inline="no-display-inline">Not later than 120 days after the date of enactment of this Act, the Secretary shall submit to the
			 appropriate congressional committees a report on the feasibility, cost,
			 and benefits of establishing a Cybersecurity Fellowship Program to offer a
			 tuition payment plan for individuals pursuing undergraduate and doctoral
			 degrees who agree to work for the Department for an agreed-upon period of
			 time.</text></section></amendment-block></amendment></engrossed-amendment-body><title-amends><official-title-amendment>Amend the title so as to read: <quote>An Act to require the Secretary of Homeland Security to assess the cybersecurity workforce of the
			 Department of Homeland Security and develop a comprehensive workforce
			 strategy, and for other purposes.</quote>.</official-title-amendment></title-amends><attestation><attestation-group><attestor></attestor><role>Secretary</role></attestation-group></attestation><endorsement></endorsement></amendment-doc>


