<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Referred-in-Senate" bill-type="olc" dms-id="H18501C8646304759BB6EC395E8485BE1" public-private="public" stage-count="1">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 3107 : To require the Secretary of Homeland Security to establish cybersecurity occupation classifications, assess the cybersecurity workforce, develop a strategy to address identified gaps in the cybersecurity workforce, and for other purposes.</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-07-29</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">IIB</distribution-code>
		<congress>113th CONGRESS</congress><session>2d Session</session>
		<legis-num>H. R. 3107</legis-num>
		<current-chamber display="yes">IN THE SENATE  OF THE UNITED STATES</current-chamber>
		<action><action-date date="20140729">July 29, 2014</action-date><action-desc>Received; read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>AN ACT</legis-type>
		<official-title display="yes">To require the Secretary of Homeland Security to establish cybersecurity occupation
			 classifications, assess the cybersecurity workforce, develop a strategy to
			 address identified gaps in the cybersecurity workforce, and for other
			 purposes.</official-title>
	</form>
	<legis-body id="H35653070C740454184A7B6EEC9221505" style="OLC">
		<section id="H7FA3FD5113D54812BE66F89CC1533AD2" section-type="section-one"><enum>1.</enum><header>Homeland security cybersecurity workforce</header>
			<subsection id="HDDC89CC29524489F8D9322939FE4A245"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle C of title II of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/141">6 U.S.C. 141 et seq.</external-xref>) is amended by
			 adding at the end the following new section:</text>
				<quoted-block id="H0537D8DCCBD94C3C8D2CF2ECDCD9CA6B">
					<section id="H7A57DBF0748249B9BFEFBD2E0A647B39"><enum>226.</enum><header>Cybersecurity occupation categories, workforce assessment, and strategy</header>
						<subsection id="HD0DB9CDF96AB440688F680EEFBA4DF20"><enum>(a)</enum><header>Short title</header><text display-inline="yes-display-inline">This section may be cited as the <quote>Homeland Security Cybersecurity Boots-on-the-Ground Act</quote>.</text>
						</subsection><subsection id="HB293B4D8AB2A4AC6AEC1013698E48B28"><enum>(b)</enum><header>Cybersecurity occupation categories</header>
							<paragraph id="H0079CFE9D385460EA619DBD00175727B"><enum>(1)</enum><header>In general</header><text>Not later than 90 days after the date of the enactment of this section, the Secretary shall develop
			 and issue comprehensive occupation categories for individuals performing
			 activities in furtherance of the cybersecurity mission of the Department.</text>
							</paragraph><paragraph id="HC8E7CDF6AA924A6D991610320D15C68E"><enum>(2)</enum><header>Applicability</header><text>The Secretary shall ensure that the comprehensive occupation categories issued under paragraph (1)
			 are used throughout the Department and are made available to other Federal
			 agencies.</text>
							</paragraph></subsection><subsection id="H3D5AF5187C764CE1A5D2D2085E0C5CD0"><enum>(c)</enum><header>Cybersecurity workforce assessment</header>
							<paragraph id="HD4EEA212D9B84664A2692505B54A4BA1"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this section and annually thereafter,
			 the Secretary shall assess the readiness and capacity of the workforce of
			 the Department to meet its cybersecurity mission.</text>
							</paragraph><paragraph id="HB893FD6A6AB147A3B299B3860ACBD68A"><enum>(2)</enum><header>Contents</header><text>The assessment required under paragraph (1) shall, at a minimum, include the following:</text>
								<subparagraph id="H7D153A35EC764C9F9003DD3EA9185086"><enum>(A)</enum><text>Information where cybersecurity positions are located within the Department, specified in
			 accordance with the cybersecurity occupation categories issued under
			 subsection (b).</text>
								</subparagraph><subparagraph id="H26DA699520FA409795B4C6BF1F884F66"><enum>(B)</enum><text>Information on which cybersecurity positions are—</text>
									<clause id="HFAE9858A990F49D5BEFD40E293BC3C37"><enum>(i)</enum><text>performed by—</text>
										<subclause id="HF627A7FCE723428CACC85CDE0187EA5C"><enum>(I)</enum><text>permanent full time departmental employees, together with demographic information about such
			 employees’ race, ethnicity, gender, disability status, and veterans
			 status;</text>
										</subclause><subclause id="H583FF7F71D2146DAA819C28515FF9AEE"><enum>(II)</enum><text>individuals employed by independent contractors; and</text>
										</subclause><subclause id="HC7549F50C3EA44F1A6348ABAAFA09A06"><enum>(III)</enum><text>individuals employed by other Federal agencies, including the National Security Agency; and</text>
										</subclause></clause><clause id="H7062EADB7793496EA0813F7CBD0E0290"><enum>(ii)</enum><text>vacant.</text>
									</clause></subparagraph><subparagraph id="H3AB5F1CCB9C6471092ADDDB858588BDB"><enum>(C)</enum><text>The number of individuals hired by the Department pursuant to the authority granted to the
			 Secretary in 2009 to permit the Secretary to fill 1,000 cybersecurity
			 positions across the Department over a three year period, and information
			 on what challenges, if any, were encountered with respect to the
			 implementation of such authority.</text>
								</subparagraph><subparagraph id="H1014AB0E8FC841CDBEA2F259183E96D6"><enum>(D)</enum><text>Information on vacancies within the Department’s cybersecurity supervisory workforce, from first
			 line supervisory positions through senior departmental cybersecurity
			 positions.</text>
								</subparagraph><subparagraph id="HD930807156074AA186902D6B1112C460"><enum>(E)</enum><text>Information on the percentage of individuals within each cybersecurity occupation category who
			 received essential training to perform their jobs, and in cases in which
			 such training is not received, information on what challenges, if any,
			 were encountered with respect to the provision of such training.</text>
								</subparagraph><subparagraph id="HE820C04E9AE24685B2E92AB79F831C53"><enum>(F)</enum><text>Information on recruiting costs incurred with respect to efforts to fill cybersecurity positions
			 across the Department in a manner that allows for tracking of overall
			 recruiting and identifying areas for better coordination and leveraging of
			 resources within the Department.</text>
								</subparagraph></paragraph></subsection><subsection id="HFE8C56B2CD564135ADB5D1C12079D16E"><enum>(d)</enum><header>Workforce strategy</header>
							<paragraph id="H498261D27CFB4BE39CD5E63BFF7CD8B4"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this section, the Secretary shall
			 develop, maintain, and, as necessary, update, a comprehensive workforce
			 strategy that enhances the readiness, capacity, training, recruitment, and
			 retention of the cybersecurity workforce of the Department.</text>
							</paragraph><paragraph id="H33255453382143F5B293E9607630F0B0"><enum>(2)</enum><header>Contents</header><text>The comprehensive workforce strategy developed under paragraph (1) shall include—</text>
								<subparagraph id="H8B26026A9C614DCD8039967F1F34063E"><enum>(A)</enum><text display-inline="yes-display-inline">a multiphased recruitment plan, including relating to experienced professionals, members of
			 disadvantaged or underserved communities, the unemployed, and veterans;</text>
								</subparagraph><subparagraph id="HC5537F7AF7844C92BAD35FAE865EFD01"><enum>(B)</enum><text>a 5-year implementation plan;</text>
								</subparagraph><subparagraph id="H2A138ADEE81F42FBA3487FB7C8EDCE19"><enum>(C)</enum><text>a 10-year projection of the Department’s cybersecurity workforce needs; and</text>
								</subparagraph><subparagraph id="H91D9E3306CB242A586284F781D97952E"><enum>(D)</enum><text>obstacles impeding the hiring and development of a cybersecurity workforce at the Department.</text>
								</subparagraph></paragraph></subsection><subsection id="HB1C734F131F04D99ADC9059305D45FDE"><enum>(e)</enum><header>Information security training</header><text display-inline="yes-display-inline">Not later than 270 days after the date of the enactment of this section, the Secretary shall
			 establish and maintain a process to verify on an ongoing basis that
			 individuals employed by independent contractors who serve in cybersecurity
			 positions at the Department receive initial and recurrent information
			 security training comprised of general security awareness training
			 necessary to perform their job functions, and role-based security training
			 that is commensurate with assigned responsibilities. The Secretary shall
			 maintain documentation to ensure that training provided to an individual
			 under this subsection meets or exceeds requirements for such individual’s
			 job function.</text>
						</subsection><subsection commented="no" id="HDA45A7DBC48A4147BA9F926E95098061"><enum>(f)</enum><header>Updates</header><text>The Secretary shall submit to the appropriate congressional committees annual updates regarding the
			 cybersecurity workforce assessment required under subsection (c),
			 information on the progress of carrying out the comprehensive workforce
			 strategy developed under subsection (d), and information on the status of
			 the implementation of the information security training required under
			 subsection (e).</text>
						</subsection><subsection id="HA1B9E4520A2948CCB255358551CD2B92"><enum>(g)</enum><header>GAO study</header><text display-inline="yes-display-inline">The Secretary shall provide the Comptroller General of the United States with information on the
			 cybersecurity workforce assessment required under subsection (c) and
			 progress on carrying out the comprehensive workforce strategy developed
			 under subsection (d). The Comptroller General shall submit to the
			 Secretary and the appropriate congressional committees a study on such
			 assessment and strategy.</text>
						</subsection><subsection id="HB07A2DA7A2B54038B799A11EF586557A"><enum>(h)</enum><header>Cybersecurity Fellowship Program</header><text>Not later than 120 days after the date of the enactment of this section, the Secretary shall submit
			 to the appropriate congressional committees a report on the feasibility of
			 establishing a Cybersecurity Fellowship Program to offer a tuition payment
			 plan for undergraduate and doctoral candidates who agree to work for the
			 Department for an agreed-upon period of time.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HF82CBD56F4DE421FBBAF029648D875E3"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of such Act is amended by adding after the item relating to
			 section 225 the following new item:</text>
				<quoted-block display-inline="no-display-inline" id="H613404C50AF1422D85A0CDB809318BDC" style="OLC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">Sec. 226. Cybersecurity occupation categories, workforce assessment, and strategy.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section id="H2C082D26A9354B028341EF07A93B91E2"><enum>2.</enum><header>Personnel authorities</header>
			<subsection id="HC9D1944DD1664D6791C0F7EB57D804E0"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle C of title II of the Homeland Security Act of 2002, as amended by section 1 of this Act,
			 is further amended by adding at the end the following new section:</text>
				<quoted-block display-inline="no-display-inline" id="H6D749A76C9F74CC9B6E6317E87966213" style="OLC">
					<section id="H085E156DCBE942DCB831553399D5F9A0"><enum>227.</enum><header>Personnel authorities</header>
						<subsection id="H69522EC4E93344E990DA7E86173AF14B"><enum>(a)</enum><header>In general</header>
							<paragraph id="H50555282B8AE423C868895F6A37697E6"><enum>(1)</enum><header>Personnel authorities</header><text display-inline="yes-display-inline">The Secretary may exercise with respect to qualified employees of the Department the same authority
			 that the Secretary of Defense has with respect to civilian intelligence
			 personnel and the scholarship program under sections 1601, 1602, 1603, and
			 2200a of title 10, United States Code, to establish as positions in the
			 excepted service, appoint individuals to such positions, fix pay, and pay
			 a retention bonus to any employee appointed under this section if the
			 Secretary determines that such is needed to retain essential personnel.
			 Before announcing the payment of a bonus under this paragraph, the
			 Secretary shall submit to the Committee on Homeland Security of the House
			 of Representatives and the Committee on Homeland Security and Governmental
			 Affairs of the Senate a written explanation of such determination. Such
			 authority shall be exercised—</text>
								<subparagraph id="H3BC80CB62B3443B487D402E0518E450D"><enum>(A)</enum><text display-inline="yes-display-inline">to the same extent and subject to the same conditions and limitations that the Secretary of Defense
			 may exercise such authority with respect to civilian intelligence
			 personnel of the Department of Defense; and</text>
								</subparagraph><subparagraph id="H8AF74E12F72646E3B9135F8890BA20E8"><enum>(B)</enum><text display-inline="yes-display-inline">in a manner consistent with the merit system principles set forth in <external-xref legal-doc="usc" parsable-cite="usc/5/2301">section 2301</external-xref> of title 5,
			 United States Code.</text>
								</subparagraph></paragraph><paragraph id="HA94489DB22B44C449786A3AEAEA185B8"><enum>(2)</enum><header>Civil service protections</header><text display-inline="yes-display-inline">Sections 1221 and 2302, and <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/5/75">chapter 75</external-xref> of title 5, United States Code, shall apply to the positions
			 established pursuant to the authorities provided under paragraph (1).</text>
							</paragraph><paragraph id="H78AE3BC6EAD04EE38A5FBF74986F925C"><enum>(3)</enum><header>Plan for execution of authorities</header><text display-inline="yes-display-inline">Not later than 120 days after the date of the enactment of this section, the Secretary shall submit
			 to the Committee on Homeland Security of the House of Representatives and
			 the Committee on Homeland Security and Governmental Affairs of the Senate
			 a report that contains a plan for the use of the authorities provided
			 under this subsection.</text>
							</paragraph></subsection><subsection id="H269390532E6246519071D5EAF47B318A"><enum>(b)</enum><header>Annual report</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this section and annually thereafter for
			 four years, the Secretary shall submit to the Committee on Homeland
			 Security of the House of Representatives and the Committee on Homeland
			 Security and Governmental Affairs of the Senate a detailed report
			 (including appropriate metrics on actions occurring during the reporting
			 period) that discusses the processes used by the Secretary in implementing
			 this section and accepting applications, assessing candidates, ensuring
			 adherence to veterans’ preference, and selecting applicants for vacancies
			 to be filled by a qualified employee.</text>
						</subsection><subsection id="H087505DB6FBA4D2F8BB0D837ACEEA94F"><enum>(c)</enum><header>Definition of qualified employee</header><text display-inline="yes-display-inline">In this section, the term <term>qualified employee</term> means an employee who performs functions relating to the security of Federal civilian information
			 systems, critical infrastructure information systems, or networks of
			 either of such systems.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HA80353FBE6814466966F87D8B3C24DCB"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of such Act is amended by adding after the item relating to
			 section 226 (as added by section 1 of this Act) the following new item:</text>
				<quoted-block display-inline="no-display-inline" id="H2E7BCF59488548D795FA4A8709ABB7C0" style="OLC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">Sec. 227. Personnel authorities.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section id="H180A0543E567436AB815B7B9F411C568"><enum>3.</enum><header>Clarification regarding authorization of appropriations</header><text display-inline="no-display-inline">No additional amounts are authorized to be appropriated by reason of this Act or the amendments
			 made by this Act.</text>
		</section></legis-body>
	<attestation><attestation-group><attestation-date chamber="House" date="20140728">Passed the House of Representatives July 28, 2014.</attestation-date><attestor display="yes">Karen L. Haas,</attestor><role>Clerk</role></attestation-group></attestation>
</bill>


