<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Referred-in-Senate" bill-type="olc" dms-id="HA46112F61C00445FA7C700A52064D0EE" public-private="public" stage-count="1">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 3635 : Safe and Secure Federal Websites Act of 2014</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-07-29</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">IIB</distribution-code>
		<congress display="yes">113th CONGRESS</congress><session display="yes">2d Session</session>
		<legis-num>H. R. 3635</legis-num>
		<current-chamber display="yes">IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action><action-date date="20140729">July 29, 2014</action-date><action-desc>Received; read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>AN ACT</legis-type>
		<official-title display="yes">To ensure the functionality and security of new Federal websites that collect personally
			 identifiable information, and for other purposes.</official-title>
	</form>
	<legis-body display-enacting-clause="yes-display-enacting-clause" id="H093ACC5E942D48C1AD12C17D19259141" style="OLC">
		<section id="H47108CCB40BB4A07B0B42C589D48C86F" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Safe and Secure Federal Websites Act of 2014</short-title></quote>.</text>
		</section><section id="HB6E12A01990C418C890C111C15BB5DE7"><enum>2.</enum><header>Ensuring functionality and security of new Federal websites that collect personally identifiable
			 information</header>
			<subsection id="H20C80868181044D38F8C2C97A0D9E59D"><enum>(a)</enum><header>Certification requirement</header>
				<paragraph id="H20E5ED55A3FD4B1E9BCED43CA343814C"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Except as otherwise provided under this subsection, an agency may not deploy or make available to
			 the public a new Federal PII website until the date on which the chief
			 information officer of the agency submits a certification to Congress that
			 the website is fully functional and secure.</text>
				</paragraph><paragraph id="H8010B997F78C4C7C9FC58BECA126975B"><enum>(2)</enum><header>Transition</header><text display-inline="yes-display-inline">In the case of a new Federal PII website that is operational on the date of the enactment of this
			 Act, paragraph (1) shall not apply until the end of the 90-day period
			 beginning on such date of enactment. If the certification required under
			 paragraph (1) for such website has not been submitted to Congress before
			 the end of such period, the head of the responsible agency shall render
			 the website inaccessible to the public until such certification is
			 submitted to Congress.</text>
				</paragraph><paragraph id="H26B66B1A50D24A578F292223319AF1B5"><enum>(3)</enum><header>Exception for beta website with explicit permission</header><text>Paragraph (1) shall not apply to a website (or portion thereof) that is in a development or testing
			 phase, if the following conditions are met:</text>
					<subparagraph commented="no" id="HA4470A84976F415DBAA9A39A743285D6"><enum>(A)</enum><text>A member of the public may access PII-related portions of the website only after executing an
			 agreement that acknowledges the risks involved.</text>
					</subparagraph><subparagraph id="HDEE21761081142618D9F53CF08A48A89"><enum>(B)</enum><text>No agency compelled, enjoined, or otherwise provided incentives for such a member to access the
			 website for such purposes.</text>
					</subparagraph></paragraph><paragraph id="H5C604F030E9847278A39637A69976170"><enum>(4)</enum><header>Construction</header><text>Nothing in this section shall be construed as applying to a website that is operated entirely by an
			 entity (such as a State or locality) that is independent of the Federal
			 Government, regardless of the receipt of funding in support of such
			 website from the Federal Government.</text>
				</paragraph></subsection><subsection id="H9A1DCDF372574A6BA06A327B1E1ED82A"><enum>(b)</enum><header>Definitions</header><text>In this section:</text>
				<paragraph id="H7DB84547405E491D8FE0DA2AC48101CD"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given that term under <external-xref legal-doc="usc" parsable-cite="usc/5/551">section 551</external-xref> of title 5, United States Code.</text>
				</paragraph><paragraph id="H7D6300D67F1C442BBC0CA3BDF2AF1E55"><enum>(2)</enum><header>Fully functional</header><text>The term <term>fully functional</term> means, with respect to a new Federal PII website, that the website can fully support the
			 activities for which it is designed or intended with regard to the
			 eliciting, collection, storage, or maintenance of personally identifiable
			 information, including handling a volume of queries relating to such
			 information commensurate with the purpose for which the website is
			 designed.</text>
				</paragraph><paragraph id="H8FD3BDEC906A4EE1AC25592E26F70EA8"><enum>(3)</enum><header>New Federal personally identifiable information website (New Federal PII website)</header><text display-inline="yes-display-inline">The terms <term>new Federal personally identifiable information website</term> and <term>new Federal PII website</term> mean a website that—</text>
					<subparagraph id="H71F4EDCC371C4B7F9ADB3ACC236112A1"><enum>(A)</enum><text display-inline="yes-display-inline">is operated by (or under a contract with) an agency;</text>
					</subparagraph><subparagraph id="HB1E73281C884461C822AE657E5BB68B8"><enum>(B)</enum><text display-inline="yes-display-inline">elicits, collects, stores, or maintains personally identifiable information of individuals and is
			 accessible to the public; and</text>
					</subparagraph><subparagraph id="H01C65FEB072F4571A5C9F518B025A66E"><enum>(C)</enum><text display-inline="yes-display-inline">is first made accessible to the public and collects or stores personally identifiable information
			 of individuals, on or after October 1, 2012.</text>
					</subparagraph></paragraph><paragraph id="HFE243FE591D94663B9DBD055480DEA0B"><enum>(4)</enum><header>Operational</header><text>The term <term>operational</term> means, with respect to a website, that such website elicits, collects, stores, or maintains
			 personally identifiable information of members of the public and is
			 accessible to the public.</text>
				</paragraph><paragraph commented="no" id="H5D172A15430B48A4A6352D610885B6ED"><enum>(5)</enum><header>Personally identifiable information (PII)</header><text display-inline="yes-display-inline">The terms <term>personally identifiable information</term> and <term>PII</term> mean any information about an individual elicited, collected, stored, or maintained by an agency,
			 including—</text>
					<subparagraph commented="no" id="H8E9A9CE9958D4E56AF2009A82564FA87"><enum>(A)</enum><text>any information that can be used to distinguish or trace the identity of an individual, such as a
			 name, a social security number, a date and place of birth, a mother’s
			 maiden name, or biometric records; and</text>
					</subparagraph><subparagraph commented="no" id="H76066E2BE3544510A44F9ECAA0134661"><enum>(B)</enum><text>any other information that is linked or linkable to an individual, such as medical, educational,
			 financial, and employment information.</text>
					</subparagraph></paragraph><paragraph id="H93BAB9D428054A9ABA4B626F93378CB4"><enum>(6)</enum><header>Responsible agency</header><text>The term <term>responsible agency</term> means, with respect to a new Federal PII website, the agency that is responsible for the operation
			 (whether directly or through contracts with other entities) of the
			 website.</text>
				</paragraph><paragraph id="H30FFCACD90674943AF361C208C6C8B63"><enum>(7)</enum><header>Secure</header><text>The term <term>secure</term> means, with respect to a new Federal PII website, that the following requirements are met:</text>
					<subparagraph id="H308490D7A72344B296E817A3AB3524AA"><enum>(A)</enum><text>The website is in compliance with subchapter III of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code.</text>
					</subparagraph><subparagraph id="H67C76FAED1804D5AB4BE5488B7DE5974"><enum>(B)</enum><text>The website ensures that personally identifiable information elicited, collected, stored, or
			 maintained in connection with the website is captured at the latest
			 possible step in a user input sequence.</text>
					</subparagraph><subparagraph id="HBB28E054047D48BCA47FC858B9D2D9F0"><enum>(C)</enum><text display-inline="yes-display-inline">The responsible agency for the website has taken reasonable efforts to minimize domain name
			 confusion, including through additional domain registrations.</text>
					</subparagraph><subparagraph id="H1DFB265E8F134F008C78DEAF86B86792"><enum>(D)</enum><text>The responsible agency requires all personnel who have access to personally identifiable
			 information in connection with the website to have completed a Standard
			 Form 85P and signed a non-disclosure agreement with respect to personally
			 identifiable information, and the agency takes proper precautions to
			 ensure only trustworthy persons may access such information.</text>
					</subparagraph><subparagraph id="HDF766A109D9743F3B65F94463DF6E832"><enum>(E)</enum><text>The responsible agency maintains (either directly or through contract) sufficient personnel to
			 respond in a timely manner to issues relating to the proper functioning
			 and security of the website, and to monitor on an ongoing basis existing
			 and emerging security threats to the website.</text>
					</subparagraph></paragraph><paragraph id="H63596468601F4DBB9785A9DCAE05A6CA"><enum>(8)</enum><header>State</header><text display-inline="yes-display-inline">The term <term>State</term> means each State of the United States, the District of Columbia, each territory or possession of
			 the United States, and each federally recognized Indian tribe.</text>
				</paragraph></subsection></section><section id="H5DB861A268684A31AE5EA82F8C6DF067"><enum>3.</enum><header>Privacy breach requirements</header>
			<subsection id="H90BF55A8F77D4440892F3A5B5EBF2653"><enum>(a)</enum><header>Information security amendment</header><text display-inline="yes-display-inline">Subchapter III of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="HE1D8F76F8BB1403399FF8E01E2AF5C84" style="USC">
					<section id="HA8B70858C133474CBAEC925D41A4E84C"><enum>3550.</enum><header>Privacy breach requirements</header>
						<subsection id="H781589C4BF17447A8B4BF0BCAE90FF16"><enum>(a)</enum><header>Policies and Procedures</header><text display-inline="yes-display-inline">The Director of the Office of Management and Budget shall establish and oversee policies and
			 procedures for agencies to follow in the event of a breach of information
			 security involving the disclosure of personally identifiable information,
			 including requirements for—</text>
							<paragraph id="HC47CBE6449224DC2A1BEBCA0487CCB87"><enum>(1)</enum><text display-inline="yes-display-inline">not later than 72 hours after the agency discovers such a breach, or discovers evidence that
			 reasonably indicates such a breach has occurred, notice to the individuals
			 whose personally identifiable information could be compromised as a result
			 of such breach;</text>
							</paragraph><paragraph id="H981051D02BCF4C6D9E2F09B4B1D306BB"><enum>(2)</enum><text>timely reporting to a Federal cybersecurity center, as designated by the Director of the Office of
			 Management and Budget; and</text>
							</paragraph><paragraph id="H94D82979DB8147D89BAF72651B49CDD3"><enum>(3)</enum><text>any additional actions that the Director finds necessary and appropriate, including data breach
			 analysis, fraud resolution services, identity theft insurance, and credit
			 protection or monitoring services.</text>
							</paragraph></subsection><subsection id="H862268F27748444E9CD490FB29450EE5"><enum>(b)</enum><header>Required Agency Action</header><text display-inline="yes-display-inline">The head of each agency shall ensure that actions taken in response to a breach of information
			 security involving the disclosure of personally identifiable information
			 under the authority or control of the agency comply with policies and
			 procedures established by the Director of the Office of Management and
			 Budget under subsection (a).</text>
						</subsection><subsection id="H537DF9FF47D64AA58E27296A3025ECF4"><enum>(c)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than March 1 of each year, the Director of the Office of Management and Budget shall
			 report to Congress on agency compliance with the policies and procedures
			 established under subsection (a).</text>
						</subsection><subsection id="H5A7A6360785A44609F539EBF90823528"><enum>(d)</enum><header>Federal cybersecurity center defined</header><text display-inline="yes-display-inline">The term <term>Federal cybersecurity center</term> means any of the following:</text>
							<paragraph id="HBD3FC66A95524320889093738068E2CB"><enum>(1)</enum><text>The Department of Defense Cyber Crime Center.</text>
							</paragraph><paragraph id="H4955864FA9DF479C94B87D33BB6167EB"><enum>(2)</enum><text>The Intelligence Community Incident Response Center.</text>
							</paragraph><paragraph id="H4C1F194A79C24A32B4020B13FA85CD63"><enum>(3)</enum><text>The United States Cyber Command Joint Operations Center.</text>
							</paragraph><paragraph id="H0EE07C1E772D4853B92B1FBCDF3CB5EA"><enum>(4)</enum><text>The National Cyber Investigative Joint Task Force.</text>
							</paragraph><paragraph commented="no" id="H67F1DE73960C4DEB86B82E6DAB97A40D"><enum>(5)</enum><text>Central Security Service Threat Operations Center of the National Security Agency.</text>
							</paragraph><paragraph id="H78242F8591E0411BA009A5D55644AD96"><enum>(6)</enum><text>The United States Computer Emergency Readiness Team.</text>
							</paragraph><paragraph id="HC371D9560E12477B911CF9399162B232"><enum>(7)</enum><text>Any successor to a center, team, or task force described in paragraphs (1) through (6).</text>
							</paragraph><paragraph id="HDE45D4BD4315437A9B13D826FA7B0C1C"><enum>(8)</enum><text>Any center that the Director of the Office of Management and Budget determines is appropriate to
			 carry out the requirements of this section.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HFC351F4CA41A439C872D1C3E7AFDB712"><enum>(b)</enum><header>Technical and Conforming Amendment</header><text display-inline="yes-display-inline">The table of sections for subchapter III of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended
			 by adding at the end the following:</text>
				<quoted-block display-inline="no-display-inline" id="H0A26950BDDB54ACC88D83146C3CD2D5F" style="USC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">3550. Privacy breach requirements.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body>
	<attestation><attestation-group><attestation-date chamber="House" date="20140728">Passed the House of Representatives July 28, 2014.</attestation-date><attestor display="yes">Karen L. Haas,</attestor><role>Clerk</role></attestation-group></attestation>
</bill>


