<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H88606CECC1BF4678BF460F508CE33E55" public-private="public">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 4356 IH: Department of Veterans Affairs Information Security Protection Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-04-01</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>113th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 4356</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20140401">April 1, 2014</action-date>
			<action-desc><sponsor name-id="K000368">Mrs. Kirkpatrick</sponsor> (for herself and <cosponsor name-id="M001149">Mr. Michaud</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HVR00">Committee on Veterans’ Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend title 38, United States Code, to make certain improvements in the information security of
			 the Department of Veterans Affairs, and for other purposes.</official-title>
	</form>
	<legis-body id="H2BA25BD75C2B48109A0FE836FF9F0741" style="OLC">
		<section id="HF5DC4E5EE91F404BA4067497EA5F23D1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Department of Veterans Affairs Information Security Protection Act</short-title></quote>.</text>
		</section><section id="HCD30DE0567BE4D71907350F532D22FCB"><enum>2.</enum><header>Department of Veterans Affairs information security improvements</header>
			<subsection id="H5866617B2C55497081C3EE25797A42D6"><enum>(a)</enum><header>Submittal of quarterly information security report to Congress</header><text display-inline="yes-display-inline">Paragraph (14) of subsection (b) of <external-xref legal-doc="usc" parsable-cite="usc/38/5723">section 5723</external-xref> of title 38, United States Code, is amended by
			 inserting <quote>and to the Committees on Veterans’ Affairs of the Senate and House of Representatives</quote> after <quote>to the Secretary</quote>.</text>
			</subsection><subsection commented="no" id="HB37474169A4B484EAC371D4AA6269750"><enum>(b)</enum><header>Plan for addressing known information security vulnerabilities</header><text>Such subsection is further amended by adding at the end the following new paragraph:</text>
				<quoted-block display-inline="no-display-inline" id="H4AB95367B27E409ABD5D901010E24057" style="USC">
					<paragraph commented="no" id="HABE61FE341814877B3BFF76894329C16"><enum>(17)</enum><text display-inline="yes-display-inline">Submitting to the Chairs and Ranking Members of the Committees on Veterans’ Affairs of the Senate
			 and House of Representatives, by not later than 30 days after the date of
			 the enactment of this paragraph, and quarterly thereafter, a plan of
			 action to address critical known information security vulnerabilities that
			 includes—</text>
						<subparagraph commented="no" id="H0A83E645F69343B3B05FF116CCBD5129"><enum>(A)</enum><text>specific milestones regarding time­lines to address such vulnerabilities;</text>
						</subparagraph><subparagraph commented="no" id="HF1A0917D645D444F996392C76E14387E"><enum>(B)</enum><text>a summary of any reports provided to the Assistant Secretary for Information and Technology
			 pursuant to subsection (e)(3) during the period covered by the report;</text>
						</subparagraph><subparagraph commented="no" id="HDFC60C2A708D4BE0AB411B8FDC4AE2FB"><enum>(C)</enum><text>a discussion of any risk assessment analysis undertaken by the Department that led to the inclusion
			 of any such vulnerability; and</text>
						</subparagraph><subparagraph commented="no" id="H646C210DCD9D4C399F0007014470D834"><enum>(D)</enum><text>a summary of such plan of action that could be made publicly available.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H0F4EB4B8F73442AAA3DF37A2D070D54C"><enum>(c)</enum><header>Plan for replacing outdated operating systems</header><text>Such subsection is further amended by adding at the end the following new paragraph:</text>
				<quoted-block display-inline="no-display-inline" id="H83DC04A9E4454EBB9D626BF887D07F8E" style="USC">
					<paragraph id="H65D0F589719240148BBD8F4FAEEFDEBB"><enum>(18)</enum><text display-inline="yes-display-inline">Submitting to the Committees on Veterans’ Affairs of the Senate and House of Representatives, by
			 not later than January 1 of each year, a plan for identifying and
			 replacing operating systems of the Department that are out-of-date or
			 unsupported and that includes—</text>
						<subparagraph id="H7279D78FF978416DA4AA3F53C4CDBEA4"><enum>(A)</enum><text>requirements that such an operating system be removed from the network of the Department no later
			 than 15 days after the date on which the operating system was identified
			 as being out-of-date or unsupported; and</text>
						</subparagraph><subparagraph id="HEF52714C85854443A96C0AAD2827DCEB"><enum>(B)</enum><text>information concerning the number of systems so identified during the year preceding the year in
			 which the report is submitted, when each such system was so identified,
			 and when each system so identified was removed from the network of the
			 Department.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HAD9E4F4A1A8346568181AB35EC5CD91B"><enum>(d)</enum><header>Software security</header><text>Such subsection is further amended by adding at the end the following new paragraph:</text>
				<quoted-block display-inline="no-display-inline" id="H8F32BB4F77AA4520B434F1DC64C7BA15" style="USC">
					<paragraph id="H0319C48A5534474EA2584AE1FEA5B55B"><enum>(19)</enum><text display-inline="yes-display-inline">Ensuring that any software or Internet applications used on systems by the Department are secure
			 from vulnerabilities that could affect the confidentiality of sensitive
			 personal information of veterans.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section id="HBB3B6EAC286740DAA106C3EA8F5094A2"><enum>3.</enum><header>Information technology reporting requirements</header>
			<subsection id="H71006F6DBC97482B8FCE117AC25F6493"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline"><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/38/57">Chapter 57</external-xref> of title 38, United States Code, is amended—</text>
				<paragraph id="H24073A1871164620B28A45452E7B0817"><enum>(1)</enum><text>by redesignating sections 5727 and 5728 as sections 5729 and 5730, respectively; and</text>
				</paragraph><paragraph id="HCAFC7BC2E21849CD8C8A7C630E307D62"><enum>(2)</enum><text>by inserting after section 5726 the following new sections:</text>
					<quoted-block display-inline="no-display-inline" id="H89FBE92784424AE48C58F3360A4CF43D" style="USC">
						<section id="HA0C42DBE34AE441FB6590368A3A1518F"><enum>5727.</enum><header>Reporting requirements</header><text display-inline="no-display-inline">Not later than 30 days after the last day of each fiscal quarter, the Secretary shall submit to the
			 Committees on Veterans’ Affairs of the Senate and House of Representatives
			 a report that includes the following information for that fiscal quarter:</text>
							<paragraph id="HAC81120B6B98483ABE63F58A6CCF7C7B"><enum>(1)</enum><text>A detailed description of any incidents of failure to comply with established information security
			 policies that occurred during that quarter.</text>
							</paragraph><paragraph id="HC156C875D394434AB1561625C79F8632"><enum>(2)</enum><text>Any actions taken in response to such an incident.</text>
							</paragraph><paragraph id="H46A0FE74C283410DB4BDC750A2D5A42E"><enum>(3)</enum><text>Any reports made under paragraphs (8) through (10) of subsection (b) of section 5723 of this title
			 during that quarter.</text>
							</paragraph><paragraph id="H3423FBD9F2D94DA09EF2CF8953ED79C3"><enum>(4)</enum><text display-inline="yes-display-inline">Written certification that the requirements of section 5722(c) of this title were followed during
			 that quarter.</text>
							</paragraph><paragraph id="H6140A80948CD4300B414C4938D0308D5"><enum>(5)</enum><text display-inline="yes-display-inline">A detailed discussion of whether each recommendation made by the National Institute of Standards
			 and Technology, the Office of Management and Budget, or the Department of
			 Homeland Security relating to information security have been implemented
			 by the Department, and if not, an explanation of why such recommendation
			 was not implemented.</text>
							</paragraph><paragraph id="HBDBD789E39A64AB396A0422D42B369EC"><enum>(6)</enum><text display-inline="yes-display-inline">Steps taken to ensure the security of the Veterans Health Information Systems and Technology
			 Architecture of the Department that allows for an integrated inpatient and
			 outpatient electronic health record for patients and provides
			 administrative tools to employees of the Department taken during that
			 quarter.</text>
							</paragraph></section><section id="H68B161E43B844EAFB5236B4145A4710E"><enum>5728.</enum><header>Information security strategic plan</header>
							<subsection id="HACC83D54558049F5A04603F7E40E28AE"><enum>(a)</enum><header>Plan required</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this section, the Secretary, in
			 consultation with the Secretary of Homeland Security, the Director of the
			 Office of Management and Budget, the Secretary of Defense, the Director of
			 the National Institute of Standards and Technology, the heads of other
			 appropriate Federal agencies, veterans groups, and appropriate industry
			 specialists, shall submit to the Committees on Veterans’ Affairs of the
			 Senate and House of Representatives a strategic plan for improving the
			 information security of the Department. Such plan shall address—</text>
								<paragraph id="H0BE88C07CD964EDD8BD440CD45BF6DFB"><enum>(1)</enum><text display-inline="yes-display-inline">methods of protecting the sensitive personal information of veterans while not unduly interfering
			 with the ability of the Department to provide benefits and services to
			 veterans and their dependents;</text>
								</paragraph><paragraph id="H45D5FC54C8F144FCB419020F628EC7B6"><enum>(2)</enum><text>how the Department can improve its compliance with information security requirements;</text>
								</paragraph><paragraph id="H10124A11767E4A779053C57BE07A0E2F"><enum>(3)</enum><text>training and recruitment of employees with the necessary expertise and abilities in information
			 security; and</text>
								</paragraph><paragraph id="HCADF9CDB5AEE4CBDA865B95994894F46"><enum>(4)</enum><text>the institutional capability of the Department to address information security threats and to
			 implement best practices related to information security.</text>
								</paragraph></subsection><subsection id="H0D6FE9A715694B7EB82F99090E4C0464"><enum>(b)</enum><header>Biannual updates</header><text display-inline="yes-display-inline">The Secretary shall submit to the Committees on Veterans’ Affairs of the Senate and House of
			 Representatives biannual updates to the plan required by subsection (a).</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HE24B2F1441994C638732EF54421305D3"><enum>(b)</enum><header>Clerical amendments</header><text>The table of sections at the beginning of such chapter is amended by striking the items relating to
			 sections 5727 and 5728 and inserting the following new items:</text>
				<quoted-block display-inline="no-display-inline" id="HB219DAC8F21D460889FED8EA1DA293C7" style="USC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">5727. Reporting requirements.</toc-entry>
						<toc-entry level="section">5728. Information security strategic plan.</toc-entry>
						<toc-entry level="section">5729. Definitions.</toc-entry>
						<toc-entry level="section">5730. Authorization of appropriations.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section id="H807370D60D844C358A5DAF057444A35F"><enum>4.</enum><header>Requirements for Department of Veterans Affairs contracts for data processing or maintenance</header>
			<subsection id="H1D2F334809A745718B76936143F63B0B"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline"><external-xref legal-doc="usc" parsable-cite="usc/38/5725">Section 5725(a)</external-xref> of title 38, United States Code, is amended—</text>
				<paragraph id="H8C294F9CC3994EC99A6F33F7B9382909"><enum>(1)</enum><text>in paragraph (2), by striking the period and inserting <quote>; and</quote>; and</text>
				</paragraph><paragraph id="HA94919F98CAA4544B8D7C3CBABE4DF27"><enum>(2)</enum><text>by adding at the end the following new paragraph:</text>
					<quoted-block display-inline="no-display-inline" id="H5510C1EBE06F40FC9C28C7E7EDA9C83E" style="USC">
						<paragraph id="H3C3DF7149DBC4788891897516DB300E1"><enum>(3)</enum><text display-inline="yes-display-inline">the contractor shall provide protective measures to safeguard from possible information security
			 threats any information provided by the Department that will be resident
			 on or transiting through information systems controlled by the contractor.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="H2AA9E25AB5404F15AAEFDEE0D0775DB2"><enum>(b)</enum><header>Applicability</header><text display-inline="yes-display-inline">Paragraph (3) of <external-xref legal-doc="usc" parsable-cite="usc/38/5725">section 5725(a)</external-xref> of title 38, United States Code, shall apply with respect to a
			 contract entered into after the date of the enactment of this Act.</text>
			</subsection></section></legis-body>
</bill>


