<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H022FF88610D04F9980D6C0FA1E18B0D3" public-private="public">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 HR 4500 IH: To improve the management of cyber and information technology ranges and facilities of the Department of Defense, and for other purposes.</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2014-04-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>113th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 4500</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20140428">April 28, 2014</action-date>
			<action-desc><sponsor name-id="K000381">Mr. Kilmer</sponsor> (for himself, <cosponsor name-id="T000465">Ms. Tsongas</cosponsor>, and <cosponsor name-id="C001078">Mr. Connolly</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To improve the management of cyber and information technology ranges and facilities of the
			 Department of Defense, and for other purposes.</official-title>
	</form>
	<legis-body id="H78A8959F6830453FA3F97AF5F7ADBD0E" style="OLC">
		<section id="H3BD85BEC0E264A19BB29B69682D90A72" section-type="section-one"><enum>1.</enum><header>Cyber and information technology ranges</header>
			<subsection id="H31B822BC9E7E4D5ABFF503FED3FCAC93"><enum>(a)</enum><header>Management of cyber ranges and facilities</header><text>Subsection (b) of section 932 of the National Defense Authorization Act for Fiscal Year 2014
			 (<external-xref legal-doc="public-law" parsable-cite="pl/113/66">Public Law 113–66</external-xref>) is amended—</text>
				<paragraph id="H91BC2F617E85415794B8324E43A838DD"><enum>(1)</enum><text>by adding at the end the following new paragraphs:</text>
					<quoted-block display-inline="no-display-inline" id="HC375D4849BD640C6A53399FA55613CDB" style="OLC">
						<paragraph id="HE7875E7ADC5C4E4E9B716EC4ECC3C2F1"><enum>(3)</enum><header>List of cyber and information technology ranges and facilities</header>
							<subparagraph id="H16B05570412042EC82F3B8B4436D860F"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">The Principal Cyber Advisor designated under subsection (c)(1) shall establish a comprehensive list
			 of the cyber and information technology ranges and facilities of the
			 Department of Defense.</text>
							</subparagraph><subparagraph id="H1A63D0469EDA4124B6CC89B6FB84CCE3"><enum>(B)</enum><header>Terminology</header><text display-inline="yes-display-inline">In establishing the list under subparagraph (A), the Principal Cyber Advisor shall denote whether
			 each cyber and information technology range and facility is—</text>
								<clause id="H6AA0B052E56348BAAA901EC93E4804D2"><enum>(i)</enum><text>a <quote>cyber range</quote>, as defined by the Principal Cyber Advisor pursuant to subsection (c)(2)(C); or</text>
								</clause><clause id="H2FB92B8233994A588C0FEFDA527D8C57"><enum>(ii)</enum><text>an <quote>IT range</quote>, as defined by the Principal Cyber Advisor pursuant to such subsection.</text>
								</clause></subparagraph><subparagraph id="H43C66F2C8745498883EE305FB76F14BE"><enum>(C)</enum><header>Submission</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of the National Defense Authorization Act
			 for Fiscal Year 2015, the Principal Cyber Advisor shall submit to the
			 congressional defense committees the list established under subparagraph
			 (A).</text>
							</subparagraph></paragraph><paragraph id="H286275BB3B3049E1B98DAE48867BF3F4"><enum>(4)</enum><header>Management of systems</header><text display-inline="yes-display-inline">The Principal Cyber Advisor shall determine, on a case by case basis, whether a cyber and
			 information technology range and facility listed under paragraph (3)(A)
			 should be centrally managed under paragraph (5) to increase efficiency,
			 provide capability or capacity to more elements of the Department of
			 Defense, or both.</text>
						</paragraph><paragraph id="H6D525A67C16A4C54BB775D514AE90A25"><enum>(5)</enum><header>Coordinating entity</header>
							<subparagraph id="H6522CC66994E438C9E65FB5508DB8651"><enum>(A)</enum><header>Establishment</header><text display-inline="yes-display-inline">Not later than 270 days after the date of the enactment of the National Defense Authorization Act
			 for Fiscal Year 2015, the Secretary of Defense shall establish an entity,
			 or designate an element of the Department of Defense, to coordinate cyber
			 and information technology ranges and facilities that the Principal Cyber
			 Advisor determines should be centrally managed under paragraph (4).</text>
							</subparagraph><subparagraph id="H14D425B91A604AB0A12321CE438164AA"><enum>(B)</enum><header>Duties</header><text display-inline="yes-display-inline">With respect to the cyber and information technology ranges and facilities designated under
			 paragraph (4), the head of the entity established or designated under
			 subparagraph (A) shall be responsible for the following:</text>
								<clause id="H3A45816CBCDE4494B9AD21D89C6CDC1E"><enum>(i)</enum><text display-inline="yes-display-inline">Managing the cyber and information technology ranges and facilities, including coordinating the
			 scheduling of ranges and facilities.</text>
								</clause><clause id="HBFB149CDA1B1470AB5A79C1857B13186"><enum>(ii)</enum><text display-inline="yes-display-inline">Identifying and providing guidance to the Secretary with respect to opportunities for integration
			 among the cyber and information technology ranges and facilities regarding
			 testing, training, and developing functions.</text>
								</clause><clause id="HB1044678E237481DB0DD5591E6BEAD55"><enum>(iii)</enum><text display-inline="yes-display-inline">Assisting the military departments, the National Guard, and the elements of the Department gain
			 access to the cyber and information technology ranges and facilities.</text>
								</clause></subparagraph><subparagraph id="HA8396414B3174B2FBB711CA9E08BDD45"><enum>(C)</enum><header>Reports</header><text display-inline="yes-display-inline">The head of the entity established or designated under subparagraph (A) shall submit to the
			 congressional defense committees—</text>
								<clause id="H3DFE8E444B6C4FF68505B86E09CE1B86"><enum>(i)</enum><text display-inline="yes-display-inline">an annual report on the opportunities for cost reduction and improvements to the integration and
			 coordination of the cyber and information technology ranges and
			 facilities; and</text>
								</clause><clause id="H8E3A0D3095BF41479DDD5BC9FFD8B509"><enum>(ii)</enum><text display-inline="yes-display-inline">by not later than one year after the date of the enactment of the National Defense Authorization
			 Act for Fiscal Year 2015, an initial report on the status, integration
			 efforts, and usage of cyber and information technology ranges and
			 facilities.</text>
								</clause></subparagraph></paragraph><paragraph id="H5AD523EE002E43FFA4FED97E8D3F58A5"><enum>(6)</enum><header>Cyber and information technology ranges and facilities defined</header><text display-inline="yes-display-inline">In this subsection, the term <quote>cyber and information technology ranges and facilities</quote> means cyber ranges, test facilities, test beds, and other means of the Department of Defense for
			 testing, training, and developing software, personnel, and tools for
			 accommodating the mission of the Department.</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block>
				</paragraph><paragraph id="H11E23A5E81524D4CB0952AD90993C3C5"><enum>(2)</enum><text>in the heading, by inserting <quote><header-in-text level="subsection" style="OLC">and information technology</header-in-text></quote> after <quote><header-in-text level="subsection" style="OLC">Cyber</header-in-text></quote>.</text>
				</paragraph></subsection><subsection id="H2D3FBEA23E0F4A55B27AF9C7D4BEFC3E"><enum>(b)</enum><header>Common terms</header>
				<paragraph id="H706ED992E11C4B8DB6694193743D3A38"><enum>(1)</enum><header>In general</header><text>Subsection (c)(2) of such section is amended by adding at the end the following new subparagraph:</text>
					<quoted-block display-inline="no-display-inline" id="HDA1831564F8D404F9B4D2E02FFA4F680" style="OLC">
						<subparagraph id="H4ADC179134E64C0E81401CE30DA36B6A"><enum>(C)</enum><text display-inline="yes-display-inline">Establishing and maintaining a list of terms and definitions with respect to commonly used terms
			 relating to cyber matters to improve the coordination and cooperation
			 among the military departments and among other departments and agencies of
			 the Federal Government.</text></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph><paragraph id="H744208ADA09E4CB3BA8D8C63D3A5F0DC"><enum>(2)</enum><header>Establishment</header><text display-inline="yes-display-inline">In carrying out section 932(c)(2)(C) of the National Defense Authorization Act for Fiscal Year 2014
			 (<external-xref legal-doc="public-law" parsable-cite="pl/113/66">Public Law 113–66</external-xref>), as added by paragraph (1), the Principal Cyber
			 Advisor shall—</text>
					<subparagraph id="H7F0A50C5B72F4B63BF0A7E5C4AAD4C0C"><enum>(A)</enum><text display-inline="yes-display-inline">establish the list of terms and definitions by not later than 270 days after the date of the
			 enactment of this Act; and</text>
					</subparagraph><subparagraph id="HE0EF46F0F1F141DD88C9F83775F0E304"><enum>(B)</enum><text>use as a basis for such list Joint Publication 1–02, Department of Defense Dictionary of Military
			 and Associated Terms (as amended through 31 January 2011).</text>
					</subparagraph></paragraph></subsection><subsection id="HC50A3D9DD1E942EB8D5C40E75BBF167E"><enum>(c)</enum><header>Pilot program</header>
				<paragraph id="H4D90AB69AF4B4F5288BAB5D0C820D9C9"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The head of the entity established or designated under section 932(b)(5)(A) of the National Defense
			 Authorization Act for Fiscal Year 2014 (<external-xref legal-doc="public-law" parsable-cite="pl/113/66">Public Law 113–66</external-xref>), as added by
			 subsection (a), shall carry out one or more pilot programs to demonstrate
			 commercially available, cloud-based cyber training, exercise, and test
			 environments (both unclassified and classified) that are available to meet
			 the mission of the Department of Defense while providing the defense
			 laboratories, the National Guard, academia, and the private sector access
			 to such training, exercise, and test environments.</text>
				</paragraph><paragraph id="HEDFF63BB1F784A67B8D95A9FB20ED019"><enum>(2)</enum><header>Evaluation</header><text>The pilot programs under paragraph (1) shall evaluate the costs and benefits with respect to the
			 following matters:</text>
					<subparagraph id="HA6C26C90A9CF42758A805412041F8D4C"><enum>(A)</enum><text>Persistent capability.</text>
					</subparagraph><subparagraph id="H8F34AE3CCD894080BA4E22C388BEABB6"><enum>(B)</enum><text>Remote access.</text>
					</subparagraph><subparagraph id="HB873E4AA01B14A3BA825E43F98A739A2"><enum>(C)</enum><text>Capability to transfer information across classification levels.</text>
					</subparagraph><subparagraph id="HD2086E9144F647B99F5BCC2CECC99340"><enum>(D)</enum><text>Reuse of environments.</text>
					</subparagraph><subparagraph id="H5D98B6FBD38C44E6A75FF56859E747CE"><enum>(E)</enum><text>Routine integration of new technologies.</text>
					</subparagraph><subparagraph id="H674E722F3D9C4A5E8A07F4D5CEE4B465"><enum>(F)</enum><text display-inline="yes-display-inline">Use of commercially available cloud-based solutions that are compliant with the Federal Risk and
			 Authorization Management Program.</text>
					</subparagraph><subparagraph id="H83994DC211F548278EFE8CEBC825D89C"><enum>(G)</enum><text>Pay-per-use utility pricing model.</text>
					</subparagraph><subparagraph id="H543823AE8FCD48FFA6697CB06DC44644"><enum>(H)</enum><text>Any other matters the head determines appropriate.</text>
					</subparagraph></paragraph><paragraph id="HB9318E65DE544CA69FF4F7D4CE225489"><enum>(3)</enum><header>Eligible entities</header><text>The head shall select, using competitive procedures, defense laboratories and federally funded
			 research and development centers to carry out pilot programs under
			 paragraph (1).</text>
				</paragraph><paragraph id="HF31B30D7D5FB4C4E860BFB77C9FD1640"><enum>(4)</enum><header>Follow-on activities</header><text>Based on the information learned under the pilot programs under paragraph (1), the Secretary of
			 Defense may carry out any of the following activities:</text>
					<subparagraph id="HD8965CE12BA041D8824963F48A12F180"><enum>(A)</enum><text display-inline="yes-display-inline">Transition a pilot program to be carried out by the Secretary for operations, maintenance, and
			 continued use by cyber organizations of the Department.</text>
					</subparagraph><subparagraph id="HD988A08F8AC64458B02AD71EBE5FFAC8"><enum>(B)</enum><text>Provide persistent year-round accessibility of the environment for continued training during
			 non-exercise periods.</text>
					</subparagraph><subparagraph id="H0354E09F069F4BB48E08E6FAF01508FE"><enum>(C)</enum><text>Provide a <quote>certification quality</quote> environment for initial and recurring training of all cyber teams.</text>
					</subparagraph><subparagraph id="H9891C82AA00B4349A2D04254A880A5B9"><enum>(D)</enum><text>Replicate the capability of a pilot program to provide similar high-end training and exercise
			 opportunities for non-Department cyber professionals, including in
			 coordination with the Secretary of Homeland Security.</text>
					</subparagraph><subparagraph id="H0AE2349E9A2D4D4E9BFBC03D512262EE"><enum>(E)</enum><text>Sustain the research and development effort under a pilot program to continue updating network
			 environments, targets and defended assets, and integration of new cyber
			 tools.</text>
					</subparagraph><subparagraph id="H555DEC0348AC4D5C89DB0296837E0420"><enum>(F)</enum><text>Sustain technology infusion under a pilot program to apply and evaluate advanced concepts and
			 solutions to problems that affect multiple mission spaces of the
			 Department.</text>
					</subparagraph><subparagraph id="HDB21B12E9A2D4FBB9507E10BCA703668"><enum>(G)</enum><text>Create a library of virtual cyber templates that are ready to be used on short notice without the
			 capital expenditures that would otherwise be required.</text>
					</subparagraph></paragraph></subsection></section></legis-body>
</bill>


