<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H61AB48CF5D3549909697403E32EEB5A1" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 3403 IH: Cyber Valuing Individual Cybersecurity Through Interagency Measures Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2017-07-26</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 3403</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20170726">July 26, 2017</action-date><action-desc><sponsor name-id="B001304">Mr. Brown of Maryland</sponsor> (for himself, <cosponsor name-id="R000576">Mr. Ruppersberger</cosponsor>, and <cosponsor name-id="W000804">Mr. Wittman</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HGO00">Committee on Oversight and Government Reform</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To provide for an interagency cyber victim coordinator to respond to data breaches and other cyber
			 attacks on Federal employees.</official-title></form>
	<legis-body id="HB5ABDD3A66784749ABF7CBA4745098B4" style="OLC">
 <section id="H66FD004C9BF0401C831CFC0E35722ABF" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Valuing Individual Cybersecurity Through Interagency Measures Act</short-title></quote> or the <quote><short-title>Cyber VICTIM Act</short-title></quote>.</text> </section><section id="H619466540BF14C229D4FD047CE3FFE84" section-type="subsequent-section"><enum>2.</enum><header>Interagency cyber victim response</header> <subsection id="H26230A776A514E0E8EFBDF82BB13AD1F"><enum>(a)</enum><header>Interagency cyber victim coordinator</header> <paragraph id="H9612EF2BA65C4679B12B54599AFDC310"><enum>(1)</enum><header>In general</header><text>Not later than 60 days after the date of the enactment of this Act, the President shall designate a Federal official to coordinate efforts to respond to data breaches and other cyber attacks on Federal employees. Such official shall have the title of interagency cyber victim response coordinator.</text>
 </paragraph><paragraph id="H23AF472466EE46CCA8B192E1EB6ED18E"><enum>(2)</enum><header>Duties</header><text>The coordinator designated under paragraph (1) shall have the following duties:</text> <subparagraph id="HF51158949EEA4764AD6AAFBEDFF2AECC"><enum>(A)</enum><text>Coordinate activities of the Federal Government relating to incidents of data breaches in which the data of Federal employees, including Social Security numbers, personal financial information, addresses, and other private identifying information, has been compromised, to—</text>
 <clause id="H33B90B647F5344328F14C4331109B364"><enum>(i)</enum><text>ensure victims receive appropriate response and assistance from the Federal Government; and</text> </clause><clause id="H153690D7D7DB4C27B6B0C261A72A2474"><enum>(ii)</enum><text>ensure synchronization of intelligence and responses among Federal law enforcement agencies to incidents of cyber attacks against Federal employees.</text>
 </clause></subparagraph><subparagraph id="HB4D0E3BF088D400E8FC22F61C4A585CF"><enum>(B)</enum><text>Chair an interagency working group consisting of appropriate personnel of the Federal Government with purview over response to cyber attacks against Federal employees.</text>
 </subparagraph><subparagraph id="HBE7633A94BD24D0787A7D13403EA1B9B"><enum>(C)</enum><text>Ensure sufficient representation of each Federal agency and department at any interagency working group established under subparagraph (B).</text>
 </subparagraph><subparagraph id="H63C05F456B8948F0B754F03F57C10A6C"><enum>(D)</enum><text>Develop processes and procedures to keep victims informed of efforts to—</text> <clause id="HF86A1C5E93914080B8AD94B4BA92BF75"><enum>(i)</enum><text>mitigate damage from data breaches; and</text>
 </clause><clause id="H45DB5A3C308D49FA996ECFE7DC13CAF5"><enum>(ii)</enum><text>prosecute perpetrators.</text> </clause></subparagraph></paragraph></subsection><subsection id="H5CC58240657842D582B89CCAC983C23F"><enum>(b)</enum><header>Annual report</header> <paragraph id="HE12B8903610E45CC89B4D3509CA6B00B"><enum>(1)</enum><header>In general</header><text>On an annual basis, the Coordinator shall submit to the appropriate congressional committees a report that includes a summary of each data breach described in subsection (a)(1) that occurred during the year for which the report is submitted.</text>
 </paragraph><paragraph id="HEFB527A2685143CC85DEB0944957760E"><enum>(2)</enum><header>Form of report</header><text>Each report under paragraph (1) may be submitted in classified or unclassified form.</text> </paragraph></subsection><subsection id="HCD1D1893822A4622817AA974B68ADA49"><enum>(c)</enum><header>Comprehensive plan To address cyber attacks</header><text>Not later than 180 days after the date of the enactment of this Act, the President shall develop a comprehensive plan for the United States response to data breaches of personal information of Federal employees.</text>
 </subsection><subsection id="H005EFA51613C43D0A4440F517732992B"><enum>(d)</enum><header>Definitions</header><text>In this section, the following definitions apply:</text> <paragraph id="H516ED8628E094AB796AFDBD3BFAD7910"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <quote>appropriate congressional committees</quote> means—</text>
 <subparagraph id="HC2F444FE0AB4488AA0735E8CADBC03F3"><enum>(A)</enum><text>the Committee on Armed Services, the Committee on the Judiciary, the Permanent Select Committee on Intelligence, and the Committee on Homeland Security of the House of Representatives; and</text>
 </subparagraph><subparagraph id="HA3527486F8DA45C8B64CFA19DA1D8D45"><enum>(B)</enum><text>the Committee on Armed Services, the Committee on the Judiciary, the Select Committee on Intelligence, and the Committee on Homeland Security and Governmental Affairs of the Senate.</text>
 </subparagraph></paragraph><paragraph id="HBC926B7406884203A70A4CF878C1FAFD"><enum>(2)</enum><header>Data breach</header><text>The term <quote>data breach</quote> means an unauthorized intrusion of a Federal database resulting in a breach of personal information of a Federal employee, including—</text>
 <subparagraph id="HAA0D4128AF4B4B2D9822D30B251B7F0A"><enum>(A)</enum><text>the 2015 breaches of the Office of Personnel Management databases relating to background security checks and Federal employee background information; and</text>
 </subparagraph><subparagraph id="HDBB33B2D9CD64FE9A2EFD320B81B334F"><enum>(B)</enum><text>the November 2014 breach of the United States Postal Service employee database system.</text> </subparagraph></paragraph></subsection></section></legis-body></bill> 

