<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HA6141BFFB0C04619B65716FD93822C65" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 666 IH: Department of Homeland Security Insider Threat and Mitigation Act of 2017</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2017-01-24</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 666</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20170124">January 24, 2017</action-date><action-desc><sponsor name-id="K000210">Mr. King of New York</sponsor> (for himself, <cosponsor name-id="B001269">Mr. Barletta</cosponsor>, <cosponsor name-id="M001157">Mr. McCaul</cosponsor>, and <cosponsor name-id="D000625">Mr. Donovan</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Homeland Security Act of 2002 to establish the Insider Threat Program, and for other
			 purposes.</official-title></form>
	<legis-body id="H368BEE7020BE4E419366858A46C53030" style="OLC">
 <section id="H6C53AAB825914C77979617F55D2348CC" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Department of Homeland Security Insider Threat and Mitigation Act of 2017</short-title></quote>.</text> </section><section id="H7DB4D3CA5048403F8DEC203913B13CF4"><enum>2.</enum><header>Establishment of Insider Threat Program</header> <subsection id="H03FC53244AD042FE9FCC462E28B772AA"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Title I of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/111">6 U.S.C. 111</external-xref> et seq.) is amended by adding at the end the following new section:</text>
				<quoted-block display-inline="no-display-inline" id="HAC7143C1861943C7913E34779D0B2AAC" style="OLC">
					<section id="H22013DED3D554895A8DDC50378436576"><enum>104.</enum><header>Insider Threat Program</header>
 <subsection id="HCB4C0E574DF24F1EAF7B2B92857783C8"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">The Secretary shall establish an Insider Threat Program within the Department. Such Program shall—</text> <paragraph id="H44D8160F0D7548D48B3E5E301277D56A"><enum>(1)</enum><text>provide training and education for Department personnel to identify, prevent, mitigate, and respond to insider threat risks to the Department’s critical assets;</text>
 </paragraph><paragraph id="HB51A63C7C8ED4892B0CE34BE58965DC3"><enum>(2)</enum><text>provide investigative support regarding potential insider threats that may pose a risk to the Department’s critical assets; and</text>
 </paragraph><paragraph id="HBC8C8AFBABB8402288CE96FBD6C5BECA"><enum>(3)</enum><text>conduct risk mitigation activities for insider threats.</text> </paragraph></subsection><subsection id="HF774032A97824DD696B9DB4FA1599E8D"><enum>(b)</enum><header>Steering Committee</header> <paragraph id="H192C1CE96BE9444AA6FBFA6D791D3F3B"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Secretary shall establish a Steering Committee within the Department. The Under Secretary for Intelligence and Analysis shall serve as the Chair of the Steering Committee. The Chief Security Officer shall serve as the Vice Chair. The Steering Committee shall be comprised of representatives of the Office of Intelligence and Analysis, the Office of the Chief Information Officer, the Office of the General Counsel, the Office for Civil Rights and Civil Liberties, the Privacy Office, the Office of the Chief Human Capital Officer, the Office of the Chief Financial Officer, the Federal Protective Service, the Office of the Chief Procurement Officer, the Science and Technology Directorate, and other components or offices of the Department as appropriate. Such representatives shall meet on a regular basis to discuss cases and issues related to insider threats to the Department’s critical assets, in accordance with subsection (a).</text>
 </paragraph><paragraph id="H85A88F573ED94F6C8033B327F4F5936E"><enum>(2)</enum><header>Responsibilities</header><text>Not later than one year after the date of the enactment of this section, the Under Secretary for Intelligence and Analysis and the Chief Security Officer, in coordination with the Steering Committee established pursuant to paragraph (1), shall—</text>
 <subparagraph id="H78284B92DF89405D8D745C3D66340887"><enum>(A)</enum><text display-inline="yes-display-inline">develop a holistic strategy for Department-wide efforts to identify, prevent, mitigate, and respond to insider threats to the Department’s critical assets;</text>
 </subparagraph><subparagraph id="H93F79FBAE3E64D85AF15498A5D64241E"><enum>(B)</enum><text>develop a plan to implement the insider threat measures identified in the strategy developed under subparagraph (A) across the components and offices of the Department;</text>
 </subparagraph><subparagraph id="HD6865480B42D450690001412DC6392BB"><enum>(C)</enum><text>document insider threat policies and controls;</text> </subparagraph><subparagraph id="H4A8A6508F1C54394ADE0A66B54139951"><enum>(D)</enum><text>conduct a baseline risk assessment of insider threats posed to the Department’s critical assets;</text>
 </subparagraph><subparagraph id="H7ABE87DD630742778FC915B20C7FA3CA"><enum>(E)</enum><text display-inline="yes-display-inline">examine existing programmatic and technology best practices adopted by the Federal Government, industry, and research institutions to implement solutions that are validated and cost-effective;</text>
 </subparagraph><subparagraph id="HA5FE5F7F2F1147F9B19865FAC30EBEB7"><enum>(F)</enum><text display-inline="yes-display-inline">develop a timeline for deploying workplace monitoring technologies, employee awareness campaigns, and education and training programs related to identifying, preventing, mitigating, and responding to potential insider threats to the Department’s critical assets;</text>
 </subparagraph><subparagraph id="H420D4360AD6441A0A2693F957DADFA10"><enum>(G)</enum><text display-inline="yes-display-inline">require the Chair and Vice Chair of the Steering Committee to consult with the Under Secretary for Science and Technology and other appropriate stakeholders to ensure the Insider Threat Program is informed, on an ongoing basis, by current information regarding threats, beset practices, and available technology; and</text>
 </subparagraph><subparagraph id="H405EB1156F9748268E851375442C6872"><enum>(H)</enum><text display-inline="yes-display-inline">develop, collect, and report metrics on the effectiveness of the Department’s insider threat mitigation efforts.</text>
 </subparagraph></paragraph></subsection><subsection id="H43FB66787E064B9590D7418FD4296BE0"><enum>(c)</enum><header>Definitions</header><text>In this section:</text> <paragraph id="HA07E988B7A1647559C1DEB8DAEBA4BC8"><enum>(1)</enum><header>Critical assets</header><text>The term <quote>critical assets</quote> means the people, facilities, information, and technology required for the Department to fulfill its mission.</text>
 </paragraph><paragraph id="HE3D93E4A52404800A572061ED80E5E79"><enum>(2)</enum><header>Insider</header><text>The term <quote>insider</quote> means—</text> <subparagraph id="H12FB7B4EAE5B4886A23BF62D8BFCE1FA"><enum>(A)</enum><text display-inline="yes-display-inline">any person who has access to classified national security information and is employed by, detailed to, or assigned to the Department, including members of the Armed Forces, experts or consultants to the Department, industrial or commercial contractors, licensees, certificate holders, or grantees of the Department, including all subcontractors, personal services contractors, or any other category of person who acts for or on behalf of the Department, as determined by the Secretary; or</text>
 </subparagraph><subparagraph id="H9E851B0EA95247E79F7608D8594B9744"><enum>(B)</enum><text>State, local, tribal, territorial, and private sector personnel who possess security clearances granted by the Department.</text>
 </subparagraph></paragraph><paragraph id="H45BC07E6AF8141E7867ABD1F48EEA839"><enum>(3)</enum><header>Insider threat</header><text display-inline="yes-display-inline">The term <quote>insider threat</quote> means the threat that an insider will use his or her authorized access, wittingly or unwittingly, to do harm to the security of the United States, including damage to the United States through espionage, terrorism, the unauthorized disclosure of classified national security information, or through the loss or degradation of departmental resources or capabilities.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H966D78EFEA724E189EEA2836AA788307"><enum>(b)</enum><header>Reporting</header>
 <paragraph id="H40C061BC3B5F4F66AA341B455DAED162"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than two years after the date of the enactment of section 104 of the Homeland Security Act of 2002 (as added by subsection (a) of this section) and the biennially thereafter for the next four years, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and the Permanent Select Committee on Intelligence of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Select Committee on Intelligence of the Senate a report on how the Department of Homeland Security and its components and offices have implemented the strategy developed pursuant to subsection (b)(2)(A) of such section 104, the status of the Department’s risk assessment of critical assets, the types of insider threat training conducted, the number of Department employees who have received such training, and information on the effectiveness of the Insider Threat Program (established pursuant to subsection (a) of such section 104), based on metrics developed, collected, and reported pursuant to subsection (b)(2)(H) of such section 104.</text>
 </paragraph><paragraph id="H8554A1656C6641638A36AFB445989584"><enum>(2)</enum><header>Definitions</header><text>In this subsection, the terms <quote>critical assets</quote>, <quote>insider</quote>, and <quote>insider threat</quote> have the meanings given such terms in section 104 of the Homeland Security Act of 2002 (as added by subsection (a) of this section).</text>
 </paragraph></subsection><subsection id="H532ECC4CA8474D37B899E9508F39734D"><enum>(c)</enum><header>Clerical amendment</header><text>The table of contents of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 103 the following new item:</text>
				<quoted-block display-inline="no-display-inline" id="H6CC4664354DE4ACFAF9F7EBED2FA9170" style="OLC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">Sec. 104. Insider Threat Program.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body></bill>


