<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Enrolled-Bill" bill-type="olc" dms-id="HDC135B6F20C541D4BABBA4D058B5FC30" key="H" public-private="public" stage-count="1"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title> HR 4921 ENR: STB Information Security Improvement Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="no">IB</distribution-code> 
<congress display="yes">One Hundred Fifteenth Congress of the United States of America</congress><session display="yes">At the Second Session</session><enrolled-dateline>Begun and held at the City of Washington on Wednesday, the third day of January, two thousand and eighteen</enrolled-dateline> 
<legis-num display="yes">H. R. 4921</legis-num> 
<current-chamber display="no"></current-chamber> 
<legis-type>AN ACT</legis-type> 
<official-title display="yes">To require the Surface Transportation Board to implement certain recommendations of the Inspector General of the Department of Transportation.</official-title> 
</form> 
<legis-body id="HF5185847C37F43A487484D88E7249A95" style="OLC" display-enacting-clause="yes-display-enacting-clause"> 
<section id="HD84368AE6D914336ABE8E39E28FCC575" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>STB Information Security Improvement Act</short-title></quote>.</text> </section> <section id="H640F0B01D9304D66A2656C4981575E39"><enum>2.</enum><header>Requirements</header> <subsection id="H0C064094BCDC4117B882CF5CB3CA654D"><enum>(a)</enum><header>In general</header><text>The Surface Transportation Board (in this section referred to as the <quote>STB</quote>) shall develop a timeline and plan to implement the recommendations of the Inspector General of the Department of Transportation in Report No. FI2018002, including improvements—</text> 
<paragraph id="H8F0BBB05B4D74C05BDB80B8AE067DAC1"><enum>(1)</enum><text>to identify controls, including risk management, weakness remediation, and security authorization;</text> </paragraph> <paragraph id="H498C640FC11545BFB649F965229F9736"><enum>(2)</enum><text>to protect controls, including configuration management, user identity and access management, and security training;</text> </paragraph> 
<paragraph id="H8D51221974DD480EBBBBFB18254D34C9"><enum>(3)</enum><text>to detect controls, including continuous monitoring;</text> </paragraph> <paragraph id="H5E6D9A74E991445D809E91035A78BBD7"><enum>(4)</enum><text>to respond controls, including incident handling and reporting;</text> </paragraph> 
<paragraph id="H743E84C91CF94DDB92F008F9577885AC"><enum>(5)</enum><text>to recover controls for contingency planning; and</text> </paragraph> <paragraph commented="no" id="H3049EABAB8174978B793FDA38D05BB41"><enum>(6)</enum><text>any additional tools that will improve the implementation of the recommendations.</text> </paragraph></subsection> 
<subsection id="H01E57AB841E044C388688DF1B1B31E6A"><enum>(b)</enum><header>Implementation</header> 
<paragraph id="HB7C6D6C8F7B44289862B22A24C353843"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of enactment of this Act, the STB shall submit the plan and timeline developed under subsection (a) to the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Commerce of the Senate.</text> </paragraph> <paragraph id="HD52DEAAD9E3D4B3997C817779D13B17E"><enum>(2)</enum><header>Report</header><text>The STB shall report annually to such Committees on the progress on implementation of the recommendations until the implementation is complete.</text> </paragraph> 
<paragraph id="H395F23534E3B4F35A45C29DE4B6AA317"><enum>(3)</enum><header>Plan implementation</header><text>The STB shall designate an individual to implement the plan developed under subsection (a).</text> </paragraph></subsection></section> <section id="HBFC24BF9F9A249F6B6B0A696CFB9D092"><enum>3.</enum><header>No additional funds authorized</header><text display-inline="no-display-inline">No additional funds are authorized to carry out the requirements of this Act. Such requirements shall be carried out using amounts otherwise authorized.</text> </section> 
</legis-body> <attestation><attestation-group><role>Speaker of the House of Representatives.</role></attestation-group><attestation-group><role>Vice President of the United States and President of the Senate.</role></attestation-group></attestation>
</bill> 


