<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN21783-353-GP-RF7"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>111 S2902 RS: Federal Information Security Modernization Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-12-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 673</calendar><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 2902</legis-num><associated-doc role="report">[Report No. 117–274]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210929">September 29, 2021</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself, <cosponsor name-id="S349">Mr. Portman</cosponsor>, and <cosponsor name-id="S277">Mr. Carper</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20221219">December 19, 2022</action-date><action-desc>Reported by <sponsor name-id="S380">Mr. Peters</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To modernize Federal information security management, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Information Security Modernization Act of 2021</short-title></quote>.</text></section><section id="id3D5D7FF2CAF9466C9530BEE12C9B04BD" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>2.</enum><header>Table of contents</header><text display-inline="no-display-inline">The table of contents for this Act is as follows:</text><toc changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc-entry level="section" idref="S1">Sec. 1. Short title.</toc-entry><toc-entry level="section" idref="id3D5D7FF2CAF9466C9530BEE12C9B04BD">Sec. 2. Table of contents.</toc-entry><toc-entry level="section" idref="idA6F5F6D48B854DC3B8051A1A3206E772">Sec. 3. Definitions.</toc-entry><toc-entry level="title" idref="idA32CA59DB4584307AA1FB91684E44150">TITLE I—Updates to FISMA</toc-entry><toc-entry level="section" idref="id744FB6C47AD74AE19A83A0829E153575">Sec. 101. Title 44 amendments.</toc-entry><toc-entry level="section" idref="id3C33B291D5D6406890C11DCBA266F3DD">Sec. 102. Amendments to subtitle III of title 40.</toc-entry><toc-entry level="section" idref="idDB6C12AFB4E6446AA2ADC93C9C80792F">Sec. 103. Actions to enhance Federal incident response.</toc-entry><toc-entry level="section" idref="idFD13785A520E4503ACADB2CDC0C27474">Sec. 104. Additional guidance to agencies on FISMA updates.</toc-entry><toc-entry level="section" idref="id02714F2B4ED54D0482D6E01336B563DB">Sec. 105. Agency requirements to notify entities impacted by incidents.</toc-entry><toc-entry level="title" idref="idDFED287744094E38B44FBB2D9BE4BD08">TITLE II—Improving Federal cybersecurity</toc-entry><toc-entry level="section" idref="id7D2C6E371E9642DBA819AA9F24B98A2B">Sec. 201. Evaluation of effectiveness of standards.</toc-entry><toc-entry level="section" idref="id446F8C8CA5B84DAE8E829DC5579DDD53">Sec. 202. Mobile security standards.</toc-entry><toc-entry level="section" idref="idBB9764D29C4445B9A5BD6E6D3DDD069C">Sec. 203. Quantitative cybersecurity metrics.</toc-entry><toc-entry level="section" idref="idb525875190584d70b0d6d272d5fba18b">Sec. 204. Data and logging retention for incident response.</toc-entry><toc-entry level="section" idref="id88e7b24239424c1b998e8f9625612584">Sec. 205. CISA agency advisors.</toc-entry><toc-entry level="section" idref="idD88B1A0B7F3B453E823C7504B69891F8">Sec. 206. Federal penetration testing policy.</toc-entry><toc-entry level="section" idref="id8E8BC5E043594941B1573F54B420CA0D">Sec. 207. Ongoing threat hunting program.</toc-entry><toc-entry level="section" idref="idDC48A75DC52C4CD5A59E5BB7106014DF">Sec. 208. Codifying vulnerability disclosure programs.</toc-entry><toc-entry level="section" idref="id909456EA06AE4DCAA452E4BD1F8ADD39">Sec. 209. Implementing presumption of compromise and zero trust architectures.</toc-entry><toc-entry level="section" idref="idf7af9dbfed7549b6a1fba7943bfaee3b">Sec. 210. Automation reports.</toc-entry><toc-entry level="section" idref="idE3E31296AFAE41B39A2EBFC2B794E119">Sec. 211. Extension of Federal Acquisition Security Council.</toc-entry><toc-entry level="title" idref="id0D79C2148CBF4AA398F0D242747F4BC7">TITLE III—Pilot programs to enhance Federal cybersecurity</toc-entry><toc-entry level="section" idref="id7FB4254ED7724E2D9AEF65C9840619C2">Sec. 301. Continuous independent FISMA evaluation pilot.</toc-entry><toc-entry level="section" idref="id27A831E42EC1493DAE21F02361F75446">Sec. 302. Active cyber defensive pilot.</toc-entry><toc-entry level="section" idref="id6c32b416e29b4d86834d526563796b7f">Sec. 303. Security operations center as a service pilot.</toc-entry></toc></section><section id="idA6F5F6D48B854DC3B8051A1A3206E772" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, unless otherwise specified:</text><paragraph id="id6FB2BB8590604830AD7642ABCE33DD5B"><enum>(1)</enum><header>Additional cybersecurity procedure</header><text>The term <term>additional cybersecurity procedure</term> has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act.</text></paragraph><paragraph id="id3283C4A32DD343AAB410B2979486EFD6"><enum>(2)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="id4952B5D268C9475AB9C9187980DEEFCC"><enum>(3)</enum><header>Appropriate congressional committees</header><text display-inline="yes-display-inline">The term <term>appropriate congressional committees</term> means—</text><subparagraph id="idd5b286bc7e794297b1232ec2be997d50"><enum>(A)</enum><text display-inline="yes-display-inline">the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name>;</text></subparagraph><subparagraph id="id23940f4ae0ed4030938936d633b5083b"><enum>(B)</enum><text>the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name>; and</text></subparagraph><subparagraph id="id3108f1f4141d4577aee58f71067cd6e5"><enum>(C)</enum><text>the <committee-name committee-id="">Committee on Homeland Security of the House of Representatives.</committee-name></text></subparagraph></paragraph><paragraph id="id0D74AAFA84634CC898E0D3F3A232CC0D"><enum>(4)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office of Management and Budget.</text></paragraph><paragraph id="id5D0EC84A3ACA49B2BD470E772F39D972"><enum>(5)</enum><header>Incident</header><text>The term <term>incident</term> has the meaning given the term in section 3552(b) of title 44, United States Code.</text></paragraph><paragraph id="id6FC2625BD2D840FCB5EFE22B5C37D73A"><enum>(6)</enum><header>Penetration test</header><text>The term <term>penetration test</term> has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act.</text></paragraph><paragraph id="id1EE4C264C8BA4781BDF82A4686603CFB"><enum>(7)</enum><header>Threat hunting</header><text>The term <term>threat hunting</term> means proactively and iteratively searching for threats to systems that evade detection by automated threat detection systems.</text></paragraph><paragraph id="id761B2B4BCF074360A8142BB72BE05022"><enum>(8)</enum><header>Verification specification</header><text>The term <term>verification specification</term> means a specification developed under section 11331(f) of title 40, United States Code, as amended by this Act. </text></paragraph></section><title id="idA32CA59DB4584307AA1FB91684E44150" style="OLC" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>I</enum><header>Updates to FISMA</header><section id="id744FB6C47AD74AE19A83A0829E153575"><enum>101.</enum><header>Title 44 amendments</header><subsection id="idF3811BA1B56A487B8B46DA452AA7860F"><enum>(a)</enum><header>Subchapter I amendments</header><text display-inline="yes-display-inline">Subchapter I of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended—</text><paragraph id="id0156139A122D4813B6C84E99128E6B15"><enum>(1)</enum><text>in section 3504—</text><subparagraph id="id1D57176F8D694CF4AD9307D82C0B8BC1"><enum>(A)</enum><text display-inline="yes-display-inline">in subsection (a)(1)(B)(v), by striking <quote>confidentiality, security, disclosure, and sharing of information</quote> and inserting <quote>disclosure, sharing of information, and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, confidentiality and security</quote>;</text></subparagraph><subparagraph id="id3B9BD02A11B341C4B3E1B89202BDAB2B"><enum>(B)</enum><text display-inline="yes-display-inline">in subsection (b)(2)(B), by inserting <quote>in coordination with the Director of the Cybersecurity and Infrastructure Security Agency</quote> after <quote>standards for security</quote>;</text></subparagraph><subparagraph id="id432B48F5836B402F8765DB2BA580E0EE"><enum>(C)</enum><text>in subsection (g), by striking paragraph (1) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idFCBD7DBFA51448478EFE3F64A23DE329" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id0095A979A1454C51B45ACB42A8BF6E0B"><enum>(1)</enum><text>with respect to information collected or maintained by or for agencies—</text><subparagraph id="id7079BF8F11A2441D8DAFD06C08C0872B"><enum>(A)</enum><text>develop and oversee the implementation of policies, principles, standards, and guidelines on privacy, disclosure, and sharing of the information; and</text></subparagraph><subparagraph id="id00D27B8DC7AB4C1890776CD615D6B5DE"><enum>(B)</enum><text>in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, develop and oversee policies, principles, standards, and guidelines on confidentiality and security of the information; and</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="idAAC3CB8A04BF4D95A50C7F20B4342A82"><enum>(D)</enum><text>in subsection (h)(1)—</text><clause id="id4647A1276115453A824C782FCC687B4D"><enum>(i)</enum><text>in the matter preceding subparagraph (A)—</text><subclause id="idE2511133BDC94009A2E7D51E05C23DAB"><enum>(I)</enum><text>by inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency,</quote> before <quote>the Director</quote>; and</text></subclause><subclause id="idC1F27A039A434F5688B3D4A7750E64D5"><enum>(II)</enum><text>by inserting a comma before <quote>and the Administrator</quote>; and</text></subclause></clause><clause id="id5093FFF7165C42E0BCD9346729977E00"><enum>(ii)</enum><text>in subparagraph (A), by inserting <quote>security and</quote> after <quote>information technology</quote>;</text></clause></subparagraph></paragraph><paragraph id="idF44373CD48A442DBBD3BF75DE55419C9"><enum>(2)</enum><text>in section 3505—</text><subparagraph id="idF8B901A1F05A40B595C6E985BD43F336"><enum>(A)</enum><text>in paragraph (3) of the first subsection designated as subsection (c)—</text><clause id="id9386A8338DB14192BDECAF1A3DF294ED"><enum>(i)</enum><text>in subparagraph (B)—</text><subclause id="id9D0E5D1E298E476BB14E28CD1006C4A0"><enum>(I)</enum><text>by inserting <quote>and the Director of the Cybersecurity and Infrastructure Security Agency</quote> after <quote>Comptroller General</quote>; and</text></subclause><subclause id="id27821C104A934059AE418D53ADAD4421"><enum>(II)</enum><text>by striking <quote>and</quote> at the end;</text></subclause></clause><clause id="id4D7C056313C143D5B53E4011832C8DBC"><enum>(ii)</enum><text>in subparagraph (C)(v), by striking the period at the end and inserting <quote>; and</quote>; and</text></clause><clause id="id37DAF0CCDD8B4BD39B5601C109BB6263"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id553CCA43B83A42DA84F8774660B05988" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="idD73DBAB192E74241B22AF425CF850E3E" indent="up1"><enum>(D)</enum><text>maintained on a continual basis through the use of automation, machine-readable data, and scanning.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id1B4F69468061442AB31145527877C406"><enum>(B)</enum><text>by striking the second subsection designated as subsection (c);</text></subparagraph></paragraph><paragraph id="idD76920FDAB7740E3958DF8C12E2661AE"><enum>(3)</enum><text>in section 3506—</text><subparagraph id="id2CB4D14F321D49DAAE10F3CFC37AFB67"><enum>(A)</enum><text>in subsection (b)—</text><clause id="idF0A483F44C2641DDAB894913BE24D210"><enum>(i)</enum><text>in paragraph (1)(C), by inserting <quote>, availability</quote> after <quote>integrity</quote>; and</text></clause><clause id="id0915AEF46C554B58A93CD9AB314F1DE8"><enum>(ii)</enum><text>in paragraph (4), by inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency,</quote> after <quote>General Services,</quote>; and</text></clause></subparagraph><subparagraph id="idD9C9F64681FF42329C200FBC0AA3E0EF"><enum>(B)</enum><text>in subsection (h)(3), by inserting <quote>security,</quote> after <quote>efficiency,</quote>;</text></subparagraph></paragraph><paragraph id="idDF4AD19C4B974675B1F706CDA6A256DB"><enum>(4)</enum><text>in section 3513—</text><subparagraph id="idF7FE4D4BB9994201B45026C2369F5FF1"><enum>(A)</enum><text>in subsection (a), by inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency,</quote> before <quote>the Administrator of General Services</quote>;</text></subparagraph><subparagraph id="idB5EC63D3756B48D6B1EA9D12E32A763E"><enum>(B)</enum><text>by redesignating subsection (c) as subsection (d); and</text></subparagraph><subparagraph id="id95C43667CF544449948A9BC77085D891"><enum>(C)</enum><text>by inserting after subsection (b) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idF8A96C7E46F94FD5A147F09FEE24AED9" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subsection id="idFFC29A30F1824DDD9FD7C14726A67FD5"><enum>(c)</enum><text>Each agency providing a written plan under subsection (b) shall provide any portion of the written plan addressing information security or cybersecurity to the Director of the Cybersecurity and Infrastructure Security Agency.</text></subsection><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="idAD934995D4474FE580DFC2D1117CE1B6"><enum>(5)</enum><text>in section 3520A(b)—</text><subparagraph id="id85960549D7B144ADA7389AD7BE933C4B"><enum>(A)</enum><text>in paragraph (1), by striking <quote>, protection</quote>;</text></subparagraph><subparagraph id="id8F6AEF33F381444CBCC35EF154AA81DC"><enum>(B)</enum><text>by redesignating paragraphs (2), (3), (4), and (5) as paragraphs (3), (4), (5), and (6), respectively; and</text></subparagraph><subparagraph id="id63FB20492CD047399BDAA42F8A410A3B"><enum>(C)</enum><text>by inserting after paragraph (1) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id93CAFD89E42A472A987E96C2BACA25B4" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id259ACFDF6547476780F9206A2EB8B10B"><enum>(2)</enum><text>in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, establish Governmentwide best practices for the protection of data;</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph></subsection><subsection id="id4492DCA3A7AF4B2CAB83D2EDFC818C46"><enum>(b)</enum><header>Suchapter II definitions</header><paragraph id="id8FF292C735CB426E8353ED7E6B1C5FE0"><enum>(1)</enum><header>In general</header><text>Section 3552(b) of title 44, United States Code, is amended—</text><subparagraph id="idCEDC80436D6D477D8F6590EB9A80BF82"><enum>(A)</enum><text>by redesignating paragraphs (1), (2), (3), (4), (5), (6), and (7) as paragraphs (2), (3), (4), (5), (6), (9), and (11), respectively;</text></subparagraph><subparagraph id="idDC5F7BAE1798472B9C72F2D5B82DC0C4"><enum>(B)</enum><text>by inserting before paragraph (2), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id41653760A2E5454BB86A2849311ED230" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idC84C58FD59224AA79863F9F26B46D53A"><enum>(1)</enum><text>The term <term>additional cybersecurity procedure</term> means a process, procedure, or other activity that is established in excess of the information security standards promulgated under section 11331(b) of title 40 to increase the security and reduce the cybersecurity risk of agency systems, such as continuous threat hunting, increased network segmentation, endpoint detection and response, or persistent penetration testing.</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="id694277D8835249A88CE55F3AD97989F2"><enum>(C)</enum><text>by inserting after paragraph (6), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idCD106A01A9864E878CD03E2BA8978C84" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id55EBDBA2676C479891AEFADE27EF743E"><enum>(7)</enum><text>The term <term>high value asset</term> means information or an information system that the head of an agency determines so critical to the agency that the loss or corruption of the information or the loss of access to the information system would have a serious impact on the ability of the agency to perform the mission of the agency or conduct business.</text></paragraph><paragraph id="id4D81E110632B43598734B2E5C39B943C"><enum>(8)</enum><text>The term <term>major incident</term> has the meaning given the term in guidance issued by the Director under section 3598(a).</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="idFEC95AC37DB54CE392C9F8AE6AA3D865"><enum>(D)</enum><text>by inserting after paragraph (9), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id82D54495349D4C9FB5B7C8B90B6F7DA9" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id29E2AD56C4534A4CA1D9DDEA4EB0C751"><enum>(10)</enum><text>The term <term>penetration test</term> means a specialized type of assessment that—</text><subparagraph id="id35EB646C15544844B5BAC04CB11A427E"><enum>(A)</enum><text>is conducted on an information system or a component of an information system; and</text></subparagraph><subparagraph id="id23D43FCA38B0468D981A6E0655DF3F61"><enum>(B)</enum><text>emulates an attack or other exploitation capability of a potential adversary, typically under specific constraints, in order to identify any vulnerabilities of an information system or a component of an information system that could be exploited.</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="id1602B804B89344249A4464646177C3FA"><enum>(E)</enum><text>by inserting after paragraph (11), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idE26C91B16BF843448FDB3B21A9C4B3A7" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idC70BB4E6056B4B4BA94EF3016DAE3DDF" commented="no" display-inline="no-display-inline"><enum>(12)</enum><text>The term <term>shared service</term> means a business or mission function that is provided for use by multiple organizations within or between agencies.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idCCEC828E1D5C4930A183A9FF60AA7FA4"><enum>(13)</enum><text>The term <term>verification specification</term> means a specification developed under section 11331(f) of title 40.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="idA09766A6AB2B415E8CC0E98D738D90AA"><enum>(2)</enum><header>Conforming amendments</header><subparagraph id="id4832A8D066E54DD494C5B9FFFC27E525"><enum>(A)</enum><header>Homeland Security Act of 2002</header><text>Section 1001(c)(1)(A) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/511">6 U.S.C. 511(1)(A)</external-xref>) is amended by striking <quote>section 3552(b)(5)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id97A100FFCFD849DABD7495C3D563A828"><enum>(B)</enum><header>Title 10</header><clause id="id0C8B222E537E4A858A694810CECBAF50"><enum>(i)</enum><header>Section 2222</header><text>Section 2222(i)(8) of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)(A)</quote> and inserting <quote>section 3552(b)(9)(A)</quote>.</text></clause><clause id="id32D44CA900F2487FB3E9227EE23FFE2D"><enum>(ii)</enum><header>Section 2223</header><text>Section 2223(c)(3) of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause><clause id="id2BD78E342C164183853CB6F4F37A32A5"><enum>(iii)</enum><header>Section 2315</header><text>Section 2315 of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause><clause id="idD2F2362EFF7544C59803857633D8396C"><enum>(iv)</enum><header>Section 2339a</header><text>Section 2339a(e)(5) of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause></subparagraph><subparagraph id="id2B798897DF024C7AA0FD33F8A84AE2F7"><enum>(C)</enum><header>High-Performance Computing Act of 1991</header><text>Section 207(a) of the High-Performance Computing Act of 1991 (<external-xref legal-doc="usc" parsable-cite="usc/15/5527">15 U.S.C. 5527(a)</external-xref>) is amended by striking <quote>section 3552(b)(6)(A)(i)</quote> and inserting <quote>section 3552(b)(9)(A)(i)</quote>.</text></subparagraph><subparagraph id="id2C77F0CB8B3B4A69A8FF31E514A4EAB7" commented="no"><enum>(D)</enum><header>Internet of Things Cybersecurity Improvement Act of 2020</header><text>Section 3(5) of the Internet of Things Cybersecurity Improvement Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3a">15 U.S.C. 278g–3a</external-xref>) is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id690867B0C1C54AC9A727787E45FBABA1"><enum>(E)</enum><header>National Defense Authorization Act for Fiscal Year 2013</header><text>Section 933(e)(1)(B) of the National Defense Authorization Act for Fiscal Year 2013 (<external-xref legal-doc="usc" parsable-cite="usc/10/2224">10 U.S.C. 2224</external-xref> note) is amended by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id81FB25AFD9EE41CB8B68FE87C7BB51AF"><enum>(F)</enum><header>Ike Skelton National Defense Authorization Act for Fiscal Year 2011</header><text>The Ike Skelton National Defense Authorization Act for Fiscal Year 2011 (<external-xref legal-doc="public-law" parsable-cite="pl/111/383">Public Law 111–383</external-xref>) is amended—</text><clause id="id28ABC39B5ED64CFDADE4AB8EEB34BB4C"><enum>(i)</enum><text>in section 806(e)(5) (<external-xref legal-doc="usc" parsable-cite="usc/10/2304">10 U.S.C. 2304</external-xref> note), by striking <quote>section 3542(b)</quote> and inserting <quote>section 3552(b)</quote>;</text></clause><clause id="id4D6E954DCF39420E88B02B0F1AAE4DA9"><enum>(ii)</enum><text>in section 931(b)(3) (<external-xref legal-doc="usc" parsable-cite="usc/10/2223">10 U.S.C. 2223</external-xref> note), by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>; and</text></clause><clause id="id2F2012B090C84302B63B746E76F23E75"><enum>(iii)</enum><text>in section 932(b)(2) (<external-xref legal-doc="usc" parsable-cite="usc/10/2224">10 U.S.C. 2224</external-xref> note), by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause></subparagraph><subparagraph id="id2C5F86811AE146049B4F541119E64906"><enum>(G)</enum><header>E-Government Act of 2002</header><text>Section 301(c)(1)(A) of the E-Government Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/44/3501">44 U.S.C. 3501</external-xref> note) is amended by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id2779491D21F8468BB74A5EE276F8D128"><enum>(H)</enum><header>National Institute of Standards and Technology Act</header><text>Section 20 of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g–3</external-xref>) is amended—</text><clause id="idC72BD1C222AF46E297E0457FB3C7EBC9"><enum>(i)</enum><text>in subsection (a)(2), by striking <quote>section 3552(b)(5)</quote> and inserting <quote>section 3552(b)</quote>; and</text></clause><clause id="id30D8D0F17D21418C8F8408A5E7FE5311"><enum>(ii)</enum><text>in subsection (f)—</text><subclause id="id5C9EA510A1544C68A287241F412B6A6E"><enum>(I)</enum><text>in paragraph (3), by striking <quote>section 3532(1)</quote> and inserting <quote>section 3552(b)</quote>; and</text></subclause><subclause id="id174D4CB4EA8544BC952E3386050FC670"><enum>(II)</enum><text>in paragraph (5), by striking <quote>section 3532(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></subclause></clause></subparagraph></paragraph></subsection><subsection id="id95FB650A378C400AB228BCF228D933EB"><enum>(c)</enum><header>Subchapter II amendments</header><text>Subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended—</text><paragraph id="id23DC772C238C4C03AA188CEDEE60FD50"><enum>(1)</enum><text>in section 3551—</text><subparagraph id="idE76980FEEBC242EAA6A68425929A45B0"><enum>(A)</enum><text>by redesignating paragraphs (3), (4), (5), and (6) as paragraphs (4), (5), (6), and (7), respectively;</text></subparagraph><subparagraph id="id68AE2E2D8F964FBC94D9A46951E512D7"><enum>(B)</enum><text>by inserting after paragraph (2) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id2EEBF07358BC4DA2B54A4ADFD62946B1" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idFFA2E5D3147C4E85A4A53856B5322349"><enum>(3)</enum><text>recognize the role of the Cybersecurity and Infrastructure Security Agency as the lead cybersecurity entity for operational coordination across the Federal Government;</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="idCDF87796FDBB4C17A9908641DA1DF329"><enum>(C)</enum><text>in paragraph (5), as so redesignated, by striking <quote>diagnose and improve</quote> and inserting <quote>integrate, deliver, diagnose, and improve</quote>;</text></subparagraph><subparagraph id="idD0886197DAC64116898C4C423A65B7F2"><enum>(D)</enum><text>in paragraph (6), as so redesignated, by striking <quote>and</quote> at the end; and</text></subparagraph><subparagraph id="idDA6F60DCEED740839380B869D7D08B25"><enum>(E)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id0FD75E7B193744C2A37317F0DB48DF56" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id123146A41ED644C1A431049F0F0CB9AC" commented="no"><enum>(8)</enum><text>recognize that each agency has specific mission requirements and, at times, unique cybersecurity requirements to meet the mission of the agency;</text></paragraph><paragraph id="id00C5D799265E4DCE956D492E1A3D9FB3" commented="no"><enum>(9)</enum><text>recognize that each agency does not have the same resources to secure agency systems, and an agency should not be expected to have the capability to secure the systems of the agency from advanced adversaries alone; and</text></paragraph><paragraph id="id7DBA4B983B36455497ACE54DA30576B6" commented="no"><enum>(10)</enum><text>recognize that—</text><subparagraph commented="no" id="idC0C9BDFCDC55440A9E037E8B457161FC"><enum>(A)</enum><text>a holistic Federal cybersecurity model is necessary to account for differences between the missions and capabilities of agencies; and</text></subparagraph><subparagraph commented="no" id="idCA5FF1ECE18241429C7C93F59D0E4DBC"><enum>(B)</enum><text>in accounting for the differences described in subparagraph (A) and ensuring overall Federal cybersecurity—</text><clause id="id60817f24f27a4f3a8882b017e6004c3e"><enum>(i)</enum><text>the Office of Management and Budget is the leader for policy development and oversight of Federal cybersecurity; </text></clause><clause commented="no" id="id229D1A6F2CDB4DEAA1C0C2A965BDACEF"><enum>(ii)</enum><text>the Cybersecurity and Infrastructure Security Agency is the leader for implementing operations at agencies; and</text></clause><clause id="idaa1506cdade048698f8931b7bfd0c1d7"><enum>(iii)</enum><text>the National Cyber Director is responsible for developing the overall cybersecurity strategy of the United States and advising the President on matters relating to cybersecurity.</text></clause></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="idD749490DC9DA4F7A99A709CDA582E24D"><enum>(2)</enum><text>in section 3553, as amended by section 1705 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/283">Public Law 116–283</external-xref>)—</text><subparagraph id="idED0CAFADB0D240A49A89D0D710B951C9"><enum>(A)</enum><text>in subsection (a)—</text><clause id="id814E6688AA8648B1B10F43C3307744F8"><enum>(i)</enum><text>in paragraph (1)—</text><subclause id="id6234D83D87954ABEBE9899EFD8543031"><enum>(I)</enum><text>by striking <quote>developing and</quote> and inserting <quote>in coordination with the Director of the Cybersecurity and Infrastructure Security Agency,</quote>; and</text></subclause><subclause id="id96592E5A2A66445A9EFA27D19C56F72D"><enum>(II)</enum><text>by inserting <quote>and associated verification specifications</quote> before <quote>promulgated</quote>; and</text></subclause></clause><clause id="idF7203B35B29B476C8A505D8D8298BB0C"><enum>(ii)</enum><text>in paragraph (5), by inserting <quote>, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency,</quote> before <quote>agency compliance</quote>;</text></clause></subparagraph><subparagraph id="id2EF4B47D2CE7441D8E755ED70C1BC79E"><enum>(B)</enum><text>in subsection (b)—</text><clause id="id9227D5D08F61474596C8FC80BF883859"><enum>(i)</enum><text>by striking the subsection heading and inserting <quote><header-in-text style="USC" level="subsection">Cybersecurity and Infrastructure Security Agency</header-in-text></quote>;</text></clause><clause id="id1E5FC333495541208567CFED7063D1E2"><enum>(ii)</enum><text>in the matter preceding paragraph (1), by striking <quote>the Secretary</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency</quote>;</text></clause><clause id="id8B486D1453574AE0BAA2FCEEF0D50E22"><enum>(iii)</enum><text>in paragraph (2)—</text><subclause id="id25279678B4DE416AA605F6FD00CF714F"><enum>(I)</enum><text>in subparagraph (A), by inserting <quote>and reporting requirements under subchapter IV of this title</quote> after <quote>section 3556</quote>; and</text></subclause><subclause id="id2E6C86D2337E42A0AF1A5D1223229634"><enum>(II)</enum><text>in subparagraph (D), by striking <quote>the Director or Secretary</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency</quote>;</text></subclause></clause><clause id="idB5108B8C5B7B47289DA207C3CCEED1A3"><enum>(iv)</enum><text>in paragraph (5), by striking <quote>coordinating</quote> and inserting <quote>leading the coordination of</quote>;</text></clause><clause id="idFA05FBB3945A4F518BE25D485EF3F88C"><enum>(v)</enum><text>in paragraph (6)—</text><subclause id="id9518F08268CB45D2B02CE439BBFDD66E"><enum>(I)</enum><text>in the matter preceding subparagraph (A), by inserting <quote>and verifications specifications</quote> before <quote>promulgated under</quote>;</text></subclause><subclause id="id93E5B994F49B4B079A35D1FDEABAF348"><enum>(II)</enum><text>in subparagraph (C), by striking <quote>and</quote> at the end;</text></subclause><subclause id="id28C218B0EB3F46A48954F0F85FD0FC59"><enum>(III)</enum><text>in subparagraph (D), by adding <quote>and</quote> at the end; and</text></subclause><subclause id="id2B3466BE31B64C69B2DF6BF4623BC233"><enum>(IV)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id1FF8CEEF05B04C5DA8A14C606E0B00FD" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="idB4C3A46AE62041C092D3E2E1BE7C9D22"><enum>(E)</enum><text>taking any other action that the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director—</text><clause id="idFAC8C3D251394B8E93FADF70A9802E7A"><enum>(i)</enum><text>may determine necessary; and</text></clause><clause id="id9A3355B3108448F689301AC73C4BAF3E"><enum>(ii)</enum><text>is authorized to perform;</text></clause></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subclause></clause><clause id="id295D6D90B156411F9B89E28DC11827D9"><enum>(vi)</enum><text>in paragraph (8), by striking <quote>the Secretary's discretion</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency's discretion</quote>; and</text></clause><clause id="id11FD99379E4A44CB98ACDBF0C5A2D7B7"><enum>(vii)</enum><text>in paragraph (9), by striking <quote>as the Director or the Secretary, in consultation with the Director,</quote> and inserting <quote>as the Director of the Cybersecurity and Infrastructure Security Agency</quote>;</text></clause></subparagraph><subparagraph id="id23DB3A436D87410E8782C96C42C1EBE0"><enum>(C)</enum><text>in subsection (c)—</text><clause id="id147E73C0E34942B482FB2A3BA104AEDE"><enum>(i)</enum><text>in paragraph (4), by striking <quote>and</quote> at the end;</text></clause><clause id="id9DD6273C751D442F961E81D003C226D3"><enum>(ii)</enum><text>by redesignating paragraph (5) as paragraph (7); and</text></clause><clause id="id64EE0657078946C59CF0EAF88881F3AC"><enum>(iii)</enum><text>by inserting after paragraph (4) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id6C8AC948DCAE47648132E3ED20D805C0" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id19D6ED9E01584D768EE1D86A8253D2C3"><enum>(5)</enum><text>an assessment of agency use of automated verification of standards for the standards promulgated under section 11331 of title 40 using verification specifications;</text></paragraph><paragraph id="id07600118CC60422EACC50B49797346E1"><enum>(6)</enum><text>a summary of each assessment of Federal risk posture performed under subsection (i); and</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="idE5BD0379C42645D0B91FE65F35CB1DB6"><enum>(D)</enum><text>in subsection (f)(2)(B), by striking <quote>conflict with</quote> and inserting <quote>reduce the security posture of agencies established under</quote>;</text></subparagraph><subparagraph id="id464304555AAB46189E7482D1C17EA58D"><enum>(E)</enum><text>by redesignating subsections (i), (j), (k), and (l) as subsections (j), (k), (l), and (m) respectively;</text></subparagraph><subparagraph id="id443BA269BD99412993A7DAF464573C2B"><enum>(F)</enum><text>by inserting after subsection (h) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id852DA73DCC78421BBB290231B5C1FBEB" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subsection id="idF985C7B86FEC433D8D7555836E53097C"><enum>(i)</enum><header>Federal risk assessments</header><text>The Director of the Cybersecurity and Infrastructure Security Agency, in coordination with the Director, shall perform, on an ongoing and continuous basis, assessments of Federal risk posture using any available information on the cybersecurity posture of agencies, including— </text><paragraph id="idE98B076BDC6743359086271E8D38002C"><enum>(1)</enum><text>the status of agency cybersecurity remedial actions described in section 3554(b)(7);</text></paragraph><paragraph id="idA2ECA45E19844B60BA2911E035A9144A"><enum>(2)</enum><text>any vulnerability information relating to the systems of an agency that is known by the agency;</text></paragraph><paragraph id="idED4E3FC2FD0D40919FE23359CCA4468E"><enum>(3)</enum><text>analysis of incident information under section 3597;</text></paragraph><paragraph id="idE2847A5D59D341D98D45C3DA529F4B94"><enum>(4)</enum><text>evaluation of penetration testing performed under section 3559A;</text></paragraph><paragraph id="id3C465075B4C84C69A799AD604988F586"><enum>(5)</enum><text>evaluation of vulnerability disclosure program information under section 3559B;</text></paragraph><paragraph id="idEB8195E2146445F996B3B2647EC4B24C"><enum>(6)</enum><text>evaluation of agency threat hunting results;</text></paragraph><paragraph id="id9C40D352B7E54D2DBBF5184C571A5739"><enum>(7)</enum><text>evaluation of Federal and non-Federal threat intelligence;</text></paragraph><paragraph id="id0A63DE99AE074770A8AEEA3F707A3CB2"><enum>(8)</enum><text>data on compliance with standards issued under section 11331 of title 40 that, when appropriate, uses verification specifications;</text></paragraph><paragraph id="id6F5932C12A1F4CEC8AE8792A514C2173"><enum>(9)</enum><text>agency system risk assessments performed under section 3554(a)(1)(A); and</text></paragraph><paragraph id="id588ECD03D10F4E9F966540CAEFB71778"><enum>(10)</enum><text>any other information the Secretary determines relevant.</text></paragraph></subsection><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="id58A2370616654104A230927EADB47A6A"><enum>(G)</enum><text>in subsection (j), as so redesignated—</text><clause id="idE0D9627A31DB4CB387F94DDEEEF90D3A"><enum>(i)</enum><text>by striking <quote>regarding the specific</quote> and inserting “that includes a summary of—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id5D354C1706174F62B3CDA0B00F5D3AF9" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id279810C8E9844BDCAF48AB9469D84927"><enum>(1)</enum><text>the specific</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="idBD3889C7D9AE42A99331ADED991627F1"><enum>(ii)</enum><text>in paragraph (1), as so designated, by striking the period at the end and inserting <quote>; and</quote> and</text></clause><clause id="id1E87A0123D36460C815DEB763577F48A"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id2BF417C9C4AA43179E629757123DFA3D" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id61FA2F76B9A443619AE5560556BCB3F2"><enum>(2)</enum><text>the trends identified in the Federal risk assessment performed under subsection (i).</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause></subparagraph></paragraph><paragraph id="id99C82098D805412E9076B368DAEE027B"><enum>(3)</enum><text>in section 3554—</text><subparagraph id="idB7385BD748C645AEB8D105CBC0878D13"><enum>(A)</enum><text>in subsection (a)—</text><clause id="idC9DBE5CC2E1D419C933D87B4EC58D327"><enum>(i)</enum><text>in paragraph (1)—</text><subclause id="idFAE22F03570F44F1A0992C10121E3460"><enum>(I)</enum><text>by redesignating subparagraphs (A), (B), and (C) as subparagraphs (B), (C), and (D), respectively;</text></subclause><subclause id="idD959E036220E45B4A9F6BD48740DF8C4"><enum>(II)</enum><text>by inserting before subparagraph (B), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9ECEB248DF964ED3890DC86C8C76C255" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="idEEEA817A095D4A8384AEAC75AE027CD6"><enum>(A)</enum><text>performing, not less frequently than once every 2 years or based on a significant change to system architecture or security posture, an agency system risk assessment that—</text><clause id="id4a1b0f136f41491d872fcaae8425a326"><enum>(i)</enum><text>identifies and documents the high value assets of the agency using guidance from the Director;</text></clause><clause id="id0e7744e599364b969674c486eae3d0b1"><enum>(ii)</enum><text>evaluates the data assets inventoried under section 3511 of title 44 for sensitivity to compromises in confidentiality, integrity, and availability;</text></clause><clause id="idfd0075a62c924472b643e332f55a570a"><enum>(iii)</enum><text>identifies agency systems that have access to or hold the data assets inventoried under section 3511 of title 44;</text></clause><clause id="ida9a251e75804419fa1871cb449e672e4"><enum>(iv)</enum><text>evaluates the threats facing agency systems and data, including high value assets, based on Federal and non-Federal cyber threat intelligence products, where available;</text></clause><clause id="id851b555e0219495ead7fadd4f408da87"><enum>(v)</enum><text>evaluates the vulnerability of agency systems and data, including high value assets, based on—</text><subclause id="id7c9e1debdddd4373aa3c650c657cf87f"><enum>(I)</enum><text>the results of penetration testing performed by the Department of Homeland Security under section 3553(b)(9);</text></subclause><subclause id="id90f1d710935043be965179cc9395196c"><enum>(II)</enum><text>the results of penetration testing performed under section 3559A;</text></subclause><subclause id="idaaf71320e6b44b20b5e890ac8fc553e5"><enum>(III)</enum><text>information provided to the agency through the vulnerability disclosure program of the agency under section 3559B;</text></subclause><subclause id="id66f0e59ade9b45b4a8c641bf364f26d2"><enum>(IV)</enum><text>incidents; and</text></subclause><subclause id="id1a81239286ad448aa7a26928198a6dc1"><enum>(V)</enum><text>any other vulnerability information relating to agency systems that is known to the agency;</text></subclause></clause><clause id="idccccf475b7f046fb84242c69c3af6d9a"><enum>(vi)</enum><text>assesses the impacts of potential agency incidents to agency systems, data, and operations based on the evaluations described in clauses (ii) and (iv) and the agency systems identified under clause (iii); and</text></clause><clause id="id299c1178a1ae4bfd84642c2d63816a58"><enum>(vii)</enum><text>assesses the consequences of potential incidents occurring on agency systems that would impact systems at other agencies, including due to interconnectivity between different agency systems or operational reliance on the operations of the system or data in the system;</text></clause></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subclause><subclause id="idB22F6E39760E47F7B2B14777CF5827D0"><enum>(III)</enum><text>in subparagraph (B), as so redesignated—</text><item id="id4FCF4CC5A05C482E91D88A60CD3F7A01"><enum>(aa)</enum><text>in the matter preceding clause (i), by striking <quote>providing information</quote> and inserting <quote>using information from the assessment conducted under subparagraph (A), providing, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, information</quote>;</text></item><item id="id199820660B3445299768040BD58F57C5"><enum>(bb)</enum><text>in clause (i), by striking <quote>and</quote> at the end;</text></item><item id="idB39BFE45E1D847F2A58E3A394960FBE1"><enum>(cc)</enum><text>in clause (ii), by adding <quote>and</quote> at the end; and</text></item><item id="idC93C631FC7EB40118F80578309DCC025"><enum>(dd)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idDD7C2D1CA48146E987B012C85E4314F8" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="id14586F6036B547949E5C808319696958"><enum>(iii)</enum><text>in consultation with the Director and the Director of the Cybersecurity and Infrastructure Security Agency, information or information systems used by agencies through shared services, memoranda of understanding, or other agreements;</text></clause><after-quoted-block>;</after-quoted-block></quoted-block></item></subclause><subclause id="idA8DF7A1F8EDA441F9D431D68139C92E7"><enum>(IV)</enum><text>in subparagraph (C), as so redesignated—</text><item id="id2865778D880E4D25B0F934BA02E49550"><enum>(aa)</enum><text>in clause (ii) by inserting <quote>binding</quote> before <quote>operational</quote>; and</text></item><item id="idC37B6A8532A24AE38C0526A309FC5908"><enum>(bb)</enum><text>in clause (vi), by striking <quote>and</quote> at the end; and</text></item></subclause><subclause id="idD68C1575639F464CB41D5F1D57169FB3"><enum>(V)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idAB04824634094CF3BE74356FA3418E45" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id23c1b6b99c3b4522b5985ed6803acf69"><enum>(E)</enum><text>not later than 30 days after the date on which an agency system risk assessment is performed under subparagraph (A), providing the assessment to—</text><clause id="id557ef412afc2461cb5efe90a070a0aab"><enum>(i)</enum><text>the Director;</text></clause><clause id="id5bd486dc4d984d01974ff26eaf725179"><enum>(ii)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency; and</text></clause><clause id="idFEB231941DDC426C9DEBBAB9DA2E66C1"><enum>(iii)</enum><text>the National Cyber Director;</text></clause></subparagraph><subparagraph id="idacc1a306d4c14f579a79215c718bf4b3"><enum>(F)</enum><text>in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and not less frequently than annually, performing an evaluation of whether additional cybersecurity procedures are appropriate for securing a system of, or under the supervision of, the agency, which shall—</text><clause id="id706bf8d3b2a84ecfac1351ab7b7854e6"><enum>(i)</enum><text>be completed considering the agency system risk assessment performed under subparagraph (A); and</text></clause><clause id="id084b5855dc4942b495959018ea90d4de"><enum>(ii)</enum><text>include a specific evaluation for high value assets; and</text></clause></subparagraph><subparagraph id="id977aad679ac34d56855297f2d18abbef"><enum>(G)</enum><text>not later than 30 days after completing the evaluation performed under subparagraph (F), providing the evaluation and an implementation plan for using additional cybersecurity procedures determined to be appropriate to—</text><clause display-inline="no-display-inline" commented="no" id="idE849D072E63142FDA222A0BAA94A415D"><enum>(i)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency;</text></clause><clause display-inline="no-display-inline" commented="no" id="id184073E109ED4AA89C24AFD82FF388D3"><enum>(ii)</enum><text>the Director; and</text></clause><clause display-inline="no-display-inline" commented="no" id="id28BD9267EE5E4F3CAD4AB3C2240BEBC5"><enum>(iii)</enum><text>the National Cyber Director.</text></clause></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subclause></clause><clause id="id366217CC319A418EA41D042F1DF6560B"><enum>(ii)</enum><text>in paragraph (2)—</text><subclause id="id026892E61A8D4338BE724B72E1E1D448"><enum>(I)</enum><text>in subparagraph (A), by inserting <quote>in accordance with the agency system risk assessment performed under paragraph (1)(A)</quote> after <quote>information systems</quote>;</text></subclause><subclause id="id714A8BE345AE47079C96ADDE43B0B385"><enum>(II)</enum><text>in subparagraph (B)—</text><item id="id828ECE5FB02A417184D83FD509A4EF2D"><enum>(aa)</enum><text>by striking <quote>in accordance with standards</quote> and inserting “in accordance with—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id8A5C9EF203484D5AAEE20C93EF6EC22D" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="idA937AEDB3B1C4032B9704FE51139EA92"><enum>(i)</enum><text>standards</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item><item id="id6E16763448E74E5DA40C75DE9385797B"><enum>(bb)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idC81FA3C92B1F448DA8DE9A209ABC31EF" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="id27F31589D8564C33BC39445970077674"><enum>(ii)</enum><text>the evaluation performed under paragraph (1)(F); and</text></clause><clause id="id949160A8A80C4B36B8FABF45AB612E68"><enum>(iii)</enum><text>the implementation plan described in paragraph (1)(G);</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item></subclause><subclause id="idACCFDEAF1F464FE7BC378F70D22178B2"><enum>(III)</enum><text>in subparagraph (D), by inserting <quote>, through the use of penetration testing, the vulnerability disclosure program established under section 3559B, and other means,</quote> after <quote>periodically</quote>;</text></subclause></clause><clause id="id63066F397B20482BADDC483F68BCD631"><enum>(iii)</enum><text>in paragraph (3)—</text><subclause id="id1C62B3D190774410B7256C9962945AA0"><enum>(I)</enum><text>in subparagraph (B), by inserting <quote>, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency,</quote> after <quote>maintaining</quote>;</text></subclause><subclause id="idD55B7732024046008E2846DE5DB9B793"><enum>(II)</enum><text>in subparagraph (D), by striking <quote>and</quote> at the end;</text></subclause><subclause id="idDD402DDF9E1D453F9F238F6F726DA099"><enum>(III)</enum><text>in subparagraph (E), by adding <quote>and</quote> at the end; and</text></subclause><subclause id="id1C09B9A54A074B658D33C0D4865F16A7"><enum>(IV)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id058CC80872A9452CB1D5E698EEEA3360" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id28E3D533884B4E0399B1BB2545073272"><enum>(F)</enum><text>implementing mechanisms for using verification specifications, or alternate verification specifications validated by the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director of the National Institute of Standards and Technology, to automatically verify the implementation of standards of agency systems promulgated under section 11331 of title 40 or any additional cybersecurity procedures, as applicable;</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subclause></clause><clause id="id29A8431F33D54BC8941ECA7B0E0CB7E7"><enum>(iv)</enum><text>in paragraph (5), by inserting <quote>and the Director of the Cybersecurity and Infrastructure Security Agency</quote> before <quote>on the effectiveness</quote>;</text></clause></subparagraph><subparagraph id="idCCB4DB8D30924DDEB263F0789DB315EE"><enum>(B)</enum><text>in subsection (b)—</text><clause id="idC9426538E1B54D0599E555ABA9DE3F11"><enum>(i)</enum><text>by striking paragraph (1) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id1ACC3E34BB6E465D88C4EC70A8381EE6" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idCB904E5DC1D24A98A829A2D228CD9774"><enum>(1)</enum><text>pursuant to subsection (a)(1)(A), performing an agency system risk assessment, which shall include using automated tools consistent with standards, verification specifications, and guidelines promulgated under section 11331 of title 40, as applicable;</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id0B1A3AC8ED234056B933CC80E5EB7CCE"><enum>(ii)</enum><text>in paragraph (2)(D)—</text><subclause id="idA4D4FB61AEEA4C21A4ABA55913A8FD2E"><enum>(I)</enum><text>by redesignating clauses (iii) and (iv) as clauses (iv) and (v), respectively;</text></subclause><subclause id="idCF236D8916644533B9014D280476714E"><enum>(II)</enum><text>by inserting after clause (ii) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id20C9E479A7234CF8809E4C0738C4F457" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="idCCDF52DD7A26462F8CC1C97DA592D78A"><enum>(iii)</enum><text>binding operational directives and emergency directives promulgated by the Director of the Cybersecurity and Infrastructure Security Agency under section 3553 of title 44;</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></subclause><subclause id="id41BE51B89B624CEEA027123111692CB3"><enum>(III)</enum><text>in clause (iv), as so redesignated, by striking <quote>as determined by the agency; and</quote> and inserting “as determined by the agency—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3B2DA455E71F4F71BF2F26D66C5C7B34" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subclause id="idECCFDFB51BEF436D95CD1C2DEC692F25"><enum>(I)</enum><text>in coordination with the Director of the Cybersecurity and Infrastructure Security Agency; and</text></subclause><subclause id="id54C382C630A148FBA7E6EABD9723E3E4"><enum>(II)</enum><text>in consideration of—</text><item id="id514F2A00D8F64FBB97624A1CF678C2E5"><enum>(aa)</enum><text>the agency risk assessment performed under subsection (a)(1)(A); and</text></item><item id="id8BC11B8DC6C24166A7F5D71FB952C888"><enum>(bb)</enum><text>the determinations of applying more stringent standards and additional cybersecurity procedures pursuant to section 11331(c)(1) of title 40; and</text></item></subclause><after-quoted-block>;</after-quoted-block></quoted-block></subclause></clause><clause id="id59EA0D6FB2404D71819B55AEFCE48670"><enum>(iii)</enum><text>in paragraph (5)—</text><subclause id="id606F97962D1C44DB88B9732B9E99E17A"><enum>(I)</enum><text>in subparagraph (A), by inserting <quote>, including penetration testing, as appropriate,</quote> after <quote>shall include testing</quote>; and</text></subclause><subclause id="idA5BBE3682A194250A1FEFEE305F6CC70"><enum>(II)</enum><text>in subparagraph (C), by inserting <quote>, verification specifications,</quote> after <quote>with standards</quote>;</text></subclause></clause><clause id="idED750A05CDD548658EE298B531A801B6"><enum>(iv)</enum><text>in paragraph (6), by striking <quote>planning, implementing, evaluating, and documenting</quote> and inserting <quote>planning and implementing and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, evaluating and documenting</quote>;</text></clause><clause id="id54DB19CE054342CB97797CB33BD008C3"><enum>(v)</enum><text>by redesignating paragraphs (7) and (8) as paragraphs (9) and (10), respectively;</text></clause><clause id="id055A0BF304204F5C9135E267DFA4FDB0"><enum>(vi)</enum><text>by inserting after paragraph (6) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9F77509AA6474D49AA467F6C7C72233D" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idf5a69c7584d34a259f0e86680f8fed31"><enum>(7)</enum><text>a process for providing the status of every remedial action and known system vulnerability to the Director and the Director of the Cybersecurity and Infrastructure Security Agency, using automation and machine-readable data to the greatest extent practicable;</text></paragraph><paragraph id="ide24c55e10a16418582ab4163937917bd"><enum>(8)</enum><text>a process for providing the verification of the implementation of standards promulgated under section 11331 of title 40 using verification specifications, automation, and machine-readable data, to the Director and the Director of the Cybersecurity and Infrastructure Security Agency;</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause><clause id="idF2E15CD58C2C4A4196DCB45C2E84A7A0"><enum>(vii)</enum><text>in paragraph (9)(C), as so redesignated—</text><subclause id="id455799DA95454D87B248CB4F2B7BA1FE"><enum>(I)</enum><text>by striking clause (ii) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id96C883F4D66A4B2AB0E69F8BE0164A32" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="idC764A92FFADC4E9B9CFD72ACE43AD4C9"><enum>(ii)</enum><text>notifying and consulting with the Federal information security incident center established under section 3556 pursuant to the requirements of section 3594;</text></clause><after-quoted-block>;</after-quoted-block></quoted-block></subclause><subclause id="idAF256891FCF34611B83355F0054130A1"><enum>(II)</enum><text>by redesignating clause (iii) as clause (iv);</text></subclause><subclause id="id5D900E353EFB4E7B8B117A6290E367B7"><enum>(III)</enum><text>by inserting after clause (ii) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idD52295AC29A54890839E22A950DEAF28" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="id7A0EBA9D8F5F4B30A84110F912202888"><enum>(iii)</enum><text>performing the notifications and other activities required under subchapter IV of this title; and</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></subclause><subclause id="id2854806B43374C9E9D5FBED4294D7AED"><enum>(IV)</enum><text>in clause (iv), as so redesignated—</text><item id="id95D98C6A6FD341EAA4B05699EC97FC4B"><enum>(aa)</enum><text>in subclause (I), by striking <quote>and relevant Offices of Inspector General</quote>;</text></item><item id="id812556723B87458EA573E27B952C20BF"><enum>(bb)</enum><text>in subclause (II), by adding <quote>and</quote> at the end;</text></item><item id="idD34D3756B32D4E9F88F90F1E4D181E6F"><enum>(cc)</enum><text>by striking subclause (III); and</text></item><item id="id030020D9345047F2A649E4D5891158A7"><enum>(dd)</enum><text>by redesignating subclause (IV) as subclause (III);</text></item></subclause></clause></subparagraph><subparagraph id="id2592D33CEF8648CDA088B2FB4C7A984E"><enum>(C)</enum><text>in subsection (c)—</text><clause id="id6242E3B3BE584300AE6230B1D7CC0420"><enum>(i)</enum><text>in paragraph (1)—</text><subclause id="id4E291CA1D7114D14AFFDF8240D06F7D1"><enum>(I)</enum><text>in subparagraph (A)—</text><item id="id894792A288124FE7855B59B85BCE860E"><enum>(aa)</enum><text>in the matter preceding clause (i), by striking <quote>on the adequacy and effectiveness of information security policies, procedures, and practices, including</quote> and inserting <quote>that includes</quote>; and</text></item><item id="id996188B3A43B409EADFC0F53C86E439F"><enum>(bb)</enum><text>in clause (ii), by inserting <quote>unless the Director issues a waiver to the agency under subparagraph (B)(iii),</quote> before <quote>the total number</quote>; and</text></item></subclause><subclause id="idB35F9EC9DE9F46EE8A36DC98CD5D64A0"><enum>(II)</enum><text>by striking subparagraph (B) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id10E62128F14B4B63982F21A8D146066E" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id003D43FE9BDF4AC0A2546FC9ED9B469D"><enum>(B)</enum><header>Incident reporting waiver</header><clause id="id4085B4A41D3A4C1A9BDE8420DF347280"><enum>(i)</enum><header>Certification of agency information sharing</header><text>If the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, determines that an agency shares any information relating to any incident pursuant to section 3594(a), the Director shall certify that the agency is in compliance with that section.</text></clause><clause id="id4ECBA2D2F99548CF9841A8E31593C05E"><enum>(ii)</enum><header>Certification of issuing report</header><text>If the Director determines that the Director of the Cybersecurity and Infrastructure Security Agency uses the information described in clause (i) with respect to a particular agency to submit to Congress an annex required under section 3597(c)(3) for that agency, the Director shall certify that the Cybersecurity and Infrastructure Security Agency is in compliance with that section with respect to that agency.</text></clause><clause id="id7EDC2D52D4DD40778B759F3BEF5FE558"><enum>(iii)</enum><header>Waiver</header><text>The Director may waive the reporting requirement with respect to the information required to be included in the report under subparagraph (A)(ii) for a particular agency if—</text><subclause id="idD8805AFC63E34B2DB07235F092DFDD73"><enum>(I)</enum><text>the Director has issued a certification for the agency under clause (i); and</text></subclause><subclause id="id48416CCEB5EF433C9CE7FB7F15862A22"><enum>(II)</enum><text>the Director has issued a certification with respect to the annex of the agency under clause (ii).</text></subclause></clause><clause id="idA1BDECD8D9AE40CAA56348A00A91E412"><enum>(iv)</enum><header>Revocation of waiver or certifications</header><subclause id="id3FC697563F624739AB3BA800BDDDC390"><enum>(I)</enum><header>Waiver</header><text>If, at any time, the Director determines that the Director of the Cybersecurity and Infrastructure Security Agency cannot submit to Congress an annex for a particular agency under section 3597(c)(3)—</text><item id="id0F29979C6ED941CF90ECCB6B16B19E17"><enum>(aa)</enum><text>any waiver previously issued under clause (iii) with respect to that agency shall be considered void; and</text></item><item id="id9D408D12ABE54766A1B53884FE387FAE"><enum>(bb)</enum><text>the Director shall revoke the certification for the annex of that agency under clause (ii).</text></item></subclause><subclause id="idA0F911A7262D4E3A8E717916F96E2494"><enum>(II)</enum><header>Certifications</header><text>If, at any time, the Director determines that an agency has not provided to the Director of the Cybersecurity and Infrastructure Security Agency the totality of incident information required under section 3594(a)—</text><item id="idE1947BF3208A4E7B93EB0AFBEB694DA0"><enum>(aa)</enum><text>any waiver previously issued under clause (iii) with respect to that agency shall be considered void; and</text></item><item id="id72FF2DA724264138B09E7E7DF8A8E087"><enum>(bb)</enum><text>the Director shall revoke the certification for that agency under clause (i).</text></item></subclause><subclause id="idBFF315C4C9254D0F851A99584944FB8B"><enum>(III)</enum><header>Reissuance</header><text>If the Director revokes a waiver under this clause, the Director may issue a subsequent waiver if the Director issues new certifications under clauses (i) and (ii).</text></subclause></clause></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subclause></clause><clause id="id275485FC4DD54510AFBE8550F82ACF5E"><enum>(ii)</enum><text>by redesignating paragraphs (2) through (5) as paragraphs (4) through (7), respectively; and</text></clause><clause id="id32BBCDABA62747C78DABEB2FD3D4790A"><enum>(iii)</enum><text>by inserting after paragraph (1) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id76C6C120C5DE46358E05FD3093A72F25" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id65AE44440E6943EC955AB09E034B2C4B" commented="no"><enum>(2)</enum><header>Biannual report</header><text>Not later than 180 days after the date on which an agency completes an agency system risk assessment under subsection (a)(1)(A) and not less frequently than every 2 years, each agency shall submit to the Director, the Secretary, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, the appropriate authorization and appropriations committees of Congress, the National Cyber Director, and the Comptroller General of the United States a report that—</text><subparagraph id="id3F6C3142E3E24DFDA186BCEF63D0043D"><enum>(A)</enum><text>summarizes the agency system risk assessment performed under subsection (a)(1)(A);</text></subparagraph><subparagraph id="id6144517B812C41EF89856BF6F0F649A0"><enum>(B)</enum><text>evaluates the adequacy and effectiveness of information security policies, procedures, and practices of the agency to address the risks identified in the system risk assessment performed under subsection (a)(1)(A); and</text></subparagraph><subparagraph id="id7D2A89CA89CC46A590673F604A857C16"><enum>(C)</enum><text>summarizes the evaluations and implementation plans described in subparagraphs (F) and (G) of subsection (a)(1) and whether those evaluations and implementation plans call for the use of additional cybersecurity procedures determined to be appropriate by the agency.</text></subparagraph></paragraph><paragraph id="idC841B47E99594EF1B1082108285A2F19"><enum>(3)</enum><header>Unclassified reports</header><text>Each report submitted under paragraphs (1) and (2)—</text><subparagraph id="idCEF2B09FF47F48329883721F5244B39A"><enum>(A)</enum><text>shall be, to the greatest extent practicable, in an unclassified and otherwise uncontrolled form; and </text></subparagraph><subparagraph id="id94EDCA7F5B11486D82D8C980294C5D24"><enum>(B)</enum><text>may include a classified annex.</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id93E711A2E8D6492D91ADA49635FB29E4"><enum>(D)</enum><text>in subsection (d)(1), in the matter preceding subparagraph (A), by inserting <quote>and the Director of the Cybersecurity and Infrastructure Security Agency</quote> after <quote>the Director</quote>;</text></subparagraph></paragraph><paragraph id="id280037D1E2F04481896FD3EED47E965A"><enum>(4)</enum><text>in section 3555—</text><subparagraph id="id20C98D4F83B04DB8B210D40511EA60D5"><enum>(A)</enum><text>in subsection (a)(2)(A), by inserting <quote>, including by penetration testing and analyzing the vulnerability disclosure program of the agency</quote> after <quote>information systems</quote>;</text></subparagraph><subparagraph id="idD973C4A689AE44E5A26212640625CCC4"><enum>(B)</enum><text>by striking subsection (f) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id26B0CDDDF7F34A5E8B0F10DB1305D82F" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subsection id="id10FAD6F4BF7F4C4B911BD02BC4D53C72"><enum>(f)</enum><header>Protection of information</header><paragraph commented="no" display-inline="yes-display-inline" id="idBF572A6A222E4333BA48FDA1CC339828"><enum>(1)</enum><text>Agencies and evaluators shall take appropriate steps to ensure the protection of information which, if disclosed, may adversely affect information security.</text></paragraph><paragraph id="idCF054218DAA2462E9E9B147840DA0C5C" indent="up1"><enum>(2)</enum><text>The protections required under paragraph (1) shall be commensurate with the risk and comply with all applicable laws and regulations.</text></paragraph><paragraph id="id53D6BD69628D4FE2BD73910BDFF59868" indent="up1"><enum>(3)</enum><text>With respect to information that is not related to national security systems, agencies and evaluators shall make a summary of the information unclassified and publicly available, including information that does not identify—</text><subparagraph id="id7A20D9AFEFE948479673BA0CD3468DD6"><enum>(A)</enum><text>specific information system incidents; or</text></subparagraph><subparagraph id="id8FE68416D6C147B1BC9C6A9FDDC74D83"><enum>(B)</enum><text>specific information system vulnerabilities. </text></subparagraph></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="id9B88978F523340E99EA22AAD5E428880"><enum>(C)</enum><text>in subsection (g)(2)—</text><clause id="id27EB043E60FB4C7F83CC312E802F4CDE"><enum>(i)</enum><text>by striking <quote>this subsection shall</quote> and inserting “this subsection—</text><quoted-block style="OLC" display-inline="no-display-inline" id="idF2B6E3760CD44DF0A8C6C01189240569" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id5FD194522B354CB78A6AAB642782AC87" indent="up1"><enum>(A)</enum><text>shall</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id967EF214627A4BACA87DA77679E0362A"><enum>(ii)</enum><text>in subparagraph (A), as so designated, by striking the period at the end and inserting <quote>; and</quote>; and</text></clause><clause id="idBDA74A292D984C31B3382ACC739B3E04"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id26A575BFC8974CE6926F569C3EEC4878" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id9F7C815CB7224CE4BCBE785AFF340E4C" indent="up1"><enum>(B)</enum><text>identify any entity that performs an independent audit under subsection (b).</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="idE54DD251F6D04DC59570AE8878B73378"><enum>(D)</enum><text>in subsection (j), by striking <quote>the Secretary</quote> and inserting <quote>the Director of the Cyber Security and Infrastructure Security Agency</quote>; and</text></subparagraph></paragraph><paragraph id="id1292F4DC8BAB4B4E8B399298B9A15C8E"><enum>(5)</enum><text>in section 3556(a)—</text><subparagraph id="idC84E6EDB8F25498BAF77AB7BEE6C9BBA"><enum>(A)</enum><text>in the matter preceding paragraph (1), by inserting <quote>within the Cybersecurity and Infrastructure Security Agency</quote> after <quote>incident center</quote>; and</text></subparagraph><subparagraph id="id41FB15E61655421B8AF6F1F5CACF4F61"><enum>(B)</enum><text>in paragraph (4), by striking <quote>3554(b)</quote> and inserting <quote>3554(a)(1)(A)</quote>.</text></subparagraph></paragraph></subsection><subsection id="id3F936CAB63174534898E1BE426F62E67"><enum>(d)</enum><header>Federal system incident response</header><paragraph id="id7941492729B74FDE9B0C3D528ACDB3EC"><enum>(1)</enum><header>In general</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">Chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block id="id514105A0AED648C888EDD88B2BB2FF77" display-inline="no-display-inline" style="USC" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subchapter id="id6239B413F1CE4BEFA7315E330430A40D" style="USC"><enum>IV</enum><header>Federal System Incident Response</header><section section-type="subsequent-section" id="idDCD8135600B84C439AA7D352E8D01733"><enum>3591.</enum><header>Definitions</header><subsection id="id84393b8166cb4afbbc95a219e294fa0c"><enum>(a)</enum><header>In general</header><text>Except as provided in subsection (b), the definitions under sections 3502 and 3552 shall apply to this subchapter.</text></subsection><subsection id="id6a6e8b3d4bc444a7bf77d84012ab8f79"><enum>(b)</enum><header>Additional definitions</header><text>As used in this subchapter:</text><paragraph id="idCA3999600B2F4786B9BA3C666C07BB31"><enum>(1)</enum><header>Appropriate notification entities</header><text>The term <term>appropriate notification entities</term> means—</text><subparagraph id="id49B33538CD254A5484DED89F040BE3F1"><enum>(A)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></subparagraph><subparagraph id="idDAD9B0757A7A40788C37768423F3A06D"><enum>(B)</enum><text>the Committee on Oversight and Reform of the House of Representatives;</text></subparagraph><subparagraph id="id79A13F5D77734A0C874491B1130CCBAD"><enum>(C)</enum><text>the Committee on Homeland Security of the House of Representatives;</text></subparagraph><subparagraph id="id228CD665A2094B7C9568AF1430213208"><enum>(D)</enum><text>the appropriate authorization and appropriations committees of Congress;</text></subparagraph><subparagraph id="id04E2B18549304807B843CBA6C3A73992"><enum>(E)</enum><text>the Director;</text></subparagraph><subparagraph id="idc020e63a9c2243a2ab5308f2594b561e"><enum>(F)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency;</text></subparagraph><subparagraph id="idABCA757F50AD494982046C2FA79FD87C"><enum>(G)</enum><text>the National Cyber Director; and</text></subparagraph><subparagraph id="id1B3A406E42C24D7EA76AB6E7311C8805"><enum>(H)</enum><text>the Comptroller General of the United States.</text></subparagraph></paragraph><paragraph id="id6718275C13CD4B8F9BAC330FB656C173"><enum>(2)</enum><header>Contractor</header><text>The term <term>contractor</term>—</text><subparagraph id="id668DD8322AD4483DA8247CF605F06737"><enum>(A)</enum><text>means any person or business that collects or maintains information that includes personally identifiable information or sensitive personal information on behalf of an agency; and</text></subparagraph><subparagraph id="id6B949DF8BB7B4F1A8ED5DD1E43A4B168"><enum>(B)</enum><text>includes any subcontractor of a person or business described in subparagraph (A). </text></subparagraph></paragraph><paragraph id="id214f30cb82e24ac2a2e27a44ef24ad36"><enum>(3)</enum><header>Intelligence community</header><text>The term <term>intelligence community</term> has the meaning given the term in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>).</text></paragraph><paragraph id="id03D44B934678479299DD3D29585B90A3"><enum>(4)</enum><header>Nationwide consumer reporting agency</header><text>The term <term>nationwide consumer reporting agency</term> means a consumer reporting agency described in section 603(p) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(p)</external-xref>).</text></paragraph><paragraph id="id5467A33F0C984E7F85D883C58C5A5C2D"><enum>(5)</enum><header>Vulnerability disclosure</header><text>The term <term>vulnerability disclosure</term> means a vulnerability identified under section 3559B.</text></paragraph></subsection></section><section id="id07EE716BA8C246E088B7B23075C938F2"><enum>3592.</enum><header>Notification of high risk exposure after major incident</header><subsection id="id55ce07f783cc415dac8e20fae7f46a5c"><enum>(a)</enum><header>Notification</header><text>As expeditiously as practicable and without unreasonable delay, and in any case not later than 30 days after an agency has a reasonable basis to conclude that a major incident has occurred due to a high risk exposure of personal identifiable information, as described in section 3598(c)(2), the head of the agency shall provide notice of the major incident in accordance with subsection (b) in writing to the last known home mailing address of each individual whom the major incident may have impacted.</text></subsection><subsection id="id1d78f6c98cd548cc887066af21ae9af3"><enum>(b)</enum><header>Contents of notice</header><text>Each notice to an individual required under subsection (a) shall include—</text><paragraph id="idc4a12358385f458a83c452dceb2791bd"><enum>(1)</enum><text>a description of the rationale for the determination that the major incident resulted in a high risk of exposure of the personal information of the individual;</text></paragraph><paragraph id="idEEBA177637FA4880B3AE4238823A8F55"><enum>(2)</enum><text>an assessment of the type of risk the individual may face as a result of an exposure;</text></paragraph><paragraph id="idA5EAC5303EF74F2DAB2463D73129FF39" commented="no"><enum>(3)</enum><text>contact information for the Federal Bureau of Investigation or other appropriate entity;</text></paragraph><paragraph id="idaa6ef909b8684dd3a093e6ddd80456df"><enum>(4)</enum><text>the contact information of each nationwide consumer reporting agency;</text></paragraph><paragraph id="id83c9508045fa441c9d41ce615353628f"><enum>(5)</enum><text>the contact information for questions to the agency, including a telephone number, e-mail address, and website;</text></paragraph><paragraph id="id57e8da8e71f44074bb51624a9463da6a"><enum>(6)</enum><text>information on any remedy being offered by the agency; </text></paragraph><paragraph id="id76a994d19b094064a424c5bfe5cd95a5"><enum>(7)</enum><text>consolidated Federal Government recommendations on what to do in the event of a major incident; and</text></paragraph><paragraph id="id1a4c747ca88141fb8b192bd22be292e6"><enum>(8)</enum><text>any other appropriate information as determined by the head of the agency.</text></paragraph></subsection><subsection id="id1c206eb069df460daca7d70c96deb1ea"><enum>(c)</enum><header>Delay of notification</header><paragraph id="id6bcc903b8b1642d78991953ec11e18ea"><enum>(1)</enum><header>In general</header><text>The Attorney General, the Director of National Intelligence, or the Secretary of Homeland Security may impose a delay of a notification required under subsection (a) if the notification would disrupt a law enforcement investigation, endanger national security, or hamper security remediation actions.</text></paragraph><paragraph id="id8c55ca0cb8124815810e78225ed3a956"><enum>(2)</enum><header>Documentation</header><subparagraph id="id07a9f9d4a6294658a8f48f104b677e39"><enum>(A)</enum><header>In general</header><text>Any delay under paragraph (1) shall be reported in writing to the head of the agency, the Director, the Director of the Cybersecurity and Infrastructure Security Agency, and the Office of Inspector General of the agency that experienced the major incident.</text></subparagraph><subparagraph id="ide0c17848cbf744e8b8122fba250083d7"><enum>(B)</enum><header>Contents</header><text>A statement required under subparagraph (A) shall include a written statement from the entity that delayed the notification explaining the need for the delay.</text></subparagraph><subparagraph id="idfdba49277129462883d3561387fead18"><enum>(C)</enum><header>Form</header><text>The statement required under subparagraph (A) shall be unclassified, but may include a classified annex.</text></subparagraph></paragraph><paragraph id="idcfa1cb9c42b7444fbebd1297e34fe44c"><enum>(3)</enum><header>Renewal</header><text>A delay under paragraph (1) shall be for a period of 2 months and may be renewed.</text></paragraph></subsection><subsection id="idee5b18556e744dd7b793eeaa0aaed7a8"><enum>(d)</enum><header>Update notification</header><text>If an agency determines there is a change in the reasonable basis to conclude that a major incident occurred, or that there is a change in the details of the information provided to impacted individuals as described in subsection (b), the agency shall as expeditiously as practicable and without unreasonable delay, and in any case not later than 30 days after such a determination, notify all such individuals who received a notification pursuant to subsection (a) of those changes.</text></subsection><subsection id="id8d3943d094224a6c8d1a11be874bd8a3"><enum>(e)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to limit—</text><paragraph id="id8CC25FD0822F48DFAFFD8B78694DCFEA"><enum>(1)</enum><text>the Director from issuing guidance regarding notifications or the head of an agency from sending notifications to individuals impacted by incidents not determined to be major incidents; or</text></paragraph><paragraph id="idd636eb0f4d2b479abfde79cb2812e370"><enum>(2)</enum><text>the Director from issuing guidance regarding notifications of major incidents or the head of an agency from issuing notifications to individuals impacted by major incidents that contain more information than described in subsection (b). </text></paragraph></subsection></section><section id="idA126318270A14FB89C6F07571E8DCC50"><enum>3593.</enum><header>Congressional notifications and reports</header><subsection id="idB22E347D08CB44C9A36C4DE7987B21A5"><enum>(a)</enum><header>Initial report</header><paragraph id="idA731C7AB8EDB466D8516F33DBC009E2C"><enum>(1)</enum><header>In general</header><text>Not later than 5 days after the date on which an agency has a reasonable basis to conclude that a major incident occurred, the head of the agency shall submit a written notification and, to the extent practicable, provide a briefing, to the appropriate notification entities, taking into account—</text><subparagraph id="id8ADF92C4D1F74C1985785FAF81C63FE2"><enum>(A)</enum><text>the information known at the time of the notification;</text></subparagraph><subparagraph id="id4D2E280C6BE7411CBED6C96307F0B5A9"><enum>(B)</enum><text>the sensitivity of the details associated with the major incident; and</text></subparagraph><subparagraph id="idA30C2866BA9942E1A9BD490E9B74D67C"><enum>(C)</enum><text>the classification level of the information contained in the notification.</text></subparagraph></paragraph><paragraph id="id62C7C4054F69416898D1F37143EA796D"><enum>(2)</enum><header>Contents</header><text>A notification required under paragraph (1) shall include—</text><subparagraph id="ide754995fe29945929254a13e1208b962"><enum>(A)</enum><text>a summary of the information available about the major incident, including how the major incident occurred, based on information available to agency officials as of the date on which the agency submits the report;</text></subparagraph><subparagraph id="idb98234fe87ec4f39bbc0117931a50e69"><enum>(B)</enum><text>if applicable, an estimate of the number of individuals impacted by the major incident, including an assessment of the risk level to impacted individuals based on the guidance promulgated under section 3598(c)(1) and any information available to agency officials on the date on which the agency submits the report; </text></subparagraph><subparagraph id="id2253320adbf646a19ccc0e0397137656"><enum>(C)</enum><text>if applicable, a description and any associated documentation of any circumstances necessitating a delay in or exemption to notification granted under subsection (c) or (d) of section 3592; and</text></subparagraph><subparagraph id="id480a372cf70e48f2836882fe9a98025c"><enum>(D)</enum><text>if applicable, an assessment of the impacts to the agency, the Federal Government, or the security of the United States, based on information available to agency officials on the date on which the agency submits the report. </text></subparagraph></paragraph></subsection><subsection id="id3B30794EA2C04B869FBC30AC16EB4997"><enum>(b)</enum><header>Supplemental report</header><text>Within a reasonable amount of time, but not later than 45 days after the date on which additional information relating to a major incident for which an agency submitted a written notification under subsection (a) is discovered by the agency, the head of the agency shall submit to the appropriate notification entities updates to the written notification that include summaries of—</text><paragraph id="idA31A2FDC013E451B823C465AAA4E1EAF"><enum>(1)</enum><text>the threats and threat actors, vulnerabilities, means by which the major incident occurred, and impacts to the agency relating to the major incident;</text></paragraph><paragraph id="idb6b253b396584ed58215d340808af90b"><enum>(2)</enum><text>any risk assessment and subsequent risk-based security implementation of the affected information system before the date on which the major incident occurred; </text></paragraph><paragraph id="id55fd20b9cad64ea294dd175eaaf5c87c"><enum>(3)</enum><text>the status of compliance of the affected information system with applicable security requirements at the time of the major incident;</text></paragraph><paragraph id="id72551fbefeaa4c0f88096db611548739"><enum>(4)</enum><text>an estimate of the number of individuals affected by the major incident based on information available to agency officials as of the date on which the agency submits the update;</text></paragraph><paragraph id="id5b2b5d1ffd8e406e87b469fdaefcc0a2"><enum>(5)</enum><text>an update to the assessment of the risk of harm to impacted individuals affected by the major incident based on information available to agency officials as of the date on which the agency submits the update; </text></paragraph><paragraph id="id4f50b031bdb14f46bb9e23a5821166e2"><enum>(6)</enum><text>an update to the assessment of the risk to agency operations, or to impacts on other agency or non-Federal entity operations, affected by the major incident based on information available to agency officials as of the date on which the agency submits the update; and </text></paragraph><paragraph id="id51620782c74a4b2c9a24514eedf1c84d"><enum>(7)</enum><text>the detection, response, and remediation actions of the agency, including any support provided by the Cybersecurity and Infrastructure Security Agency under section 3594(d) and status updates on the notification process described in section 3592(a), including any delay or exemption described in subsection (c) or (d), respectively, of section 3592, if applicable.</text></paragraph></subsection><subsection id="idee8801591bb74b71ac7d7d0608c4c8b0"><enum>(c)</enum><header>Update Report</header><text>If the agency determines that there is any significant change in the understanding of the agency of the scope, scale, or consequence of a major incident for which an agency submitted a written notification under subsection (a), the agency shall provide an updated report to the appropriate notification entities that includes information relating to the change in understanding.</text></subsection><subsection id="id16F308CC83BE4175A5540251F818AAA0"><enum>(d)</enum><header>Annual report</header><text>Each agency shall submit as part of the annual report required under section 3554(c)(1) of this title a description of each major incident that occurred during the 1-year period preceding the date on which the report is submitted.</text></subsection><subsection id="ide8745564206c4c0bb4ed727167b4a969"><enum>(e)</enum><header>Delay and exemption report</header><text>The Director shall submit to the appropriate notification entities an annual report on all notification delays and exemptions granted pursuant to subsections (c) and (d) of section 3592.</text></subsection><subsection id="idE16C9B541A554230B8BFB7A7A2CAD8DF"><enum>(f)</enum><header>Report delivery</header><text>Any written notification or report required to be submitted under this section may be submitted in a paper or electronic format.</text></subsection><subsection id="id97f37d9a14de4517846b17451181769c"><enum>(g)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to limit—</text><paragraph id="idC3B1985959974631868371ED8C0C5A96"><enum>(1)</enum><text>the ability of an agency to provide additional reports or briefings to Congress; or</text></paragraph><paragraph id="id597C52260FDB4239A84DFDC1D5C2F96E"><enum>(2)</enum><text>Congress from requesting additional information from agencies through reports, briefings, or other means.</text></paragraph></subsection><subsection id="idB8F4F976EAA242E094D46F692FE4415D"><enum>(h)</enum><header>Binding operational directive</header><text>If the Director of the Cybersecurity and Infrastructure Security Agency issues a binding operational directive or an emergency directive under section 3553, not later than 2 days after the date on which the binding operational directive requires an agency to take an action, each agency shall provide to the appropriate notification entities the status of the implementation of the binding operational directive at the agency.</text></subsection></section><section id="idF0ADA73D95834E4E9D4B9114275700B4"><enum>3594.</enum><header>Government information sharing and incident response</header><subsection id="id16A114E9B6DC45F7BBE4861C2DDCFF06"><enum>(a)</enum><header>In general</header><paragraph id="idCACAF05D0A1849278C0E7A2C1C816A3D"><enum>(1)</enum><header>Incident reporting</header><text>The head of each agency shall provide any information relating to any incident, whether the information is obtained by the Federal Government directly or indirectly, to the Cybersecurity and Infrastructure Security Agency and the Office of Management and Budget.</text></paragraph><paragraph id="id6CD3A792991F4462A5E9A182382B0EF6"><enum>(2)</enum><header>Contents</header><text>A provision of information relating to an incident made by the head of an agency under paragraph (1) shall—</text><subparagraph id="id4A9B67AB04F948078F733C317303DE1D"><enum>(A)</enum><text>include detailed information about the safeguards that were in place when the incident occurred;</text></subparagraph><subparagraph id="id9409BC37F0204A5CB9294F2DCF87BDF0"><enum>(B)</enum><text>whether the agency implemented the safeguards described in subparagraph (A) correctly; and</text></subparagraph><subparagraph id="idEEDDF9EE97864B1AA46BE309065BE26F"><enum>(C)</enum><text>in order to protect against a similar incident, identify—</text><clause id="id2BDA5EEBF2804808802CACD510A4557A"><enum>(i)</enum><text>how the safeguards described in subparagraph (A) should be implemented differently; and</text></clause><clause id="idC2571053971A4ADABF942EFF9136792F"><enum>(ii)</enum><text>additional necessary safeguards.</text></clause></subparagraph></paragraph></subsection><subsection id="id244008E2722449929A2D5F053692677B"><enum>(b)</enum><header>Compliance</header><text>The information provided under subsection (a) shall—</text><paragraph id="idEF91ECCD04C84B39A1DF5A9E18CAC08E"><enum>(1)</enum><text>take into account the level of classification of the information and any information sharing limitations relating to law enforcement; and</text></paragraph><paragraph id="id86D0E1A2470E48F092F04584CE0B81ED"><enum>(2)</enum><text>be in compliance with the requirements limiting the release of information under section 552a of title 5 (commonly known as the <term>Privacy Act of 1974</term>).</text></paragraph></subsection><subsection id="id4e01d1aa938249f39f4b4e678fec0064"><enum>(c)</enum><header>Responding to information requests from agencies experiencing incidents</header><text>An agency that receives a request from another agency or Federal entity for information specifically intended to assist in the remediation or notification requirements due to an incident shall provide that information to the greatest extent possible, in accordance with guidance issued by the Director and taking into account classification, law enforcement, national security, and compliance with section 552a of title 5 (commonly known as the <term>Privacy Act of 1974</term>).</text></subsection><subsection id="idF62F66839670417E9C2E139775214D06"><enum>(d)</enum><header>Incident response</header><text>Each agency that has a reasonable basis to conclude that a major incident occurred, regardless of delays from notification granted for a major incident, shall consult with the Cybersecurity and Infrastructure Security Agency regarding—</text><paragraph id="id4BE52EBCA8E94E1D9DA7DDF48995AA1C"><enum>(1)</enum><text>incident response and recovery; and</text></paragraph><paragraph id="idD3FED70959CF498D9DE3D8A8DB083551"><enum>(2)</enum><text>recommendations for mitigating future incidents.</text></paragraph></subsection></section><section id="idE1C530B2382A461D88D79590540C23EA"><enum>3595.</enum><header>Responsibilities of contractors and grant recipients</header><subsection id="id6f18d2934ea9416ca38659715a1415b9"><enum>(a)</enum><header>Notification</header><paragraph id="id877DB715E0CB48358AB5D2E716C0F8F0"><enum>(1)</enum><header>In general</header><text>Subject to paragraph (3), any contractor of an agency or recipient of a grant from an agency that has a reasonable basis to conclude that an incident involving Federal information has occurred shall immediately notify the agency.</text></paragraph><paragraph id="id466CE0050A8E4E77896C623D13F327E5"><enum>(2)</enum><header>Procedures</header><subparagraph id="id29AFE5051C9C41EE9655E302DA70131A"><enum>(A)</enum><header>Major incident</header><text>Following notification of a major incident by a contractor or recipient of a grant under paragraph (1), an agency, in consultation with the contractor or grant recipient, as applicable, shall carry out the requirements under sections 3592, 3593, and 3594 with respect to the major incident.</text></subparagraph><subparagraph id="idF8B884E67FA046C48C6CD925F8675A6E"><enum>(B)</enum><header>Incident</header><text>Following notification of an incident by a contractor or recipient of a grant under paragraph (1), an agency, in consultation with the contractor or grant recipient, as applicable, shall carry out the requirements under section 3594 with respect to the incident.</text></subparagraph></paragraph><paragraph id="id67CB67943BE7422E8B75B8F76A43D355"><enum>(3)</enum><header>Applicability</header><text>This subsection shall apply to a contractor of an agency or a recipient of a grant from an agency that—</text><subparagraph id="id2e70729ee2634ce4b8749167d2715dab"><enum>(A)</enum><text>receives information from the agency that the contractor or recipient, as applicable, is not contractually authorized to receive; </text></subparagraph><subparagraph id="id049108b9e9ff4f9fa43a8ccbf9dbf8bf"><enum>(B)</enum><text>experiences an incident relating to Federal information on an information system of the contractor or recipient, as applicable; or</text></subparagraph><subparagraph id="idE32D2C8DFBED4B809A9328511327BA94"><enum>(C)</enum><text>identifies an incident involving a Federal information system.</text></subparagraph></paragraph></subsection><subsection id="id3523b44cff28414786e5109cba028606"><enum>(b)</enum><header>Incident response</header><text>Any contractor of an agency or recipient of a grant from an agency that has a reasonable basis to conclude that a major incident occurred shall, in coordination with the agency, consult with the Cybersecurity and Infrastructure Security Agency regarding— </text><paragraph id="idea031a3ae7c54d6aa66c01c8bdaa85c4"><enum>(1)</enum><text>incident response assistance; and</text></paragraph><paragraph id="id44ad972150274a038e5a8f037ea2fd07"><enum>(2)</enum><text>recommendations for mitigating future incidents at the agency.</text></paragraph></subsection><subsection id="id0801A72AFDD94B089C157F654DC5C43F"><enum>(c)</enum><header>Effective date</header><text>This section shall apply on and after the date that is 1 year after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>.</text></subsection></section><section id="id2ACD494311CC4812B73F262D5D425A44"><enum>3596.</enum><header>Training</header><subsection id="idAA21F2DC1556427F8DF3A2727FE4FAAE"><enum>(a)</enum><header>In general</header><text>Each agency shall develop training for individuals at the agency with access to Federal information or information systems on how to identify and respond to an incident, including—</text><paragraph id="id75744DC3378B4AD8807C2976E7FB2B1A"><enum>(1)</enum><text>the internal process at the agency for reporting an incident; and</text></paragraph><paragraph id="idCCB924EE18504738A8183CFDE1195474"><enum>(2)</enum><text>the obligation of the individual to report to the agency a confirmed major incident and any suspected incident, involving information in any medium or form, including paper, oral, and electronic.</text></paragraph></subsection><subsection id="idE0933A74169A412486A0ECEF8CA1EDEA"><enum>(b)</enum><header>Applicability</header><text>The training developed under subsection (a) shall—</text><paragraph id="idC8617D3AE3DB48E584DC8786168F6B79"><enum>(1)</enum><text>be required for an individual before the individual may access Federal information or information systems; and</text></paragraph><paragraph id="idB795677A28B7421387F29A20EC242D81"><enum>(2)</enum><text>apply to individuals with temporary access to Federal information or information systems, such as detailees, contractors, subcontractors, grantees, volunteers, and interns.</text></paragraph></subsection><subsection id="id1951c87a8b094119a62377e581e1781e"><enum>(c)</enum><header>Inclusion in annual training</header><text>The training developed under subsection (a) may be included as part of an annual privacy or security awareness training of the agency, as applicable.</text></subsection></section><section id="idC1D3A87955F74DA097619936EE4F2B65"><enum>3597.</enum><header>Analysis and report on Federal incidents</header><subsection id="idAC37DBC1F3234129BE54742E19346EDD" commented="no"><enum>(a)</enum><header>Definition of compromise</header><text>In this section, the term <term>compromise</term> means—</text><paragraph commented="no" id="id23DBF2ED6C334FA1B07195CA381B6776"><enum>(1)</enum><text>an incident;</text></paragraph><paragraph commented="no" id="idAA469E38E31941D19F33420EC67ECF8E"><enum>(2)</enum><text>a result of a penetration test in which the tester successfully gains access to a system within the standards under section 3559A;</text></paragraph><paragraph commented="no" id="idA76EE47A63994B5389B177D5175E13C7"><enum>(3)</enum><text>a vulnerability disclosure; or</text></paragraph><paragraph commented="no" id="id3E37A204240444CBA82C3BE0EB3D0683"><enum>(4)</enum><text>any other event that the Director of the Cybersecurity and Infrastructure Security Agency determines identifies an exploitable vulnerability in an agency system.</text></paragraph></subsection><subsection id="id92CC2A1AF151417AA52321A982C8638B"><enum>(b)</enum><header>Analysis of Federal incidents</header><paragraph id="idD76E6624A9844083BC94096625F19BCF"><enum>(1)</enum><header>In general</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall perform continuous monitoring of compromises of agencies.</text></paragraph><paragraph id="id3B399647F82B4C3F9FA75A0127D09A21"><enum>(2)</enum><header>Quantitative and Qualitative analyses</header><text>The Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, shall develop and perform continuous monitoring and quantitative and qualitative analyses of compromises of agencies, including—</text><subparagraph id="idA47F127096FD4DF097F2EF38607FEF15"><enum>(A)</enum><text>the causes of successful compromises, including—</text><clause id="idD639E808CCC944119614D9A969956441"><enum>(i)</enum><text>attacker tactics, techniques, and procedures; and</text></clause><clause id="id74EE6B5A065A4E238462CDF2DF445205"><enum>(ii)</enum><text>system vulnerabilities, including zero days, unpatched systems, and information system misconfigurations;</text></clause></subparagraph><subparagraph id="idB950E87A74524FB8A77A870D92685C9B"><enum>(B)</enum><text>the scope and scale of compromises of agencies;</text></subparagraph><subparagraph id="id4C4A11F18D4C4DFCBF98685366DA30B9"><enum>(C)</enum><text>cross Federal Government root causes of compromises of agencies;</text></subparagraph><subparagraph id="id47DFC9DFF28641A2B31836C68A1D7653"><enum>(D)</enum><text>agency response, recovery, and remediation actions and effectiveness of incidents, as applicable; and</text></subparagraph><subparagraph id="idA66BB19C7F984DCBB882CF93104CEEC4"><enum>(E)</enum><text>lessons learned and recommendations in responding, recovering, remediating, and mitigating future incidents.</text></subparagraph></paragraph><paragraph id="idBB00F0DBE6C546828516261796BDA6DC"><enum>(3)</enum><header>Automated analysis</header><text>The analyses developed under paragraph (2) shall, to the greatest extent practicable, use machine readable data, automation, and machine learning processes.</text></paragraph><paragraph commented="no" id="id7189B86907C743D2BF821628021F8EB5"><enum>(4)</enum><header>Sharing of data and analysis</header><subparagraph commented="no" id="idF4E5906E2B804662969727D5DAE72677"><enum>(A)</enum><header>In general</header><text>The Director shall share on an ongoing basis the analyses required under this subsection with agencies to—</text><clause commented="no" id="id3498EC3CBDEF4220A2291FA8C727AE7A"><enum>(i)</enum><text>improve the understanding of agencies with respect to risk; and</text></clause><clause commented="no" id="id09EB30636FAA425DBDEB3EFD695FDF87"><enum>(ii)</enum><text>support the cybersecurity improvement efforts of agencies.</text></clause></subparagraph><subparagraph commented="no" id="idAAFAE54F734A4B218AB3FB407B85D7D5"><enum>(B)</enum><header>Format</header><text>In carrying out subparagraph (A), the Director shall share the analyses—</text><clause commented="no" id="idA663BEA9305B48D1820F1B2FD7D40127"><enum>(i)</enum><text>in human-readable written products; and</text></clause><clause commented="no" id="id7130894357D646919BD39674344EBDC6"><enum>(ii)</enum><text>to the greatest extent practicable, in machine-readable formats in order to enable automated intake and use by agencies.</text></clause></subparagraph></paragraph></subsection><subsection id="idecbdd15a0fd747428cbc4c2523a9a9bb"><enum>(c)</enum><header>Annual report on Federal compromises</header><text>Not later than 2 years after the date of enactment of this section, and not less frequently than annually thereafter, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, shall submit to the appropriate notification entities a report that includes—</text><paragraph id="id3CBC031820604150A17CD8D2B8225A83"><enum>(1)</enum><text>a summary of causes of compromises from across the Federal Government that categorizes those compromises by the items described in paragraphs (1) through (4) of subsection (a);</text></paragraph><paragraph id="id3F338BC6D19C444682C3FEBC2696BD83"><enum>(2)</enum><text>the quantitative and qualitative analyses of compromises developed under subsection (b)(2) on an agency-by-agency basis and comprehensively; and</text></paragraph><paragraph id="id4BD2D4647C6F4C71A3BD04B15CDDF8A3"><enum>(3)</enum><text>an annex for each agency that includes the total number of compromises of the agency and categorizes those compromises by the items described in paragraphs (1) through (4) of subsection (a).</text></paragraph></subsection><subsection id="id1D4197C1837449D2941E232C9722F473"><enum>(d)</enum><header>Publication</header><text>A version of each report submitted under subsection (c) shall be made publicly available on the website of the Cybersecurity and Infrastructure Security Agency during the year in which the report is submitted.</text></subsection><subsection id="id4030ca61496b41c1ba03110549ba4a00"><enum>(e)</enum><header>Information provided by agencies</header><text>The analysis required under subsection (b) and each report submitted under subsection (c) shall utilize information provided by agencies pursuant to section 3594(d).</text></subsection><subsection id="id1d800cb6e3ea4fd7b9d61b0932362d51"><enum>(f)</enum><header>Requirement To Anonymize Information</header><text>In publishing the public report required under subsection (d), the Director of the Cybersecurity and Infrastructure Security Agency shall sufficiently anonymize and compile information such that no specific incidents of an agency can be identified, except with the concurrence of the Director of the Office of Management and Budget and in consultation with the impacted agency.</text></subsection></section><section id="id6EC29ACEA25D49DAA12065E86163CEAD"><enum>3598.</enum><header>Major incident guidance</header><subsection id="id190EB68780EF400DBA6FBAA93D741190"><enum>(a)</enum><header>In general</header><text>Not later than 90 days after the date of enactment of the Federal Information Security Management Act of 2021, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and promulgate guidance on the definition of the term <quote>major incident</quote> for the purposes of subchapter II and this subchapter.</text></subsection><subsection id="idF354AFD4556547059B296D403B54E11D"><enum>(b)</enum><header>Requirements</header><text>With respect to the guidance issued under subsection (a), the definition of the term <term>major incident</term> shall—</text><paragraph id="idA17010F9449A4D569648EC54B78C0A2C"><enum>(1)</enum><text>include, with respect to any information collected or maintained by or on behalf of an agency or an information system used or operated by an agency or by a contractor of an agency or another organization on behalf of an agency—</text><subparagraph id="id99B3B19B7498458CA83D37052529D907"><enum>(A)</enum><text>any incident the head of the agency determines is likely to have an impact on the national security, homeland security, or economic security of the United States;</text></subparagraph><subparagraph id="idF0626D6A161F4D0AA895BB8C15B02A7E"><enum>(B)</enum><text>any incident the head of the agency determines is likely to have an impact on the operations of the agency, a component of the agency, or the Federal Government, including an impact on the efficiency or effectiveness of agency information systems;</text></subparagraph><subparagraph id="id8E3BB620174F442BAAB7F4490F25095C"><enum>(C)</enum><text>any incident that the head of an agency, in consultation with the Chief Privacy Officer of the agency, determines involves a high risk incident in accordance with the guidance issued under subsection (c)(1);</text></subparagraph><subparagraph id="idA35BAA075B0E4DE4927F38594CBF4B70"><enum>(D)</enum><text>any incident that involves the unauthorized disclosure of personally identifiable information of not less than 500 individuals, regardless of the risk level determined under the guidance issued under subsection (c)(1);</text></subparagraph><subparagraph id="idEFFEBC89546546859151EDCBB79E5192"><enum>(E)</enum><text>any incident the head of the agency determines involves a high value asset owned or operated by the agency; and</text></subparagraph><subparagraph id="id279BD84A3FF1450383BB9792D8821058"><enum>(F)</enum><text>any other type of incident determined appropriate by the Director;</text></subparagraph></paragraph><paragraph id="id548241381EA94795AA518F38E14B24DA"><enum>(2)</enum><text>stipulate that every agency shall be considered to have experienced a major incident if the Director of the Cybersecurity and Infrastructure Security Agency determines that an incident that occurs at not less than 2 agencies—</text><subparagraph id="id8397d6d0f9b849bf86b54d7ce031eef8"><enum>(A)</enum><text>is enabled by a common technical root cause, such as a supply chain compromise, a common software or hardware vulnerability; or</text></subparagraph><subparagraph id="id0d05fb4bf14a45219c89cfe782dc69c5"><enum>(B)</enum><text>is enabled by the related activities of a common actor; and</text></subparagraph></paragraph><paragraph id="id0C96B445666E49A3A5A78514A0B6DA2F"><enum>(3)</enum><text>stipulate that, in determining whether an incident constitutes a major incident because that incident—</text><subparagraph id="idB305EA3E643E4643AC67A2057169D5C6"><enum>(A)</enum><text>is any incident described in paragraph (1), the head of an agency shall consult with the Director of the Cybersecurity and Infrastructure Security Agency;</text></subparagraph><subparagraph id="id13EF7E8C365A4648989D203FD90825C3"><enum>(B)</enum><text>is an incident described in paragraph (1)(A), the head of the agency shall consult with the National Cyber Director; and</text></subparagraph><subparagraph id="idC141E2D23B6943DB9BEC27273E190D42"><enum>(C)</enum><text>is an incident described in subparagraph (C) or (D) of paragraph (1), the head of the agency shall consult with—</text><clause id="id7D79A9B4D2FE46DB897297CAF1925304"><enum>(i)</enum><text>the Privacy and Civil Liberties Oversight Board; and</text></clause><clause id="id702A769FF988450CABE9DFCB94992202"><enum>(ii)</enum><text>the Executive Director of the Federal Trade Commission.</text></clause></subparagraph></paragraph></subsection><subsection id="idceffe5e364b6483e8c1389797938c293"><enum>(c)</enum><header>Guidance on risk to individuals</header><paragraph id="id2B7624A10A9C45F5BAE4224BF445FA77"><enum>(1)</enum><header>In general</header><text>Not later than 90 days after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, the Privacy and Civil Liberties Oversight Board, and the Executive Director of the Federal Trade Commission, shall develop and issue guidance to agencies that establishes a risk-based framework for determining the level of risk that an incident involving personally identifiable information could result in substantial harm, physical harm, embarrassment, or unfairness to an individual.</text></paragraph><paragraph id="idDA3E279AA82B42CE95FC73136D00B966"><enum>(2)</enum><header>Risk levels and considerations</header><text>The risk-based framework included in the guidance issued under paragraph (1) shall—</text><subparagraph id="idE58D025EEEA44B17AB215B29FDDC3FC1"><enum>(A)</enum><text>include a range of risk levels, including a high risk level; and</text></subparagraph><subparagraph id="id688C15C868464F71ACA84B474E8A6BA8"><enum>(B)</enum><text>consider—</text><clause id="id0EBD5135305F40C79AFF02F7316A4A0B"><enum>(i)</enum><text>any personally identifiable information that was exposed as a result of an incident;</text></clause><clause id="id60AB6759A47C43F582A725D23F9ED6D5"><enum>(ii)</enum><text>the circumstances under which the exposure of personally identifiable information of an individual occurred; and</text></clause><clause id="idF7F2B28BD361472B9B126290ADCD7F0B"><enum>(iii)</enum><text>whether an independent evaluation of the information affected by an incident determines that the information is unreadable, including, as appropriate, instances in which the information is—</text><subclause id="id904DD29493124228B51E19117E7E9EAB"><enum>(I)</enum><text>encrypted; and</text></subclause><subclause id="idCB34B2D7CF6E4EB6A2D3A295D4FBF0D4"><enum>(II)</enum><text>determined by the Director of the Cybersecurity and Infrastructure Security Agency to be of sufficiently low risk of exposure.</text></subclause></clause></subparagraph></paragraph><paragraph id="id28200DAA15024C8ABA2049560B8EF810"><enum>(3)</enum><header>Approval</header><subparagraph id="id9A447BDBE46F46D99DABC90FD1FB1BF4"><enum>(A)</enum><header>In general</header><text>The guidance issued under paragraph (1) shall include a process by which the Director, jointly with the Director of the Cybersecurity and Infrastructure Security Agency and the Attorney General, may approve the designation of an incident that would be considered high risk as lower risk if information exposed by the incident is unreadable, as described in paragraph (2)(B)(iii).</text></subparagraph><subparagraph id="idA89B34F86E704F9E876DF36307305475"><enum>(B)</enum><header>Documentation</header><text>The Director shall report any approval of an incident granted by the Director under subparagraph (A) to—</text><clause id="idB670C9D1A7D247C9A8EB3C50CE535328"><enum>(i)</enum><text>the head of the agency that experienced the incident;</text></clause><clause id="idEB6CAC0BAAAF4618991D5206900927DF"><enum>(ii)</enum><text>the inspector general of the agency that experienced the incident; and</text></clause><clause id="id3E359F6D117140919E4F7910391FED97"><enum>(iii)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency.</text></clause></subparagraph></paragraph></subsection><subsection id="idc940a1dc1b4943ff845436f736c8b367"><enum>(d)</enum><header>Evaluation and updates</header><text>Not later than 2 years after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, and not less frequently than every 2 years thereafter, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives an evaluation, which shall include—</text><paragraph id="id09a80743dae948ef8ecd81441424fd38"><enum>(1)</enum><text>an update, if necessary, to the guidance issued under subsections (a) and (c);</text></paragraph><paragraph id="id4dca4167581e4a1282be62015c94085b"><enum>(2)</enum><text>the definition of the term <quote>major incident</quote> included in the guidance issued under subsection (a);</text></paragraph><paragraph id="id76cf78ea562d4c1bb2d47f74557996d6"><enum>(3)</enum><text>an explanation of, and the analysis that led to, the definition described in paragraph (2); and</text></paragraph><paragraph id="id137C36B4869E4260B3866F2AAFABCB27"><enum>(4)</enum><text>an assessment of any additional datasets or risk evaluation criteria that should be included in the risk-based framework included in the guidance issued under subsection (c)(1).</text></paragraph></subsection></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block></paragraph><paragraph id="id696C6151AEC349B7B6037F964C4A73E6"><enum>(2)</enum><header>Clerical amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="USC" id="id31d1d8c6-798c-488f-a518-0cfc332b5b42" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc-entry level="subchapter" idref="id6239B413F1CE4BEFA7315E330430A40D">SUBCHAPTER IV—Federal System Incident Response </toc-entry><toc-entry level="section" idref="idDCD8135600B84C439AA7D352E8D01733">3591. Definitions. </toc-entry><toc-entry level="section" idref="id07EE716BA8C246E088B7B23075C938F2">3592. Notification of high risk exposure after major incident. </toc-entry><toc-entry level="section" idref="idA126318270A14FB89C6F07571E8DCC50">3593. Congressional notifications and reports. </toc-entry><toc-entry level="section" idref="idF0ADA73D95834E4E9D4B9114275700B4">3594. Government information sharing and incident response. </toc-entry><toc-entry level="section" idref="idE1C530B2382A461D88D79590540C23EA">3595. Responsibilities of contractors and grant recipients. </toc-entry><toc-entry level="section" idref="id2ACD494311CC4812B73F262D5D425A44">3596. Training. </toc-entry><toc-entry level="section" idref="idC1D3A87955F74DA097619936EE4F2B65">3597. Analysis and report on Federal incidents. </toc-entry><toc-entry level="section" idref="id6EC29ACEA25D49DAA12065E86163CEAD">3598. Major incident guidance.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id3C33B291D5D6406890C11DCBA266F3DD"><enum>102.</enum><header>Amendments to subtitle III of title 40</header><subsection id="id0534697F0B1F4A0ABCFDAB26C7B7C31E"><enum>(a)</enum><header>Information Technology Modernization Centers of Excellence Program Act</header><text>Section 2(c)(4)(A)(ii) of the Information Technology Modernization Centers of Excellence Program Act (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note) is amended by striking the period at the end and inserting <quote>, which shall be provided in coordination with the Director of the Cybersecurity and Infrastructure Security Agency.</quote>.</text></subsection><subsection id="idD4395901EBAE4EFD9745AF922AE75102"><enum>(b)</enum><header>Modernizing Government Technology</header><text>Subtitle G of title X of Division A of the National Defense Authorization Act for Fiscal Year 2018 (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note) is amended—</text><paragraph id="idF66E595A32FE4129BD3357480F6C362D"><enum>(1)</enum><text>in section 1077(b)—</text><subparagraph id="id294F082112654B5490C3CC6602898E68"><enum>(A)</enum><text>in paragraph (5)(A), by inserting <quote>improving the cybersecurity of systems and</quote> before <quote>cost savings activities</quote>; and</text></subparagraph><subparagraph id="idCBFB8A3ADA504CA6A2D6B1825A9677F6"><enum>(B)</enum><text>in paragraph (7)—</text><clause id="id8AA85853516D464687A844A26CAAE82C"><enum>(i)</enum><text>in the paragraph heading, by striking <quote><header-in-text style="OLC" level="paragraph">cio</header-in-text></quote> and inserting <quote><header-in-text style="OLC" level="paragraph">CIO</header-in-text></quote>;</text></clause><clause id="id5272FD33B11C4B11A7D4F6FEB05E237F"><enum>(ii)</enum><text>by striking <quote>In evaluating projects</quote> and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id63E7720CA0A34782A799673A5C5CA5C0" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id74DE6C545A5542409128CBF4ACB409B7"><enum>(A)</enum><header>Consideration of guidance</header><text>In evaluating projects</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id02CD780C3A9B4D8FA715B46149B01BD3"><enum>(iii)</enum><text>in subparagraph (A), as so designated, by striking <quote>under section 1094(b)(1)</quote> and inserting <quote>guidance issued by the Director</quote>; and</text></clause><clause id="id1DA98F4480BA432BBCB54BCA15081C58"><enum>(iv)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id262138DD74F0428CA5A5A6F1A22EC534" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="id438433AB0D41447DB89EFDCF855F2187"><enum>(B)</enum><header>Consultation</header><text>In using funds under paragraph (3)(A), the Chief Information Officer of the covered agency shall consult with the Director of the Cybersecurity and Infrastructure Security Agency.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph></paragraph><paragraph id="id863BCAFBC8404655ADE5F35140C2D74E"><enum>(2)</enum><text>in section 1078—</text><subparagraph id="idD0E6F3907A2749D180BAFF353F3F2E7E"><enum>(A)</enum><text>by striking subsection (a) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idC57BC4666D3C48FDA7B020B534BCDEB1" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subsection id="id61FAFD247E44491988595731A3053665"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idF937BEC5068441D9BC7E761AC5BF464A"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 551 of title 5, United States Code.</text></paragraph><paragraph id="id04606CA5FECB4D03863D44263B07E8DF"><enum>(2)</enum><header>High value asset</header><text>The term <term>high value asset</term> has the meaning given the term in section 3552 of title 44, United States Code.</text></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="idF435C608415C45C88BFD0A9DED23EFCB"><enum>(B)</enum><text>in subsection (b), by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id19F0A027AA5B409783369E8BD221F0B1" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idD1A433EF3E7043F8B0FAEC22F1C41543"><enum>(8)</enum><header>Proposal evaluation</header><text>The Director shall—</text><subparagraph id="id62DAE818126B44A58070C09B80CF9322"><enum>(A)</enum><text>give consideration for the use of amounts in the Fund to improve the security of high value assets; and</text></subparagraph><subparagraph id="idA40E472AEF16411B8EAC5F03F744B25C"><enum>(B)</enum><text>require that any proposal for the use of amounts in the Fund includes a cybersecurity plan, including a chain risk management plan, to be reviewed by the member of the Technology Modernization Board described in subsection (c)(5)(C).</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="id0CD118852B9745D5996CEC729F840F74"><enum>(C)</enum><text>in subsection (c)—</text><clause id="id3764418D050A4B4EA254894782DCF9D3"><enum>(i)</enum><text>in paragraph (2)(A)(i), by inserting <quote>, including a consideration of the impact on high value assets</quote> after <quote>operational risks</quote>;</text></clause><clause id="id885A9F5ED15246F58324E1F3AD73317D"><enum>(ii)</enum><text>in paragraph (5)—</text><subclause id="id6A83CCE1D6284B5EBD681F4C9FA212CE"><enum>(I)</enum><text>in subparagraph (A), by striking <quote>and</quote> at the end;</text></subclause><subclause id="id7A1D4C8DAC27453D8826832307F27EB4"><enum>(II)</enum><text>in subparagraph (B), by striking the period at the end and inserting <quote>and</quote>; and</text></subclause><subclause id="idD00B5BFC0AE543979B3C460A4E9EBF6C"><enum>(III)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id0BD5FC4914BA4DFFAD423C4306899EF5" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="idBA914B70770E4A71A9599D50C3605172"><enum>(C)</enum><text>a senior official from the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, appointed by the Director.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subclause></clause><clause id="id6F1E651CD06044EBABAE2B4CCD383AD8"><enum>(iii)</enum><text>in paragraph (6)(A), by striking <quote>shall be—</quote> and all that follows through <quote>4 employees</quote> and inserting <quote>shall be 4 employees</quote>.</text></clause></subparagraph></paragraph></subsection><subsection id="id50CD2A5EF58148E493DCC92251D8294D"><enum>(c)</enum><header>Subchapter I</header><text>Subchapter I of subtitle III of title 40, United States Code, is amended—</text><paragraph id="id749C74EAB67C4453BDFDF325E5D33EAD"><enum>(1)</enum><text>in section 11302—</text><subparagraph id="idDDB9D9F53D3640AC992F14762F23D666"><enum>(A)</enum><text>in subsection (b), by striking <quote>use, security, and disposal of</quote> and inserting <quote>use, and disposal, and, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, promote and improve the security, of</quote>;</text></subparagraph><subparagraph id="idB4C3BE92653C4717860AAABAD18EB91B"><enum>(B)</enum><text>in subsection (c)—</text><clause id="id2B1ECC734F044C6FBDA35BAABC6DE12F"><enum>(i)</enum><text>in paragraph (2), by inserting <quote>in consultation with the Director of the Cybersecurity and Infrastructure Security Agency</quote> before <quote>, and results of</quote>;</text></clause><clause id="idFE7A9F0CAD874CC5B02D145F8E527D95"><enum>(ii)</enum><text>in paragraph (3)—</text><subclause id="id072F6388EC9243BF8AA296B4CCA2C6DE"><enum>(I)</enum><text>in subparagraph (A), by striking <quote>, and performance</quote> and inserting <quote>security, and performance</quote>; and</text></subclause><subclause id="idF8D738C7F4F345378DE9071FA7C71610"><enum>(II)</enum><text>in subparagraph (C)—</text><item id="idAFFAF99A25774C2E9DF6E52FDEF577F6"><enum>(aa)</enum><text>by striking <quote>For each major</quote> and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idF7C688E7182842BF99DED2DE1B7297F1" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="id4AE73119FDF64F8CBC6A3FF2B9B361A2"><enum>(i)</enum><header>In general</header><text>For each major</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item><item id="id0FDA1F5C033444ACAFC067B2309F9CE0"><enum>(bb)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idE8E441566658461480A1FF1A78157C78" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="id429943EFF2F14F5B9B014627AA651C6A"><enum>(ii)</enum><header>Cybersecurity</header><text>In categorizing an investment according to risk under clause (i), the Chief Information Officer of the covered agency shall consult with the Director of the Cybersecurity and Infrastructure Security Agency on the cybersecurity or supply chain risk.</text></clause><clause id="idE4F378ADEFB64DA5BE6541741A4EF3C4"><enum>(iii)</enum><header>Security risk guidance</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance for the categorization of an investment under clause (i) according to the cybersecurity or supply chain risk.</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item></subclause></clause><clause id="id23C823D2974E414DA8AB5B1250642F3C"><enum>(iii)</enum><text>in paragraph (4)—</text><subclause id="id57F6635BB69741A59B004349F7AA0735"><enum>(I)</enum><text>in subparagraph (A)—</text><item id="id89E846A95B6D417FBD7160619FAE2357"><enum>(aa)</enum><text>in clause (ii), by striking <quote>and</quote> at the end;</text></item><item id="idA97F36A1B5A74406BE0ACA02408E00DC"><enum>(bb)</enum><text>in clause (iii), by striking the period at the end and inserting <quote>; and</quote>; and</text></item><item id="id6E5332C626D84C97BB29458A1F9D9CD4"><enum>(cc)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id7BAD9EDA556A4B35BBF832D73F3D3D99" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="idE5D80C7683224C32B45C679CFA9B153A"><enum>(iv)</enum><text>in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the cybersecurity risks of the investment.</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item></subclause><subclause id="idDA2327332D14427EA0D558A8688056AB"><enum>(II)</enum><text>in subparagraph (B), in the matter preceding clause (i), by inserting <quote>not later than 30 days after the date on which the review under subparagraph (A) is completed, </quote> before <quote>the Administrator</quote>;</text></subclause></clause></subparagraph><subparagraph id="id19838DCB58834A7BBF85B10D4DD24901"><enum>(C)</enum><text>in subsection (f)—</text><clause id="idB4757FEC32D94DA6B199B57751A3C034"><enum>(i)</enum><text>by striking <quote>heads of executive agencies to develop</quote> and inserting “heads of executive agencies to—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id1C8EB3D678134E5199DAC1CBD516BACD" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idEADE19196AF2453DBF07F8320295624F"><enum>(1)</enum><text>develop</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id308C0CD86CCB417BADF5B31A08F35667"><enum>(ii)</enum><text>in paragraph (1), as so designated, by striking the period at the end and inserting <quote>; and</quote>; and</text></clause><clause id="id27E0239F5D0449918137D80F81D4C0DE"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idAED2F59885F846CF82D8631654BE545D" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="idA3562F8F4B3E4B3BA981701200E9E170"><enum>(2)</enum><text>consult with the Director of the Cybersecurity and Infrastructure Security Agency for the development and use of supply chain security best practices.</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="idEC3B31DC407747938700DD3F58D17597"><enum>(D)</enum><text>in subsection (h), by inserting <quote>, including cybersecurity performances, </quote> after <quote>the performances</quote>; and</text></subparagraph></paragraph><paragraph id="idCB77D29A9E8C4447A717C9915AA8F2B0"><enum>(2)</enum><text>in section 11303(b)(2)(B)—</text><subparagraph id="id0F559B7B2B1349109ED776C0519013BD"><enum>(A)</enum><text>in clause (i), by striking <quote>or</quote> at the end;</text></subparagraph><subparagraph id="id5F4002CB05604AB2B8CD6AAB5A3C78F4"><enum>(B)</enum><text>in clause (ii), by adding <quote>or</quote> at the end; and</text></subparagraph><subparagraph id="idF08E5B53D2CB43459E54336EED9DE4EB"><enum>(C)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idC14EAE03F47E46C8AF8A8A06669DC024" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><clause id="idFD89DC82E6CD4690B5B87CA9FCD06B7F"><enum>(iii)</enum><text>whether the function should be performed by a shared service offered by another executive agency;</text></clause><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph></subsection><subsection id="idE8E5E0B514B4478496BF6A9924214B06"><enum>(d)</enum><header>Subchapter II</header><text>Subchapter II of subtitle III of title 40, United States Code, is amended—</text><paragraph id="id2A7A28E440DC428D82A58F2CFEACFA15"><enum>(1)</enum><text>in section 11312(a), by inserting <quote>, including security risks</quote> after <quote>managing the risks</quote>;</text></paragraph><paragraph id="id8408012D78BF4B23B06D9DB7989CB0AB"><enum>(2)</enum><text>in section 11313(1), by striking <quote>efficiency and effectiveness</quote> and inserting <quote>efficiency, security, and effectiveness</quote>;</text></paragraph><paragraph id="id6578A95F3C2146C793833ADCDA63889B"><enum>(3)</enum><text>in section 11317, by inserting <quote>security, </quote> before <quote>or schedule</quote>; and</text></paragraph><paragraph id="id8128FCEA43094237B3A8BC797FF5D618"><enum>(4)</enum><text>in section 11319(b)(1), in the paragraph heading, by striking <quote><header-in-text style="USC" level="paragraph">cios</header-in-text></quote> and inserting <quote><header-in-text style="USC" level="paragraph">Chief Information Officers</header-in-text></quote>.</text></paragraph></subsection><subsection id="id639B6365CFE4472B8ABC416F94C776AB"><enum>(e)</enum><header>Subchapter III</header><text>Section 11331 of title 40, United States Code, is amended—</text><paragraph id="idA25681FE7AB149279321D657A9BC4C0D"><enum>(1)</enum><text>in subsection (a), by striking <quote>section 3532(b)(1)</quote> and inserting <quote>section 3552(b)</quote>;</text></paragraph><paragraph id="id313D45BDE832412F967F393CD90DAC02"><enum>(2)</enum><text>in subsection (b)(1)(A)—</text><subparagraph id="id177DDA8D57C54A538522CFB79288B21C"><enum>(A)</enum><text>by striking <quote>in consultation</quote> and inserting <quote>in coordination</quote>;</text></subparagraph><subparagraph id="id2D42D5AF307D4062A1569759D11449C7"><enum>(B)</enum><text>by striking <quote>the Secretary of Homeland Security</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency</quote>; and</text></subparagraph><subparagraph id="idFD09BDC272664027A3B8B64078898919"><enum>(C)</enum><text>by inserting <quote>and associated verification specifications developed under subsection (g)</quote> before <quote>pertaining to Federal</quote>;</text></subparagraph></paragraph><paragraph id="idA5067EAF88804BE291990A1A652EAE2E"><enum>(3)</enum><text>by striking subsection (c) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idCC4F0A47B5234C29A3BC30F44567437C" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subsection id="idFE4873A9CF4C445DB376F451C7C5AAAC"><enum>(c)</enum><header>Application of more stringent standards</header><paragraph id="id27B6AFDB1FE24945898EB2BED64E9CD0"><enum>(1)</enum><header>In general</header><text>The head of an agency shall—</text><subparagraph id="id4E34AE526F1B45F0B8EB9E7EB60ECB0C"><enum>(A)</enum><text>evaluate the need to employ standards for cost-effective, risk-based information security for all systems, operations, and assets within or under the supervision of the agency that are more stringent than the standards promulgated by the Director under this section, if such standards contain, at a minimum, the provisions of those applicable standards made compulsory and binding by the Director; and</text></subparagraph><subparagraph id="id54D32BF4E60E4E9C93E771238C9C440A"><enum>(B)</enum><text>to the greatest extent practicable and if the head of the agency determines that the standards described in subparagraph (A) are necessary, employ those standards.</text></subparagraph></paragraph><paragraph id="id88D410D3DD404BDF9B68F9833E4A2E8F"><enum>(2)</enum><header>Evaluation of more stringent standards</header><text>In evaluating the need to employ more stringent standards under paragraph (1), the head of an agency shall consider available risk information, including—</text><subparagraph id="ide704302ce27642f8b686f3ce9977d101"><enum>(A)</enum><text>the status of cybersecurity remedial actions of the agency;</text></subparagraph><subparagraph id="id98dcc20854b643c68199da6b7e69cff6"><enum>(B)</enum><text>any vulnerability information relating to agency systems that is known to the agency;</text></subparagraph><subparagraph id="id06484cc6653547b1ac68a7345ab5e379"><enum>(C)</enum><text>incident information of the agency;</text></subparagraph><subparagraph id="idb83b0dbf9b7643d08622d919a03017b4"><enum>(D)</enum><text>information from—</text><clause id="id53AF803D2E4147C087479175801B5826"><enum>(i)</enum><text>penetration testing performed under section 3559A of title 44; and</text></clause><clause id="id364CFDB867D44EA4911E1F648EAABF46"><enum>(ii)</enum><text>information from the verification disclosure program established under section 3559B of title 44;</text></clause></subparagraph><subparagraph id="idda4bbbfba8374558b2202d74b03e16dc"><enum>(E)</enum><text>agency threat hunting results under section 207 of the <short-title>Federal Information Security Modernization Act of 2021</short-title>;</text></subparagraph><subparagraph id="idc7e24758287b4662a4fd8d0a173fdca8"><enum>(F)</enum><text>Federal and non-Federal threat intelligence;</text></subparagraph><subparagraph id="ideaf32e219ffa416395ebd64a9d7830f6"><enum>(G)</enum><text>data on compliance with standards issued under this section, using the verification specifications developed under subsection (f) when appropriate;</text></subparagraph><subparagraph id="id111d37c001574f688a33bf88ee09fdfc"><enum>(H)</enum><text>agency system risk assessments of the agency performed under section 3554(a)(1)(A) of title 44; and</text></subparagraph><subparagraph id="id31217efeb23b4e80b910379ff94efd58"><enum>(I)</enum><text>any other information determined relevant by the head of the agency. </text></subparagraph></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></paragraph><paragraph id="idA82E10CF873245149751D3F66B3A91A2"><enum>(4)</enum><text>in subsection (d)(2)—</text><subparagraph id="idD99F2BAC36274E4D815F09D116715A81"><enum>(A)</enum><text>by striking the paragraph heading and inserting <quote><header-in-text style="USC" level="paragraph">Consultation, notice, and comment</header-in-text></quote>;</text></subparagraph><subparagraph id="idFA8FDBDE20F7470BB7836BA7E887FAC7"><enum>(B)</enum><text>by inserting <quote>promulgate, </quote> before <quote>significantly modify</quote>; and</text></subparagraph><subparagraph id="id66FC08C23CB14921BE412EF0CBBC820A"><enum>(C)</enum><text>by striking <quote>shall be made after the public is given an opportunity to comment on the Director's proposed decision.</quote> and inserting “shall be made—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id122CF6E09BA4449D9705FD19D7CCF8D9" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subparagraph id="idBCDFE23C8A054B50A8AAE52954F4DE1C"><enum>(A)</enum><text>for a decision to significantly modify or not promulgate such a proposed standard, after the public is given an opportunity to comment on the Director's proposed decision;</text></subparagraph><subparagraph id="id61D04BD7E7CA4EC3A588CC914A0E62A8"><enum>(B)</enum><text>in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency; </text></subparagraph><subparagraph id="id62D2E05C4A474EB5876D81BFABD895F8"><enum>(C)</enum><text>considering the Federal risk assessments performed under section 3553(i) of title 44; and</text></subparagraph><subparagraph id="id24ADD761C7D14DF6A70E5D8EB8E40815"><enum>(D)</enum><text>considering the extent to which the proposed standard reduces risk relative to the cost of implementation of the standard.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="id4E7E680E35D34FE4B3BF562C9348C352"><enum>(5)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idA22C7A3C018A4CD39B37D6B6A55CB91A" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><subsection id="idb00bc8169ff040b38d3437d7225f8816"><enum>(e)</enum><header>Review of promulgated standards</header><paragraph id="id53379e57a5db49adadf5e8872f1fbfa0"><enum>(1)</enum><header>In general</header><text>Not less frequently than once every 2 years, the Director of the Office of Management and Budget, in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency shall review the efficacy of the standards in effect promulgated under this section in reducing cybersecurity risks and determine whether any changes to those standards are appropriate based on— </text><subparagraph id="idd244f266fd304864b474c78606e2f1b5"><enum>(A)</enum><text>the Federal risk assessment developed under section 3553(i) of title 44;</text></subparagraph><subparagraph id="idcdeaa0b0dda94966ad8ab280204067bb"><enum>(B)</enum><text>public comment; and</text></subparagraph><subparagraph id="idb9e7a4204aad4291adc43932d7ad2b50"><enum>(C)</enum><text>an assessment of the extent to which the proposed standards reduce risk relative to the cost of implementation of the standards.</text></subparagraph></paragraph><paragraph id="id81EDA9ECDB274BFEB28823FF7F0C6645"><enum>(2)</enum><header>Updated guidance</header><text>Not later than 90 days after the date of the completion of the review under paragraph (1), the Director of the Office of Management and Budget shall issue guidance to agencies to make any necessary updates to the standards in effect promulgated under this section based on the results of the review.</text></paragraph><paragraph id="iddcc15a8587f64392a86f4eb9dcfc31c0"><enum>(3)</enum><header>Congressional report</header><text>Not later than 30 days after the date on which a review is completed under paragraph (1), the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name> a report that includes—</text><subparagraph id="idaf973693ce2e45708740d1c759cb768b"><enum>(A)</enum><text>the review of the standards in effect promulgated under this section conducted under paragraph (1);</text></subparagraph><subparagraph id="idF37534F3B87C482F98559D681718072E"><enum>(B)</enum><text>the risk mitigation offered by each standard described in subparagraph (A); and</text></subparagraph><subparagraph id="id834772e89c394b0c8666799188ae6439"><enum>(C)</enum><text>a summary of—</text><clause id="id70C604D59C2A41EC9BCE2CD3298A9432"><enum>(i)</enum><text>the standards to which changes were determined appropriate during the review; and</text></clause><clause id="id8568303C9DEF4F17A42040C1F1CFD0C3"><enum>(ii)</enum><text>anticipated changes to the standards under this section in guidance issued under paragraph (2).</text></clause></subparagraph></paragraph></subsection><subsection id="id1726dc0f5cd54782acbf3660c892c26e"><enum>(f)</enum><header>Verification specifications</header><text>Not later than 1 year after the date on which the Director of the National Institute of Standards and Technology issues a proposed standard pursuant to paragraphs (2) and (3) of section 20(a) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g–3(a)</external-xref>), the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director of the National Institute of Standards and Technology, as practicable, shall develop technical specifications to enable the automated verification of the implementation of the controls within the standard.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="idDB6C12AFB4E6446AA2ADC93C9C80792F"><enum>103.</enum><header>Actions to enhance Federal incident response</header><subsection id="idc0c0943bcf55406c920de3e7105f1cf0"><enum>(a)</enum><header>Responsibilities of the Cybersecurity and Infrastructure Security Agency</header><paragraph id="id13F052B818F74680AE1D13D680AC4E06"><enum>(1)</enum><header>Recommendations</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in coordination with the Chair of the Federal Trade Commission, the Chair of the Securities and Exchange Commission, the Secretary of the Treasury, the Director of the Federal Bureau of Investigation, the Director of the National Institute of Standards and Technology, and the head of any other appropriate Federal or non-Federal entity, shall consolidate, maintain, and make publicly available recommendations for individuals whose personal information, as defined in section 3591 of title 44, United States Code, as added by this Act, is inappropriately exposed as a result of a high risk incident described in section 3598(c)(2) of title 44, United States Code.</text></paragraph><paragraph id="id8C0F7F388F6145E5BEE9C4E19640EAC4"><enum>(2)</enum><header>Plan for analysis of, and report on, Federal incidents</header><subparagraph id="idC563E7D8F184465888C2BED28C31D747"><enum>(A)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall—</text><clause id="id017A51D9295F451F86B60811C43B431E"><enum>(i)</enum><text>develop a plan for the development of the analysis required under section 3597(b) of title 44, United States Code, as added by this Act, and the report required under subsection (c) of that section that includes—</text><subclause id="id1BF0D9F6F3F8432AB8EA4D1F9680A954"><enum>(I)</enum><text>a description of any challenges the Director anticipates encountering; and</text></subclause><subclause id="id33F82E4C2B1F4706A647789ACC4C60C2"><enum>(II)</enum><text>the use of automation and machine-readable formats for collecting, compiling, monitoring, and analyzing data; and</text></subclause></clause><clause id="id78376E7B4D9440588F8FBD39907B0A12"><enum>(ii)</enum><text>provide to the appropriate congressional committees a briefing on the plan developed under clause (i).</text></clause></subparagraph><subparagraph id="id2ABF645FFA5541AF83310E701FB098D4"><enum>(B)</enum><header>Briefing</header><text>Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the appropriate congressional committees a briefing on—</text><clause id="id11E1C7E579B14E35A67F6C5F449902DD"><enum>(i)</enum><text>the execution of the plan required under subparagraph (A); and</text></clause><clause id="id409B5E5584E24DF58A12B3723DCD4930"><enum>(ii)</enum><text>the development of the report required under section 3597(c) of title 44, United States Code, as added by this Act.</text></clause></subparagraph></paragraph></subsection><subsection id="idAB7424E506924C10AAA4BB7BE3913F9E"><enum>(b)</enum><header>Responsibilities of the Director of the Office of Management and Budget</header><paragraph id="idC3C88866135F4B6896CC3EE0D1183A52"><enum>(1)</enum><header>FISMA</header><text>Section 2 of the Federal Information Security Modernization Act of 2014 (<external-xref legal-doc="usc" parsable-cite="usc/44/3554">44 U.S.C. 3554</external-xref> note) is amended—</text><subparagraph id="idA7D0C201D03F4EE381B8B0D8D29D9F93"><enum>(A)</enum><text>by striking subsection (b); and</text></subparagraph><subparagraph id="id5635DDA7922B45BCBDE054DA07D7A101"><enum>(B)</enum><text>by redesignating subsections (c) through (f) as subsections (b) through (e), respectively. </text></subparagraph></paragraph><paragraph id="id5BC29BB6650548B28228F3E9E687CB7F"><enum>(2)</enum><header>Incident data sharing</header><subparagraph id="id0b4b6a30c45a4680be13dee41e7425d1"><enum>(A)</enum><header>In general</header><text>The Director shall develop guidance, to be updated not less frequently than once every 2 years, on the content, timeliness, and format of the information provided by agencies under section 3594(a) of title 44, United States Code, as added by this Act.</text></subparagraph><subparagraph id="idF79FCFE32A4D4BC580C0AE874025C080"><enum>(B)</enum><header>Requirements</header><text>The guidance developed under subparagraph (A) shall—</text><clause id="id30B1736FB8964036ABCDAD3B4003A7B2"><enum>(i)</enum><text>prioritize the availability of data necessary to understand and analyze—</text><subclause id="idb3ab7c987ebc474fb72cccc3776d2bd1"><enum>(I)</enum><text>the causes of incidents;</text></subclause><subclause id="id3b6d023b208744fe92f801821a49a9e7"><enum>(II)</enum><text>the scope and scale of incidents within the agency networks and systems;</text></subclause><subclause id="id109c904c82f94b6488b77c7bb3f1253a"><enum>(III)</enum><text>cross Federal Government root causes of incidents;</text></subclause><subclause id="id333a66443d7944d99ebce350e7e12300"><enum>(IV)</enum><text>agency response, recovery, and remediation actions; and</text></subclause><subclause id="id44034A8759E341D2ADEBA2E84B4B0300"><enum>(V)</enum><text>the effectiveness of incidents;</text></subclause></clause><clause id="idc193a4198610491caa8b793936929283"><enum>(ii)</enum><text>enable the efficient development of—</text><subclause id="id1f52d1f986c0462f8d526556ed9b5923"><enum>(I)</enum><text>lessons learned and recommendations in responding to, recovering from, remediating, and mitigating future incidents; and</text></subclause><subclause id="id873ab44a4c2b4c3b887c4f72e03a983f"><enum>(II)</enum><text>the report on Federal compromises required under section 3597(c) of title 44, United States Code, as added by this Act;</text></subclause></clause><clause id="idC4895C8E1B764328819282A343EA6ED7"><enum>(iii)</enum><text>include requirements for the timeliness of data production; and</text></clause><clause id="idD512EAB3911940B1BFBA951E3DEDE25A"><enum>(iv)</enum><text>include requirements for using automation and machine-readable data for data sharing and availability.</text></clause></subparagraph></paragraph><paragraph id="id6C0450B7EA7240AB92B66F7EB29F8E44"><enum>(3)</enum><header>Guidance on responding to information requests</header><text>Not later than 1 year after the date of enactment of this Act, the Director shall develop guidance for agencies to implement the requirement under section 3594(c) of title 44, United States Code, as added by this Act, to provide information to other agencies experiencing incidents.</text></paragraph><paragraph id="idA3FEF5F31C634B34BC9F9050BA5AB492"><enum>(4)</enum><header>Standard guidance and templates</header><text>Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop guidance and templates, to be reviewed and, if necessary, updated not less frequently than once every 2 years, for use by Federal agencies in the activities required under sections 3592, 3593, and 3596 of title 44, United States Code, as added by this Act.</text></paragraph><paragraph id="idEE90BF207A06413285262EA88CFDEE1E"><enum>(5)</enum><header>Contractor and grantee guidance</header><subparagraph id="id9F5852D018134CAFAE9619A5358B592D"><enum>(A)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the Secretary of Homeland Security, the Secretary of Defense, the Administrator of General Services, and the heads of other agencies determined appropriate by the Director, shall issue guidance to Federal agencies on how to deconflict existing regulations, policies, and procedures relating to the responsibilities of contractors and grant recipients established under section 3595 of title 44, United States Code, as added by this Act.</text></subparagraph><subparagraph id="idB06A4B24D9B84019923A2FAC959C847A"><enum>(B)</enum><header>Existing processes</header><text>To the greatest extent practicable, the guidance issued under subparagraph (A) shall allow contractors and grantees to use existing processes for notifying Federal agencies of incidents involving information of the Federal Government.</text></subparagraph></paragraph><paragraph id="id53BA501180084E85A17DD7B72A56E93D"><enum>(6)</enum><header>Updated briefings</header><text>Not less frequently than once every 2 years, the Director shall provide to the appropriate congressional committees an update on the guidance and templates developed under paragraphs (2) through (4).</text></paragraph></subsection><subsection id="id1AB17A9E544349F18C083106CF21833B"><enum>(c)</enum><header>Update to the Privacy Act of 1974</header><text>Section 552a(b) of title 5, United States Code (commonly known as the <term>Privacy Act of 1974</term>) is amended—</text><paragraph id="id5522C3C4F7804CAEB3039D1A1856322D"><enum>(1)</enum><text>in paragraph (11), by striking <quote>or</quote> at the end;</text></paragraph><paragraph id="id95F8EF69165944BBB3CA7B3FEF92E245"><enum>(2)</enum><text>in paragraph (12), by striking the period at the end and inserting <quote>; and</quote>; and</text></paragraph><paragraph id="idE2D7807926354AEDADE2DD8B47568FAB"><enum>(3)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idEDF72819145D44A69A179B1591FCDDE2" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id65010c8c13224bb1886761bcb0247142"><enum>(13)</enum><text>to another agency in furtherance of a response to an incident (as defined in section 3552 of title 44) and pursuant to the information sharing requirements in section 3594 of title 44 if the head of the requesting agency has made a written request to the agency that maintains the record specifying the particular portion desired and the activity for which the record is sought.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="idFD13785A520E4503ACADB2CDC0C27474"><enum>104.</enum><header>Additional guidance to agencies on FISMA updates</header><text display-inline="no-display-inline">Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance for agencies on—</text><paragraph id="id0D2131C4620E4DE490DDE0237552C60F"><enum>(1)</enum><text>completing the agency system risk assessment required under section 3554(a)(1)(A) of title 44, United States Code, as amended by this Act;</text></paragraph><paragraph id="id7A7DFDB728DB4A31BC27FC00A0BA8B89"><enum>(2)</enum><text>implementing additional cybersecurity procedures, which shall include resources for shared services; </text></paragraph><paragraph id="id7D02E091333F4B1492E5AE92647458D6"><enum>(3)</enum><text>establishing a process for providing the status of each remedial action under section 3554(b)(7) of title 44, United States Code, as amended by this Act, to the Director and the Cybersecurity and Infrastructure Security Agency using automation and machine-readable data, as practicable, which shall include—</text><subparagraph id="idC9B7E51F7CAC4DAEB99343D66F31842E"><enum>(A)</enum><text>specific standards for the automation and machine-readable data; and</text></subparagraph><subparagraph id="id032231A9D4464D3481BC212B59DC1440"><enum>(B)</enum><text>templates for providing the status of the remedial action;</text></subparagraph></paragraph><paragraph id="id0B85BEBC87824110AAC7ED18973E1F68"><enum>(4)</enum><text>interpreting the definition of <quote>high value asset</quote> in section 3552 of title 44, United States Code, as amended by this Act;</text></paragraph><paragraph id="id819D13D7165B4D89A618B1EA0FA90676"><enum>(5)</enum><text>implementing standards in agency authorization processes to encourage the tailoring of processes to agency and system risk that are proportionate to the sensitivity of systems, which shall include—</text><subparagraph id="id149081D0566A48E5A9DDB3FC3FC743A6"><enum>(A)</enum><text>a clarification of—</text><clause id="id841F4D406723423B8CE0F666C4A0BC03"><enum>(i)</enum><text>the acceptable use and development of customization of standards promulgated under section 11331 of title 40, United States Code; and</text></clause><clause id="id97969D4B901A4FF99862EFD3825BBD80"><enum>(ii)</enum><text>the acceptable use of risk-based authorization procedures authorized on the date of enactment of this Act; and</text></clause></subparagraph><subparagraph id="idFFEC483D591243CEA4B902C63CAEC88B"><enum>(B)</enum><text>a requirement to coordinate with Inspectors Generals of agencies to ensure consistent understanding and application of agency policies for the purpose of Inspector General audits; and</text></subparagraph></paragraph><paragraph id="idDF9153F2ED104E438CF276BEA688E809"><enum>(6)</enum><text>requiring, as practicable and pursuant to section 203, an evaluation of agency cybersecurity using metrics that are—</text><subparagraph id="idECC13ED248E04AAAB35C8CD8D89665D8"><enum>(A)</enum><text>based on outcomes; and</text></subparagraph><subparagraph id="id50188A145F824171B476A577498E9334"><enum>(B)</enum><text>based on time.</text></subparagraph></paragraph></section><section id="id02714F2B4ED54D0482D6E01336B563DB"><enum>105.</enum><header>Agency requirements to notify entities impacted by incidents</header><text display-inline="no-display-inline">Not later than 180 days after the date of enactment of this Act, the Director shall issue guidance that requires agencies to notify entities that are compelled to share sensitive information with the agency of an incident that impacts—</text><paragraph id="idB3639324ED584E87A2380DF9852A9D4F"><enum>(1)</enum><text>sensitive information shared with the agency by the entity; or</text></paragraph><paragraph id="id668B3445F7634C94B8DDB0AD2480C051"><enum>(2)</enum><text>the systems used to the transmit sensitive information described in paragraph (1) to the agency.</text></paragraph></section></title><title style="OLC" id="idDFED287744094E38B44FBB2D9BE4BD08" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>II</enum><header>Improving Federal cybersecurity</header><section section-type="subsequent-section" id="id7D2C6E371E9642DBA819AA9F24B98A2B"><enum>201.</enum><header>Evaluation of effectiveness of standards</header><subsection id="idd8ddcbe12f6e49d68b1dbde8c36d4797"><enum>(a)</enum><header>In general</header><text>As a component of the evaluation and report required under section 3555(h) of title 44, United States Code, and not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall perform a study that—</text><paragraph id="id7004690ba8df4eb4ba0515cee0117737"><enum>(1)</enum><text>assesses the standards promulgated under section 11331(b) of title 40, United States Code to determine the degree to which agencies use the authority under section 11331(c)(1) of title 40, United States Code to customize the standards relative to the risks facing each agency and agency system;</text></paragraph><paragraph id="idb9f07881152146a58d75ad6e7199851d"><enum>(2)</enum><text>assesses the effectiveness of the standards described in paragraph (1), including any standards customized by agencies under section 11331(c)(1) of title 40, United States Code, at improving agency cybersecurity;</text></paragraph><paragraph id="idAD072C1A1C3D496E9950E7A9B5082E13"><enum>(3)</enum><text>examines the quantification of cybersecurity risk in the private sector for any applicability for use by the Federal Government;</text></paragraph><paragraph id="idA2982FA2755A4B8D91E4133F31126394"><enum>(4)</enum><text>examines cybersecurity metrics existing as of the date of enactment of this Act used by the Director, the Director of the Cybersecurity and Infrastructure Security Agency, and the heads of other agencies to evaluate the effectiveness of information security policies and practices; and</text></paragraph><paragraph id="idb6d3faeee94a4d98baf5f9eb33f7b9ec"><enum>(5)</enum><text>with respect to the standards described in paragraph (1), provides recommendations for—</text><subparagraph id="id9634D3F73EA84B79B77B4F7CB1AECA17"><enum>(A)</enum><text>the addition or removal of standards; or</text></subparagraph><subparagraph id="id53677F7D61744C15BC5B1CB65DE39585"><enum>(B)</enum><text>the customization of—</text><clause id="id75550B01F5E14FBB9B2D2EBCD28D6D0A"><enum>(i)</enum><text>the standards by agencies under section 11331(c)(1) of title 40, United <italic></italic>States Code; or</text></clause><clause id="id7DF3A4F95A0D4B988E660D454E4F682D"><enum>(ii)</enum><text>specific controls within the standards.</text></clause></subparagraph></paragraph></subsection><subsection id="ida1a82785f79b448bbd4caf479adfe521"><enum>(b)</enum><header>Incorporation of study</header><text>The Director shall incorporate the results of the study performed under subsection (a) into the review of standards required under section 11331(e) of title 40, United States Code.</text></subsection><subsection id="id7b6f6baf84aa4962890a7bd25f3fa875"><enum>(c)</enum><header>Briefing</header><text>Not later than 30 days after the date on which the study performed under subsection (a) is completed, the Comptroller General of the United States shall provide to the appropriate congressional committees a briefing on the study.</text></subsection></section><section section-type="subsequent-section" id="id446F8C8CA5B84DAE8E829DC5579DDD53"><enum>202.</enum><header>Mobile security standards</header><subsection id="id20ecd63566874864be6e486a0a0b0550"><enum>(a)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Director shall—</text><paragraph id="id8e17defc8d5b40208d761cc817ebcc51"><enum>(1)</enum><text>evaluate mobile application security standards promulgated under section 11331(b) of title 44, United States Code; and</text></paragraph><paragraph id="id6ad254e0740c4f199900b66f05e6d289"><enum>(2)</enum><text>issue guidance to implement mobile security standards in effect on the date of enactment of this Act promulgated under section 11331(b) of title 40, United States Code, including for mobile applications, for every agency.</text></paragraph></subsection><subsection id="idDD5FD6C187C443D7870A438C6F761D33"><enum>(b)</enum><header>Contents</header><text>The guidance issued under subsection (a)(2) shall include—</text><paragraph id="idBCF088050257429F84118ACF4771484E"><enum>(1)</enum><text>a requirement, pursuant to section 3506(b)(4) of title 44, United States Code, for every agency to maintain a continuous inventory of every—</text><subparagraph id="ide2ba0fa85ef24e2b804e387557563ad9"><enum>(A)</enum><text>mobile device operated by or on behalf of the agency;</text></subparagraph><subparagraph id="id1e30990655914ac78de28aa21834cebf"><enum>(B)</enum><text>mobile application installed on a mobile device described in subparagraph (A); and</text></subparagraph><subparagraph id="id534C4323DB8A4A979B504776DBF7F054"><enum>(C)</enum><text>vulnerability identified by the agency associated with a mobile device or mobile application described in subparagraphs (A) and (B); and</text></subparagraph></paragraph><paragraph id="id5bb1d695312f4ca0a4d7c8f8139a5f3d"><enum>(2)</enum><text>a requirement for every agency to perform continuous evaluation of the vulnerabilities described in paragraph (1)(C) and other risks.</text></paragraph></subsection><subsection id="idc9d3e38335d045689103fcf52cb95f20"><enum>(c)</enum><header>Information sharing</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance to agencies for sharing the inventory of the agency required under subsection (b)(1) with the Director of the Cybersecurity and Infrastructure Security Agency, using automation and machine-readable data to the greatest extent practicable.</text></subsection><subsection id="id2b6eab8a929d48bdb5a65ec131f86886"><enum>(d)</enum><header>Briefing</header><text>Not later than 60 days after the date on which the Director issues guidance under subsection (a)(2), the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall provide to the appropriate congressional committees a briefing on the guidance.</text></subsection></section><section id="idBB9764D29C4445B9A5BD6E6D3DDD069C"><enum>203.</enum><header>Quantitative cybersecurity metrics</header><subsection id="id943c1c5e66114621ba610cecf869d063"><enum>(a)</enum><header>Establishing time-Based metrics</header><paragraph id="idA688CE0EC361440AA084E9A64CB8705A"><enum>(1)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall—</text><subparagraph id="id2B46C92DB865489EBBA91DB6396A2753"><enum>(A)</enum><text>update the metrics used to measure security under section 3554 of title 44, United States Code, including any metrics developed pursuant to section 224(c) of the Cybersecurity Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1522">6 U.S.C. 1522(c)</external-xref>), to include standardized metrics to quantitatively evaluate and identify trends in agency cybersecurity performance, including performance for incident response; and</text></subparagraph><subparagraph id="id9C97D9E639BE489CAFAC2260D20A97E4"><enum>(B)</enum><text>evaluate the metrics described in subparagraph (A).</text></subparagraph></paragraph><paragraph id="id5A61AE9B41FF4F66857B89FD92F61E98"><enum>(2)</enum><header>Qualities</header><text>With respect to the updated metrics required under paragraph (1)—</text><subparagraph id="ide2929b03056e4c59949126ae1d4a4e17"><enum>(A)</enum><text>not less than 2 of the metrics shall be time-based; and</text></subparagraph><subparagraph id="id3D4E8666C7F84D42B2F447C4A9044CFB"><enum>(B)</enum><text>the metrics may include other measurable outcomes.</text></subparagraph></paragraph><paragraph id="idf0bcd5b479954d9ab6f509d6c10f0d05"><enum>(3)</enum><header>Evaluation</header><text>The evaluation required under paragraph (1)(B) shall evaluate—</text><subparagraph id="id637b6c88f8c14d4c80384da4fba94231"><enum>(A)</enum><text>the amount of time it takes for an agency to detect an incident; and</text></subparagraph><subparagraph id="idb71cf0611e83488ea5f11f857de29642"><enum>(B)</enum><text>the amount of time that passes between—</text><clause id="id142811527837476A8169FF1D09AB1FF9"><enum>(i)</enum><text>the detection and remediation of an incident; and</text></clause><clause id="id310A3E6269B44DDFBB21ACAED3977188"><enum>(ii)</enum><text>the remediation of an incident and the recovery from the incident.</text></clause></subparagraph></paragraph></subsection><subsection id="id0e320f04c4d048829eaed5afd4bc101b"><enum>(b)</enum><header>Implementation</header><paragraph id="id26B75F0D1AFA4225BD1BAFE5D72198BE"><enum>(1)</enum><header>In general</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall promulgate guidance that requires the use of the updated metrics developed under subsection (a)(1)(A) by every agency over a 4-year period beginning on the date on which the metrics are developed to track trends in the incident response capabilities of agencies.</text></paragraph><paragraph id="idcdb340d83b4f441587600d9c31e058ac"><enum>(2)</enum><header>Penetration tests</header><text>On not less than 2 occasions during the 2-year period following the date on which guidance is promulgated under paragraph (1), not less than 3 agencies shall be subjected to substantially similar penetration tests in order to validate the utility of the metrics developed under subsection (a)(1)(A).</text></paragraph><paragraph id="id5297C67F866E476398C537861C3638FA"><enum>(3)</enum><header>Database</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall develop and use a database that—</text><subparagraph id="id56B92ED927BF4773BA6939FF44EDB959"><enum>(A)</enum><text>stores agency metrics information; and</text></subparagraph><subparagraph id="id191A79F0DF184ECEBE38147A9A951DCE"><enum>(B)</enum><text>allows for the performance of cross-agency comparison of agency incident response capability trends.</text></subparagraph></paragraph></subsection><subsection id="idc428675fa0e54224846a9e0158e5ae88"><enum>(c)</enum><header>Updated metrics</header><paragraph id="id5B7E68078EA2470B849E2E9898F4CBEE"><enum>(1)</enum><header>In general</header><text>The Director may issue guidance that updates the metrics developed under subsection (a)(1)(A) if the updated metrics—</text><subparagraph id="idB3D8900A9EBA4529864C0B46EE447575"><enum>(A)</enum><text>have the qualities described in subsection (a)(2); and</text></subparagraph><subparagraph id="idC56B06459A7446A38F7B3697BBF7D190"><enum>(B)</enum><text>can be evaluated under subsection (a)(3).</text></subparagraph></paragraph><paragraph id="idEB2D6BA168CB4FBC8DE377677DE74162"><enum>(2)</enum><header>Data sharing</header><text>The guidance issued under paragraph (1) shall require agencies to share with the Director of the Cybersecurity and Infrastructure Security Agency data demonstrating the performance of the agency with the updated metrics included in that guidance against the metrics developed under subsection (a)(1)(A).</text></paragraph></subsection><subsection id="idD2BD877FE72E4BC8B4D84CD9F3DFF386"><enum>(d)</enum><header>Congressional reports</header><paragraph id="id8B1AC64D53A445459DE780FA7F147415"><enum>(1)</enum><header>Updated metrics</header><text>Not later than 30 days after the date on which the Director of the Cybersecurity and Infrastructure Security completes the evaluation required under subsection (a)(1)(B), the Director of the Cybersecurity and Infrastructure Security Agency shall submit to the appropriate congressional committees a report on the updated metrics developed under subsection (a)(1)(A).</text></paragraph><paragraph id="id85831D24B8F44B80952ABF3CA24DA143"><enum>(2)</enum><header>Program</header><text>Not later than 180 days after the date on which guidance is promulgated under subsection (b)(1), the Director shall submit to the appropriate congressional committees a report on the results of the use of the updated metrics developed under subsection (a)(1)(A) by agencies.</text></paragraph></subsection></section><section id="idb525875190584d70b0d6d272d5fba18b"><enum>204.</enum><header>Data and logging retention for incident response</header><subsection id="idcd85f95d79294cc29e937709cd24f1e7"><enum>(a)</enum><header>Recommendations</header><text>Not later than 60 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Attorney General and the National Cyber Director, shall submit to the Director recommendations on requirements for logging events on agency systems and retaining other relevant data within the systems and networks of an agency. </text></subsection><subsection id="id8d21dfca1aab4a698f281b5d5d3d8c8d"><enum>(b)</enum><header>Contents</header><text>The recommendations provided under subsection (a) shall include—</text><paragraph id="idec1aef4552e94ff5b5b26f5e3c69d693"><enum>(1)</enum><text>the types of logs to be maintained;</text></paragraph><paragraph id="id38c6a82801f646fda7f25ed066702b00"><enum>(2)</enum><text>the time periods to retain the logs and other relevant data;</text></paragraph><paragraph id="id5f23bc3013fc4e38a0bb383879c77019"><enum>(3)</enum><text>the time periods for agencies to enable recommended logging and security requirements; </text></paragraph><paragraph id="id8f2b10ce9d8744a2a70e0d936a2ae41a"><enum>(4)</enum><text>how to ensure the confidentiality, integrity, and availability of logs;</text></paragraph><paragraph id="id281986c446ad473fbf534dc20a936f8d"><enum>(5)</enum><text>requirements to ensure that, upon request, agencies provide logs to—</text><subparagraph id="id5c5ac6fb73ad4567a9cdbd18b0e1165c"><enum>(A)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency for a cybersecurity purpose; and</text></subparagraph><subparagraph id="idfea32cbc5f97445787410a8c4278ef69"><enum>(B)</enum><text>the Federal Bureau of Investigation to investigate potential criminal activity; and</text></subparagraph></paragraph><paragraph id="ida961891b3d6c4b65aed23758a3a8b993"><enum>(6)</enum><text>ensuring the highest level security operations center of each agency has visibility into all agency logs.</text></paragraph></subsection><subsection id="ide4385bb6414d48bd85ad1ffb24284f86"><enum>(c)</enum><header>Guidance</header><text>Not later than 90 days after receiving the recommendations submitted under subsection (a), the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the Attorney General, shall promulgate guidance to agencies to establish requirements for logging, log retention, log management, and sharing of log data with other appropriate agencies.</text></subsection><subsection id="id9D4023D53DDB42A6903DB77458F1BA86"><enum>(d)</enum><header>Periodic review</header><text>Not later than 2 years after the date on which the Director of the Cybersecurity and Infrastructure Security Agency submits the recommendations required under subsection (a), and not less frequently than every 2 years thereafter, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Attorney General, shall evaluate the recommendations and provide an update on the recommendations to the Director as necessary.</text></subsection></section><section id="id88e7b24239424c1b998e8f9625612584"><enum>205.</enum><header>CISA agency advisors</header><subsection id="id31680941ffdc467ca7748d5ab39d624b"><enum>(a)</enum><header>In general</header><text>Not later than 120 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall assign not less than 1 cybersecurity professional employed by the Cybersecurity and Infrastructure Security Agency to be the Cybersecurity and Infrastructure Security Agency advisor to the Chief Information Officer of each agency.</text></subsection><subsection id="id150c09f714e04ddb8740e4f16932b12f"><enum>(b)</enum><header>Qualifications</header><text>Each advisor assigned under subsection (a) shall have knowledge of—</text><paragraph id="idd4619645a4a34a2ca08009919d8406a7"><enum>(1)</enum><text>cybersecurity threats facing agencies, including any specific threats to the assigned agency;</text></paragraph><paragraph id="id87652081ed3b44d9a12f58fb81b621c9"><enum>(2)</enum><text>performing risk assessments of agency systems; and</text></paragraph><paragraph id="id303dc7513a7b4906b539a79d32ce2cc7"><enum>(3)</enum><text>other Federal cybersecurity initiatives.</text></paragraph></subsection><subsection id="id92f0e4bb8a6f4d1eb5c72958b60ef49f"><enum>(c)</enum><header>Duties</header><text>The duties of each advisor assigned under subsection (a) shall include—</text><paragraph id="id2eebd0a6a90542a7929f0bdff4a039cc"><enum>(1)</enum><text>providing ongoing assistance and advice, as requested, to the agency Chief Information Officer;</text></paragraph><paragraph id="idf90ba275475443d7a0adace40d293265"><enum>(2)</enum><text>serving as an incident response point of contact between the assigned agency and the Cybersecurity and Infrastructure Security Agency; and</text></paragraph><paragraph id="id80ba6148f93149ab8e850b6a9ccb315c"><enum>(3)</enum><text>familiarizing themselves with agency systems, processes, and procedures to better facilitate support to the agency in responding to incidents.</text></paragraph></subsection><subsection id="idB733088993BA4913B978ADF3C0B2890D"><enum>(d)</enum><header>Limitation</header><text>An advisor assigned under subsection (a) shall not be a contractor.</text></subsection><subsection id="id7D6C12940E90459CB817D5721FD1B019" commented="no" display-inline="no-display-inline"><enum>(e)</enum><header>Multiple assignments</header><text>One individual advisor made be assigned to multiple agency Chief Information Officers under subsection (a).</text></subsection></section><section id="idD88B1A0B7F3B453E823C7504B69891F8"><enum>206.</enum><header>Federal penetration testing policy</header><subsection id="iddedf38576e0a4b38ad1dbfb32fe8137b"><enum>(a)</enum><header>In general</header><text>Subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="USC" display-inline="no-display-inline" id="id4A80E3F75F53428291AA7A00207FFDF7" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="id4CFA7FCCBE5B4C36A1F7A2B9B130E24E"><enum>3559A.</enum><header>Federal penetration testing</header><subsection id="idC8EAB573C0314A5099405EE8C663D5DA"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id39093E751BD34ED8911DC6FDF2E30FCF"><enum>(1)</enum><header>Agency operational plan</header><text>The term <term>agency operational plan</term> means a plan of an agency for the use of penetration testing.</text></paragraph><paragraph id="id7581C5250EBE4243A99F7C7E1C23833B"><enum>(2)</enum><header>Rules of engagement</header><text>The term <term>rules of engagement</term> means a set of rules established by an agency for the use of penetration testing.</text></paragraph></subsection><subsection id="iddee7bc4bc07b4c698a6a70eacba8cf74"><enum>(b)</enum><header>Guidance</header><paragraph id="idE934EFC220F949DB8E2DDB9F77926FF5"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Director shall issue guidance that—</text><subparagraph id="id52C7A6E9485345F1A43ACD860E2F4F3E"><enum>(A)</enum><text>requires agencies to use, when and where appropriate, penetration testing on agency systems; and</text></subparagraph><subparagraph id="idAD135D3BBC76464B80A2C054DFBE82A0"><enum>(B)</enum><text>requires agencies to develop an agency operational plan and rules of engagement that meet the requirements under subsection (c).</text></subparagraph></paragraph><paragraph id="ida0580d545f604177b880b0cd46f21f39"><enum>(2)</enum><header>Penetration testing guidance</header><text>The guidance issued under this section shall—</text><subparagraph id="id23b304531c434db485cf9d401080fea2"><enum>(A)</enum><text>permit an agency to use, for the purpose of performing penetration testing—</text><clause id="idC2EA087C5E224EDEB57C232DB69C685F"><enum>(i)</enum><text>a shared service of the agency or another agency; or</text></clause><clause id="id31100907F9D544FC92FACC669102C607"><enum>(ii)</enum><text>an external entity, such as a vendor;</text></clause></subparagraph><subparagraph id="id59e72e66585a4b369216425b9c9992dd"><enum>(B)</enum><text>include templates and frameworks for reporting the results of penetration testing, without regard to the status of the entity that performs the penetration testing; and</text></subparagraph><subparagraph id="ide662a16bf6384067ab8e76496ef69685"><enum>(C)</enum><text>require agencies to provide the rules of engagement and results of penetration testing to the Director and the Director of the Cybersecurity and Infrastructure Security Agency, without regard to the status of the entity that performs the penetration testing.</text></subparagraph></paragraph></subsection><subsection id="id584dc2d6365e439ea3bfd1020143e927"><enum>(c)</enum><header>Agency plans and rules of engagement</header><text>The agency operational plan and rules of engagement of an agency shall—</text><paragraph id="idb218f34dbc314bb6b51bd9016649f816"><enum>(1)</enum><text>require the agency to perform penetration testing on the high value assets of the agency;</text></paragraph><paragraph id="id300f776b146a4ae2a39b5c8530b2f1a7"><enum>(2)</enum><text>establish guidelines for avoiding, as a result of penetration testing—</text><subparagraph id="id0F76B22B6471461BBF643D41D575BAFD"><enum>(A)</enum><text>adverse impacts to the operations of the agency;</text></subparagraph><subparagraph id="ida6be95ab476649aaac0092754411b02a"><enum>(B)</enum><text>adverse impacts to operational networks and systems of the agency; and</text></subparagraph><subparagraph id="id5d1879f44ce843f3b6bf9ed98f94b1ee"><enum>(C)</enum><text>inappropriate access to data;</text></subparagraph></paragraph><paragraph id="idb8a14c85788644d59563b84a269d64d9"><enum>(3)</enum><text>require the results of penetration testing to include feedback to improve the cybersecurity of the agency; and</text></paragraph><paragraph id="idbda17987254946f2b3c98de3e23ac7a2"><enum>(4)</enum><text>include mechanisms for providing consistently formatted, and, if applicable, automated and machine-readable, data to the Director and the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph></subsection><subsection id="idfb92cac0b8654421a2203e2c3b8b23be"><enum>(d)</enum><header>Responsibilities of CISA</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall—</text><paragraph id="ideab9043fb5524d03b04ff17181566443"><enum>(1)</enum><text>establish a certification process for the performance of penetration testing by both Federal and non-Federal entities that establishes minimum quality controls for penetration testing;</text></paragraph><paragraph id="id347ff48eb3844bcd80eb9df8cd873182"><enum>(2)</enum><text>develop operational guidance for instituting penetration testing programs at agencies;</text></paragraph><paragraph id="id7f3687cace6d48b9a4873aeec47dbf27"><enum>(3)</enum><text>develop and maintain a centralized capability to offer penetration testing as a service to Federal and non-Federal entities; and</text></paragraph><paragraph id="id282296fa83354c5f82ee3390d1e82bf9"><enum>(4)</enum><text>provide guidance to agencies on the best use of penetration testing resources.</text></paragraph></subsection><subsection id="id5f0ac7ec905341d7bfeb7d1d6cdf25de"><enum>(e)</enum><header>Responsibilities of OMB</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall—</text><paragraph id="idf5a2e290d9014d0db1bf27ac6b42f123"><enum>(1)</enum><text>not less frequently than annually, inventory all Federal penetration testing assets; and</text></paragraph><paragraph id="id22f04cb6f051468fb090514095391b52"><enum>(2)</enum><text>develop and maintain a Federal strategy for the use of penetration testing.</text></paragraph></subsection><subsection id="iddffa1d5f0429410f8daa960d6c4a45c2"><enum>(f)</enum><header>Prioritization of penetration testing resources</header><paragraph id="id5D4AF4BBC52C449293F8DFC3237FDFE5"><enum>(1)</enum><header>In general</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop a framework for prioritizing Federal penetration testing resources among agencies.</text></paragraph><paragraph id="id3beb097384fb42de933c897265fc1053"><enum>(2)</enum><header>Considerations</header><text>In developing the framework under this subsection, the Director shall consider—</text><subparagraph id="ida83833e455804db2b34991cbe2cf7e94"><enum>(A)</enum><text>agency system risk assessments performed under section 3554(a)(1)(A);</text></subparagraph><subparagraph id="idf790b2c4fc84427f9ca77be05c22c2e1"><enum>(B)</enum><text>the Federal risk assessment performed under section 3553(i);</text></subparagraph><subparagraph id="id7854c55c9bd94b2896de35b040887775"><enum>(C)</enum><text>the analysis of Federal incident data performed under section 3597; and</text></subparagraph><subparagraph id="idbdeccff2c1af49dba33bde2e0fb4daf5"><enum>(D)</enum><text>any other information determined appropriate by the Director or the Director of the Cybersecurity and Infrastructure Security Agency.</text></subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id675C63B1E1E34D09A489172657CE9FAF"><enum>(b)</enum><header>Clerical amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding after the item relating to section 3559 the following:</text><quoted-block style="USC" id="id3379934c-13aa-4a9d-a3c4-02694e0bfc23" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc-entry level="section" idref="id4CFA7FCCBE5B4C36A1F7A2B9B130E24E">3559A. Federal penetration testing.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id540a9ff923bd4d7f8ff9f3f17c0656c3"><enum>(c)</enum><header>Penetration testing by the Secretary of Homeland Security</header><text>Section 3553(b) of title 44, United States Code, as amended by section 1705 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/283">Public Law 116–283</external-xref>) and section 101, is further amended—</text><paragraph id="id24ED8EF202A5456D8C95D0B0B9EB7A7D"><enum>(1)</enum><text>in paragraph (8)(B), by striking <quote>and</quote> at the end;</text></paragraph><paragraph id="id320540AD7BCE437DA0CF7FDCD708F4B6"><enum>(2)</enum><text>by redesignating paragraph (9) as paragraph (10); and</text></paragraph><paragraph id="idE579CD002D6E481EB9014A911BCB3D1B"><enum>(3)</enum><text>by inserting after paragraph (8) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id98629B7B416447ECBDC17E7223C4AC7C" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><paragraph id="id9016088c34ec46b495ce05930e9d5ba9"><enum>(9)</enum><text>performing penetration testing with or without advance notice to, or authorization from, agencies, to identify vulnerabilities within Federal information systems; and</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id8E8BC5E043594941B1573F54B420CA0D"><enum>207.</enum><header>Ongoing threat hunting program</header><subsection id="ida06d2a4c2b6e4aba9767cf4c87e42caa"><enum>(a)</enum><header>Threat hunting program</header><paragraph id="ida9a84f9fa11a4990856210abc5f196bc"><enum>(1)</enum><header>In general</header><text>Not later than 540 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.</text></paragraph><paragraph id="id64d4e5b31c514dba8d9a6fb0cdf5ec08"><enum>(2)</enum><header>Plan</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish the program required under paragraph (1) that describes how the Director of the Cybersecurity and Infrastructure Security Agency plans to—</text><subparagraph id="idde14ce01006d4e84835a9aca8ade8693"><enum>(A)</enum><text>determine the method for collecting, storing, accessing, and analyzing appropriate agency data;</text></subparagraph><subparagraph id="idff3b708bd97e460b9f73140822e82eb1"><enum>(B)</enum><text>provide on-premises support to agencies;</text></subparagraph><subparagraph id="id80382ddecbb3462b8baf7d89918b53ca"><enum>(C)</enum><text>staff threat hunting services;</text></subparagraph><subparagraph id="id6fb4023107404442ac0e302d9c8217cd"><enum>(D)</enum><text>allocate available human and financial resources to implement the plan; and</text></subparagraph><subparagraph id="id2f73ca50f5b645c294a6d25a1f8b36ef"><enum>(E)</enum><text>provide input to the heads of agencies on the use of—</text><clause id="id6b3fd9c2993145cabf8363bbb795d2bc"><enum>(i)</enum><text>more stringent standards under section 11331(c)(1) of title 40, United States Code; and</text></clause><clause id="idf0cf48bc664d4487a54bbd16a4d4d1b9"><enum>(ii)</enum><text>additional cybersecurity procedures under section 3554 of title 44, United States Code.</text></clause></subparagraph></paragraph></subsection><subsection id="ida02cc133c69a4b43b453af75e5c4509a" commented="no"><enum>(b)</enum><header>Reports</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall submit to the appropriate congressional committees—</text><paragraph commented="no" id="id788FB1C9B89943909056CA1C3D940A94"><enum>(1)</enum><text>not later than 30 days after the date on which the Director of the Cybersecurity and Infrastructure Security Agency completes the plan required under subsection (a)(2), a report on the plan to provide threat hunting services to agencies;</text></paragraph><paragraph id="id87a5bbf5539843e49c3e686ef53e9bb4"><enum>(2)</enum><text>not less than 30 days before the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services under the program, a report providing any updates to the plan developed under subsection (a)(2); and</text></paragraph><paragraph id="id7209108ef44445c393262b451cd39347"><enum>(3)</enum><text>not later than 1 year after the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services to agencies other than the Cybersecurity and Infrastructure Security Agency, a report describing lessons learned from providing those services.</text></paragraph></subsection></section><section id="idDC48A75DC52C4CD5A59E5BB7106014DF"><enum>208.</enum><header>Codifying vulnerability disclosure programs</header><subsection id="ida9e831816a964d1d8f3a5599226e5821"><enum>(a)</enum><header>In general</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">Chapter 35</external-xref> of title 44 of United States Code is amended by inserting after section 3559A, as added by section 206 of this Act, the following:</text><quoted-block style="USC" display-inline="no-display-inline" id="idBDC52930BFF64E2BAEACD53F67163260" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="id73E48C87C36647B4A04F95E509415EEE"><enum>3559B.</enum><header>Federal vulnerability disclosure programs</header><subsection id="idF4619ED8C32142879B2BE8CEFADD6748"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idDD3F5EEE15894A82B249E929A2A908EF"><enum>(1)</enum><header>Report</header><text>The term <term>report</term> means a vulnerability disclosure made to an agency by a reporter.</text></paragraph><paragraph id="id65100588E07245228653310777CDB346"><enum>(2)</enum><header>Reporter</header><text>The term <term>reporter</term> means an individual that submits a vulnerability report pursuant to the vulnerability disclosure process of an agency.</text></paragraph></subsection><subsection id="id7707323946EF419FAD9C34357A8E136A"><enum>(b)</enum><header>Responsibilities of OMB</header><paragraph id="idA8345CCA9622452B9DCB2596560BBF50"><enum>(1)</enum><header>Limitation on legal action</header><text>The Director, in consultation with the Attorney General, shall issue guidance to agencies to not recommend or pursue legal action against a reporter or an individual that conducts a security research activity that the head of the agency determines—</text><subparagraph id="id0F1301815526421A95AC253E552F14B8"><enum>(A)</enum><text>represents a good faith effort to follow the vulnerability disclosure policy developed under subsection (d)(2) of the agency; and</text></subparagraph><subparagraph id="idC102EE8A4FC34E10BB5B492BCC356C6F"><enum>(B)</enum><text>is authorized under the vulnerability disclosure policy developed under subsection (d)(2) of the agency.</text></subparagraph></paragraph><paragraph id="idC8727FD681184F14BE14EA1BBC3EE40F"><enum>(2)</enum><header>Sharing information with CISA</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance to agencies on sharing relevant information in a consistent, automated, and machine readable manner with the Cybersecurity and Infrastructure Security Agency, including—</text><subparagraph id="id7A4CB0E1F5C74CE1A93C912FBA710C3D"><enum>(A)</enum><text>any valid or credible reports of newly discovered or not publicly known vulnerabilities (including misconfigurations) on an agency information system that uses commercial software or services;</text></subparagraph><subparagraph id="idC8A8AB32D12D415B83FAB8BEBC5091E2"><enum>(B)</enum><text>information relating to vulnerability disclosure, coordination, or remediation activities of an agency, particularly as those activities relate to outside organizations—</text><clause id="id432CE107EDCE4474AE609C31B7C2C8EC"><enum>(i)</enum><text>with which the head of the agency believes the Director of the Cybersecurity and Infrastructure Security can assist; or</text></clause><clause id="idB1FB6E44BF784AE38F00F70E11712803"><enum>(ii)</enum><text>about which the head of the agency believes the Director of the Cybersecurity and Infrastructure Security should know; and</text></clause></subparagraph><subparagraph id="id5AB098D9EEAE495D9CDBF001153701EB"><enum>(C)</enum><text>any other information with respect to which the head of the agency determines helpful or necessary to involve the Cybersecurity and Infrastructure Security Agency.</text></subparagraph></paragraph><paragraph id="idE347AC539FEA49559CD9DCCCBB2AA8FF"><enum>(3)</enum><header>Agency vulnerability disclosure policies</header><subparagraph id="id752F14B4DF724BEA8F9BB480AAE2BA18"><enum>(A)</enum><header>In general</header><text>The Director shall issue guidance to agencies on the required minimum scope of agency systems covered by the vulnerability disclosure policy of an agency required under subsection (d)(2).</text></subparagraph><subparagraph id="id2AE28D37F2814229A5FA9568DEC5C5C6"><enum>(B)</enum><header>Deadline</header><text>Not later than 2 years after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, the Director shall update the guidance issued under subparagraph (A) to require that every agency system that is connected to the internet is covered by the vulnerability disclosure policy of the agency. </text></subparagraph></paragraph></subsection><subsection id="id4B390149F4BE4CE5AE556959905E8F9D"><enum>(c)</enum><header>Responsibilities of CISA</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall—</text><paragraph id="id6FAF89B1B5BA4BD0B5BE18A24F8B54EF"><enum>(1)</enum><text>provide support to agencies with respect to the implementation of the requirements of this section;</text></paragraph><paragraph id="idE859C6395A714571812BD6BB7356FAE0"><enum>(2)</enum><text>develop tools, processes, and other mechanisms determined appropriate to offer agencies capabilities to implement the requirements of this section; and</text></paragraph><paragraph id="id850054EA2BCB48359580F9F13E20AEDF"><enum>(3)</enum><text>upon a request by an agency, assist the agency in the disclosure to vendors of newly identified vulnerabilities in vendor products and services.</text></paragraph></subsection><subsection id="id3A73C75344C2494CA3D12E719BD3F94A"><enum>(d)</enum><header>Responsibilities of agencies</header><paragraph id="idC3EC059D19164B26AAE23A30C9F13C47"><enum>(1)</enum><header>Public information</header><text>The head of each agency shall make publicly available, with respect to each internet domain under the control of the agency that is not a national security system—</text><subparagraph id="id09CDF60151BB4D328DB29748D6858ED2"><enum>(A)</enum><text>an appropriate security contact; and</text></subparagraph><subparagraph id="id48DA4BE2B0FC4DF896955E2256E87AC1"><enum>(B)</enum><text>the component of the agency that is responsible for the internet accessible services offered at the domain.</text></subparagraph></paragraph><paragraph id="id85AB17CB31B0475797BDCA949D787B46"><enum>(2)</enum><header>Vulnerability disclosure policy</header><text>The head of each agency shall develop and make publicly available a vulnerability disclosure policy for the agency, which shall—</text><subparagraph id="id130D2911B23A45BAA07BD20E5CCB7DDC"><enum>(A)</enum><text>describe—</text><clause id="id410ECB61921F40119F04DA19D7E1E3EB"><enum>(i)</enum><text>the scope of the systems of the agency included in the vulnerability disclosure policy;</text></clause><clause id="idA8B872398A5A4E0EA05C43FC39B71577"><enum>(ii)</enum><text>the type of information system testing that is authorized by the agency;</text></clause><clause id="id3308C88F09014EBA98E251082E74EF69"><enum>(iii)</enum><text>the type of information system testing that is not authorized by the agency; and</text></clause><clause id="id900AF30FA359419DB1AA82145C4BD072"><enum>(iv)</enum><text>the disclosure policy of the agency for sensitive information;</text></clause></subparagraph><subparagraph id="id1A321008D75A4ED68368DA3F67034B28"><enum>(B)</enum><text>include a provision that authorizes the anonymous submission of a vulnerability by a reporter;</text></subparagraph><subparagraph id="id8E17F502D50A4160B142343D171B4FA2"><enum>(C)</enum><text>with respect to a report to an agency, describe—</text><clause id="idE741CA3C8B18432C946D0E264ECFC631"><enum>(i)</enum><text>how the reporter should submit the report; and</text></clause><clause id="id62774A8D2DAE471CB71317EEA90F37BC"><enum>(ii)</enum><text>if the report is not anonymous under subparagraph (B), when the reporter should anticipate an acknowledgment of receipt of the report by the agency; and</text></clause></subparagraph><subparagraph id="id96DECAC0E9B04D5EBA01789926E2AE0C"><enum>(D)</enum><text>include any other relevant information.</text></subparagraph></paragraph><paragraph id="idA68C8342EBF843269772269A7934C148"><enum>(3)</enum><header>Identified vulnerabilities</header><text>The head of each agency shall incorporate any vulnerabilities reported under paragraph (2) into the vulnerability management process of the agency in order to track and remediate the vulnerability.</text></paragraph></subsection><subsection id="id9009521A44D948C68840F5B2AAA9EF3F"><enum>(e)</enum><header>Paperwork Reduction Act exemption</header><text>The requirements of subchapter I (commonly known as the <quote>Paperwork Reduction Act</quote>) shall not apply to a vulnerability disclosure program established under this section.</text></subsection><subsection id="idB10D4C3D5DAF48CCAB81D9328C22EACB"><enum>(f)</enum><header>Congressional reporting</header><text>Not later than 90 days after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, and annually thereafter for a 3-year period, the Director shall provide to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name> and the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name> a briefing on the status of the use of vulnerability disclosure policies under this section at agencies, including, with respect to the guidance issued under subsection (b)(3), an identification of the agencies that are compliant and not compliant.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id0761380566C64B609CD78C8CB5C2A75E"><enum>(b)</enum><header>Clerical amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding after the item relating to section 3559A the following:</text><quoted-block style="USC" id="idFF5AE354E2EC4C8EAC2A4A1FF0B1ACC5" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc-entry level="section" idref="id4CFA7FCCBE5B4C36A1F7A2B9B130E24E">3559B. Federal vulnerability disclosure programs.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section><section id="id909456EA06AE4DCAA452E4BD1F8ADD39"><enum>209.</enum><header>Implementing presumption of compromise and zero trust architectures</header><subsection id="id46a5327495dd41d5a6adca1b969ffc88"><enum>(a)</enum><header>Recommendations</header><text>Not later than 60 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director of the National Institute of Standards and Technology, shall develop recommendations to increase the internal defenses of agency systems to—</text><paragraph id="idd1c69452729342f1b7b66e3fb3c33fab"><enum>(1)</enum><text>limit the ability of entities that cause incidents to move laterally through or between agency systems;</text></paragraph><paragraph id="id24f1757116ec48b19b608e40748f4d73"><enum>(2)</enum><text>identify incidents more quickly;</text></paragraph><paragraph id="idcf72dc9e7ace4e17b9645a657962b0d4"><enum>(3)</enum><text>isolate and remove unauthorized entities from agency systems more quickly;</text></paragraph><paragraph id="id4BABA3043D1142628E97D9815268950C"><enum>(4)</enum><text>implement zero trust architecture; and</text></paragraph><paragraph id="ida4367ef3174845c68d4e48d11ee00e1d"><enum>(5)</enum><text>otherwise increase the resource costs for entities that cause incidents; and</text></paragraph></subsection><subsection id="id058873eb125549b685b19d54037611cc"><enum>(b)</enum><header>OMB Guidance</header><text>Not later than 180 days after the date on which the recommendations under subsection (a) are completed, the Director shall issue guidance to agencies that requires the implementation of the recommendations.</text></subsection><subsection id="id5a0abf8683304b8c82e097df0715d3e4"><enum>(c)</enum><header>Agency implementation plans</header><text>Not later than 60 days after the date on which the Director issues guidance under subsection (b), the head of each agency shall submit to the Director a plan to implement zero trust architecture that includes—</text><paragraph id="id248ABF443B554398A3A96C6064D1A593"><enum>(1)</enum><text>a description of any steps the agency has completed;</text></paragraph><paragraph id="id819C77E597334E29AD5AA30F6F51958B"><enum>(2)</enum><text>an identification of activities that will have the most immediate security impact; and</text></paragraph><paragraph id="idC3CD171DF037499DA027531347E61AEE"><enum>(3)</enum><text>a schedule to implement the plan.</text></paragraph></subsection><subsection id="id8E3805CC460D448EB5AFCE479FF95823"><enum>(d)</enum><header>Report and briefing</header><text>Not later than 90 days after the date on which the Director issues guidance required under subsection (b), the Director shall provide a briefing to the appropriate congressional committees on the guidance and the agency implementation plans submitted under subsection (c).</text></subsection></section><section id="idf7af9dbfed7549b6a1fba7943bfaee3b"><enum>210.</enum><header>Automation reports</header><subsection id="id9abf4629768d4480a88759635a329337"><enum>(a)</enum><header>OMB Report</header><text>Not later than 180 days after the date of enactment of this Act, the Director shall submit to the appropriate congressional committees a report on the use of automation under paragraphs (1), (5)(C) and (7)(B) of section 3554(b) of title 44, United States Code. </text></subsection><subsection id="id54725f7ee78045ae8b1c99327f122a66"><enum>(b)</enum><header>GAO Report</header><text>Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall perform a study on the use of automation and machine readable data across the Federal Government for cybersecurity purposes, including the automated updating of cybersecurity tools, sensors, or processes by agencies. </text></subsection></section><section id="idE3E31296AFAE41B39A2EBFC2B794E119"><enum>211.</enum><header>Extension of Federal Acquisition Security Council</header><text display-inline="no-display-inline">Section 1328 of title 41, United States Code, is amended by striking <quote>the date</quote> and all that follows and inserting <quote>December 31, 2026.</quote>.</text></section></title><title style="OLC" id="id0D79C2148CBF4AA398F0D242747F4BC7" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>III</enum><header>Pilot programs to enhance Federal cybersecurity</header><section id="id7FB4254ED7724E2D9AEF65C9840619C2"><enum>301.</enum><header>Continuous independent FISMA evaluation pilot</header><subsection id="id5b55d447bf94460ebe929dc3124d6b78"><enum>(a)</enum><header>In general</header><text>Not later than 2 years after the date of enactment of this Act, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall establish a pilot program to perform continual agency auditing of the standards promulgated under section 11331 of title 40, United States Code.</text></subsection><subsection id="idCE2FA19FC0CF4C24950BA4A059492694"><enum>(b)</enum><header>Purpose</header><paragraph id="idDCA6527247EA42428FE69450971ED43F"><enum>(1)</enum><header>In general</header><text>The purpose of the pilot program established under subsection (a) shall be to develop the capability to continuously audit agency cybersecurity postures, rather than performing an annual audit.</text></paragraph><paragraph id="id4B47646207234188BCBFBA2F6C7FE8D8"><enum>(2)</enum><header>Use of information</header><text>It is the sense of Congress that information relating to agency cybersecurity postures should be used, on an ongoing basis, to increase agency understanding of cybersecurity risk and improve agency cybersecurity.</text></paragraph></subsection><subsection id="id41a4f711e92345279e66a9b6132bd861"><enum>(c)</enum><header>Participating agencies</header><paragraph id="id1D6C56C7F2614B9DA1637724A176BEA4"><enum>(1)</enum><header>In general</header><text>The Director, in coordination with the Council of the Inspectors General on Integrity and Efficiency and in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall identify not less than 1 agency and the Inspector General of each identified agency to participate in the pilot program established under subsection (a).</text></paragraph><paragraph id="id91d98b3ccba8493681221eb9553b71ff"><enum>(2)</enum><header>Capabilities of agency</header><text>An agency selected under paragraph (1) shall have advanced cybersecurity capabilities, including the capability to implement verification specifications and other automated and machine-readable means of sharing information.</text></paragraph><paragraph id="idb612622a8bfd49bf959157c626f4bc00"><enum>(3)</enum><header>Capabilities of Inspector General</header><text>The Inspector General of an agency selected under paragraph (1) shall have advanced cybersecurity capabilities, including the ability—</text><subparagraph id="idb9caace9b8f54cb2a0eaf31fc3e2ee67"><enum>(A)</enum><text>to perform real-time or almost real-time and continuous analysis of the use of verification specifications by the agency to assess compliance with standards promulgated under section 11331 of title 40, United States Code; and</text></subparagraph><subparagraph id="idfc2f654e585d42b5befeef1f6b6920da"><enum>(B)</enum><text>to assess the impact and deployment of additional cybersecurity procedures.</text></subparagraph></paragraph></subsection><subsection id="id3c336995ea44405fa9d11b66d52e2a3b"><enum>(d)</enum><header>Duties</header><text>The Director, in coordination with the Council of the Inspectors General on Integrity and Efficiency, the Director of the Cybersecurity and Infrastructure Security Agency, and the head of each agency participating in the pilot program under subsection (c), shall develop processes and procedures to perform a continuous independent evaluation of—</text><paragraph id="id86c74a4318de42b4ba46392227215f03"><enum>(1)</enum><text>the compliance of the agency with—</text><subparagraph id="idcbdc536b8f194f44b76950d1da44ec19"><enum>(A)</enum><text>the standards promulgated under section 11331 of title 40, United States Code, using verification specifications to the greatest extent practicable; and</text></subparagraph><subparagraph id="ide316ca22d1cc4cfb95979d0028881f69"><enum>(B)</enum><text>any additional cybersecurity procedures implemented by the agency as a result of the evaluation performed under section 3554(a)(1)(F) of title 44, United States Code; and</text></subparagraph></paragraph><paragraph id="ide48371c7f7aa46a8a8d134795d766643"><enum>(2)</enum><text>the overall cybersecurity posture of the agency, which may include an evaluation of—</text><subparagraph id="id7b03166dab514253a7c0e498a18c45d2"><enum>(A)</enum><text>the status of cybersecurity remedial actions of the agency;</text></subparagraph><subparagraph id="id5e767507ea8c42a59756d150707686e4"><enum>(B)</enum><text>any vulnerability information relating to agency systems that is known to the agency;</text></subparagraph><subparagraph id="id7f3ccedba2a142e5a5299f6d4fc56b1d"><enum>(C)</enum><text>incident information of the agency;</text></subparagraph><subparagraph id="idff94487928f249b28c11e4a35218cd69"><enum>(D)</enum><text>penetration testing performed by an external entity under section 3559A of title 44, United States Code;</text></subparagraph><subparagraph id="idcf8c34932f7b4f7884dac85a057bc066"><enum>(E)</enum><text>information from the vulnerability disclosure program information established under section 3559B of title 44, United States Code;</text></subparagraph><subparagraph id="id2c707135d6224012adf1c60d10d6e4ef"><enum>(F)</enum><text>agency threat hunting results; and</text></subparagraph><subparagraph id="id2dc1c84297e1475b84edf24b17e3f5d8"><enum>(G)</enum><text>any other information determined relevant by the Director.</text></subparagraph></paragraph></subsection><subsection id="id7145622f1cab4504bcf1efa6df099707"><enum>(e)</enum><header>Independent evaluation waiver</header><text>With respect to an agency that participates in the pilot program under subsection (a) during any year other than the first year during which the pilot program is conducted, the Director, with the concurrence of the Director of the Cybersecurity and Infrastructure Security Agency, may waive any requirement of the agency with respect to the annual independent evaluation under section 3555 of title 44, United States Code.</text></subsection><subsection id="id137fea41ff91468a925ba923f9bcb894"><enum>(f)</enum><header>Duration</header><text>The pilot program established under this section—</text><paragraph id="idc3dddf6854d24103b00a36a33334d574"><enum>(1)</enum><text>shall be performed over a period of not less than 2 years at each agency that participates in the pilot program under subsection (c), unless the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the Council of the Inspectors General on Integrity and Efficiency, determines that continuing the pilot program would reduce the cybersecurity of the agency; and</text></paragraph><paragraph id="id7bb37da5502f4421950114278fbf2e6e"><enum>(2)</enum><text>may be extended by the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the Council of the Inspectors General on Integrity and Efficiency, if the Director makes the determination described in paragraph (1).</text></paragraph></subsection><subsection id="id99e69c5388334a089d417e93f478064d"><enum>(g)</enum><header>Reports</header><paragraph id="id02ecd991b319428b963901b976646070"><enum>(1)</enum><header>Pilot program plan</header><text>Before identifying any agencies to participate in the pilot program under subsection (c), the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the Council of the Inspectors General on Integrity and Efficiency, shall submit to the appropriate congressional committees a plan for the pilot program that outlines selection criteria and preliminary plans to implement the pilot program.</text></paragraph><paragraph id="id8af9253bf7d346699570aef1e3f77df2"><enum>(2)</enum><header>Briefing</header><text>Before commencing a continuous independent evaluation of any agency under the pilot program established under subsection (a), the Director shall provide to the appropriate congressional committees a briefing on—</text><subparagraph id="id9DAC718DDC7541B7982AF1737936DC1F"><enum>(A)</enum><text>the selection of agencies to participate in the pilot program; and</text></subparagraph><subparagraph id="id9BAF1C49BF4F4FB596BD2E5B23FF6834"><enum>(B)</enum><text>processes and procedures to perform a continuous independent evaluation of agencies.</text></subparagraph></paragraph><paragraph id="id51469715c11647cdaa44466b599fed2d"><enum>(3)</enum><header>Pilot results</header><text>Not later than 60 days after the final day of each year during which an agency participates in the pilot program established under subsection (a), the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the Council of the Inspectors General on Integrity and Efficiency, shall submit to the appropriate congressional committees a report on the results of the pilot program for each agency that participates in the pilot program during that year.</text></paragraph></subsection></section><section id="id27A831E42EC1493DAE21F02361F75446"><enum>302.</enum><header>Active cyber defensive pilot</header><subsection id="id04a6b9175b944b3da55cdd4d61816f34"><enum>(a)</enum><header>Definition</header><text>In this section, the term <term>active defense technique</term>—</text><paragraph id="id5C90202E9DC244C68A656CE18D0658ED"><enum>(1)</enum><text>means an action taken on the systems of an entity to increase the security of information on the network of an agency by misleading an adversary; and</text></paragraph><paragraph id="id19A014DD2A944DD791188D5FFA53362C"><enum>(2)</enum><text>includes a honeypot, deception, or purposefully feeding false or misleading data to an adversary when the adversary is on the systems of the entity.</text></paragraph></subsection><subsection id="idd6d17f44ed844628b332b410d55a6cc5"><enum>(b)</enum><header>Study</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall perform a study on the use of active defense techniques to enhance the security of agencies, which shall include—</text><paragraph id="id47c3104227bf47dea27fcf50a31b2338"><enum>(1)</enum><text>a review of legal restrictions on the use of different active cyber defense techniques on Federal networks;</text></paragraph><paragraph id="id1f53858c8a5b4fbeabadfa8da7f7804d"><enum>(2)</enum><text>an evaluation of—</text><subparagraph id="id715B4D19BEFA4B74BF52FFF2EA1D0BAD"><enum>(A)</enum><text>the efficacy of a selection of active defense techniques determined by the Director of the Cybersecurity and Infrastructure Security Agency; and</text></subparagraph><subparagraph id="idF9250C6B5E8145909476873C676CF2A9"><enum>(B)</enum><text>factors that impact the efficacy of the active defense techniques evaluated under subparagraph (A); and</text></subparagraph></paragraph><paragraph id="id254787c848e94648b4b2355cf419c514"><enum>(3)</enum><text>the development of a framework for the use of different active defense techniques by agencies.</text></paragraph></subsection><subsection id="id18924ee2156c4c2fb6bf23bcdefc87f2"><enum>(c)</enum><header>Pilot program</header><text>Not later than 180 days after the date of enactment of this Act, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall establish a pilot program at not less than 2 agencies to implement, and assess the effectiveness of, not less than 1 active cyber defense technique.</text></subsection><subsection id="idA77EED5421E9403E9B3C5241F7EDF151"><enum>(d)</enum><header>Purpose</header><text>The purpose of the pilot program established under subsection (c) shall be to—</text><paragraph id="id8A447B006EF143D5AEEB776782466752"><enum>(1)</enum><text>identify any statutory or policy limitations on using active defense techniques;</text></paragraph><paragraph id="idBC9A723354694041AFDF15DFDD382846"><enum>(2)</enum><text>understand the efficacy of using active defense techniques; and</text></paragraph><paragraph id="id0251D7A18B81483D8F40D4D282B688A2" commented="no" display-inline="no-display-inline"><enum>(3)</enum><text>implement the use of effective techniques to improve agency systems. </text></paragraph></subsection><subsection id="id390a658ae7564b67a03d81af71b47fc4"><enum>(e)</enum><header>Plan</header><text>Not later than 360 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in coordination with the Director, shall develop a plan to offer any active defense technique determined to be successful during the pilot program established under subsection (c) as a shared service to other agencies.</text></subsection><subsection id="idE4A3DF6AD7F74038898CF4E0FDED6B6A"><enum>(f)</enum><header>Reports</header><text>Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall—</text><paragraph id="ide94dd0d3021949469672ae2870a72c32"><enum>(1)</enum><text>provide to the appropriate congressional committees a briefing on—</text><subparagraph id="id928FD979424444CA9586CFBB2B514E6B"><enum>(A)</enum><text>the results of the study performed under subsection (b); and</text></subparagraph><subparagraph id="id8E2359A865584FF185F9F0FC34D14817"><enum>(B)</enum><text>the agencies selected to participate in the pilot program established under subsection (c);</text></subparagraph></paragraph><paragraph id="id264be92d8aca47318d58ff95a17d2489"><enum>(2)</enum><text>submit to the appropriate congressional committees a report on the results of the pilot program established under subsection (c), including any recommendations developed from the results of the pilot program; and</text></paragraph><paragraph id="id493f31d8bfd9429f925990dc3e82bfe0"><enum>(3)</enum><text>submit to the appropriate congressional committees a copy of the plan developed under subsection (e).</text></paragraph></subsection><subsection id="id0D10BADCB6924F959C00C07E843A3CEA"><enum>(g)</enum><header>Sunset</header><paragraph id="id0B3F6BFD96EE4D15AA9ABD41CA93A170"><enum>(1)</enum><header>In general</header><text>The requirements of this section shall terminate on the date that is 3 years after the date of enactment of this Act.</text></paragraph><paragraph id="idE48FF9BDCDCE4901ABC21E541D93B97A"><enum>(2)</enum><header>Authority to continue use of techniques</header><text>Notwithstanding paragraph (1), after the date described in paragraph (1), the Director of the Cybersecurity and Infrastructure Security Agency may continue to offer any active defense technique determined to be successful during the pilot program established under subsection (c) as a shared service to agencies.</text></paragraph></subsection></section><section id="id6c32b416e29b4d86834d526563796b7f"><enum>303.</enum><header>Security operations center as a service pilot</header><subsection id="idcafa84b0065342e2b3a7749d3a13950b"><enum>(a)</enum><header>Purpose</header><text>The purpose of this section is for the Cybersecurity and Infrastructure Security Agency to run a security operation center on behalf of another agency, alleviating the need to duplicate this function at every agency, and empowering a greater centralized cybersecurity capability. </text></subsection><subsection id="idb31623dba486430e97c250be7d5277e6"><enum>(b)</enum><header>Plan</header><text>Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish a centralized Federal security operations center shared service offering within the Cybersecurity and Infrastructure Security Agency.</text></subsection><subsection id="id1d906f6e3bb745e489f5948f33866d14"><enum>(c)</enum><header>Contents</header><text>The plan required under subsection (b) shall include considerations for—</text><paragraph id="idd74dca5145bb4245a6661039d5793de5"><enum>(1)</enum><text>collecting, organizing, and analyzing agency information system data in real time;</text></paragraph><paragraph id="idf15fc3324e5945d59e54fec2e12d9986"><enum>(2)</enum><text>staffing and resources; and</text></paragraph><paragraph id="id63d16c421d3e472b9e315554edca7581"><enum>(3)</enum><text>appropriate interagency agreements, concepts of operations, and governance plans.</text></paragraph></subsection><subsection id="id80630534ebfa49698a61c5502a50cf43"><enum>(d)</enum><header>Pilot program</header><paragraph id="id72945c2058e947a0bf692ed8259517d7"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date on which the plan required under subsection (b) is developed, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, shall enter into a 1-year agreement with not less than 2 agencies to offer a security operations center as a shared service.</text></paragraph><paragraph id="ida9fc330f5f6b4183a0d9bc2e958b254c"><enum>(2)</enum><header>Additional agreements</header><text>After the date on which the briefing required under subsection (e)(1) is provided, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, may enter into additional 1-year agreements described in paragraph (1) with agencies.</text></paragraph></subsection><subsection id="id564e0c7fce664d499799118d6eee660e"><enum>(e)</enum><header>Briefing and report</header><paragraph id="id421f0d29f15944e3a5c9c0172b9412e9"><enum>(1)</enum><header>Briefing</header><text>Not later than 260 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Oversight and Reform of the House of Representatives a briefing on the parameters of any 1-year agreements entered into under subsection (d)(1).</text></paragraph><paragraph id="id8db4db6d6dfb4a9dbdfea6e6efe5afd3"><enum>(2)</enum><header>Report</header><text>Not later than 90 days after the date on which the first 1-year agreement entered into under subsection (d) expires, the Director of the Cybersecurity and Infrastructure Security Agency shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Oversight and Reform of the House of Representatives a report on—</text><subparagraph id="idecb4fc0afa904da3a426760eec40b81b"><enum>(A)</enum><text>the agreement; and</text></subparagraph><subparagraph id="idfdb128c36d7d45dab99d92c4e958a691"><enum>(B)</enum><text>any additional agreements entered into with agencies under subsection (d). </text></subparagraph></paragraph></subsection></section></title></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section id="id2f20a8f8-6cc0-4151-b8e7-c93c11861007" section-type="section-one" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Information Security Modernization Act of 2021</short-title></quote>.</text></section><section id="idede8a4ad-3405-42e8-b280-21320a7a128f" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>2.</enum><header>Table of contents</header><text display-inline="no-display-inline">The table of contents for this Act is as follows:</text><toc changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="section" idref="S1">Sec. 1. Short title.</toc-entry><toc-entry level="section" idref="id3D5D7FF2CAF9466C9530BEE12C9B04BD">Sec. 2. Table of contents.</toc-entry><toc-entry level="section" idref="idA6F5F6D48B854DC3B8051A1A3206E772">Sec. 3. Definitions.</toc-entry><toc-entry level="title" idref="idA32CA59DB4584307AA1FB91684E44150">TITLE I—Updates to FISMA</toc-entry><toc-entry level="section" idref="id744FB6C47AD74AE19A83A0829E153575">Sec. 101. Title 44 amendments.</toc-entry><toc-entry level="section" idref="id3C33B291D5D6406890C11DCBA266F3DD">Sec. 102. Amendments to subtitle III of title 40.</toc-entry><toc-entry level="section" idref="id8ccc627da4bd46e0bdd48489ba7c6485">Sec. 103. Actions to enhance Federal incident response.</toc-entry><toc-entry level="section" idref="idFD13785A520E4503ACADB2CDC0C27474">Sec. 104. Additional guidance to agencies on FISMA updates.</toc-entry><toc-entry level="section" idref="id02714F2B4ED54D0482D6E01336B563DB">Sec. 105. Agency requirements to notify private sector entities impacted by incidents.</toc-entry><toc-entry level="title" idref="idDFED287744094E38B44FBB2D9BE4BD08">TITLE II—Improving Federal cybersecurity</toc-entry><toc-entry level="section" idref="id446F8C8CA5B84DAE8E829DC5579DDD53">Sec. 201. Mobile security standards.</toc-entry><toc-entry level="section" idref="idb525875190584d70b0d6d272d5fba18b">Sec. 202. Data and logging retention for incident response.</toc-entry><toc-entry level="section" idref="id88e7b24239424c1b998e8f9625612584">Sec. 203. CISA agency advisors.</toc-entry><toc-entry level="section" idref="idD88B1A0B7F3B453E823C7504B69891F8">Sec. 204. Federal penetration testing policy.</toc-entry><toc-entry level="section" idref="id8E8BC5E043594941B1573F54B420CA0D">Sec. 205. Ongoing threat hunting program.</toc-entry><toc-entry level="section" idref="idDC48A75DC52C4CD5A59E5BB7106014DF">Sec. 206. Codifying vulnerability disclosure programs.</toc-entry><toc-entry level="section" idref="ide5684d3fad7e4f56b75dba6cd0e97ffb">Sec. 207. Implementing presumption of compromise and least privilege principles.</toc-entry><toc-entry level="section" idref="id8b0e41d840ae4395902d3df5effa3f05">Sec. 208. Automation reports.</toc-entry><toc-entry level="section" idref="ida9af080b73ed477baca48a97214a35aa">Sec. 209. Extension of Federal acquisition security council.</toc-entry><toc-entry level="section" idref="ida81471996a584d75940dabe4f8de9e29">Sec. 210. Council of the Inspectors General on Integrity and Efficiency dashboard.</toc-entry><toc-entry level="title" idref="idBA76D8C1347D4082B6AD3C5262A370EC">TITLE III—Risk-based budget model</toc-entry><toc-entry level="section" idref="id61d6ec96e759421ca9949058bbc78dd6">Sec. 301. Definitions.</toc-entry><toc-entry level="section" idref="id8425fbd074984e3196cb527331f4167c">Sec. 302. Establishment of risk-based budget model.</toc-entry><toc-entry level="title" idref="id0D79C2148CBF4AA398F0D242747F4BC7">TITLE IV—Pilot programs to enhance Federal cybersecurity</toc-entry><toc-entry level="section" idref="id27A831E42EC1493DAE21F02361F75446">Sec. 401. Active cyber defensive study.</toc-entry><toc-entry level="section" idref="id6c32b416e29b4d86834d526563796b7f">Sec. 402. Security operations center as a service pilot.</toc-entry></toc></section><section id="id710e9d81-8ef9-4d46-91ee-b774ebc67fd9" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act, unless otherwise specified:</text><paragraph id="id16ba3ca9-3f0e-4455-b1c6-e234f0d1175b"><enum>(1)</enum><header>Additional cybersecurity procedure</header><text>The term <term>additional cybersecurity procedure</term> has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act.</text></paragraph><paragraph id="id87eef4b8-666e-47cc-b991-2d16eab04f66"><enum>(2)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="id38d4421a-5ec3-4a44-9ee5-6dcafa2da734"><enum>(3)</enum><header>Appropriate congressional committees</header><text display-inline="yes-display-inline">The term <term>appropriate congressional committees</term> means—</text><subparagraph id="idcb3a498c-96aa-42b5-970e-329457782fad"><enum>(A)</enum><text display-inline="yes-display-inline">the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name>;</text></subparagraph><subparagraph id="id0deb68d6-0c21-405f-a4c9-13034b08a056"><enum>(B)</enum><text>the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name>; and</text></subparagraph><subparagraph id="id5b351855-9115-45cf-b174-b454d2f526b3"><enum>(C)</enum><text>the <committee-name committee-id="">Committee on Homeland Security of the House of Representatives.</committee-name></text></subparagraph></paragraph><paragraph id="id9531ddcd-cca7-44cb-8bc6-67b6544a5a9b"><enum>(4)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office of Management and Budget.</text></paragraph><paragraph id="id1900abcc-46d7-45ab-a640-410c1ff8f904"><enum>(5)</enum><header>Incident</header><text>The term <term>incident</term> has the meaning given the term in section 3552(b) of title 44, United States Code.</text></paragraph><paragraph id="idc851705fbcd14888a5eb251eeba306dd"><enum>(6)</enum><header>National security system</header><text>The term <term>national security system</term> has the meaning given the term in section 3552(b) of title 44, United States Code. </text></paragraph><paragraph id="idf5e438d8-9640-420b-b87e-f7cdf9384357"><enum>(7)</enum><header>Penetration test</header><text>The term <term>penetration test</term> has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act.</text></paragraph><paragraph id="ideacda231-60ac-4bb2-b9eb-9963a104ecbf"><enum>(8)</enum><header>Threat hunting</header><text>The term <term>threat hunting</term> means proactively and iteratively searching for threats to systems that evade detection by automated threat detection systems.</text></paragraph></section><title id="ide69037cb-8e48-4917-84e6-81872f245ae6" style="OLC" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>I</enum><header>Updates to FISMA</header><section id="ideff19cb6-49ee-47f2-bdd8-88c90da12203"><enum>101.</enum><header>Title 44 amendments</header><subsection id="idee08cc1a-2405-4186-877c-8b623dd159a6"><enum>(a)</enum><header>Subchapter I amendments</header><text display-inline="yes-display-inline">Subchapter I of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended—</text><paragraph id="idbb942b39-bea9-46ed-a7a0-1c05e661f198"><enum>(1)</enum><text>in section 3504—</text><subparagraph id="id941144cf01d5490b9acde529b9afede3"><enum>(A)</enum><text>in subsection (a)(1)(B)—</text><clause id="id96E0F96D76274242AA2A033F48DCBBFA"><enum>(i)</enum><text>by striking clause (v) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id5F132B7059DE458EB5FE4094E9C2C3C1" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id0441E298BC9F4550B88415A8FD86B295" indent="up1"><enum>(v)</enum><text>confidentiality, disclosure, and sharing of information;</text></clause><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id29fd9906057b4060a69be12e3c7c63f4"><enum>(ii)</enum><text>by redesignating clause (vi) as clause (vii); and</text></clause><clause id="id1a8de0b428d148a693d24fb51614047f"><enum>(iii)</enum><text>by inserting after clause (v) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3d62f96123894b8ca568f46757d4c7da" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="ide85a255fea4744dcb7b9ace2971827fd" indent="up1"><enum>(vi)</enum><text>in consultation with the National Cyber Director and the Director of the Cybersecurity and Infrastructure Security Agency, security of information; and</text></clause><after-quoted-block>;</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="ide0a87a96096c462d90e7ea21b47e9315"><enum>(B)</enum><text>in subsection (g), by striking paragraph (1) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id98c72362c5f04c1fae22861b229fee2a" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id1a01cb563b3b469f8773fef9394294f7"><enum>(1)</enum><text>with respect to information collected or maintained by or for agencies—</text><subparagraph id="id287d2b1c48f34bfb826d1aa77d76e03d"><enum>(A)</enum><text>develop and oversee the implementation of policies, principles, standards, and guidelines on privacy, confidentiality, disclosure, and sharing of the information; and</text></subparagraph><subparagraph id="idfc19f3ed30d34436a81ebb6f4b2bb18d"><enum>(B)</enum><text>in consultation with the National Cyber Director and the Director of the Cybersecurity and Infrastructure Security Agency, develop and oversee policies, principles, standards, and guidelines on security of the information; and</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="id3a1e6b50-b31f-4a82-9d2c-86fd9e7c67bf"><enum>(C)</enum><text>in subsection (h)(1)—</text><clause id="idfe08e249-c6c8-4f8e-b4ab-c860d084a524"><enum>(i)</enum><text>in the matter preceding subparagraph (A)—</text><subclause id="id21cdea69-c7ec-4a0c-a2b5-57ad7286ed12"><enum>(I)</enum><text>by inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director,</quote> before <quote>the Director</quote>; and</text></subclause><subclause id="idd6d2fccb-afbf-4799-a695-e2aec2ff19fd"><enum>(II)</enum><text>by inserting a comma before <quote>and the Administrator</quote>; and</text></subclause></clause><clause id="id00275777-50d2-44fa-b5fd-5620ac69d632"><enum>(ii)</enum><text>in subparagraph (A), by inserting <quote>security and</quote> after <quote>information technology</quote>;</text></clause></subparagraph></paragraph><paragraph id="id71552599-d869-482b-aa6c-877be713add8"><enum>(2)</enum><text>in section 3505—</text><subparagraph id="ide540a6ed-33ee-43e9-8a3f-dfcb83138887"><enum>(A)</enum><text>in paragraph (3) of the first subsection designated as subsection (c)—</text><clause id="id172b67f3-a57e-4331-a877-58fb9188fdcf"><enum>(i)</enum><text>in subparagraph (B)—</text><subclause id="id0b26b92e69f64566af6605a938ee7b3b"><enum>(I)</enum><text>by inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, and</quote> before <quote>the Comptroller General</quote>; and </text></subclause><subclause id="id354a7bb4-b475-4a49-9238-cb95303ce4f8"><enum>(II)</enum><text>by striking <quote>and</quote> at the end;</text></subclause></clause><clause id="idf16942ea-0a9f-4e4f-b761-d8f1d0786c7e"><enum>(ii)</enum><text>in subparagraph (C)(v), by striking the period at the end and inserting <quote>; and</quote>; and</text></clause><clause id="id1114d1d0-db24-4f35-ab1f-51effaa0a12d"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="ide91d8496-77f1-4651-b17b-4f6543c1462c" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="idd942a3ed-5f66-4081-b89f-bc35e0bf7d14" indent="up1"><enum>(D)</enum><text>maintained on a continual basis through the use of automation, machine-readable data, and scanning.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id93af2417-f6c7-4dff-8faa-24b4f1b0f8f5"><enum>(B)</enum><text>by striking the second subsection designated as subsection (c);</text></subparagraph></paragraph><paragraph id="idda4cae17-cd14-4b97-892f-a99d4a415d9b"><enum>(3)</enum><text>in section 3506—</text><subparagraph id="iddbe1a031-2fc0-4d66-b8e0-7537b8d4dfc6"><enum>(A)</enum><text>in subsection (b)(1)(C), by inserting <quote>, availability</quote> after <quote>integrity</quote>; and</text></subparagraph><subparagraph id="id08f3285b-c16c-451f-bba5-e31f02dd8422"><enum>(B)</enum><text>in subsection (h)(3), by inserting <quote>security,</quote> after <quote>efficiency,</quote>; and</text></subparagraph></paragraph><paragraph id="id4aeb4b7f-eea6-4b5e-a927-10321bc47543"><enum>(4)</enum><text>in section 3513—</text><subparagraph id="id6e943a1a-9f45-433d-a4ba-dd9345e7210a"><enum>(A)</enum><text>by redesignating subsection (c) as subsection (d); and</text></subparagraph><subparagraph id="id96f0099c-c1c4-4551-8492-b6defe18de13"><enum>(B)</enum><text>by inserting after subsection (b) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id1680453f-c589-4863-9579-d013e52f61b4" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="id40f43d26-59cb-4dc2-8590-6901ceff6175"><enum>(c)</enum><text>Each agency providing a written plan under subsection (b) shall provide any portion of the written plan addressing information security or cybersecurity to the Director of the Cybersecurity and Infrastructure Security Agency.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph></subsection><subsection id="idcc0c5a52-133a-4152-9dac-55824f5a6a3c"><enum>(b)</enum><header>Subchapter II definitions</header><paragraph id="ida93e3aa5-70cc-44fb-b82b-692e1955e1be"><enum>(1)</enum><header>In general</header><text>Section 3552(b) of title 44, United States Code, is amended—</text><subparagraph id="id6c852c9f-0dac-4d28-8597-4bc946daa6ef"><enum>(A)</enum><text>by redesignating paragraphs (1), (2), (3), (4), (5), (6), and (7) as paragraphs (2), (3), (4), (5), (6), (9), and (11), respectively;</text></subparagraph><subparagraph id="id5452da3b-0707-46dc-bebc-81c5b92cc0be"><enum>(B)</enum><text>by inserting before paragraph (2), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id6f352304-e767-4e62-be84-abfc717c4f26" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="ide03103f8-176c-4c60-a4d1-d1e4095e374b"><enum>(1)</enum><text>The term <term>additional cybersecurity procedure</term> means a process, procedure, or other activity that is established in excess of the information security standards promulgated under section 11331(b) of title 40 to increase the security and reduce the cybersecurity risk of agency systems.</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="idb1b98feb-8444-4b7b-a67a-1eef42c31753"><enum>(C)</enum><text>by inserting after paragraph (6), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9e580108-8a44-4dbd-ab34-2cf5d1f5b73d" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="idf6834da4-2f90-465a-a610-56b00a6c48bc"><enum>(7)</enum><text>The term <term>high value asset</term> means information or an information system that the head of an agency determines so critical to the agency that the loss or corruption of the information or the loss of access to the information system would have a serious impact on the ability of the agency to perform the mission of the agency or conduct business.</text></paragraph><paragraph id="id3c6aa09e-40c4-4a6a-9cb1-777ec27f1474"><enum>(8)</enum><text>The term <term>major incident</term> has the meaning given the term in guidance issued by the Director under section 3598(a).</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="id2e6d3e2a-fc05-470d-ae6a-cb5eb9a9bce9"><enum>(D)</enum><text>by inserting after paragraph (9), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9acd9fa2-cc6e-4d06-b491-f3fe8ad8e484" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id507184b5-198a-467f-80c8-04269bf71e14"><enum>(10)</enum><text>The term <term>penetration test</term> means a specialized type of assessment that—</text><subparagraph id="idb9913888-d79f-4278-b121-cb8632471112"><enum>(A)</enum><text>is conducted on an information system or a component of an information system; and</text></subparagraph><subparagraph id="ide3c3676d-18b8-4543-8739-982de2794a0a"><enum>(B)</enum><text>emulates an attack or other exploitation capability of a potential adversary, typically under specific constraints, in order to identify any vulnerabilities of an information system or a component of an information system that could be exploited.</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="idca776728-9330-45c8-9dad-0ce8dce633b8"><enum>(E)</enum><text>by inserting after paragraph (11), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idb34113c98c3e47eb805186e9ebd42d42" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id30ff5b7c7d6f49f0944b7db792859dc7"><enum>(12)</enum><text>The term <term>shared service</term> means a centralized business or mission capability that is provided to multiple organizations within an agency or to multiple agencies.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="id76bea976-3311-4812-af38-98ef1eb415fa"><enum>(2)</enum><header>Conforming amendments</header><subparagraph id="ide1bf5d4e-e74f-4a5c-8cc2-340f9a9d55b0"><enum>(A)</enum><header>Homeland Security Act of 2002</header><text>Section 1001(c)(1)(A) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/511">6 U.S.C. 511(1)(A)</external-xref>) is amended by striking <quote>section 3552(b)(5)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id4f6f4f84-8ed8-4a9d-859e-1e812f054975"><enum>(B)</enum><header>Title 10</header><clause id="id6eefa65a-a9c1-4bf4-9676-8b4bc37e6883"><enum>(i)</enum><header>Section 2222</header><text>Section 2222(i)(8) of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)(A)</quote> and inserting <quote>section 3552(b)(9)(A)</quote>.</text></clause><clause id="id2672ec8d-81df-4838-98cf-15080e6a7287"><enum>(ii)</enum><header>Section 2223</header><text>Section 2223(c)(3) of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause><clause id="id9203ab71-e8c5-4135-ad25-4e046f4bf6c7"><enum>(iii)</enum><header>Section 2315</header><text>Section 2315 of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause><clause id="id65ba8e2f-ede6-4968-9dee-a019f3db42cc"><enum>(iv)</enum><header>Section 2339a</header><text>Section 2339a(e)(5) of title 10, United States Code, is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause></subparagraph><subparagraph id="id4bc95475-9a9d-4d9a-8117-ee19a43c48e7"><enum>(C)</enum><header>High-Performance Computing Act of 1991</header><text>Section 207(a) of the High-Performance Computing Act of 1991 (<external-xref legal-doc="usc" parsable-cite="usc/15/5527">15 U.S.C. 5527(a)</external-xref>) is amended by striking <quote>section 3552(b)(6)(A)(i)</quote> and inserting <quote>section 3552(b)(9)(A)(i)</quote>.</text></subparagraph><subparagraph id="idc38e1b7b-d88c-49bd-a9e0-3c43298b7fbf" commented="no"><enum>(D)</enum><header>Internet of Things Cybersecurity Improvement Act of 2020</header><text>Section 3(5) of the Internet of Things Cybersecurity Improvement Act of 2020 (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3a">15 U.S.C. 278g–3a</external-xref>) is amended by striking <quote>section 3552(b)(6)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id3e336811-86fc-4632-ad24-19b37e7ba0e7"><enum>(E)</enum><header>National Defense Authorization Act for Fiscal Year 2013</header><text>Section 933(e)(1)(B) of the National Defense Authorization Act for Fiscal Year 2013 (<external-xref legal-doc="usc" parsable-cite="usc/10/2224">10 U.S.C. 2224</external-xref> note) is amended by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="idc569f1c5-f5ea-43b2-89ef-80f27185c517"><enum>(F)</enum><header>Ike Skelton National Defense Authorization Act for Fiscal Year 2011</header><text>The Ike Skelton National Defense Authorization Act for Fiscal Year 2011 (<external-xref legal-doc="public-law" parsable-cite="pl/111/383">Public Law 111–383</external-xref>) is amended—</text><clause id="id87397e95-7f71-4bce-8ce5-e82e3cfe3368"><enum>(i)</enum><text>in section 806(e)(5) (<external-xref legal-doc="usc" parsable-cite="usc/10/2304">10 U.S.C. 2304</external-xref> note), by striking <quote>section 3542(b)</quote> and inserting <quote>section 3552(b)</quote>;</text></clause><clause id="id22cfe253-b2fa-4345-a460-3b0b51654b25"><enum>(ii)</enum><text>in section 931(b)(3) (<external-xref legal-doc="usc" parsable-cite="usc/10/2223">10 U.S.C. 2223</external-xref> note), by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>; and</text></clause><clause id="idb59ebc61-2935-4361-be8c-6fbb5a8ffb09"><enum>(iii)</enum><text>in section 932(b)(2) (<external-xref legal-doc="usc" parsable-cite="usc/10/2224">10 U.S.C. 2224</external-xref> note), by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></clause></subparagraph><subparagraph id="id494cbcf7-7a54-4247-a8fa-17058b79cfbe"><enum>(G)</enum><header>E-Government Act of 2002</header><text>Section 301(c)(1)(A) of the E-Government Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/44/3501">44 U.S.C. 3501</external-xref> note) is amended by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></subparagraph><subparagraph id="id7113da92-ab99-4b80-a365-cb1a2e41b76f"><enum>(H)</enum><header>National Institute of Standards and Technology Act</header><text>Section 20 of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g–3</external-xref>) is amended—</text><clause id="id26c3535d-75cb-4981-8a66-16c8bb47861a"><enum>(i)</enum><text>in subsection (a)(2), by striking <quote>section 3552(b)(5)</quote> and inserting <quote>section 3552(b)</quote>; and</text></clause><clause id="id35a3b031-44f1-4d2e-b54c-f28ac9f70854"><enum>(ii)</enum><text>in subsection (f)—</text><subclause id="idc1190c9f-0687-4ce2-9752-17b9a3fb0e2b"><enum>(I)</enum><text>in paragraph (3), by striking <quote>section 3532(1)</quote> and inserting <quote>section 3552(b)</quote>; and</text></subclause><subclause id="idd9e83c3a-ffb0-4a78-8744-5d55795e2494"><enum>(II)</enum><text>in paragraph (5), by striking <quote>section 3532(b)(2)</quote> and inserting <quote>section 3552(b)</quote>.</text></subclause></clause></subparagraph></paragraph></subsection><subsection id="ida1f55391-2117-48a5-9feb-673644f94cdb"><enum>(c)</enum><header>Subchapter II amendments</header><text>Subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended—</text><paragraph id="idb95e91cc-9471-484c-a2fd-888ba4a5d09f"><enum>(1)</enum><text>in section 3551—</text><subparagraph id="idb405642f-a406-4169-bc5e-6395d13e6473"><enum>(A)</enum><text>by redesignating paragraphs (3), (4), (5), and (6) as paragraphs (4), (5), (6), and (7), respectively;</text></subparagraph><subparagraph id="id6180a449-34b7-43e3-a229-837b34961374"><enum>(B)</enum><text>by inserting after paragraph (2) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idd7bc2df4-2e79-4288-99dd-df6b8c6aca08" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id4376f747-73ab-4281-9dbd-408c6a2320e6"><enum>(3)</enum><text>recognize the role of the Cybersecurity and Infrastructure Security Agency as the lead entity for operational cybersecurity coordination across the Federal Government;</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="id2807803a-3406-4077-b5e8-c76205406ade"><enum>(C)</enum><text>in paragraph (5), as so redesignated, by striking <quote>diagnose and improve</quote> and inserting <quote>integrate, deliver, diagnose, and improve</quote>;</text></subparagraph><subparagraph id="id6b8b4258-c00e-46ef-9621-93bbda47acd8"><enum>(D)</enum><text>in paragraph (6), as so redesignated, by striking <quote>and</quote> at the end;</text></subparagraph><subparagraph id="id0A32AD3962D0410B90167826410C6B85"><enum>(E)</enum><text>in paragraph (7), as so redesignated, by striking the period at the end and inserting a semi colon; and</text></subparagraph><subparagraph id="idbea02759-98b9-4725-9534-d0a53a73571b"><enum>(F)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idd7da17df-c8cb-41e5-aa14-cc2a6486c221" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id162b7a95-c611-4d33-b83d-25152be1e1ee" commented="no"><enum>(8)</enum><text>recognize that each agency has specific mission requirements and, at times, unique cybersecurity requirements to meet the mission of the agency;</text></paragraph><paragraph id="id3ec21a36-b935-4033-a621-98c1d4f403e7" commented="no"><enum>(9)</enum><text>recognize that each agency does not have the same resources to secure agency systems, and an agency should not be expected to have the capability to secure the systems of the agency from advanced adversaries alone; and</text></paragraph><paragraph id="id81e3806d-605b-4705-b042-dd9684040ef7" commented="no"><enum>(10)</enum><text>recognize that—</text><subparagraph commented="no" id="idff0619c8-1dcd-4b32-a708-599336ba9e3e"><enum>(A)</enum><text>a holistic Federal cybersecurity model is necessary to account for differences between the missions and capabilities of agencies; and</text></subparagraph><subparagraph commented="no" id="idd0b81b1d-1618-4c7e-852b-99447d80aae3"><enum>(B)</enum><text>in accounting for the differences described in subparagraph (A) and ensuring overall Federal cybersecurity—</text><clause id="id2ba0284d-dfa9-48f8-a9d7-1ff87b3aa808"><enum>(i)</enum><text>the Office of Management and Budget is the leader for policy development and oversight of Federal cybersecurity; </text></clause><clause commented="no" id="id981b3983-aa7a-443c-a00d-b03288e65bf4"><enum>(ii)</enum><text>the Cybersecurity and Infrastructure Security Agency is the leader for implementing operations at agencies; and</text></clause><clause id="idbaff97ec-1916-4022-b548-76eaf4d6abd5"><enum>(iii)</enum><text>the National Cyber Director is responsible for developing the overall cybersecurity strategy of the United States and advising the President on matters relating to cybersecurity.</text></clause></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="id65d1df73-4417-4ecb-a401-3ff411c46447"><enum>(2)</enum><text>in section 3553—</text><subparagraph id="idFE7F13929A654DC6A09B4A0299C3D4FC"><enum>(A)</enum><text>by striking the section heading and inserting <quote><header-in-text style="USC" level="section">Authority and functions of the Director and the Director of the Cybersecurity and Infrastructure Security Agency</header-in-text></quote>.</text></subparagraph><subparagraph id="id8531bfa2-6486-47be-9dd7-7dc5beb058fb"><enum>(B)</enum><text>in subsection (a)—</text><clause id="idc92d9838-1ae6-4c44-9765-33e505b8695e"><enum>(i)</enum><text>in paragraph (1), by inserting <quote>in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director,</quote> before <quote>developing and overseeing</quote>; </text></clause><clause id="id27bfd4b82fd3426c84241babd63146b0"><enum>(ii)</enum><text>in paragraph (5)—</text><subclause id="id35DCF0A26D8844008F55EA6AB10117B1"><enum>(I)</enum><text>by inserting <quote>, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director,</quote> before <quote>agency compliance</quote>; and</text></subclause><subclause id="id4FCD265E2CE145AF9A8CAB8D0E11CDE6"><enum>(II)</enum><text>by striking <quote>and</quote> at the end; and</text></subclause></clause><clause id="idacfdafc601c54c9c830f0ebcaa73e4ab"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id0d7ba3260d0946dbbee8d9fd5e1dd598" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id75f9123661f140528e4f0161d3b54136"><enum>(8)</enum><text>promoting, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the Director of the National Institute of Standards and Technology—</text><subparagraph id="ide544e23da7d64d31bd8ff9ef0d5561dc"><enum>(A)</enum><text>the use of automation to improve Federal cybersecurity and visibility with respect to the implementation of Federal cybersecurity; and</text></subparagraph><subparagraph id="id3befeba84be94a50b12156ed5be551f1"><enum>(B)</enum><text>the use of presumption of compromise and least privilege principles to improve resiliency and timely response actions to incidents on Federal systems.</text></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id8d71c5ad-279f-4aae-a0e5-ab4e74364967"><enum>(C)</enum><text>in subsection (b)—</text><clause id="id550806c3-8964-4778-b1a8-d8073ecbf0f9"><enum>(i)</enum><text>by striking the subsection heading and inserting <quote><header-in-text style="USC" level="subsection">Cybersecurity and Infrastructure Security Agency</header-in-text></quote>;</text></clause><clause id="idac4cfe2b-ef1d-4701-bc03-5350f9cfab73"><enum>(ii)</enum><text>in the matter preceding paragraph (1), by striking <quote>The Secretary, in consultation with the Director</quote> and inserting <quote>The Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director and the National Cyber Director</quote>;</text></clause><clause id="idb780b2b8-85d2-4f91-910d-e82655cddbff"><enum>(iii)</enum><text>in paragraph (2)—</text><subclause id="id8a71e1bc-a705-4772-8e93-ab030f3ad274"><enum>(I)</enum><text>in subparagraph (A), by inserting <quote>and reporting requirements under subchapter IV of this title</quote> after <quote>section 3556</quote>; and</text></subclause><subclause id="idd878cd5b-1ec1-4b9a-80c0-a615c546ca42"><enum>(II)</enum><text>in subparagraph (D), by striking <quote>the Director or Secretary</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency</quote>;</text></subclause></clause><clause id="ida8cab193-0060-431c-b356-dfc1443a481a"><enum>(iv)</enum><text>in paragraph (5), by striking <quote>coordinating</quote> and inserting <quote>leading the coordination of</quote>;</text></clause><clause id="id2803b675-727c-48b2-a34d-11ed7152b3c9"><enum>(v)</enum><text>in paragraph (8), by striking <quote>the Secretary's discretion</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency's discretion</quote>; and</text></clause><clause id="id60fb70da-128b-4918-b528-cd7a518aee89"><enum>(vi)</enum><text>in paragraph (9), by striking <quote>as the Director or the Secretary, in consultation with the Director,</quote> and inserting <quote>as the Director of the Cybersecurity and Infrastructure Security Agency</quote>;</text></clause></subparagraph><subparagraph id="id4b5a506f-1e95-4518-83e5-ac54d77c02ba"><enum>(D)</enum><text>in subsection (c)—</text><clause id="idE3A1C868617343A08089ABF20B6DAE89"><enum>(i)</enum><text>in the matter preceding paragraph (1), by striking <quote>each year</quote> and inserting <quote>each year during which agencies are required to submit reports under section 3554(c)</quote>;</text></clause><clause id="idD8363FEECB2B4ADBBA26CCA7B14D4E54"><enum>(ii)</enum><text>by striking paragraph (1);</text></clause><clause id="idBB591BEE379443EB92F4080A72B4FC56"><enum>(iii)</enum><text>by redesignating paragraphs (2), (3), and (4) as paragraphs (1), (2), and (3), respectively;</text></clause><clause id="id372a5810-ac36-4b88-8899-e6954c77769d"><enum>(iv)</enum><text>in paragraph (3), as so redesignated, by striking <quote>and</quote> at the end;</text></clause><clause id="idd6c42bf9-5e30-4e9a-bd44-0dd443e870bf"><enum>(v)</enum><text>by inserting after paragraph (3), as so redesignated the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idc6cc8b7d-23a2-44ac-9383-55d7f65c27a5" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id6a66f70a-23f3-4bb7-88c2-31385d3575fa"><enum>(4)</enum><text>a summary of each assessment of Federal risk posture performed under subsection (i);</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause><clause id="id55ABD27C1C3E4B6AAFD1A6934482294D"><enum>(vi)</enum><text>in paragraph (5), by striking the period at the end and inserting <quote>; and</quote>;</text></clause></subparagraph><subparagraph id="id38824b64-2ab1-45b4-b918-f63b87f48e09"><enum>(E)</enum><text>by redesignating subsections (i), (j), (k), and (l) as subsections (j), (k), (l), and (m) respectively;</text></subparagraph><subparagraph id="id5bdc1105-5873-4202-8157-b2e5f339a7e3"><enum>(F)</enum><text>by inserting after subsection (h) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="ida58e72196e724bbc8c8aa7b61fe85258" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="idfa586004c3da43ba92c1b2fbe588c2bb"><enum>(i)</enum><header>Federal risk assessments</header><text>On an ongoing and continuous basis, the Director of the Cybersecurity and Infrastructure Security Agency shall perform assessments of Federal risk posture using any available information on the cybersecurity posture of agencies, and brief the Director and National Cyber Director on the findings of those assessments including—</text><paragraph id="id7e51a7e6-21a2-48e6-af2e-8fa6f65b74f3"><enum>(1)</enum><text>the status of agency cybersecurity remedial actions described in section 3554(b)(7);</text></paragraph><paragraph id="id03d559f6-f01e-4b36-b477-605f3490131c"><enum>(2)</enum><text>any vulnerability information relating to the systems of an agency that is known by the agency;</text></paragraph><paragraph id="id078ec97c-47e4-4468-83b0-1c9c106dd397"><enum>(3)</enum><text>analysis of incident information under section 3597;</text></paragraph><paragraph id="id3efeb14a-1181-42d6-9bd8-c6b633685baa"><enum>(4)</enum><text>evaluation of penetration testing performed under section 3559A;</text></paragraph><paragraph id="idefcdcac4-22c3-44da-a36d-179ba33626fd"><enum>(5)</enum><text>evaluation of vulnerability disclosure program information under section 3559B;</text></paragraph><paragraph id="id5ca36d39-8ecb-4a9f-b61c-a8628285f456"><enum>(6)</enum><text>evaluation of agency threat hunting results;</text></paragraph><paragraph id="id7fba1e5e-fe74-43e3-9faa-7ff85d94f125"><enum>(7)</enum><text>evaluation of Federal and non-Federal threat intelligence;</text></paragraph><paragraph id="id83129655-55be-4639-bd6d-a9d57e8ed9e8"><enum>(8)</enum><text>data on agency compliance with standards issued under section 11331 of title 40;</text></paragraph><paragraph id="iddae11a7a-0dfb-43d9-81d9-29a61ea0b9b5"><enum>(9)</enum><text>agency system risk assessments performed under section 3554(a)(1)(A); and</text></paragraph><paragraph id="id758967d5-f486-413b-bcbc-fcbb9b1db74c"><enum>(10)</enum><text>any other information the Director of the Cybersecurity and Infrastructure Security Agency determines relevant.</text></paragraph></subsection><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="ideb2823e8-44e6-4021-abe2-fef558c58b04"><enum>(G)</enum><text>in subsection (j), as so redesignated—</text><clause id="id5b7f6801-ffeb-482b-876c-bfc7a7e33cea"><enum>(i)</enum><text>by striking <quote>regarding the specific</quote> and inserting “that includes a summary of—</text><quoted-block style="OLC" display-inline="no-display-inline" id="idc6d7b47a-fe0e-4a70-9c03-4066c4c48f49" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="idecee93c3-69f0-48b7-923c-92e127e6429b"><enum>(1)</enum><text>the specific</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id4205bd69-a5b7-4402-a7a0-d3d99975e9a0"><enum>(ii)</enum><text>in paragraph (1), as so designated, by striking the period at the end and inserting <quote>; and</quote> and</text></clause><clause id="id896a4774-b830-4f75-8be8-6f72c5c89423"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id67673916-51d4-410b-acd3-7d81ff3f2ad6" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id527fead8-4750-4aed-a1c9-211aeff4e130"><enum>(2)</enum><text>the trends identified in the Federal risk assessment performed under subsection (i).</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id24F0AC5ADB1C46D4B502F73B6F3FB939"><enum>(H)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id6FC599D2AC274B81B7A1913AA3CC76CF" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="idA310B651540F440F9D7A78CC37B89017"><enum>(n)</enum><header>Binding operational directives</header><text>If the Director of the Cybersecurity and Infrastructure Security Agency issues a binding operational directive or an emergency directive under this section, not later than 2 days after the date on which the binding operational directive requires an agency to take an action, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the appropriate reporting entities the status of the implementation of the binding operational directive at the agency.</text></subsection><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="idf20f9353-d865-4160-bc68-a508b4c01935"><enum>(3)</enum><text>in section 3554—</text><subparagraph id="id35f60afd-1932-44db-93e1-87af8ac9b831"><enum>(A)</enum><text>in subsection (a)—</text><clause id="idcf59325c-ab58-4a48-bcf6-7dca6bab0b25"><enum>(i)</enum><text>in paragraph (1)—</text><subclause id="id3cc40410-ce3a-45a2-8c2a-aaf170a1b2b1"><enum>(I)</enum><text>by redesignating subparagraphs (A), (B), and (C) as subparagraphs (B), (C), and (D), respectively;</text></subclause><subclause id="ide06f9232-3a7a-4276-951b-f617b0f0211c"><enum>(II)</enum><text>by inserting before subparagraph (B), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idf1bd5b20-5e1c-4892-ba73-1df38e6f99a9" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id3906d602-1e11-4eef-9b89-2c7d10f8cc4f"><enum>(A)</enum><text>on an ongoing and continuous basis, performing agency system risk assessments that— </text><clause id="id4efedf08-2e43-44a4-8021-09abd6fdcd67"><enum>(i)</enum><text>identify and document the high value assets of the agency using guidance from the Director;</text></clause><clause id="id94b7944b-12ac-444e-a283-b07ebc17b4cf"><enum>(ii)</enum><text>evaluate the data assets inventoried under section 3511 for sensitivity to compromises in confidentiality, integrity, and availability;</text></clause><clause id="id67ddc101-2f82-4719-84f6-7a7843a64843"><enum>(iii)</enum><text>identify agency systems that have access to or hold the data assets inventoried under section 3511;</text></clause><clause id="id893d58d6-d521-4ba6-9083-423397c2f832"><enum>(iv)</enum><text>evaluate the threats facing agency systems and data, including high value assets, based on Federal and non-Federal cyber threat intelligence products, where available;</text></clause><clause id="ide416c4d8-0a18-432a-8d51-566c7435af2e"><enum>(v)</enum><text>evaluate the vulnerability of agency systems and data, including high value assets, including by analyzing—</text><subclause id="ide5a8ed25-1c35-4394-a545-956224a6b253"><enum>(I)</enum><text>the results of penetration testing performed by the Department of Homeland Security under section 3553(b)(9);</text></subclause><subclause id="id4a032f79-fe2c-4c33-893b-28730a12be4d"><enum>(II)</enum><text>the results of penetration testing performed under section 3559A;</text></subclause><subclause id="id7d84009c-5ea2-4a90-93bb-df7d617424d8"><enum>(III)</enum><text>information provided to the agency through the vulnerability disclosure program of the agency under section 3559B;</text></subclause><subclause id="id802761d7-7118-454c-8c3a-3f2e77073540"><enum>(IV)</enum><text>incidents; and</text></subclause><subclause id="ideaa5b873-be64-4105-af3b-966266d26a2a"><enum>(V)</enum><text>any other vulnerability information relating to agency systems that is known to the agency;</text></subclause></clause><clause id="idd8039431-edce-4081-8af6-c8b8b70e8f87"><enum>(vi)</enum><text>assess the impacts of potential agency incidents to agency systems, data, and operations based on the evaluations described in clauses (ii) and (iv) and the agency systems identified under clause (iii); and</text></clause><clause id="idc862abfe-77de-4622-8b11-d29f4229a99c"><enum>(vii)</enum><text>assess the consequences of potential incidents occurring on agency systems that would impact systems at other agencies, including due to interconnectivity between different agency systems or operational reliance on the operations of the system or data in the system;</text></clause></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subclause><subclause id="id5bdbf62e-31a8-4b1b-a05c-e03b248d70a7"><enum>(III)</enum><text>in subparagraph (B), as so redesignated, in the matter preceding clause (i), by striking <quote>providing information</quote> and inserting <quote>using information from the assessment conducted under subparagraph (A), providing, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, information</quote>;</text></subclause><subclause id="idfe0193e1-b5b8-4f06-9fff-227e2f98e058"><enum>(IV)</enum><text>in subparagraph (C), as so redesignated—</text><item id="idde96240a-9fab-46ba-9add-0249fbba823a"><enum>(aa)</enum><text>in clause (ii) by inserting <quote>binding</quote> before <quote>operational</quote>; and</text></item><item id="id61587b95-db60-41a6-bf64-389664fb4467"><enum>(bb)</enum><text>in clause (vi), by striking <quote>and</quote> at the end; and</text></item></subclause><subclause id="id8eaa47ea-92b0-4a30-b040-d6062a34fcd6"><enum>(V)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3815f8f02c304f34851bb6a2f12dae2f" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id4c29888043dc4298ac37bede14249f46"><enum>(E)</enum><text>providing an update on the ongoing and continuous assessment performed under subparagraph (A)—</text><clause id="id281121F3A0504B33BF8BEBDF7B0A1F28"><enum>(i)</enum><text>upon request, to the inspector general of the agency or the Comptroller General of the United States; and</text></clause><clause id="id33F81DCBB9384121B2F98CA1B42D7377"><enum>(ii)</enum><text>on a periodic basis, as determined by guidance issued by the Director but not less frequently than annually, to—</text><subclause id="id22543c64-ef03-4103-9a0e-2aa5e74d8456"><enum>(I)</enum><text>the Director;</text></subclause><subclause id="id12da0c93-9842-406d-ab15-ddcda3fde0e9"><enum>(II)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency; and</text></subclause><subclause id="id325ff018-6542-493d-a802-2abfd3ae2128"><enum>(III)</enum><text>the National Cyber Director;</text></subclause></clause></subparagraph><subparagraph id="idef929648-6330-4c3e-b1e9-7703315d3a98"><enum>(F)</enum><text>in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and not less frequently than once every 3 years, performing an evaluation of whether additional cybersecurity procedures are appropriate for securing a system of, or under the supervision of, the agency, which shall—</text><clause id="idcd5572ce-ebaa-4209-965e-46e2ccf853df"><enum>(i)</enum><text>be completed considering the agency system risk assessment performed under subparagraph (A); and</text></clause><clause id="id8a0307df-6b63-4d45-a170-d3ce8dce3e40"><enum>(ii)</enum><text>include a specific evaluation for high value assets;</text></clause></subparagraph><subparagraph id="id49caf3cf-5f38-4128-9865-b85af923829d"><enum>(G)</enum><text>not later than 30 days after completing the evaluation performed under subparagraph (F), providing the evaluation and an implementation plan, if applicable, for using additional cybersecurity procedures determined to be appropriate to—</text><clause display-inline="no-display-inline" commented="no" id="idea7059de-11b2-4261-81e3-84d6661c19c4"><enum>(i)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency;</text></clause><clause display-inline="no-display-inline" commented="no" id="idbf6fe6d7-eac0-410c-8637-b43828713b88"><enum>(ii)</enum><text>the Director; and</text></clause><clause display-inline="no-display-inline" commented="no" id="id12c129af-dacb-418b-a7ef-519049c51e5f"><enum>(iii)</enum><text>the National Cyber Director; and</text></clause></subparagraph><subparagraph id="idf31ce8a3bd4242a8be61bcee73b45097"><enum>(H)</enum><text>if the head of the agency determines there is need for additional cybersecurity procedures, ensuring that those additional cybersecurity procedures are reflected in the budget request of the agency in accordance with the risk-based cyber budget model developed pursuant to section 3553(a)(7);</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></subclause></clause><clause id="id79f03079-53b4-4a9b-915c-0b4bdbd8a827"><enum>(ii)</enum><text>in paragraph (2)—</text><subclause id="id16f1028a-14eb-4f51-a95a-88615a8d70de"><enum>(I)</enum><text>in subparagraph (A), by inserting <quote>in accordance with the agency system risk assessment performed under paragraph (1)(A)</quote> after <quote>information systems</quote>;</text></subclause><subclause id="idd9504a29-3df1-4805-9c36-3dcae8c9dc53"><enum>(II)</enum><text>in subparagraph (B)—</text><item id="idef4f0a43-d366-4b58-8501-6e5e6a60d032"><enum>(aa)</enum><text>by striking <quote>in accordance with standards</quote> and inserting “in accordance with—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9759dafb-92e7-46eb-ae28-666a6a80311e" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="ide0a6c65b-9fd2-4c8d-81e4-0abc8a0662c0"><enum>(i)</enum><text>standards</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item><item id="iddcd4751d-9e00-44c6-9bc5-1e9d6e454fa0"><enum>(bb)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id8ec73c0e-73cf-4c96-9fec-4f7b4537e06a" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id77fc05cd-db7f-416d-9862-801aee112a5c"><enum>(ii)</enum><text>the evaluation performed under paragraph (1)(F); and</text></clause><clause id="idd85b50c6-638c-48f1-b447-9849e5a0d879"><enum>(iii)</enum><text>the implementation plan described in paragraph (1)(G);</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item></subclause><subclause id="iddf92c922-5591-40dc-a56c-782a7d985e2a"><enum>(III)</enum><text>in subparagraph (D), by inserting <quote>, through the use of penetration testing, the vulnerability disclosure program established under section 3559B, and other means,</quote> after <quote>periodically</quote>;</text></subclause></clause><clause id="ida55f7dc6-0b28-4773-b9e8-e412d34ca674"><enum>(iii)</enum><text>in paragraph (3)—</text><subclause id="idc0196970537b490b84deed37a44579b2"><enum>(I)</enum><text>in subparagraph (A)—</text><item id="ide2e0faa78c05487eb700b7c3fdf9b7e0"><enum>(aa)</enum><text>in clause (iii), by striking <quote>and</quote> at the end;</text></item><item id="id06c9f051df214e59803f9a93b1607387"><enum>(bb)</enum><text>in clause (iv), by adding <quote>and</quote> at the end; and</text></item><item id="id0152a8af9e9c49fab996915e3216397d"><enum>(cc)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3fc1de22dfc840ff9125e6f30f649a61" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id297117ad78f24c93a0bd5afcef2e430d"><enum>(v)</enum><text>ensure that—</text><subclause id="id11E3956E43D54E7C99AB6E9150C141A2"><enum>(I)</enum><text>senior agency information security officers of component agencies carry out responsibilities under this subchapter, as directed by the senior agency information security officer of the agency or an equivalent official; and</text></subclause><subclause id="id03C11335A2AD4EC6AA41036315E64F1B"><enum>(II)</enum><text>senior agency information security officers of component agencies report to—</text><item id="id526c0df8f8cd45ed8219fdd978d3a7b2"><enum>(aa)</enum><text>the senior information security officer of the agency or an equivalent official; and</text></item><item id="id42dbf9793f8f4945b2f84e64d281237f"><enum>(bb)</enum><text>the Chief Information Officer of the component agency or an equivalent official;</text></item></subclause></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item></subclause></clause><clause id="id8c06a4f4-54f6-43b3-a5af-578e068ef577"><enum>(iv)</enum><text>in paragraph (5), by inserting <quote>and the Director of the Cybersecurity and Infrastructure Security Agency</quote> before <quote>on the effectiveness</quote>;</text></clause></subparagraph><subparagraph id="id25a6c67c-013b-4876-9389-8362d82a8de5"><enum>(B)</enum><text>in subsection (b)—</text><clause id="id9df329c5-5120-48c9-89c1-36dcb14519b5"><enum>(i)</enum><text>by striking paragraph (1) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idf63a3352910845ffb5f4bafb6545adaa" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id45be30b1eda7446fb0dab50d5f2a28df"><enum>(1)</enum><text>pursuant to subsection (a)(1)(A), performing ongoing and continuous agency system risk assessments, which may include using guidelines and automated tools consistent with standards and guidelines promulgated under section 11331 of title 40, as applicable;</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id5a87f116-6a9d-4ad4-b9e4-2c8caa279654"><enum>(ii)</enum><text>in paragraph (2)—</text><subclause id="id454C2A0EB77E4A5CA5888885B64B8EC4"><enum>(I)</enum><text>by striking subparagraph (B) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id5783A4614E2D44EEB6F5BDFBF08F4AD6" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id0586DBE9D0134991A067CC47EAB7D821"><enum>(B)</enum><text>comply with the risk-based cyber budget model developed pursuant to section 3553(a)(7);</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subclause><subclause id="id27866425D5514CEC86C72F0EC73437C6"><enum>(II)</enum><text>in subparagraph (D)—</text><item id="id22780ef0-fa82-4f91-8c07-de6a1ec67ec6"><enum>(aa)</enum><text>by redesignating clauses (iii) and (iv) as clauses (iv) and (v), respectively;</text></item><item id="id898d1395-4567-4393-ba8a-421bf4872539"><enum>(bb)</enum><text>by inserting after clause (ii) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idb6ca0ef5-65f9-442b-afad-d001b0d75b8b" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id8c60ab86-f4c2-45bc-9ed0-66adfce6c468"><enum>(iii)</enum><text>binding operational directives and emergency directives promulgated by the Director of the Cybersecurity and Infrastructure Security Agency under section 3553;</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item><item id="id259895e7-1bd0-4707-aee0-ed5edb1a4bac"><enum>(cc)</enum><text>in clause (iv), as so redesignated, by striking <quote>as determined by the agency; and</quote> and inserting “as determined by the agency, considering—</text><quoted-block style="OLC" display-inline="no-display-inline" id="idA28B586174374DEA9704857FB9A67CD9" changed="added" reported-display-style="italic" committee-id="SSGA00"><subclause id="id5162e7e7d755413db7deabf6207b1d06"><enum>(I)</enum><text>the agency risk assessment performed under subsection (a)(1)(A); and</text></subclause><subclause id="id55ca4a80a56f47c5b1ca45bc33ac0874"><enum>(II)</enum><text>the determinations of applying more stringent standards and additional cybersecurity procedures pursuant to section 11331(c)(1) of title 40; and</text></subclause><after-quoted-block>;</after-quoted-block></quoted-block></item></subclause></clause><clause id="id74975cc0-3aaf-4e66-ae26-cd30cd1178be"><enum>(iii)</enum><text>in paragraph (5)(A), by inserting <quote>, including penetration testing, as appropriate,</quote> after <quote>shall include testing</quote>; </text></clause><clause id="idf5444132-99e6-46d4-b70f-909758a79e6e"><enum>(iv)</enum><text>in paragraph (6), by striking <quote>planning, implementing, evaluating, and documenting</quote> and inserting <quote>planning and implementing and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, evaluating and documenting</quote>;</text></clause><clause id="ida4a59689-bbdd-46d9-b1b1-a9c506c27831"><enum>(v)</enum><text>by redesignating paragraphs (7) and (8) as paragraphs (8) and (9), respectively;</text></clause><clause id="id0fcb94bc-2361-4fcc-b9c3-365559018595"><enum>(vi)</enum><text>by inserting after paragraph (6) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="ide1e32f6c-b043-42c5-b2a3-ea4ca61cefaa" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id2838bbb2-37c3-4119-a3d6-e46c93df341b"><enum>(7)</enum><text>a process for providing the status of every remedial action and known system vulnerability to the Director and the Director of the Cybersecurity and Infrastructure Security Agency, using automation and machine-readable data to the greatest extent practicable;</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause><clause id="idb675e527-96f4-4bb5-b22b-7aaf0c3d6215"><enum>(vii)</enum><text>in paragraph (8)(C), as so redesignated—</text><subclause id="id96cbe9bb-d9be-4b7d-b24d-55ed893cdd09"><enum>(I)</enum><text>by striking clause (ii) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3a9e7204-50aa-4da0-8e0a-568e00bb1879" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id6dcc7c01-20a0-45b0-8fbb-712d0732c9b8"><enum>(ii)</enum><text>notifying and consulting with the Federal information security incident center established under section 3556 pursuant to the requirements of section 3594;</text></clause><after-quoted-block>;</after-quoted-block></quoted-block></subclause><subclause id="ida7601345-a855-4412-a790-b78217813eba"><enum>(II)</enum><text>by redesignating clause (iii) as clause (iv);</text></subclause><subclause id="idae3c1ffa-7bb6-40c8-a6ff-1807e4c9e923"><enum>(III)</enum><text>by inserting after clause (ii) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idd03e7e75-0b1e-4035-a3f9-d4210b28e348" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id66a5e43b-60fc-4de1-97c0-9e62508b7310"><enum>(iii)</enum><text>performing the notifications and other activities required under subchapter IV of this title; and</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></subclause><subclause id="id6d8c4a4c-351d-437f-9b3a-4dff1146962f"><enum>(IV)</enum><text>in clause (iv), as so redesignated—</text><item id="id2613d157-3fd4-4459-9083-730c10ec1d51"><enum>(aa)</enum><text>in subclause (I), by striking <quote>and relevant offices of inspectors general</quote>;</text></item><item id="id984235ee-035f-41a6-b5e5-003e60bfe2af"><enum>(bb)</enum><text>in subclause (II), by adding <quote>and</quote> at the end;</text></item><item id="id61063357-c0a3-4be5-a9a4-4c2e12a1c037"><enum>(cc)</enum><text>by striking subclause (III); and</text></item><item id="idd2528671-9469-4cf1-83f0-3cd15f8a4b7e"><enum>(dd)</enum><text>by redesignating subclause (IV) as subclause (III);</text></item></subclause></clause></subparagraph><subparagraph id="id55fcc33c-fd71-4ef3-8e6f-7efa61562674"><enum>(C)</enum><text>in subsection (c)—</text><clause id="id59A91330BAA84826BA29304D03763CFB"><enum>(i)</enum><text>by redesignating paragraph (2) as paragraph (5);</text></clause><clause id="idFA7ED4D1F88445B0B794BA79CD442187"><enum>(ii)</enum><text>by striking paragraph (1) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idb5d642e2-53d3-4565-a290-963e3d9b1d27" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id5326e4b2-66c2-4fbf-b2f1-95c8d64e05d0" commented="no"><enum>(1)</enum><header>Biannual report</header><text>Not later than 2 years after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title> and not less frequently than once every 2 years thereafter, using the continuous and ongoing agency system risk assessment under subsection (a)(1)(A), the head of each agency shall submit to the Director, the Director of the Cybersecurity and Infrastructure Security Agency, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, the appropriate authorization and appropriations committees of Congress, the National Cyber Director, and the Comptroller General of the United States a report that—</text><subparagraph id="id24ce5534-b474-469d-87af-2a3639eedfe8"><enum>(A)</enum><text>summarizes the agency system risk assessment performed under subsection (a)(1)(A);</text></subparagraph><subparagraph id="id4e7c9c9e-cd8e-421e-9aea-8479517baef8"><enum>(B)</enum><text>evaluates the adequacy and effectiveness of information security policies, procedures, and practices of the agency to address the risks identified in the agency system risk assessment performed under subsection (a)(1)(A); </text></subparagraph><subparagraph id="ide2c46e13-1b7e-4a72-95b8-b4f7298539bf"><enum>(C)</enum><text>summarizes the evaluation and implementation plans described in subparagraphs (F) and (G) of subsection (a)(1) and whether those evaluation and implementation plans call for the use of additional cybersecurity procedures determined to be appropriate by the agency; and</text></subparagraph><subparagraph id="idceb8c80b48314687abfe11c76cd10590"><enum>(D)</enum><text>summarizes the status of remedial actions identified by inspector general of the agency, the Comptroller General of the United States, and any other source determined appropriate by the head of the agency. </text></subparagraph></paragraph><paragraph id="idbb5d8931-6b07-4429-95b9-b77ec01ca8e0"><enum>(2)</enum><header>Unclassified reports</header><text>Each report submitted under paragraph (1)—</text><subparagraph id="idc34ddd60-93c9-4f83-84bc-16f6a994242b"><enum>(A)</enum><text>shall be, to the greatest extent practicable, in an unclassified and otherwise uncontrolled form; and </text></subparagraph><subparagraph id="id0dd91f91-c522-4a87-bdf6-29ba10095dea"><enum>(B)</enum><text>may include a classified annex.</text></subparagraph></paragraph><paragraph id="id1e5f5b06094d458ea7194a7195c14f8e" commented="no"><enum>(3)</enum><header>Access to information</header><text>The head of an agency shall ensure that, to the greatest extent practicable, information is included in the unclassified form of the report submitted by the agency under paragraph (2)(A).</text></paragraph><paragraph commented="no" id="idE6F814E7CA374A649F4B5A5E3F9F4A38"><enum>(4)</enum><header>Briefings</header><text>During each year during which a report is not required to be submitted under paragraph (1), the Director shall provide to the congressional committees described in paragraph (1) a briefing summarizing current agency and Federal risk postures.</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause><clause id="id493CEB7C2AD94AAF909DE36148B3BDBE"><enum>(iii)</enum><text>in paragraph (5), as so redesignated, by inserting <quote>including the reporting procedures established under section 11315(d) of title 40 and subsection (a)(3)(A)(v) of this section</quote>; and</text></clause></subparagraph><subparagraph id="id92867428-79b9-47c9-8f9f-d9a7e6d2489d"><enum>(D)</enum><text>in subsection (d)(1), in the matter preceding subparagraph (A), by inserting <quote>and the Director of the Cybersecurity and Infrastructure Security Agency</quote> after <quote>the Director</quote>; and</text></subparagraph></paragraph><paragraph id="idef46a912-fbbc-471b-a6f3-4213567dfc16"><enum>(4)</enum><text>in section 3555—</text><subparagraph id="idd234560ea3744296a3efcabbb105a11e" commented="no"><enum>(A)</enum><text>in the section heading, by striking <quote><header-in-text style="OLC" level="section">Annual independent</header-in-text></quote> and inserting <quote><header-in-text style="OLC" level="section">Independent</header-in-text></quote>;</text></subparagraph><subparagraph id="id7eb15845fc524f3ebeb95823dd2fe9ec" commented="no"><enum>(B)</enum><text>in subsection (a)—</text><clause id="id4A9C20B133224905A939B4420A8D9792" commented="no"><enum>(i)</enum><text>in paragraph (1), by inserting <quote>during which a report is required to be submitted under section 3553(c),</quote> after <quote>Each year</quote>;</text></clause><clause id="id3efc4913471241b7af05edbd07e655d3" commented="no"><enum>(ii)</enum><text>in paragraph (2)(A), by inserting <quote>, including by penetration testing and analyzing the vulnerability disclosure program of the agency</quote> after <quote>information systems</quote>; and</text></clause><clause id="id8840d65a8bc749fc9dc3c4ae771dd3d0" commented="no"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idDF141EA242764F0DB13ACC95354CAB2A" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id09DD03BC81414DB8B415E7DE9AC3AE12" commented="no" indent="up1"><enum>(3)</enum><text>An evaluation under this section may include recommendations for improving the cybersecurity posture of the agency.</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="idccafc46e440f494b867027c4cdab935e" commented="no"><enum>(C)</enum><text>in subsection (b)(1), by striking <quote>annual</quote>;</text></subparagraph><subparagraph id="id0989f3ee2d1c49b5bc0c8454ca3d0a36" commented="no"><enum>(D)</enum><text>in subsection (e)(1), by inserting <quote>during which a report is required to be submitted under section 3553(c)</quote> after <quote>Each year</quote>;</text></subparagraph><subparagraph id="idfb639fba-1ef7-4a1f-9ed9-34a938cb5aec"><enum>(E)</enum><text>by striking subsection (f) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3a356b88-7a52-4065-9b35-ea78d287782a" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="id2cbdb1f1-55e4-468f-93ce-3d77b023811c"><enum>(f)</enum><header>Protection of information</header><paragraph commented="no" display-inline="yes-display-inline" id="id8f7dc3d6-9bf7-4260-ad00-d653de74ef04"><enum>(1)</enum><text>Agencies, evaluators, and other recipients of information that, if disclosed, may cause grave harm to the efforts of Federal information security officers, including the appropriate congressional committees, shall take appropriate steps to ensure the protection of that information, including safeguarding the information from public disclosure.</text></paragraph><paragraph id="id38899180-506f-4f64-87c4-cc78c1f7f31c" indent="up1"><enum>(2)</enum><text>The protections required under paragraph (1) shall be commensurate with the risk and comply with all applicable laws and regulations.</text></paragraph><paragraph id="idf7002156-561a-4be1-8d51-3e2dbc520e2f" indent="up1"><enum>(3)</enum><text>With respect to information that is not related to national security systems, agencies and evaluators shall make a summary of the information unclassified and publicly available, including information that does not identify—</text><subparagraph id="id7ee218d7-d850-4102-ac86-99d0cc8be73e"><enum>(A)</enum><text>specific information system incidents; or</text></subparagraph><subparagraph id="id5e855ee4-82cb-4020-8a51-29a4ceccd192"><enum>(B)</enum><text>specific information system vulnerabilities.</text></subparagraph></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="idfa235ea8-e59f-4530-b125-7f99769f37bc"><enum>(F)</enum><text>in subsection (g)(2)—</text><clause id="id3ed3dac2-ba96-4406-9b55-ad7d76999f78"><enum>(i)</enum><text>by striking <quote>this subsection shall</quote> and inserting “this subsection—</text><quoted-block style="OLC" display-inline="no-display-inline" id="idc864acb3-11bb-41de-8b2e-27580da4ed13" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id8324f4ea-fbb3-449b-aaf1-c15afb28e5d6" indent="up1"><enum>(A)</enum><text>shall</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id74b8193e-f820-4156-b7ff-141165c916f2"><enum>(ii)</enum><text>in subparagraph (A), as so designated, by striking the period at the end and inserting <quote>; and</quote>; and</text></clause><clause id="id70cdf08d-3215-4237-b3f5-f2b52f18d5a4"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idc775e85e-a373-4ec8-80c5-47c5c1a1b6f3" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id3a84130b-5e95-413e-9f39-fd67efe5e65d" indent="up1"><enum>(B)</enum><text>identify any entity that performs an independent evaluation under subsection (b).</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="iddde49148-fde4-47f2-a967-07dc4b201e93"><enum>(G)</enum><text>by striking subsection (j) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idF3E2734B05024879938CC3F765386803" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="idDC79D013C3ED47F4A221FAF938CE8BA2"><enum>(j)</enum><header>Guidance</header><paragraph id="id04542E9832FC4078A071CE1969A857AB"><enum>(1)</enum><header>In general</header><text>The Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the Chief Information Officers Council, the Council of the Inspectors General on Integrity and Efficiency, and other interested parties as appropriate, shall ensure the development of guidance for evaluating the effectiveness of an information security program and practices</text></paragraph><paragraph id="idd9dea04fef664a2db8580bcc2f0a88b9"><enum>(2)</enum><header>Priorities</header><text>The guidance developed under paragraph (1) shall prioritize the identification of—</text><subparagraph id="id5cd2b278f3d94dbd950ffc747efa2b61"><enum>(A)</enum><text>the most common threat patterns experienced by each agency;</text></subparagraph><subparagraph id="ida5a02332480145118b281627a1f9863b"><enum>(B)</enum><text>the security controls that address the threat patterns described in subparagraph (A); and</text></subparagraph><subparagraph id="id47ade48cc04847588bb6f5e3de99c8c8"><enum>(C)</enum><text>any other security risks unique to the networks of each agency.</text></subparagraph></paragraph></subsection><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="id27b6c25d-0bf0-47d8-a972-e160f7285860"><enum>(5)</enum><text>in section 3556(a)—</text><subparagraph id="idea3ea18a-e85b-4d9e-9431-1691a309725f"><enum>(A)</enum><text>in the matter preceding paragraph (1), by inserting <quote>within the Cybersecurity and Infrastructure Security Agency</quote> after <quote>incident center</quote>; and</text></subparagraph><subparagraph id="id801a6e5a-f99e-406e-bbf4-e4e6dea4979f"><enum>(B)</enum><text>in paragraph (4), by striking <quote>3554(b)</quote> and inserting <quote>3554(a)(1)(A)</quote>.</text></subparagraph></paragraph></subsection><subsection id="idFA391932B6E743A483AE23A0A770AA60"><enum>(d)</enum><header>Conforming amendments</header><paragraph id="idED9F539E7BA8492DBBB4AA9EB659C122"><enum>(1)</enum><header>Table of sections</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended—</text><subparagraph id="idAA3475FC628C40B88F91B6B317C8E3D2"><enum>(A)</enum><text>by striking the item relating to section 3553 and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idEA4D4A6AC2754AC7A2CA6797DED0CB1C" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="section" bold="off">3553. Authority and functions of the Director and the Director of the Cybersecurity and Infrastructure Security Agency.</toc-entry></toc><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="id50EFED2687C34C978FA17BD50F851246"><enum>(B)</enum><text>by striking the item relating to section 3555 and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id4E7285E00E804DE8A2C9C81E9D79BB22" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="section" bold="off">3555. Independent evaluation.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="id5ca46e89337140418b10252b01083a6f" commented="no"><enum>(2)</enum><header>OMB reports</header><text>Section 226(c) of the Cybersecurity Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1524">6 U.S.C. 1524(c)</external-xref>) is amended—</text><subparagraph id="id899f75f426ca4572a9be5d857a274f05" commented="no"><enum>(A)</enum><text>in paragraph (1)(B), in the matter preceding clause (i), by striking <quote>annually thereafter</quote> and inserting <quote>thereafter during the years during which a report is required to be submitted under section 3553(c) of title 44, United States Code</quote>; and</text></subparagraph><subparagraph id="ide0f0f37fc0e74436b3bff404a1de2a3b" commented="no"><enum>(B)</enum><text>in paragraph (2)(B), in the matter preceding clause (i)—</text><clause commented="no" id="idA1FE2F09A93D4A8BAB4B8D178F086B38"><enum>(i)</enum><text>by striking <quote>annually thereafter</quote> and inserting <quote>thereafter during the years during which a report is required to be submitted under section 3553(c) of title 44, United States Code</quote>; and</text></clause><clause commented="no" id="id3019F932DFC849DCBB4A20680143EE84"><enum>(ii)</enum><text>by striking <quote>the report required under section 3553(c) of title 44, United States Code</quote> and inserting <quote>that report</quote>.</text></clause></subparagraph></paragraph><paragraph id="id67677fa2c4584ec6aa44620e78bb3864" commented="no"><enum>(3)</enum><header>NIST responsibilities</header><text>Section 20(d)(3)(B) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g–3(d)(3)(B)</external-xref>) is amended by striking <quote>annual</quote>.</text></paragraph></subsection><subsection id="idcd68f592-b908-4f0e-b39a-81c9faaf0b9b"><enum>(e)</enum><header>Federal system incident response</header><paragraph id="id5c5cfa48-51cd-45bd-9023-4bbefe17bbbe"><enum>(1)</enum><header>In general</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">Chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="USC" display-inline="no-display-inline" id="idB784F698CC5A4419ACEAAA41B5B13444" changed="added" reported-display-style="italic" committee-id="SSGA00"><subchapter id="ide9047b04-f590-4f75-81de-d22a442e594d" style="USC"><enum>IV</enum><header>Federal System Incident Response</header><section section-type="subsequent-section" id="iddfc86ecf-ec25-4d4f-8a86-4d3a758593ca"><enum>3591.</enum><header>Definitions</header><subsection id="id3350d500-8ddf-4ead-9637-4de40c9fb52d"><enum>(a)</enum><header>In general</header><text>Except as provided in subsection (b), the definitions under sections 3502 and 3552 shall apply to this subchapter.</text></subsection><subsection id="id9c972761-7f37-4607-88b7-1f1aa5c5aa1a"><enum>(b)</enum><header>Additional definitions</header><text>As used in this subchapter:</text><paragraph id="id02de21b847474b94aba288314ca580c0"><enum>(1)</enum><header>Appropriate reporting entities</header><text>The term <term>appropriate reporting entities</term> means—</text><subparagraph id="idae4f968079b149f6b25cfb99e3484d2b"><enum>(A)</enum><text>the majority and minority leaders of the Senate;</text></subparagraph><subparagraph id="idca2bc10496ab4c8f85a8a3542db905df"><enum>(B)</enum><text>the Speaker and minority leader of the House of Representatives;</text></subparagraph><subparagraph id="idc91f73b7924241e29e763d6b4de638d0"><enum>(C)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></subparagraph><subparagraph id="ida8c809fd6dd74840ab7eafcde5735442"><enum>(D)</enum><text>the Committee on Oversight and Reform of the House of Representatives;</text></subparagraph><subparagraph id="ida56e23bca90949eaa6e77887cac291e0"><enum>(E)</enum><text>the Committee on Homeland Security of the House of Representatives;</text></subparagraph><subparagraph id="id963aad492f9a4458ae8fc059d6014353"><enum>(F)</enum><text>the appropriate authorization and appropriations committees of Congress;</text></subparagraph><subparagraph id="id7e3a619bdeec44c6a87de3893cce0f36"><enum>(G)</enum><text>the Director;</text></subparagraph><subparagraph id="ida92d2ffbc5684b5aaa62227c2103930f"><enum>(H)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency;</text></subparagraph><subparagraph id="id5fcaf6048ccf46ac87c1b09cb3a845ae"><enum>(I)</enum><text>the National Cyber Director; </text></subparagraph><subparagraph id="id932ae72bbd90485ea8ab4c3f711fe694"><enum>(J)</enum><text>the Comptroller General of the United States; and</text></subparagraph><subparagraph id="idc26476d5700945bcab39349e94b9187b"><enum>(K)</enum><text>the inspector general of any impacted agency.</text></subparagraph></paragraph><paragraph id="id207dedbb415a499595d51fbb2d5272cb"><enum>(2)</enum><header>Awardee</header><text>The term <term>awardee</term>—</text><subparagraph id="idbb19a69b5eb4481e94b41324e845fa1b"><enum>(A)</enum><text>means a person, business, or other entity that receives a grant from, or is a party to a cooperative agreement with, an agency; and</text></subparagraph><subparagraph id="id02629771bd8b4b06b10e2133f26fe389"><enum>(B)</enum><text>includes any subgrantee of a person, business, or other entity described in subparagraph (A).</text></subparagraph></paragraph><paragraph id="ide65bd5a208a147159e60138e2a48b9c1"><enum>(3)</enum><header>Breach</header><text>The term <term>breach</term> means—</text><subparagraph id="id11408AC4F87A4134AD0F8DF831C9CC11"><enum>(A)</enum><text>a compromise of the security, confidentiality, or integrity of data in electronic form that results in unauthorized access to, or an acquisition of, personal information; or</text></subparagraph><subparagraph id="idF244FF01FE064F3EAB0B9E50B9CDE50D"><enum>(B)</enum><text>a loss of data in electronic form that results in unauthorized access to, or an acquisition of, personal information.</text></subparagraph></paragraph><paragraph id="id0eb7fad5d0ba4b47a96f5ff62ac83cdc"><enum>(4)</enum><header>Contractor</header><text>The term <term>contractor</term> means—</text><subparagraph id="id0EAD5D3947764A5F8DC5A1A575950AC0"><enum>(A)</enum><text>a prime contractor of an agency or a subcontractor of a prime contractor of an agency; and</text></subparagraph><subparagraph id="id90112f40a972401c8d913a2335152d1f"><enum>(B)</enum><text>any person or business that collects or maintains information, including personally identifiable information, on behalf of an agency.</text></subparagraph></paragraph><paragraph id="id541a003927824ae5a54dba85189bbd5b"><enum>(5)</enum><header>Federal information</header><text>The term <term>Federal information</term> means information created, collected, processed, maintained, disseminated, disclosed, or disposed of by or for the Federal Government in any medium or form.</text></paragraph><paragraph id="ideb037eaa192a438eafdcbeeb8f1cf61e"><enum>(6)</enum><header>Federal information system</header><text>The term <term>Federal information system</term> means an information system used or operated by an agency, a contractor, or another organization on behalf of an agency.</text></paragraph><paragraph id="id7535664073d34b4a8beda713b3742adb"><enum>(7)</enum><header>Intelligence community</header><text>The term <term>intelligence community</term> has the meaning given the term in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>).</text></paragraph><paragraph id="idf6ca35563b544ea787852d0a033b618e"><enum>(8)</enum><header>Nationwide consumer reporting agency</header><text>The term <term>nationwide consumer reporting agency</term> means a consumer reporting agency described in section 603(p) of the Fair Credit Reporting Act (<external-xref legal-doc="usc" parsable-cite="usc/15/1681a">15 U.S.C. 1681a(p)</external-xref>).</text></paragraph><paragraph id="id8e8838d0c2f745ef99e7295283a16b39"><enum>(9)</enum><header>Vulnerability disclosure</header><text>The term <term>vulnerability disclosure</term> means a vulnerability identified under section 3559B.</text></paragraph></subsection></section><section id="ide036192914414a49856c042bf1f0d5d8"><enum>3592.</enum><header>Notification of breach</header><subsection id="id874153581e85498fa74928bf1def8aa4"><enum>(a)</enum><header>Notification</header><text>As expeditiously as practicable and without unreasonable delay, and in any case not later than 45 days after an agency has a reasonable basis to conclude that a breach has occurred, the head of the agency, in consultation with a senior privacy officer of the agency, shall—</text><paragraph id="idd7528fb6ec8e4c96924f679665317b91"><enum>(1)</enum><text>determine whether notice to any individual potentially affected by the breach is appropriate based on an assessment of the risk of harm to the individual that considers—</text><subparagraph id="idE6E8C59AFA954BB19D9FB6F496124B9B"><enum>(A)</enum><text>the nature and sensitivity of the personally identifiable information affected by the breach;</text></subparagraph><subparagraph id="idB19D6ED342144D9FB08F51F7CB522C9A"><enum>(B)</enum><text>the likelihood of access to and use of the personally identifiable information affected by the breach;</text></subparagraph><subparagraph id="id8B2A170985E34EFFAEF0DBA26754482A"><enum>(C)</enum><text>the type of breach; and</text></subparagraph><subparagraph id="idC5151242ABAB4A47A1497AAE882CEC7B"><enum>(D)</enum><text>any other factors determined by the Director; and</text></subparagraph></paragraph><paragraph id="idfaa91a785a4b4c7496bd07c2ffe4cf51"><enum>(2)</enum><text>as appropriate, provide written notice in accordance with subsection (b) to each individual potentially affected by the breach—</text><subparagraph id="id92025263482341308DD32288A1379AC9"><enum>(A)</enum><text>to the last known mailing address of the individual; or</text></subparagraph><subparagraph id="id7D163CA010F749ED96D2022E6BF562EE"><enum>(B)</enum><text>through an appropriate alternative method of notification that the head of the agency or a designated senior-level individual of the agency selects based on factors determined by the Director.</text></subparagraph></paragraph></subsection><subsection id="id5970a0ce24d8460ab1c016b7d969df7e"><enum>(b)</enum><header>Contents of notice</header><text>Each notice of a breach provided to an individual under subsection (a)(2) shall include—</text><paragraph id="id908dbe0f93f9433bbc2789a374c73f2d"><enum>(1)</enum><text>a brief description of the rationale for the determination that notice should be provided under subsection (a);</text></paragraph><paragraph id="ide94b3cd11bf841658b1dcd80caf2004e"><enum>(2)</enum><text>if possible, a description of the types of personally identifiable information affected by the breach;</text></paragraph><paragraph id="id54c2a8c712d5430b8e150bfa0248ffd2"><enum>(3)</enum><text>contact information of the agency that may be used to ask questions of the agency, which—</text><subparagraph id="id60489491185245A091AC2A7A4B653241"><enum>(A)</enum><text>shall include an e-mail address or another digital contact mechanism; and</text></subparagraph><subparagraph id="id130FB3D9E5034116AEF1E6DC2D2CFA89"><enum>(B)</enum><text>may include a telephone number or a website;</text></subparagraph></paragraph><paragraph id="id2c10694349d84be1b7e2b5b9f47c1f65"><enum>(4)</enum><text>information on any remedy being offered by the agency;</text></paragraph><paragraph id="iddb90f068e4e94e8492155f8486541018"><enum>(5)</enum><text>any applicable educational materials relating to what individuals can do in response to a breach that potentially affects their personally identifiable information, including relevant information to contact Federal law enforcement agencies and each nationwide consumer reporting agency; and</text></paragraph><paragraph id="iddfe49665fdd64af7bf387d5078f11ddd"><enum>(6)</enum><text>any other appropriate information, as determined by the head of the agency or established in guidance by the Director.</text></paragraph></subsection><subsection id="idb6dafb448e68452cba61e32320e37a1d"><enum>(c)</enum><header>Delay of notification</header><paragraph id="id9e711879398d41ebb30b301aa42979a1"><enum>(1)</enum><header>In general</header><text>The Attorney General, the Director of National Intelligence, or the Secretary of Homeland Security may delay a notification required under subsection (a) if the notification would—</text><subparagraph id="idA66092C269AB406E8B28472A8E2FEA0B"><enum>(A)</enum><text>impede a criminal investigation or a national security activity;</text></subparagraph><subparagraph id="id333EC8C0144148A3B380952EA2CBBE4B"><enum>(B)</enum><text>reveal sensitive sources and methods;</text></subparagraph><subparagraph id="id7CC50D347A6D4BD69F024C669E8F7EC1"><enum>(C)</enum><text>cause damage to national security; or</text></subparagraph><subparagraph id="id1367C1155D9C4B8D92C595814D060589"><enum>(D)</enum><text>hamper security remediation actions.</text></subparagraph></paragraph><paragraph id="id5944f5b8a1d84b4b96851263c88072bd"><enum>(2)</enum><header>Documentation</header><subparagraph id="id211e8cd24764451494f388b26b0fe264"><enum>(A)</enum><header>In general</header><text>Any delay under paragraph (1) shall be reported in writing to the Director, the Attorney General, the Director of National Intelligence, the Secretary of Homeland Security, the Director of the Cybersecurity and Infrastructure Security Agency, and the head of the agency and the inspector general of the agency that experienced the breach.</text></subparagraph><subparagraph id="id263e5e04215a46abaf3563cfb328373d"><enum>(B)</enum><header>Contents</header><text>A report required under subparagraph (A) shall include a written statement from the entity that delayed the notification explaining the need for the delay.</text></subparagraph><subparagraph id="id0f6511b934614ba48e3d61f85a768f62"><enum>(C)</enum><header>Form</header><text>The report required under subparagraph (A) shall be unclassified but may include a classified annex.</text></subparagraph></paragraph><paragraph id="id82cbbc0d568e4690859442cd3c99386e"><enum>(3)</enum><header>Renewal</header><text>A delay under paragraph (1) shall be for a period of 60 days and may be renewed.</text></paragraph></subsection><subsection id="id120b2d4c77214098894ef379490aca7e"><enum>(d)</enum><header>Update notification</header><text>If an agency determines there is a significant change in the reasonable basis to conclude that a breach occurred, a significant change to the determination made under subsection (a)(1), or that it is necessary to update the details of the information provided to impacted individuals as described in subsection (b), the agency shall as expeditiously as practicable and without unreasonable delay, and in any case not later than 30 days after such a determination, notify each individual who received a notification pursuant to subsection (a) of those changes.</text></subsection><subsection id="id76be0e149ea74356af0b454664d51bba"><enum>(e)</enum><header>Exemption from notification</header><paragraph id="id73ef292d690140f8b813c96391a34914"><enum>(1)</enum><header>In general</header><text>The head of an agency, in consultation with the inspector general of the agency, may request an exemption from the Director from complying with the notification requirements under subsection (a) if the information affected by the breach is determined by an independent evaluation to be unreadable, including, as appropriate, instances in which the information is—</text><subparagraph id="id25a704dbadbe41d9925a0bbe71096df4"><enum>(A)</enum><text>encrypted; and</text></subparagraph><subparagraph id="ida37ff729207149e687a2e95c2485c1d9"><enum>(B)</enum><text>determined by the Director of the Cybersecurity and Infrastructure Security Agency to be of sufficiently low risk of exposure.</text></subparagraph></paragraph><paragraph id="id067a70e185d14836bd98af7b3582ae8a"><enum>(2)</enum><header>Approval</header><text>The Director shall determine whether to grant an exemption requested under paragraph (1) in consultation with—</text><subparagraph id="id5a0f59a3ea6e41d1936e5dcb9290ee88"><enum>(A)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency; and</text></subparagraph><subparagraph id="idaef7b50cfe1941c7b535b373c5512fc8"><enum>(B)</enum><text>the Attorney General.</text></subparagraph></paragraph><paragraph id="ida73e27e1064443d7a9f29a5ef4e368c4"><enum>(3)</enum><header>Documentation</header><text>Any exemption granted by the Director under paragraph (1) shall be reported in writing to the head of the agency and the inspector general of the agency that experienced the breach and the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph></subsection><subsection id="id5e6c2c70499848f3bb6e91efda1488bc"><enum>(f)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to limit—</text><paragraph id="id4c01a626fc5a4278be9b9db1aa0704c8"><enum>(1)</enum><text>the Director from issuing guidance relating to notifications or the head of an agency from notifying individuals potentially affected by breaches that are not determined to be major incidents; or</text></paragraph><paragraph id="ida0ced500611d49e89b59e0c368e17f45"><enum>(2)</enum><text>the Director from issuing guidance relating to notifications of major incidents or the head of an agency from providing more information than described in subsection (b) when notifying individuals potentially affected by breaches.</text></paragraph></subsection></section><section id="id617d4d3a6b0c4530bbd71c35face436d"><enum>3593.</enum><header>Congressional and Executive Branch reports</header><subsection id="idd6154cf0bea94044b09546bdf06b2141"><enum>(a)</enum><header>Initial report</header><paragraph id="idc5add40818104be198ff273d5923161a"><enum>(1)</enum><header>In general</header><text>Not later than 72 hours after an agency has a reasonable basis to conclude that a major incident occurred, the head of the agency impacted by the major incident shall submit to the appropriate reporting entities a written report and, to the extent practicable, provide a briefing to the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the appropriate authorization and appropriations committees of Congress, taking into account—</text><subparagraph id="idb83b1a2448934499ae6535bba42c0c77"><enum>(A)</enum><text>the information known at the time of the report;</text></subparagraph><subparagraph id="ida3b579ab52144ba085af62d47978e203"><enum>(B)</enum><text>the sensitivity of the details associated with the major incident; and</text></subparagraph><subparagraph id="id4e22d6ce8d2c42c38d5e879a3b7da87b"><enum>(C)</enum><text>the classification level of the information contained in the report.</text></subparagraph></paragraph><paragraph id="id69af3eedda424c2baa2dd8b7a74dd283" commented="no"><enum>(2)</enum><header>Contents</header><text>A report required under paragraph (1) shall include, in a manner that excludes or otherwise reasonably protects personally identifiable information and to the extent permitted by applicable law, including privacy and statistical laws—</text><subparagraph id="idd1fa610f970842c19e3fe78257c95ca7"><enum>(A)</enum><text>a summary of the information available about the major incident, including how the major incident occurred, information indicating that the major incident may be a breach, and information relating to the major incident as a breach, based on information available to agency officials as of the date on which the agency submits the report;</text></subparagraph><subparagraph id="id8a62dd1e07d9414b81988b1e67ca5772"><enum>(B)</enum><text>if applicable, a description and any associated documentation of any circumstances necessitating a delay in or exemption to notification to individuals potentially affected by the major incident under subsection (c) or (e) of section 3592; and</text></subparagraph><subparagraph id="id2f17999cd13b480e810567adc0ddca44"><enum>(C)</enum><text>if applicable, an assessment of the impacts to the agency, the Federal Government, or the security of the United States, based on information available to agency officials on the date on which the agency submits the report.</text></subparagraph></paragraph></subsection><subsection id="idfe73756438e14ff2b7930acaf9435954"><enum>(b)</enum><header>Supplemental report</header><text>Within a reasonable amount of time, but not later than 30 days after the date on which an agency submits a written report under subsection (a), the head of the agency shall provide to the appropriate reporting entities written updates on the major incident and, to the extent practicable, provide a briefing to the congressional committees described in subsection (a)(1), including summaries of—</text><paragraph id="id42b741b57246468baba314dd3ef6b87a"><enum>(1)</enum><text>vulnerabilities, means by which the major incident occurred, and impacts to the agency relating to the major incident;</text></paragraph><paragraph id="id8979400312f74567bfa7a64daa62efd0"><enum>(2)</enum><text>any risk assessment and subsequent risk-based security implementation of the affected information system before the date on which the major incident occurred;</text></paragraph><paragraph id="ide68e1a7e9bca40fe8448ebda6c5ea1ec"><enum>(3)</enum><text>the status of compliance of the affected information system with applicable security requirements at the time of the major incident;</text></paragraph><paragraph id="id43cdaa04d2704ef2839bfeb60184c835"><enum>(4)</enum><text>an estimate of the number of individuals potentially affected by the major incident based on information available to agency officials as of the date on which the agency provides the update;</text></paragraph><paragraph id="idb5a4d2f4f1a54776a0055aab6c3dfa95"><enum>(5)</enum><text>an assessment of the risk of harm to individuals potentially affected by the major incident based on information available to agency officials as of the date on which the agency provides the update;</text></paragraph><paragraph id="iddb8b8287f165401eb6037abeab331bf4"><enum>(6)</enum><text>an update to the assessment of the risk to agency operations, or to impacts on other agency or non-Federal entity operations, affected by the major incident based on information available to agency officials as of the date on which the agency provides the update; and</text></paragraph><paragraph id="id1fdb11a6c1df4dc59ebfe9b4ca0b0cfc"><enum>(7)</enum><text>the detection, response, and remediation actions of the agency, including any support provided by the Cybersecurity and Infrastructure Security Agency under section 3594(d) and status updates on the notification process described in section 3592(a), including any delay or exemption described in subsection (c) or (e), respectively, of section 3592, if applicable.</text></paragraph></subsection><subsection id="idead7fbaf1acd4d3cba3752636c6a4a0f"><enum>(c)</enum><header>Update report</header><text>If the agency determines that there is any significant change in the understanding of the agency of the scope, scale, or consequence of a major incident for which an agency submitted a written report under subsection (a), the agency shall provide an updated report to the appropriate reporting entities that includes information relating to the change in understanding.</text></subsection><subsection id="idd5a7f8b372d94df18a10105857fe23c0"><enum>(d)</enum><header>Annual report</header><text>Each agency shall submit as part of the annual report required under section 3554(c)(1) of this title a description of each major incident that occurred during the 1-year period preceding the date on which the report is submitted.</text></subsection><subsection id="idf97e48a9fa9d455f9b784a0bbed35c62"><enum>(e)</enum><header>Delay and exemption report</header><paragraph id="id4B04B301DAEE47569FB4AD2B6C40191C"><enum>(1)</enum><header>In general</header><text>The Director shall submit to the appropriate notification entities an annual report on all notification delays and exemptions granted pursuant to subsections (c) and (d) of section 3592.</text></paragraph><paragraph id="id4E4086FE22844DAE8FBDDF08A6FD7138"><enum>(2)</enum><header>Component of other report</header><text>The Director may submit the report required under paragraph (1) as a component of the annual report submitted under section 3597(b).</text></paragraph></subsection><subsection id="idb2ded82cbf754d058e7f193c8342b231"><enum>(f)</enum><header>Report delivery</header><text>Any written report required to be submitted under this section may be submitted in a paper or electronic format.</text></subsection><subsection id="id232fe9f71689458ab48cdac32b9c3a37"><enum>(g)</enum><header>Threat briefing</header><paragraph id="id435EE040EC5146668E1987AC105E0438"><enum>(1)</enum><header>In general</header><text>Not later than 7 days after the date on which an agency has a reasonable basis to conclude that a major incident occurred, the head of the agency, jointly with the National Cyber Director and any other Federal entity determined appropriate by the National Cyber Director, shall provide a briefing to the congressional committees described in subsection (a)(1) on the threat causing the major incident.</text></paragraph><paragraph id="idA440D5544DD444E385844B9239F52AE2"><enum>(2)</enum><header>Components</header><text>The briefing required under paragraph (1)—</text><subparagraph id="id9F049270F9BB4AEAB93DE805FAB998DB"><enum>(A)</enum><text>shall, to the greatest extent practicable, include an unclassified component; and</text></subparagraph><subparagraph id="id3BB10BFDDDD440D2B1361458D21B9520"><enum>(B)</enum><text>may include a classified component.</text></subparagraph></paragraph></subsection><subsection id="id2775f553635c4bb2bb3b62b2bda6dcaa"><enum>(h)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to limit—</text><paragraph id="id6f91fe8d75434d0aa252698c864064e6"><enum>(1)</enum><text>the ability of an agency to provide additional reports or briefings to Congress; or</text></paragraph><paragraph id="id6df78e53cfdc4e05b177530d7abe2d0a"><enum>(2)</enum><text>Congress from requesting additional information from agencies through reports, briefings, or other means.</text></paragraph></subsection></section><section id="ida429bf7d0f0f4d1b959d4adecc44a970"><enum>3594.</enum><header>Government information sharing and incident response</header><subsection id="idbaca5b2604e34f06810f7984b95dfa75"><enum>(a)</enum><header>In general</header><paragraph id="id0625d8bc8c2d4c3c9b1512e548d01b9b"><enum>(1)</enum><header>Incident reporting</header><text>The head of each agency shall provide any information relating to any incident, whether the information is obtained by the Federal Government directly or indirectly, to the Cybersecurity and Infrastructure Security Agency and the Office of Management and Budget.</text></paragraph><paragraph id="id0954a79d3307403593484c4722e1d465"><enum>(2)</enum><header>Contents</header><text>A provision of information relating to an incident made by the head of an agency under paragraph (1) shall—</text><subparagraph id="id53bfb18eb4df439b8f46e8eb8df3e240"><enum>(A)</enum><text>include detailed information about the safeguards that were in place when the incident occurred;</text></subparagraph><subparagraph id="id4e9ee241bea04fc380e12e6dcbae9144"><enum>(B)</enum><text>whether the agency implemented the safeguards described in subparagraph (A) correctly;</text></subparagraph><subparagraph id="id4829a2519df041b1baf66b36fd896598"><enum>(C)</enum><text>in order to protect against a similar incident, identify—</text><clause id="id0c4414d8fd684303ace633eed0143c60"><enum>(i)</enum><text>how the safeguards described in subparagraph (A) should be implemented differently; and</text></clause><clause id="id9534ac4d73da45d08f874b74361370e3"><enum>(ii)</enum><text>additional necessary safeguards; and</text></clause></subparagraph><subparagraph id="idD9AC796120874F4BAC57A405D5E5A4B1"><enum>(D)</enum><text>include information to aid in incident response, such as—</text><clause id="idBBB1616D09784DBEB4A63B4EC28FAFD5"><enum>(i)</enum><text>a description of the affected systems or networks;</text></clause><clause id="id7643CAAEF79242848E09EC68FEC53769"><enum>(ii)</enum><text>the estimated dates of when the incident occurred; and</text></clause><clause id="idEA126656C4E543508499801946159C5A"><enum>(iii)</enum><text>information that could reasonably help identify the party that conducted the incident.</text></clause></subparagraph></paragraph><paragraph id="id1fc612d12e534f26b304d91e53415a73"><enum>(3)</enum><header>Information sharing</header><text>To the greatest extent practicable, the Director of the Cybersecurity and Infrastructure Security Agency shall share information relating to an incident with any agencies that may be impacted by the incident.</text></paragraph><paragraph id="id85eeb3adf98b4287935c15d8e0895c49"><enum>(4)</enum><header>National security systems</header><text>Each agency operating or exercising control of a national security system shall share information about incidents with the Director of the Cybersecurity and Infrastructure Security Agency to the extent consistent with standards and guidelines for national security systems issued in accordance with law and as directed by the President. </text></paragraph></subsection><subsection id="idba4d0606718c419c981dda507adb5623"><enum>(b)</enum><header>Compliance</header><text>The information provided under subsection (a) shall take into account the level of classification of the information and any information sharing limitations and protections, such as limitations and protections relating to law enforcement, national security, privacy, statistical confidentiality, or other factors determined by the Director</text></subsection><subsection id="id4e0949f3bb104793ae8513610edffa20"><enum>(c)</enum><header>Incident response</header><text>Each agency that has a reasonable basis to conclude that a major incident occurred involving Federal information in electronic medium or form, as defined by the Director and not involving a national security system, regardless of delays from notification granted for a major incident, shall coordinate with the Cybersecurity and Infrastructure Security Agency regarding—</text><paragraph id="idd7a9583e99f54c52af368709c7b570ec"><enum>(1)</enum><text>incident response and recovery; and</text></paragraph><paragraph id="id73c52c12b26c4603a75fdae58b7690a0"><enum>(2)</enum><text>recommendations for mitigating future incidents.</text></paragraph></subsection></section><section id="idb57d5aaf7bb7478fbfff861515e0a2f6"><enum>3595.</enum><header>Responsibilities of contractors and awardees</header><subsection id="id980b69f7c2694933a3c9d1251d177cd4"><enum>(a)</enum><header>Notification</header><paragraph id="id8773e3f182e64d4e809b2a88d60820cb"><enum>(1)</enum><header>In general</header><text>Unless otherwise specified in a contract, grant, or cooperative agreement, any contractor or awardee of an agency shall report to the agency within the same amount of time such agency is required to report an incident to the Cybersecurity and Infrastructure Security Agency, if the contractor or awardee has a reasonable basis to conclude that—</text><subparagraph id="id79865a13978a49c9b78d6a044b235fa6"><enum>(A)</enum><text>an incident or breach has occurred with respect to Federal information collected, used, or maintained by the contractor or awardee in connection with the contract, grant, or cooperative agreement of the contractor or awardee;</text></subparagraph><subparagraph id="idefe09270142d44cd8ef69358091c4ebf"><enum>(B)</enum><text>an incident or breach has occurred with respect to a Federal information system used or operated by the contractor or awardee in connection with the contract, grant, or cooperative agreement of the contractor or awardee; or</text></subparagraph><subparagraph id="id5c26e5c07bbc4758b3c49691ea9ca81a"><enum>(C)</enum><text>the contractor or awardee has received information from the agency that the contractor or awardee is not authorized to receive in connection with the contract, grant, or cooperative agreement of the contractor or awardee.</text></subparagraph></paragraph><paragraph id="ida0c1192c038545b78e7a4f5c7b98fcfc"><enum>(2)</enum><header>Procedures</header><subparagraph id="id214d719619514b959ad0bc9e01dca96d"><enum>(A)</enum><header>Major incident</header><text>Following a report of a breach or major incident by a contractor or awardee under paragraph (1), the agency, in consultation with the contractor or awardee, shall carry out the requirements under sections 3592, 3593, and 3594 with respect to the major incident.</text></subparagraph><subparagraph id="id71811b76f5b8479290df8a7ac48db0a2"><enum>(B)</enum><header>Incident</header><text>Following a report of an incident by a contractor or awardee under paragraph (1), an agency, in consultation with the contractor or awardee, shall carry out the requirements under section 3594 with respect to the incident.</text></subparagraph></paragraph></subsection><subsection id="idf2efe0399fda4b1c8d5dcc7034c5aadf"><enum>(b)</enum><header>Effective date</header><text>This section shall apply on and after the date that is 1 year after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>. </text></subsection></section><section id="id66b3cc885f234dddb4442d794bf046f8"><enum>3596.</enum><header>Training</header><subsection id="idE18743C0922D4286A1C3A60473F7FF7F"><enum>(a)</enum><header>Covered individual defined</header><text>In this section, the term <quote>covered individual</quote> means an individual who obtains access to Federal information or Federal information systems because of the status of the individual as an employee, contractor, awardee, volunteer, or intern of an agency.</text></subsection><subsection id="id342254d78dd94ebfbbe25e44f59ecb31"><enum>(b)</enum><header>Requirement</header><text>The head of each agency shall develop training for covered individuals on how to identify and respond to an incident, including—</text><paragraph id="idffa489213a744897966b4605d031ff2c"><enum>(1)</enum><text>the internal process of the agency for reporting an incident; and</text></paragraph><paragraph id="idd72a1b0ef6bf47e48fe6262f9403fa40"><enum>(2)</enum><text>the obligation of a covered individual to report to the agency a confirmed major incident and any suspected incident involving information in any medium or form, including paper, oral, and electronic.</text></paragraph></subsection><subsection id="id0a12c95ff351473db1a35239426f02dc"><enum>(c)</enum><header>Inclusion in annual training</header><text>The training developed under subsection (b) may be included as part of an annual privacy or security awareness training of an agency.</text></subsection></section><section id="id57ca4b1fec454926b6e0ed4bfcbddcc4"><enum>3597.</enum><header>Analysis and report on Federal incidents</header><subsection id="ideb4846cb7b5f47338c3562314c1fee0d"><enum>(a)</enum><header>Analysis of federal incidents</header><paragraph id="id655630bd67ef4392a01e8b293ba70e6e"><enum>(1)</enum><header>Quantitative and qualitative analyses</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall develop, in consultation with the Director and the National Cyber Director, and perform continuous monitoring and quantitative and qualitative analyses of incidents at agencies, including major incidents, including—</text><subparagraph id="idc530b6a3e9af4ba0b04106812c3dbf59"><enum>(A)</enum><text>the causes of incidents, including—</text><clause id="id79bec0c246364ba1a9f36179bedb0b9e"><enum>(i)</enum><text>attacker tactics, techniques, and procedures; and</text></clause><clause id="idc56bfb4659f748408792bf1f15848a6b"><enum>(ii)</enum><text>system vulnerabilities, including zero days, unpatched systems, and information system misconfigurations;</text></clause></subparagraph><subparagraph id="idb7342f4fd7c041ed87e8b7ae5cc662e2"><enum>(B)</enum><text>the scope and scale of incidents at agencies;</text></subparagraph><subparagraph id="id469894532d1e460aac7fc64b836991b6"><enum>(C)</enum><text>cross Federal Government root causes of incidents at agencies;</text></subparagraph><subparagraph id="idcb1ed7a98d8c40d4aeb6878b6de946df"><enum>(D)</enum><text>agency incident response, recovery, and remediation actions and the effectiveness of those actions, as applicable; and</text></subparagraph><subparagraph id="id0d0bb2f7a6e8433c8963c86881b63863"><enum>(E)</enum><text>lessons learned and recommendations in responding to, recovering from, remediating, and mitigating future incidents.</text></subparagraph></paragraph><paragraph id="id0e711ca18d6f4481a5bb547e55703df5"><enum>(2)</enum><header>Automated analysis</header><text>The analyses developed under paragraph (1) shall, to the greatest extent practicable, use machine readable data, automation, and machine learning processes.</text></paragraph><paragraph id="id1faf2a6319264f5f848b6479d064880e"><enum>(3)</enum><header>Sharing of data and analysis</header><subparagraph id="idc8d49429e9ea455a8e3c8fcb9a56a45d"><enum>(A)</enum><header>In general</header><text>The Director shall share on an ongoing basis the analyses required under this subsection with agencies and the National Cyber Director to—</text><clause id="id3e5553ecf56f4bdfb179be080cf2a2aa"><enum>(i)</enum><text>improve the understanding of cybersecurity risk of agencies; and</text></clause><clause id="id7b69961208d04facbf1aa489338ea2de"><enum>(ii)</enum><text>support the cybersecurity improvement efforts of agencies.</text></clause></subparagraph><subparagraph id="idc32f8258b5824b1686d3715b4a4f1171"><enum>(B)</enum><header>Format</header><text>In carrying out subparagraph (A), the Director shall share the analyses—</text><clause id="id29838664a42b4f4198898f928bb1f8bd"><enum>(i)</enum><text>in human-readable written products; and</text></clause><clause id="ide118aad71c10499aa3fe9c6a73284978"><enum>(ii)</enum><text>to the greatest extent practicable, in machine-readable formats in order to enable automated intake and use by agencies.</text></clause></subparagraph></paragraph></subsection><subsection id="id473ab22b690e41feb946901f7bb19017"><enum>(b)</enum><header>Annual report on Federal incidents</header><text>Not later than 2 years after the date of enactment of this section, and not less frequently than annually thereafter, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director and other Federal agencies as appropriate, shall submit to the appropriate notification entities a report that includes—</text><paragraph id="id418cc77785c74b2c87966b0623115856"><enum>(1)</enum><text>a summary of causes of incidents from across the Federal Government that categorizes those incidents as incidents or major incidents;</text></paragraph><paragraph id="iddd3f280bb3854b8e8f4648fb07959214"><enum>(2)</enum><text>the quantitative and qualitative analyses of incidents developed under subsection (a)(1), including specific analysis of breaches, on an agency-by-agency basis and comprehensively across the Federal Government; and</text></paragraph><paragraph id="id84c49027c6114c38b011923c2da8b3dc"><enum>(3)</enum><text>an annex for each agency that includes—</text><subparagraph id="id48CD5EBE5071466D88539EAE8A83DFF4"><enum>(A)</enum><text>a description of each major incident; and</text></subparagraph><subparagraph id="idD08142C8CFB2489C837E6FF360A172C1"><enum>(B)</enum><text>the total number of compromises of the agency.</text></subparagraph></paragraph></subsection><subsection id="id90bd9d14dadc4a88aee855aded864adf"><enum>(c)</enum><header>Publication</header><text>A version of each report submitted under subsection (b) shall be made publicly available on the website of the Cybersecurity and Infrastructure Security Agency during the year in which the report is submitted.</text></subsection><subsection id="id8a0981a11de64326a7bcdab9c15e2d67"><enum>(d)</enum><header>Information provided by agencies</header><paragraph id="iddcc3f362be514708ac01fc091645e38b"><enum>(1)</enum><header>In general</header><text>The analysis required under subsection (a) and each report submitted under subsection (b) shall use information provided by agencies under section 3594(a).</text></paragraph><paragraph id="id5670251766f943b8b1035351693aa725"><enum>(2)</enum><header>Noncompliance reports</header><subparagraph id="id68A06D7336FC4BB1A939092DF9B60BD3"><enum>(A)</enum><header>In general</header><text>Subject to subparagraph (B), during any year during which the head of an agency does not provide data for an incident to the Cybersecurity and Infrastructure Security Agency in accordance with section 3594(a), the head of the agency, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the Director, shall submit to the appropriate reporting entities a report that includes—</text><clause id="idE6510444BFE0407CB83EB425C10222CF"><enum>(i)</enum><text>data for the incident; and</text></clause><clause id="id5D528AAD984A45FE9539CFEE9C812471"><enum>(ii)</enum><text>the information described in subsection (b) with respect to the agency.</text></clause></subparagraph><subparagraph id="id95611D110BAF4D67945250B7F8F1E29E"><enum>(B)</enum><header>Exception for national security systems</header><text>The head of an agency that owns or exercises control of a national security system shall not include data for an incident that occurs on a national security system in any report submitted under subparagraph (A).</text></subparagraph></paragraph><paragraph id="id24cd53c4aa2e4920a521ee6191103ff6"><enum>(3)</enum><header>National security system reports</header><subparagraph id="id86DE1AD313744777B5511EDB2F593172"><enum>(A)</enum><header>In general</header><text>Annually, the head of an agency that operates or exercises control of a national security system shall submit a report that includes the information described in subsection (b) with respect to the agency to the extent that the submission is consistent with standards and guidelines for national security systems issued in accordance with law and as directed by the President to—</text><clause id="id03919751DB664947AF54EEBBCBC1054F"><enum>(i)</enum><text>the the majority and minority leaders of the Senate,</text></clause><clause id="idcf611ec355a34c919dc2dfb5eb64758b"><enum>(ii)</enum><text>the Speaker and minority leader of the House of Representatives;</text></clause><clause id="id12d84612728843f984dd133ce2042d33"><enum>(iii)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate;</text></clause><clause id="idE18F04D52EB34C3E9E29636DD47D4A85"><enum>(iv)</enum><text>the Select Committee on Intelligence of the Senate;</text></clause><clause id="idB50B8D8845E942B3BED3B70F1B031CC3"><enum>(v)</enum><text>the Committee on Armed Services of the Senate;</text></clause><clause id="id5a474ddbb3f74bcd968e1624624bc7f6"><enum>(vi)</enum><text>the Committee on Oversight and Reform of the House of Representatives;</text></clause><clause id="id7ca750f0f0e54cedab96a301a8f82ce0"><enum>(vii)</enum><text>the Committee on Homeland Security of the House of Representatives;</text></clause><clause id="id9A3547639E73429EBCBCCFDF858AEA34"><enum>(viii)</enum><text>the Permanent Select Committee on Intelligence of the House of Representatives; and</text></clause><clause id="idC4092A28C1B5421FA4F402604711A34E"><enum>(ix)</enum><text>the Committee on Armed Services of the House of Representatives.</text></clause></subparagraph><subparagraph id="id1B7EF26AAE704C8BBC719D3F88885537"><enum>(B)</enum><header>Classified form</header><text>A report required under subparagraph (A) may be submitted in a classified form.</text></subparagraph></paragraph></subsection><subsection id="id696AF34D3ACC41069ACF86087C1DD61B"><enum>(e)</enum><header>Requirement for compiling information</header><text>In publishing the public report required under subsection (c), the Director of the Cybersecurity and Infrastructure Security Agency shall sufficiently compile information such that no specific incident of an agency can be identified, except with the concurrence of the Director of the Office of Management and Budget and in consultation with the impacted agency.</text></subsection></section><section id="id87b0b898-6995-4478-9399-d017dd5e4ee9"><enum>3598.</enum><header>Major incident definition</header><subsection id="id7fba1c42-0647-4900-9818-5dd8e88b6c49"><enum>(a)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director, shall develop and promulgate guidance on the definition of the term <quote>major incident</quote> for the purposes of subchapter II and this subchapter.</text></subsection><subsection id="id1adc7a15-eb80-4083-868b-e04fd2906228"><enum>(b)</enum><header>Requirements</header><text>With respect to the guidance issued under subsection (a), the definition of the term <term>major incident</term> shall—</text><paragraph id="id875ee793d1b546c08f139c7ac6fdd7d6"><enum>(1)</enum><text>include, with respect to any information collected or maintained by or on behalf of an agency or an information system used or operated by an agency or by a contractor of an agency or another organization on behalf of an agency—</text><subparagraph id="id3f8aeb78f18c42fc8a40c8dea5d1d4c8"><enum>(A)</enum><text>any incident the head of the agency determines is likely to have an impact on—</text><clause id="id086948B1865F4B039D31FFD07CFB7B2A"><enum>(i)</enum><text>the national security, homeland security, or economic security of the United States; or</text></clause><clause id="id5AD601D242A747E59E1400DA9BC73987"><enum>(ii)</enum><text>the civil liberties or public health and safety of the people of the United States;</text></clause></subparagraph><subparagraph id="id3110f6c5017742afa794b607eeffefe3"><enum>(B)</enum><text>any incident the head of the agency determines likely to result in an inability for the agency, a component of the agency, or the Federal Government, to provide 1 or more critical services;</text></subparagraph><subparagraph id="idb21668313c1b4a7b8d0d85f45326ca7c"><enum>(C)</enum><text>any incident that the head of an agency, in consultation with a senior privacy officer of the agency, determines is likely to have a significant privacy impact on 1 or more individual;</text></subparagraph><subparagraph id="idc7f535882c704b0a8c075e9c08ddf759"><enum>(D)</enum><text>any incident that the head of the agency, in consultation with a senior privacy official of the agency, determines is likely to have a substantial privacy impact on a significant number of individuals;</text></subparagraph><subparagraph id="ide711ecefb6ed4a6c90bd6b7583842eee"><enum>(E)</enum><text>any incident the head of the agency determines impacts the operations of a high value asset owned or operated by the agency;</text></subparagraph><subparagraph id="idd1f115af02614fb88169c52cd1e9c189"><enum>(F)</enum><text>any incident involving the exposure of sensitive agency information to a foreign entity, such as the communications of the head of the agency, the head of a component of the agency, or the direct reports of the head of the agency or the head of a component of the agency; and</text></subparagraph><subparagraph id="id82537aa185af4ddab802edd64405f5be"><enum>(G)</enum><text>any other type of incident determined appropriate by the Director;</text></subparagraph></paragraph><paragraph id="idbc70e0eaa92d43a6afb78d89bb236891"><enum>(2)</enum><text>stipulate that the National Cyber Director shall declare a major incident at each agency impacted by an incident if the Director of the Cybersecurity and Infrastructure Security Agency determines that an incident—</text><subparagraph id="id342ae7a276114fedb5fcd7af2edf41d2"><enum>(A)</enum><text>occurs at not less than 2 agencies; and</text></subparagraph><subparagraph id="id871449290a8940c4ae4eb81a123fe1a7"><enum>(B)</enum><text>is enabled by—</text><clause id="idCA8053C2025649F1B5710DE24CA67DDA"><enum><added-phrase committee-id="SSGA00" reported-display-style="italic">(i)</added-phrase></enum><text>a common technical root cause, such as a supply chain compromise, a common software or hardware vulnerability; or</text></clause><clause id="idE0A9262A47DC4D53AB29A0BFF768D985"><enum>(ii)</enum><text>the related activities of a common threat actor; and</text></clause></subparagraph></paragraph><paragraph id="idcc0ff011-6991-446b-bd43-f93f7b076234"><enum>(3)</enum><text>stipulate that, in determining whether an incident constitutes a major incident because that incident—</text><subparagraph id="id40178382-797c-4b90-ae61-fb622fa2c4fb"><enum>(A)</enum><text>is any incident described in paragraph (1), the head of an agency shall consult with the Director of the Cybersecurity and Infrastructure Security Agency;</text></subparagraph><subparagraph id="id0bc1cef2-9df7-4183-b608-34918b122fd3"><enum>(B)</enum><text>is an incident described in paragraph (1)(A), the head of the agency shall consult with the National Cyber Director; and</text></subparagraph><subparagraph id="id92db26a4-ad92-41a2-90a5-cf7bfaab974c"><enum>(C)</enum><text>is an incident described in subparagraph (C) or (D) of paragraph (1), the head of the agency shall consult with—</text><clause id="id99b78131-7dd5-478d-95a1-1f3b6235a020"><enum>(i)</enum><text>the Privacy and Civil Liberties Oversight Board; and</text></clause><clause id="idae4515e9-e357-4aa7-9b73-3723d6806316"><enum>(ii)</enum><text>the Executive Director of the Federal Trade Commission.</text></clause></subparagraph></paragraph></subsection><subsection id="id975dc5b8-a5f8-4b6e-987f-3e651456c538"><enum>(c)</enum><header>Significant number of individuals</header><text>In determining what constitutes a significant number of individuals under subsection (b)(1)(D), the Director—</text><paragraph id="id3B577563E9204F75BD6F05E344C18D56"><enum>(1)</enum><text>may determine a threshold for a minimum number of individuals that constitutes a significant amount; and</text></paragraph><paragraph id="idB63DF28583AE4D33B930A4B41564EE04"><enum>(2)</enum><text>may not determine a threshold described in paragraph (1) that exceeds 5,000 individuals.</text></paragraph></subsection><subsection id="id796dba47-10fe-4d9c-b421-c79027385e4c"><enum>(d)</enum><header>Evaluation and updates</header><text>Not later than 2 years after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, and not less frequently than every 2 years thereafter, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives an evaluation, which shall include—</text><paragraph id="id4afee6da-8f83-4099-b28a-bd056e3e9c28"><enum>(1)</enum><text>an update, if necessary, to the guidance issued under subsection (a);</text></paragraph><paragraph id="id9d83a8d7-280b-4a94-8555-605c7170e484"><enum>(2)</enum><text>the definition of the term <quote>major incident</quote> included in the guidance issued under subsection (a); and</text></paragraph><paragraph id="idd254c48c-767a-42c2-a4cd-9845872bcf5e"><enum>(3)</enum><text>an explanation of, and the analysis that led to, the definition described in paragraph (2).</text></paragraph></subsection></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block></paragraph><paragraph id="id1026a007-920c-448f-aeca-0fee1adf5cb7"><enum>(2)</enum><header>Clerical amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="OLC" id="idf92947d1-faff-41c1-be94-2c40f557e8b3" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="subchapter" idref="id6239B413F1CE4BEFA7315E330430A40D">SUBCHAPTER IV—Federal System Incident Response </toc-entry><toc-entry level="section" idref="idDCD8135600B84C439AA7D352E8D01733">3591. Definitions. </toc-entry><toc-entry level="section" idref="ide036192914414a49856c042bf1f0d5d8">3592. Notification of breach. </toc-entry><toc-entry level="section" idref="id617d4d3a6b0c4530bbd71c35face436d">3593. Congressional and Executive Branch reports. </toc-entry><toc-entry level="section" idref="ida429bf7d0f0f4d1b959d4adecc44a970">3594. Government information sharing and incident response. </toc-entry><toc-entry level="section" idref="idb57d5aaf7bb7478fbfff861515e0a2f6">3595. Responsibilities of contractors and awardees. </toc-entry><toc-entry level="section" idref="id66b3cc885f234dddb4442d794bf046f8">3596. Training. </toc-entry><toc-entry level="section" idref="id57ca4b1fec454926b6e0ed4bfcbddcc4">3597. Analysis and report on Federal incidents. </toc-entry><toc-entry level="section" idref="id6EC29ACEA25D49DAA12065E86163CEAD">3598. Major incident definition.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id776995ad-0aee-4a02-a889-dc45a0ca9f00"><enum>102.</enum><header>Amendments to subtitle III of title 40</header><subsection id="id02538233-5476-4eae-884d-c36cf8152d89"><enum>(a)</enum><header>Information Technology Modernization Centers of Excellence Program Act</header><text>Section 2(c)(4)(A)(ii) of the Information Technology Modernization Centers of Excellence Program Act (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note) is amended by striking the period at the end and inserting <quote>, which shall be provided in coordination with the Director of the Cybersecurity and Infrastructure Security Agency.</quote>.</text></subsection><subsection id="id7f8ddd40-95a7-4835-bccf-2398d512d3ec"><enum>(b)</enum><header>Modernizing Government Technology</header><text>Subtitle G of title X of Division A of the National Defense Authorization Act for Fiscal Year 2018 (<external-xref legal-doc="usc" parsable-cite="usc/40/11301">40 U.S.C. 11301</external-xref> note) is amended—</text><paragraph id="id87baa29b-9882-4165-9dfa-a18bf96c29e8"><enum>(1)</enum><text>in section 1077(b)—</text><subparagraph id="id404718c8-b3ff-421e-9c66-412fed3bab9b"><enum>(A)</enum><text>in paragraph (5)(A), by inserting <quote>improving the cybersecurity of systems and</quote> before <quote>cost savings activities</quote>; and</text></subparagraph><subparagraph id="ide97afae1-664d-447d-b86e-e96af4414826"><enum>(B)</enum><text>in paragraph (7)—</text><clause id="id37243a2d-43c2-49f9-bf4b-9b74095cfd77"><enum>(i)</enum><text>in the paragraph heading, by striking <quote><header-in-text style="OLC" level="paragraph">cio</header-in-text></quote> and inserting <quote><header-in-text style="OLC" level="paragraph">CIO</header-in-text></quote>;</text></clause><clause id="id31a29d70-15c5-4f90-8d66-e8c9bfa1373c"><enum>(ii)</enum><text>by striking <quote>In evaluating projects</quote> and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id41a6b72f-4da7-4a7a-accb-b3faaddc273f" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="idda145836-3cfc-44fd-9641-759addd1f294"><enum>(A)</enum><header>Consideration of guidance</header><text>In evaluating projects</text></subparagraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id00ea2c15-20bb-4397-9f18-46d9f7fa3cab"><enum>(iii)</enum><text>in subparagraph (A), as so designated, by striking <quote>under section 1094(b)(1)</quote> and inserting <quote>by the Director</quote>; and</text></clause><clause id="id3fee7549-dc27-4f1e-abd3-18e3dbf9ae2a"><enum>(iv)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idf237174c-bf25-4e3c-9182-b5a4e32fe521" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="idd149ee0677ab42fab5da6219e509ea52"><enum>(B)</enum><header>Consultation</header><text>In using funds under paragraph (3)(A), the Chief Information Officer of the covered agency shall consult with the necessary stakeholders to ensure the project appropriately addresses cybersecurity risks, including the Director of the Cybersecurity and Infrastructure Security Agency, as appropriate.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph></paragraph><paragraph id="id09169643-b864-4989-af0d-181d4fba944e"><enum>(2)</enum><text>in section 1078—</text><subparagraph id="id7e94145a-9675-448d-8566-e4757d614aea"><enum>(A)</enum><text>by striking subsection (a) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9a48d8a9-a6c1-4f3c-8a8a-c2b18679ebe5" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="id3984aa7d-2a43-4c17-8b0d-eff95f910c97"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id8bf73629-f726-4e00-990b-7b405f54a2df"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given the term in section 551 of title 5, United States Code.</text></paragraph><paragraph id="idb20c18eb-036b-43be-9846-a3b74485f782"><enum>(2)</enum><header>High value asset</header><text>The term <term>high value asset</term> has the meaning given the term in section 3552 of title 44, United States Code.</text></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="id612aeed0-6b66-4873-9409-1385a52140f5"><enum>(B)</enum><text>in subsection (b), by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id3a1c4f60-0c09-4ddf-ae63-ea7b3d78c6fb" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id38e14282-f7cc-4ee2-9c77-8e3abc3ff188"><enum>(8)</enum><header>Proposal evaluation</header><text>The Director shall—</text><subparagraph id="idef7c65c8-14ad-4c2f-9cfb-1eacaa6ab937"><enum>(A)</enum><text>give consideration for the use of amounts in the Fund to improve the security of high value assets; and</text></subparagraph><subparagraph id="id700af71e-a2ab-46c5-95d8-71c514ba4be2"><enum>(B)</enum><text>require that any proposal for the use of amounts in the Fund includes a cybersecurity plan, including a supply chain risk management plan, to be reviewed by the member of the Technology Modernization Board described in subsection (c)(5)(C).</text></subparagraph></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph><subparagraph id="id34fd2f9a-6618-40e9-a5f1-13d2edbc3eaa"><enum>(C)</enum><text>in subsection (c)—</text><clause id="id754c3b6b-692e-4248-b089-3fd5b4356c43"><enum>(i)</enum><text>in paragraph (2)(A)(i), by inserting <quote>, including a consideration of the impact on high value assets</quote> after <quote>operational risks</quote>;</text></clause><clause id="idb5d95007-95ca-4f21-8c46-5b62a08f53f0"><enum>(ii)</enum><text>in paragraph (5)—</text><subclause id="ida7840cfa-d7a7-4a29-b1f8-690523ef4022"><enum>(I)</enum><text>in subparagraph (A), by striking <quote>and</quote> at the end;</text></subclause><subclause id="idf134a737-1501-444c-b907-5ca2777d2aea"><enum>(II)</enum><text>in subparagraph (B), by striking the period at the end and inserting <quote>and</quote>; and</text></subclause><subclause id="id38caeda0-c0ab-41e8-91ab-63601aa9b190"><enum>(III)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="ida7e885d5-e6ab-4df6-8d04-7ac72d618816" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id84e46c49-1df4-4b6c-903b-d8976b05f8a4"><enum>(C)</enum><text>a senior official from the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, appointed by the Director.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subclause></clause><clause id="id0662353c-024b-477a-a9cd-32d46487129d"><enum>(iii)</enum><text>in paragraph (6)(A), by striking <quote>shall be—</quote> and all that follows through <quote>4 employees</quote> and inserting <quote>shall be 4 employees</quote>.</text></clause></subparagraph></paragraph></subsection><subsection id="idd4c4417b-7672-4124-98a4-8f12b76ca75b"><enum>(c)</enum><header>Subchapter I</header><text>Subchapter I of subtitle III of title 40, United States Code, is amended—</text><paragraph id="idc4293443-38f7-4688-8295-a318b78e69f8"><enum>(1)</enum><text>in section 11302—</text><subparagraph id="id3692ce39a4d94bfbbb2492dc67ecd87e"><enum>(A)</enum><text>in subsection (b), by striking <quote>use, security, and disposal of</quote> and inserting <quote>use, and disposal of, and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director, promote and improve the security of,</quote>; </text></subparagraph><subparagraph id="id82e44b372d974a59a469de9f50841a74"><enum>(B)</enum><text>in subsection (c)—</text><clause id="id146a99850b4a4d30aea134a152024e50"><enum>(i)</enum><text>in paragraph (3)—</text><subclause id="id668957ef4f8044ac82efd160e90e68d2"><enum>(I)</enum><text>in subparagraph (A)—</text><item id="idbb8867c7a22e432d8f31fa0888e90042"><enum>(aa)</enum><text>by striking <quote>including data</quote> and inserting</text><quoted-block style="OLC" display-inline="yes-display-inline" id="ideb172d6793c54cb1a752a4bd06441a00" changed="added" reported-display-style="italic" committee-id="SSGA00"><text>which shall—</text><clause id="id2540b85036b942fabc613d2e772f8216"><enum>(i)</enum><text>include data</text></clause><after-quoted-block>;</after-quoted-block></quoted-block></item><item id="idc89d2fb8da5b4eeeb8b6d618528c0180"><enum>(bb)</enum><text>in clause (i), as so designated, by striking <quote>, and performance</quote> and inserting <quote>security, and performance; and</quote>; and</text></item><item id="id38ac39822ece4cff81eda25b94f4ece6"><enum>(cc)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id270972c113634d39b978bfb229a91d56" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="idcf9f95b290b54b5da62978514c31d762"><enum>(ii)</enum><text>specifically denote cybersecurity funding under the risk-based cyber budget model developed pursuant to section 3553(a)(7) of title 44.</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></item></subclause><subclause id="id84cf270749cc41b29fbaf1208815729b"><enum>(II)</enum><text>in subparagraph (B), adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id574d97ae9ebc4e0896c6abcbffcb07c2" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id2b963639336b40e489deb3979987330c"><enum>(iii)</enum><text>The Director shall provide to the National Cyber Director any cybersecurity funding information described in subparagraph (A)(ii) that is provided to the Director under clause (ii) of this subparagraph.</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></subclause></clause><clause id="id6eeea697743a43b8bf66c5e0463787ae"><enum>(ii)</enum><text>in paragraph (4)(B), in the matter preceding clause (i), by inserting <quote>not later than 30 days after the date on which the review under subparagraph (A) is completed,</quote> before <quote>the Administrator</quote>; </text></clause></subparagraph><subparagraph id="id08db223a30a040f89d55ca78772e720b"><enum>(C)</enum><text>in subsection (f)—</text><clause id="id9559297e3e8043c5bf96783274fb146c"><enum>(i)</enum><text>by striking <quote>heads of executive agencies to develop</quote> and inserting “heads of executive agencies to—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id14d4b08ff8bc4f95beef62cf7a15903b" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id17d92884c9924e2185024b549ea00765"><enum>(1)</enum><text>develop</text></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></clause><clause id="id705f4e738cae4c9d8c0676c2cc706280"><enum>(ii)</enum><text>in paragraph (1), as so designated, by striking the period at the end and inserting <quote>; and</quote>; and</text></clause><clause id="idf48bb39675c54f1581232750d1f0b5d6"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idf7086450744e4b46957fbfc6c2a3ea4a" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="idd188fb063d8744ce8bca5ec3e4e9d8ba"><enum>(2)</enum><text>consult with the Director of the Cybersecurity and Infrastructure Security Agency for the development and use of supply chain security best practices.</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id87362d51079940d6a8e220f3aec68c21"><enum>(D)</enum><text>in subsection (h), by inserting <quote>, including cybersecurity performances,</quote> after <quote>the performances</quote>; and</text></subparagraph></paragraph><paragraph id="id717fee8743964832ba67b9a5d244c1e7"><enum>(2)</enum><text>in section 11303(b)—</text><subparagraph id="id0af485239c6340f986ca0abbea196a09"><enum>(A)</enum><text>in paragraph (2)(B)—</text><clause id="idcd839e54b32f4b118797fa01c2aafa02"><enum>(i)</enum><text>in clause (i), by striking <quote>or</quote> at the end;</text></clause><clause id="idec12addefb554d07b3c82de701d66739"><enum>(ii)</enum><text>in clause (ii), by adding <quote>or</quote> at the end; and</text></clause><clause id="id32f5c3ee166a4534a0816a20309d1eed"><enum>(iii)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9d865657954b4a5fad382e8893b7565d" changed="added" reported-display-style="italic" committee-id="SSGA00"><clause id="id59fbd48b2cbe46c382f2fc21019e3403"><enum>(iii)</enum><text>whether the function should be performed by a shared service offered by another executive agency;</text></clause><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph id="id7fcadd5fa33b42d1bbb14bce161927a7"><enum>(B)</enum><text>in paragraph (5)(B)(i), by inserting <quote>, while taking into account the risk-based cyber budget model developed pursuant to section 3553(a)(7) of title 44</quote> after <quote>title 31</quote>.</text></subparagraph></paragraph></subsection><subsection id="ide6f81aa481724f5ab0c6e5683f6d703f"><enum>(d)</enum><header>Subchapter II</header><text>Subchapter II of subtitle III of title 40, United States Code, is amended—</text><paragraph id="idc1139c9824ea4d609d6a9a61856c291a"><enum>(1)</enum><text>in section 11312(a), by inserting <quote>, including security risks</quote> after <quote>managing the risks</quote>;</text></paragraph><paragraph id="idc410ea58249c4d8c87037586b5d01037"><enum>(2)</enum><text>in section 11313(1), by striking <quote>efficiency and effectiveness</quote> and inserting <quote>efficiency, security, and effectiveness</quote>;</text></paragraph><paragraph id="id3441867b22bb4573859895ec1770caec"><enum>(3)</enum><text>in section 11315, by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idaa969ac062974d028e48cba279e93402" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="id907d96559bf844a5a2dbcaf5908fd37c"><enum>(d)</enum><header>Component agency chief information officers</header><text>The Chief Information Officer or an equivalent official of a component agency shall report to—</text><paragraph id="id8ba5f76c31f44b508ea0fc8786f69777"><enum>(1)</enum><text>the Chief Information Officer designated under section 3506(a)(2) of title 44 or an equivalent official of the agency of which the component agency is a component; and</text></paragraph><paragraph id="id18a248d104764c9691469a7680ec963a"><enum>(2)</enum><text>the head of the component agency.</text></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></paragraph><paragraph id="id01B2D7A31D8A41D094A09CAB6D0F3ADD"><enum>(4)</enum><text>in section 11317, by inserting <quote>security,</quote> before <quote>or schedule</quote>; and</text></paragraph><paragraph id="id8042992f4476486eb725154d700fec03"><enum>(5)</enum><text>in section 11319(b)(1), in the paragraph heading, by striking <quote><header-in-text style="USC" level="paragraph">CIOS</header-in-text></quote> and inserting <quote><header-in-text style="USC" level="paragraph">Chief Information Officers</header-in-text></quote>.</text></paragraph></subsection><subsection id="idaba2682c44b34b18aa3217c4b7308976"><enum>(e)</enum><header>Subchapter III</header><text>Section 11331 of title 40, United States Code, is amended—</text><paragraph id="idc5c54935e23c4fb5b883e487fbb44333"><enum>(1)</enum><text>in subsection (a), by striking <quote>section 3532(b)(1)</quote> and inserting <quote>section 3552(b)</quote>;</text></paragraph><paragraph id="id4644a2ceee8a40d597b792138e82efe8"><enum>(2)</enum><text>in subsection (b)(1)(A)—</text><subparagraph id="id65a9d10c28dc4f29828a96c0e6c0c1f0"><enum>(A)</enum><text>by striking <quote>in consultation</quote> and inserting <quote>in coordination</quote>; and</text></subparagraph><subparagraph id="id1496b6e081cb42d9932d5f2e4520a885"><enum>(B)</enum><text>by striking <quote>the Secretary of Homeland Security</quote> and inserting <quote>the Director of the Cybersecurity and Infrastructure Security Agency</quote>; </text></subparagraph></paragraph><paragraph id="idffbaad5cfc134278918a55dbd86cc405"><enum>(3)</enum><text>by striking subsection (c) and inserting the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id161298ec02944db7aa3cda0d0e81ce2b" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="idca52cfc0101740a9a2eb4eba26357bf0"><enum>(c)</enum><header>Application of more stringent standards</header><paragraph id="idc710cfaf483c4748a0e3f9eef19211b7"><enum>(1)</enum><header>In general</header><text>The head of an agency shall—</text><subparagraph id="ida4ce8fc82f9b44458f40128e9b5c28f0"><enum>(A)</enum><text>evaluate, in consultation with the senior agency information security officers, the need to employ standards for cost-effective, risk-based information security for all systems, operations, and assets within or under the supervision of the agency that are more stringent than the standards promulgated by the Director under this section, if such standards contain, at a minimum, the provisions of those applicable standards made compulsory and binding by the Director; and</text></subparagraph><subparagraph id="id29dee9070b424981bb9f72e36865c717"><enum>(B)</enum><text>to the greatest extent practicable and if the head of the agency determines that the standards described in subparagraph (A) are necessary, employ those standards.</text></subparagraph></paragraph><paragraph id="idac10ce5d2fc543f8b79e082634405457"><enum>(2)</enum><header>Evaluation of more stringent standards</header><text>In evaluating the need to employ more stringent standards under paragraph (1), the head of an agency shall consider available risk information, such as—</text><subparagraph id="id4215915e8f1240e6a52a393b9ce8bb97"><enum>(A)</enum><text>the status of cybersecurity remedial actions of the agency;</text></subparagraph><subparagraph id="id6f39cb3c137c459085a0a78547af0191"><enum>(B)</enum><text>any vulnerability information relating to agency systems that is known to the agency;</text></subparagraph><subparagraph id="id7979b9720bb040b7af36845a0bd55921"><enum>(C)</enum><text>incident information of the agency;</text></subparagraph><subparagraph id="id185055fd5b3248c99fad0fd950742e4a"><enum>(D)</enum><text>information from—</text><clause id="idfd601d6b50be42d7bb6a1ac3c638b6ce"><enum>(i)</enum><text>penetration testing performed under section 3559A of title 44; and</text></clause><clause id="id9e721d41bab84567a92e0f91bf54227d"><enum>(ii)</enum><text>information from the vulnerability disclosure program established under section 3559B of title 44;</text></clause></subparagraph><subparagraph id="id39668b39d27040c593a85b581b8d1a6b"><enum>(E)</enum><text>agency threat hunting results under section 205 of the Federal Information Security Modernization Act of 2021;</text></subparagraph><subparagraph id="id35dd90a3fb204bd6bf1968c69eccb2b7"><enum>(F)</enum><text>Federal and non-Federal threat intelligence;</text></subparagraph><subparagraph id="id6f0431966e6f434a922696d0ed6cd6b6"><enum>(G)</enum><text>data on compliance with standards issued under this section;</text></subparagraph><subparagraph id="idfefec75814b14016ba24fa08d8444451"><enum>(H)</enum><text>agency system risk assessments performed under section 3554(a)(1)(A) of title 44; and</text></subparagraph><subparagraph id="idbbab1f01f3654868a779e97be17bff9a"><enum>(I)</enum><text>any other information determined relevant by the head of the agency.</text></subparagraph></paragraph></subsection><after-quoted-block>;</after-quoted-block></quoted-block></paragraph><paragraph id="idcb1ca1cca3824450b6bb8c9ead30b20d"><enum>(4)</enum><text>in subsection (d)(2)—</text><subparagraph id="ide46a134bcd7045b290f6cf626d600dcf"><enum>(A)</enum><text>in the paragraph heading, by striking <quote><header-in-text style="USC" level="paragraph">Notice and comment</header-in-text></quote> and inserting <quote><header-in-text style="USC" level="paragraph">Consultation, notice, and comment</header-in-text></quote>;</text></subparagraph><subparagraph id="id8e1deb86d6714714bb31fc13672624bd"><enum>(B)</enum><text>by inserting <quote>promulgate,</quote> before <quote>significantly modify</quote>; and</text></subparagraph><subparagraph id="id41c3a24ac8a94c6fbea38360c01a29e5"><enum>(C)</enum><text>by striking <quote>shall be made after the public is given an opportunity to comment on the Director’s proposed decision.</quote> and inserting “shall be made—</text><quoted-block style="OLC" display-inline="no-display-inline" id="id50d9fa7be9804646a8e1eacf8b9e17f2" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="id1917339a699f401081c6c593d680e650"><enum>(A)</enum><text>for a decision to significantly modify or not promulgate such a proposed standard, after the public is given an opportunity to comment on the Director’s proposed decision;</text></subparagraph><subparagraph id="idb7afcbad37344d5cad785b5e35d70091"><enum>(B)</enum><text>in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency;</text></subparagraph><subparagraph id="id88eeba71b0684b5c9563965756f267ba"><enum>(C)</enum><text>considering the Federal risk assessments performed under section 3553(i) of title 44; and</text></subparagraph><subparagraph id="id751ac4c8646f4dce86d1f2ed65baa090"><enum>(D)</enum><text>considering the extent to which the proposed standard reduces risk relative to the cost of implementation of the standard.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="iddc16271d45bd42778a81079dcc606cf3"><enum>(5)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id78ffdaa33f7049b1a0e33cb2da2e2349" changed="added" reported-display-style="italic" committee-id="SSGA00"><subsection id="id15bc5ff2d6644c22add9cf52767336cb"><enum>(e)</enum><header>Review of office of management and budget guidance and policy</header><paragraph id="id92c4aad4650741f0a10a32ddce2eee43"><enum>(1)</enum><header>Conduct of review</header><subparagraph id="idA7E9150EBEB94255A4451D4048FB9033"><enum>(A)</enum><header>In general</header><text>Not less frequently than once every 3 years, the Director of the Office of Management and Budget, in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency shall review the efficacy of the guidance and policy promulgated by the Director in reducing cybersecurity risks, including an assessment of the requirements for agencies to report information to the Director, and determine whether any changes to that guidance or policy is appropriate.</text></subparagraph><subparagraph id="idef100b33ded544898cd1c76eca58875e"><enum>(B)</enum><header>Federal risk assessments</header><text>In conducting the review described in subparagraph (A), the Director shall consider the Federal risk assessments performed under section 3553(i) of title 44.</text></subparagraph></paragraph><paragraph id="id2fd9d139f3444d42835ecb332455a44a"><enum>(2)</enum><header>Updated guidance</header><text>Not later than 90 days after the date on which a review is completed under paragraph (1), the Director of the Office of Management and Budget shall issue updated guidance or policy to agencies determined appropriate by the Director, based on the results of the review.</text></paragraph><paragraph id="id0398b896d2ab48758353ab433ae07200"><enum>(3)</enum><header>Public report</header><text>Not later than 30 days after the date on which a review is completed under paragraph (1), the Director of the Office of Management and Budget shall make publicly available a report that includes—</text><subparagraph id="id74edb63719574b8a9f560e579508aa4a"><enum>(A)</enum><text>an overview of the guidance and policy promulgated under this section that is currently in effect;</text></subparagraph><subparagraph id="idc1e98226365849c7856e7205515c0af5"><enum>(B)</enum><text>the cybersecurity risk mitigation, or other cybersecurity benefit, offered by each guidance or policy document described in subparagraph (A); and</text></subparagraph><subparagraph id="idbc1bf4736ac8496c85b53d7eaef1e9cb"><enum>(C)</enum><text>a summary of the guidance or policy to which changes were determined appropriate during the review and what the changes are anticipated to include.</text></subparagraph></paragraph><paragraph id="idf3254e40a6944b458f79a887cb930b64"><enum>(4)</enum><header>Congressional briefing</header><text>Not later than 30 days after the date on which a review is completed under paragraph (1), the Director shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a briefing on the review.</text></paragraph></subsection><subsection id="id5d4ac59cd2b249f889b9509997a74ef3"><enum>(f)</enum><header>Automated standard implementation verification</header><text>When the Director of the National Institute of Standards and Technology issues a proposed standard pursuant to paragraphs (2) and (3) of section 20(a) of the National Institute of Standards and Technology Act (<external-xref legal-doc="usc" parsable-cite="usc/15/278g-3">15 U.S.C. 278g–3(a)</external-xref>), the Director of the National Institute of Standards and Technology shall consider developing and, if appropriate and practical, develop, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, specifications to enable the automated verification of the implementation of the controls within the standard.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id8ccc627da4bd46e0bdd48489ba7c6485"><enum>103.</enum><header>Actions to enhance Federal incident response</header><subsection id="id2cad402e61cc443d9c0ba8abf204cac4"><enum>(a)</enum><header>Responsibilities of the cybersecurity and infrastructure security agency</header><paragraph id="idbcb8b349ff6a48ff841d16c7e39455f3"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall—</text><subparagraph id="id400dc1440f794dab957a98c1b3ff0a9a"><enum>(A)</enum><text>develop a plan for the development of the analysis required under section 3597(a) of title 44, United States Code, as added by this Act, and the report required under subsection (b) of that section that includes—</text><clause id="idc4766ad0104e45d3bd873ff6d884637c"><enum>(i)</enum><text>a description of any challenges the Director anticipates encountering; and</text></clause><clause id="id1f4e24ebd6e24d07b6649f412041f285"><enum>(ii)</enum><text>the use of automation and machine-readable formats for collecting, compiling, monitoring, and analyzing data; and</text></clause></subparagraph><subparagraph id="idb9e3deb51aae4e0991d0de3c1aff4be6"><enum>(B)</enum><text>provide to the appropriate congressional committees a briefing on the plan developed under subparagraph (A).</text></subparagraph></paragraph><paragraph id="ida35c481b2ad24c56bfafd76650112440"><enum>(2)</enum><header>Briefing</header><text>Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the appropriate congressional committees a briefing on—</text><subparagraph id="id4bea7f7775c7458aba6d6bc10d3177dc"><enum>(A)</enum><text>the execution of the plan required under paragraph (1)(A); and</text></subparagraph><subparagraph id="idbb84da2400694a87a520c7aacef98441"><enum>(B)</enum><text>the development of the report required under section 3597(b) of title 44, United States Code, as added by this Act.</text></subparagraph></paragraph></subsection><subsection id="id6be5fc8e3d754bcb9014243f21943f82"><enum>(b)</enum><header>Responsibilities of the director of the office of management and budget</header><paragraph id="id0cc1d4b32d9b4e72a827f37437ea723a"><enum>(1)</enum><header>FISMA</header><text>Section 2 of the Federal Information Security Modernization Act of 2014 (<external-xref legal-doc="usc" parsable-cite="usc/44/3554">44 U.S.C. 3554</external-xref> note) is amended—</text><subparagraph id="id8726caca7e1247ae8738bcb52504f52d"><enum>(A)</enum><text>by striking subsection (b); and</text></subparagraph><subparagraph id="idd5135c327a774589a7aeb6cf178f30d2"><enum>(B)</enum><text>by redesignating subsections (c) through (f) as subsections (b) through (e), respectively.</text></subparagraph></paragraph><paragraph id="idbff167a7250f4fe58e27bf78a92a294c"><enum>(2)</enum><header>Incident data sharing</header><subparagraph id="id188bf89d7f8d4c318259a3b2ab84783e"><enum>(A)</enum><header>In general</header><text>The Director shall develop guidance, to be updated not less frequently than once every 2 years, on the content, timeliness, and format of the information provided by agencies under section 3594(a) of title 44, United States Code, as added by this Act.</text></subparagraph><subparagraph id="id107da5e3258c41a690b9525df1fcc04c"><enum>(B)</enum><header>Requirements</header><text>The guidance developed under subparagraph (A) shall—</text><clause id="id5db858df54184b3895e06be5bff8de25"><enum>(i)</enum><text>prioritize the availability of data necessary to understand and analyze—</text><subclause id="idc7ddd1326cf3444abcaf88e4f1ab0b13"><enum>(I)</enum><text>the causes of incidents;</text></subclause><subclause id="iddaf887a0212d4e03b0a3c0d8f7063966"><enum>(II)</enum><text>the scope and scale of incidents within the environments and systems of an agency;</text></subclause><subclause id="idb691d2e254ea475daa6edea4f52365b6"><enum>(III)</enum><text>a root cause analysis of incidents that—</text><item id="id1DD6A7FE044340A991B216E73003E48A"><enum>(aa)</enum><text>are common across the Federal Government; or</text></item><item id="id3D7C0DF8841E424FA73EA399F62554C5"><enum>(bb)</enum><text>have a Government-wide impact;</text></item></subclause><subclause id="id626e4daec9ff4110ba9986712ca8537d"><enum>(IV)</enum><text>agency response, recovery, and remediation actions and the effectiveness of those actions; and</text></subclause><subclause id="id07eaf91e535344f58e2ae6c9f1199e61"><enum>(V)</enum><text>the impact of incidents;</text></subclause></clause><clause id="id1b095495e84248129a3630a96e094bc2"><enum>(ii)</enum><text>enable the efficient development of—</text><subclause id="id201d191fb9474aaa96fa0f8186af9d3d"><enum>(I)</enum><text>lessons learned and recommendations in responding to, recovering from, remediating, and mitigating future incidents; and</text></subclause><subclause id="id84b86e07a13a4126ae4f4e7c1f4ec0af"><enum>(II)</enum><text>the report on Federal incidents required under section 3597(b) of title 44, United States Code, as added by this Act;</text></subclause></clause><clause id="id67a953b6a8a24b1283649777621334fc"><enum>(iii)</enum><text>include requirements for the timeliness of data production; and</text></clause><clause id="id9d0280a1aad54dcfae5fe25fcbef5871"><enum>(iv)</enum><text>include requirements for using automation and machine-readable data for data sharing and availability.</text></clause></subparagraph></paragraph><paragraph id="id52aa0853a640489382a338df4d747ed2"><enum>(3)</enum><header>Guidance on responding to information requests</header><text>Not later than 1 year after the date of enactment of this Act, the Director shall develop guidance for agencies to implement the requirement under section 3594(c) of title 44, United States Code, as added by this Act, to provide information to other agencies experiencing incidents.</text></paragraph><paragraph id="id2d56b345e2d9404ca3778089b23e2ba1"><enum>(4)</enum><header>Standard guidance and templates</header><text>Not later than 1 year after the date of enactment of this Act, the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop guidance and templates, to be reviewed and, if necessary, updated not less frequently than once every 2 years, for use by Federal agencies in the activities required under sections 3592, 3593, and 3596 of title 44, United States Code, as added by this Act.</text></paragraph><paragraph id="ida4a3a40bd9754296b0b24ca9f4579a34"><enum>(5)</enum><header>Contractor and awardee guidance</header><subparagraph id="id4623e6fa0db549a8b213c3b7dd534348"><enum>(A)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the Secretary of Homeland Security, the Secretary of Defense, the Administrator of General Services, and the heads of other agencies determined appropriate by the Director, shall issue guidance to Federal agencies on how to deconflict, to the greatest extent practicable, existing regulations, policies, and procedures relating to the responsibilities of contractors and awardees established under section 3595 of title 44, United States Code, as added by this Act.</text></subparagraph><subparagraph id="idbb5aee79fe554bd88b24c4e68fcaefd2"><enum>(B)</enum><header>Existing processes</header><text>To the greatest extent practicable, the guidance issued under subparagraph (A) shall allow contractors and awardees to use existing processes for notifying Federal agencies of incidents involving information of the Federal Government.</text></subparagraph></paragraph><paragraph id="id710e2756548c45669682ccb909875911"><enum>(6)</enum><header>Updated briefings</header><text>Not less frequently than once every 2 years, the Director shall provide to the appropriate congressional committees an update on the guidance and templates developed under paragraphs (2) through (4).</text></paragraph></subsection><subsection id="id581b104c1a444b10935b3cb6a58c86af"><enum>(c)</enum><header>Update to the privacy act of 1974</header><text>Section 552a(b) of title 5, United States Code (commonly known as the <quote>Privacy Act of 1974</quote>) is amended—</text><paragraph id="idb32795a1d744419da6f429083575e8c3"><enum>(1)</enum><text>in paragraph (11), by striking <quote>or</quote> at the end;</text></paragraph><paragraph id="id06d168e1157e431fbea60983a8e2bdb0"><enum>(2)</enum><text>in paragraph (12), by striking the period at the end and inserting <quote>; or</quote>; and</text></paragraph><paragraph id="idb162553d2270422b9084a88f0e016e90"><enum>(3)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id592010804a4f4decb31bbdb74b610d77" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id27bc8e895ae74a0991492fcc12b8d252"><enum>(13)</enum><text>to another agency in furtherance of a response to an incident (as defined in section 3552 of title 44) and pursuant to the information sharing requirements in section 3594 of title 44 if the head of the requesting agency has made a written request to the agency that maintains the record specifying the particular portion desired and the activity for which the record is sought.</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id25f160a4-98e9-4e5e-b26f-20f2dd97cd4e"><enum>104.</enum><header>Additional guidance to agencies on FISMA updates</header><text display-inline="no-display-inline">Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance for agencies on—</text><paragraph id="id50632071f2f241f5a9dff2b4d318e020"><enum>(1)</enum><text>performing the ongoing and continuous agency system risk assessment required under section 3554(a)(1)(A) of title 44, United States Code, as amended by this Act;</text></paragraph><paragraph id="id116536c27df64318832b06ded351eb70"><enum>(2)</enum><text>implementing additional cybersecurity procedures, which shall include resources for shared services;</text></paragraph><paragraph id="id7e63537e634148e3885c5e0aa0165c90"><enum>(3)</enum><text>establishing a process for providing the status of each remedial action under section 3554(b)(7) of title 44, United States Code, as amended by this Act, to the Director and the Cybersecurity and Infrastructure Security Agency using automation and machine-readable data, as practicable, which shall include—</text><subparagraph id="idf6941056e96f4aef9a1d7c1437ccc18e"><enum>(A)</enum><text>specific guidance for the use of automation and machine-readable data; and</text></subparagraph><subparagraph id="id08fa028466a04d22be3dada921f3530d"><enum>(B)</enum><text>templates for providing the status of the remedial action;</text></subparagraph></paragraph><paragraph id="idd095a00fd2934c8f9124c68046f7f268"><enum>(4)</enum><text>interpreting the definition of <quote>high value asset</quote> under section 3552 of title 44, United States Code, as amended by this Act; and</text></paragraph><paragraph id="idcc8a9721ac8a4be9876e8e9c8621a8ec"><enum>(5)</enum><text>a requirement to coordinate with inspectors general of agencies to ensure consistent understanding and application of agency policies for the purpose of evaluations by inspectors general.</text></paragraph></section><section id="id87c2d95a-b307-45ec-81dd-09e23e4addc4"><enum>105.</enum><header>Agency requirements to notify private sector entities impacted by incidents</header><subsection id="idD56C3840E37D46DC9B6BBB5F438F03B0"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idEC58058F1C51421194D97C5A734A4ACA"><enum>(1)</enum><header>Reporting entity</header><text>The term <term>reporting entity</term> means private organization or governmental unit that is required by statute or regulation to submit sensitive information to an agency.</text></paragraph><paragraph id="idBFD97365FA184CD8BDD643869931A7EB"><enum>(2)</enum><header>Sensitive information</header><text>The term <term>sensitive information</term> has the meaning given the term by the Director in guidance issued under subsection (b).</text></paragraph></subsection><subsection id="id69E6784665C64660B208972511F67BB7"><enum>(b)</enum><header>Guidance on notification of reporting entities</header><text>Not later than 180 days after the date of enactment of this Act, the Director shall issue guidance requiring the head of each agency to notify a reporting entity of an incident that is likely to substantially affect—</text><paragraph id="id94C3B8A55E524AA19EC3230429A3C71F"><enum>(1)</enum><text>the confidentiality or integrity of sensitive information submitted by the reporting entity to the agency pursuant to a statutory or regulatory requirement; or</text></paragraph><paragraph id="id95A0524DF8974477BDA26B6782B09E47"><enum>(2)</enum><text>the agency information system or systems used in the transmission or storage of the sensitive information described in paragraph (1).</text></paragraph></subsection></section></title><title style="OLC" id="id1ccc6db7-499e-4883-a1e8-db7df256ec29" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>II</enum><header>Improving Federal cybersecurity</header><section section-type="subsequent-section" id="idcb1f5c81-6041-46c1-ac5e-f9028ab69e49"><enum>201.</enum><header>Mobile security standards</header><subsection id="id6b9cc043-9a39-4b4f-8a58-db9e0dc405a3"><enum>(a)</enum><header>In general</header><text>Not later than 1 year after the date of enactment of this Act, the Director shall—</text><paragraph id="id4a261559eea146d0bcb2f03f243c2bf1"><enum>(1)</enum><text>evaluate mobile application security guidance promulgated by the Director; and</text></paragraph><paragraph id="id171f832f086441329e148747983e924f"><enum>(2)</enum><text>issue guidance to secure mobile devices, including for mobile applications, for every agency.</text></paragraph></subsection><subsection id="idf9166b6c7e604e81881b3ab6f4bd23a6"><enum>(b)</enum><header>Contents</header><text>The guidance issued under subsection (a)(2) shall include—</text><paragraph id="id3183ba7add114a4faf9d63edaf293801"><enum>(1)</enum><text>a requirement, pursuant to section 3506(b)(4) of title 44, United States Code, for every agency to maintain a continuous inventory of every—</text><subparagraph id="id799cbc31ebe44babae83b91b2026b37f"><enum>(A)</enum><text>mobile device operated by or on behalf of the agency; and</text></subparagraph><subparagraph id="id01ab6958f9ba41d5a72620485820e35b"><enum>(B)</enum><text>vulnerability identified by the agency associated with a mobile device; and</text></subparagraph></paragraph><paragraph id="id79d077ab97004c3283bd9bdfe7be334c"><enum>(2)</enum><text>a requirement for every agency to perform continuous evaluation of the vulnerabilities described in paragraph (1)(B) and other risks associated with the use of applications on mobile devices.</text></paragraph></subsection><subsection id="id1632b6e8-27da-492c-93b6-225fe327bed8"><enum>(c)</enum><header>Information sharing</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance to agencies for sharing the inventory of the agency required under subsection (b)(1) with the Director of the Cybersecurity and Infrastructure Security Agency, using automation and machine-readable data to the greatest extent practicable.</text></subsection><subsection id="id568e7020-91e1-457d-8d2c-c5673fdce709"><enum>(d)</enum><header>Briefing</header><text>Not later than 60 days after the date on which the Director issues guidance under subsection (a)(2), the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall provide to the appropriate congressional committees a briefing on the guidance.</text></subsection></section><section id="idd5aff240-4ee2-4011-938d-981543512249"><enum>202.</enum><header>Data and logging retention for incident response</header><subsection id="id0f9d2b85fa674b4d93733cd27b1428ea"><enum>(a)</enum><header>Recommendations</header><text>Not later than 2 years after the date of enactment of this Act, and not less frequently than every 2 years thereafter, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Attorney General, shall submit to the Director recommendations on requirements for logging events on agency systems and retaining other relevant data within the systems and networks of an agency.</text></subsection><subsection id="idfd1f66e78f95498abf6701e2ba2aa98f"><enum>(b)</enum><header>Contents</header><text>The recommendations provided under subsection (a) shall include—</text><paragraph id="idf220b262e44447e799224a4506b6582e"><enum>(1)</enum><text>the types of logs to be maintained;</text></paragraph><paragraph id="id3cff0eed63614a10a585f50c1bb5ff3e"><enum>(2)</enum><text>the time periods to retain the logs and other relevant data;</text></paragraph><paragraph id="id1978d86e83844c119014887c077fdcc1"><enum>(3)</enum><text>the time periods for agencies to enable recommended logging and security requirements;</text></paragraph><paragraph id="id0d554c0ec4884c37b66fbedb4f7e9e18"><enum>(4)</enum><text>how to ensure the confidentiality, integrity, and availability of logs; </text></paragraph><paragraph id="idc79013b2e43a41a9b312c4c3c7717d9d"><enum>(5)</enum><text>requirements to ensure that, upon request, in a manner that excludes or otherwise reasonably protects personally identifiable information, and to the extent permitted by applicable law (including privacy and statistical laws), agencies provide logs to—</text><subparagraph id="id36c6729273ed4a139ba2f914a8ebd4b7"><enum>(A)</enum><text>the Director of the Cybersecurity and Infrastructure Security Agency for a cybersecurity purpose; and</text></subparagraph><subparagraph id="idb8469bb7c06748a985766855326b8eba"><enum>(B)</enum><text>the Federal Bureau of Investigation to investigate potential criminal activity; and</text></subparagraph></paragraph><paragraph id="ide899e05802e64392ba641a3a57bb9a7c"><enum>(6)</enum><text>requirements to ensure that, subject to compliance with statistical laws and other relevant data protection requirements, the highest level security operations center of each agency has visibility into all agency logs.</text></paragraph></subsection><subsection id="id991d8f542e2a49809e1322c59fef7bff"><enum>(c)</enum><header>Guidance</header><text>Not later than 90 days after receiving the recommendations submitted under subsection (a), the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the Attorney General, shall, as determined to be appropriate by the Director, update guidance to agencies regarding requirements for logging, log retention, log management, sharing of log data with other appropriate agencies, or any other logging activity determined to be appropriate by the Director.</text></subsection></section><section id="id57f53189-fc83-42bb-aa2d-60a0dd4a8764"><enum>203.</enum><header>CISA agency advisors</header><subsection id="idc938a3d9-c12a-436a-9c9e-2ae05ca8ac57"><enum>(a)</enum><header>In general</header><text>Not later than 120 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall assign not less than 1 cybersecurity professional employed by the Cybersecurity and Infrastructure Security Agency to be the Cybersecurity and Infrastructure Security Agency advisor to the senior agency information security officer of each agency.</text></subsection><subsection id="id843b1b50-c72c-4f6e-aa2f-2775fe756208"><enum>(b)</enum><header>Qualifications</header><text>Each advisor assigned under subsection (a) shall have knowledge of—</text><paragraph id="id051b691c-e57a-49dd-9bab-398057a9df62"><enum>(1)</enum><text>cybersecurity threats facing agencies, including any specific threats to the assigned agency; </text></paragraph><paragraph id="id84fbb966-d079-46b8-ac0c-e32454bb30a6"><enum>(2)</enum><text>performing risk assessments of agency systems; and</text></paragraph><paragraph id="idfbfa1ece-cd0c-4be2-937c-7cfa23723ecc"><enum>(3)</enum><text>other Federal cybersecurity initiatives.</text></paragraph></subsection><subsection id="idf613a64a-5910-4d97-9d19-e140f97c5172"><enum>(c)</enum><header>Duties</header><text>The duties of each advisor assigned under subsection (a) shall include—</text><paragraph id="id6a8086c7-4129-4d2d-8e8a-0a153aeeb296"><enum>(1)</enum><text>providing ongoing assistance and advice, as requested, to the agency Chief Information Officer;</text></paragraph><paragraph id="id86cf563d-d4a0-4ffa-b1c7-f8111ecfcd41"><enum>(2)</enum><text>serving as an incident response point of contact between the assigned agency and the Cybersecurity and Infrastructure Security Agency; and</text></paragraph><paragraph id="id7077a924-2ba3-4e9c-8a59-4d01bb381adb"><enum>(3)</enum><text>familiarizing themselves with agency systems, processes, and procedures to better facilitate support to the agency in responding to incidents.</text></paragraph></subsection><subsection id="id99295e81-3071-4caa-9f22-e492b6a7c03a"><enum>(d)</enum><header>Limitation</header><text>An advisor assigned under subsection (a) shall not be a contractor.</text></subsection><subsection id="idda922626-602e-4442-a6d3-8b7cc02b3f75" commented="no" display-inline="no-display-inline"><enum>(e)</enum><header>Multiple assignments</header><text>One individual advisor may be assigned to multiple agency Chief Information Officers under subsection (a).</text></subsection></section><section id="idcb1d5c8b-d16c-44b2-b56b-ebdf3af17e8f"><enum>204.</enum><header>Federal penetration testing policy</header><subsection id="id34159670-044a-42b2-ae90-c659dd521168"><enum>(a)</enum><header>In general</header><text>Subchapter II of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding at the end the following:</text><quoted-block style="USC" display-inline="no-display-inline" id="id5706aa5c-cfd7-4db4-9d7e-0e9c09cb660f" changed="added" reported-display-style="italic" committee-id="SSGA00"><section id="id12fed049-238b-4e92-b078-df89b5a8350b"><enum>3559A.</enum><header>Federal penetration testing</header><subsection id="id6148e2e4-2738-4b44-96a4-00df707b3ca4"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idfb44ada9-9a38-4ae9-ab6c-81e3485cc3ba"><enum>(1)</enum><header>Agency operational plan</header><text>The term <term>agency operational plan</term> means a plan of an agency for the use of penetration testing.</text></paragraph><paragraph id="id0a5e81a0-806a-4178-9b27-1a3312c59e9b"><enum>(2)</enum><header>Rules of engagement</header><text>The term <term>rules of engagement</term> means a set of rules established by an agency for the use of penetration testing.</text></paragraph></subsection><subsection id="id52ae314b-d013-4a0e-af65-3e15016e563a"><enum>(b)</enum><header>Guidance</header><paragraph id="id44f200c3-acc0-4a30-8cdd-28fcb74f80ce"><enum>(1)</enum><header>In general</header><text>The Director shall issue guidance that—</text><subparagraph id="id734fbe15-ff5d-42b4-b1c8-6f8260e9af5d"><enum>(A)</enum><text>requires agencies to use, when and where appropriate, penetration testing on agency systems; and</text></subparagraph><subparagraph id="idc41c7688-8356-480f-b4dc-fe90f082a31d"><enum>(B)</enum><text>requires agencies to develop an agency operational plan and rules of engagement that meet the requirements under subsection (c).</text></subparagraph></paragraph><paragraph id="id526daa5c-4ed4-4d59-8b3c-eaf7bac73c5f"><enum>(2)</enum><header>Penetration testing guidance</header><text>The guidance issued under this section shall—</text><subparagraph id="id09f40cb9-a8ba-48ee-8c8f-5ce32d33c91a"><enum>(A)</enum><text>permit an agency to use, for the purpose of performing penetration testing—</text><clause id="id9ebc1884-2dd0-4c42-8a9c-1f872966e8e8"><enum>(i)</enum><text>a shared service of the agency or another agency; or</text></clause><clause id="id7728dd32-98a6-444a-bf90-502c6368dd95"><enum>(ii)</enum><text>an external entity, such as a vendor; and</text></clause></subparagraph><subparagraph id="idaa700d44-7be5-44ae-af02-ec9f1e6f9e75"><enum>(B)</enum><text>require agencies to provide the rules of engagement and results of penetration testing to the Director and the Director of the Cybersecurity and Infrastructure Security Agency, without regard to the status of the entity that performs the penetration testing.</text></subparagraph></paragraph></subsection><subsection id="id015bf86c-8303-4e58-bd6a-6b0c2b4f2bc2"><enum>(c)</enum><header>Agency plans and rules of engagement</header><text>The agency operational plan and rules of engagement of an agency shall—</text><paragraph id="id566a092257454978870b8a79192a0510"><enum>(1)</enum><text>require the agency to— </text><subparagraph id="id94F6384BCEB1412193AE7BBB3FF4F9DF"><enum>(A)</enum><text>perform penetration testing on the high value assets of the agency; or </text></subparagraph><subparagraph id="id698EE165450A4689AB83AC21FC5785FB"><enum>(B)</enum><text>coordinate with the Director of the Cybersecurity and Infrastructure Security Agency to ensure that penetration testing is being performed;</text></subparagraph></paragraph><paragraph id="id4ac6e3c517254fb8b9f75dd3fb1defb8"><enum>(2)</enum><text>establish guidelines for avoiding, as a result of penetration testing—</text><subparagraph id="id6e04f9f2788a4cc9b0009318b29a15ca"><enum>(A)</enum><text>adverse impacts to the operations of the agency;</text></subparagraph><subparagraph id="id4b3782ab364c4958a712d98b8fd21398"><enum>(B)</enum><text>adverse impacts to operational environments and systems of the agency; and</text></subparagraph><subparagraph id="idaa7736b2-f3ae-4d09-9399-420e2c353288"><enum>(C)</enum><text>inappropriate access to data;</text></subparagraph></paragraph><paragraph id="id005b6177-0f96-45b2-9bca-1c95b10bb9dd"><enum>(3)</enum><text>require the results of penetration testing to include feedback to improve the cybersecurity of the agency; and</text></paragraph><paragraph id="idb9fa3557-f6c0-4f0a-b272-8377b05774c8"><enum>(4)</enum><text>include mechanisms for providing consistently formatted, and, if applicable, automated and machine-readable, data to the Director and the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph></subsection><subsection id="id76840f3c-3cbc-4ff0-8ccd-9e68fb9c0064"><enum>(d)</enum><header>Responsibilities of CISA</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall—</text><paragraph id="idb482889a-0ab5-4298-abe6-d2e2c9cf7ec7"><enum>(1)</enum><text>establish a process to assess the performance of penetration testing by both Federal and non-Federal entities that establishes minimum quality controls for penetration testing; </text></paragraph><paragraph id="id357391d9-1451-4d6c-80b2-c0592df3d42d"><enum>(2)</enum><text>develop operational guidance for instituting penetration testing programs at agencies;</text></paragraph><paragraph id="id4ae7387d-d828-426c-bdca-2ee233aa2961"><enum>(3)</enum><text>develop and maintain a centralized capability to offer penetration testing as a service to Federal and non-Federal entities; and</text></paragraph><paragraph id="id81c5ad65-d50a-430b-a1ca-b18ec002c6e2"><enum>(4)</enum><text>provide guidance to agencies on the best use of penetration testing resources.</text></paragraph></subsection><subsection id="id1874bbe6-87a1-4a06-a14d-29afeb6150b5"><enum>(e)</enum><header>Responsibilities of OMB</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall—</text><paragraph id="id98618c68-f662-4482-8d3d-9601ca0aeae0"><enum>(1)</enum><text>not less frequently than annually, inventory all Federal penetration testing assets; and</text></paragraph><paragraph id="id3a5f06d1-17be-4a02-944b-e09fc34798de"><enum>(2)</enum><text>develop and maintain a standardized process for the use of penetration testing.</text></paragraph></subsection><subsection id="idaa59b285-3409-4757-b519-a4421450a85d"><enum>(f)</enum><header>Prioritization of penetration testing resources</header><paragraph id="idf2a4b00b-dd61-45ef-bde7-c62cfdbdc449"><enum>(1)</enum><header>In general</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop a framework for prioritizing Federal penetration testing resources among agencies.</text></paragraph><paragraph id="idc3faf56e-e883-4482-82ef-2a37322f0986"><enum>(2)</enum><header>Considerations</header><text>In developing the framework under this subsection, the Director shall consider—</text><subparagraph id="id2e5c86b7-763d-4a19-a780-f63a0117c4d1"><enum>(A)</enum><text>agency system risk assessments performed under section 3554(a)(1)(A);</text></subparagraph><subparagraph id="idc0997a72-5bef-4d62-adab-d90c9214c967"><enum>(B)</enum><text>the Federal risk assessment performed under section 3553(i);</text></subparagraph><subparagraph id="ide7828c3d-eefd-42bb-803c-a30c02e4058b"><enum>(C)</enum><text>the analysis of Federal incident data performed under section 3597; and</text></subparagraph><subparagraph id="id8a6a7a2e-2abd-45ff-af21-55a37cfc71da"><enum>(D)</enum><text>any other information determined appropriate by the Director or the Director of the Cybersecurity and Infrastructure Security Agency.</text></subparagraph></paragraph></subsection><subsection id="id1d979f939fa949b08bfef382883982ca"><enum>(g)</enum><header>Exception for national security systems</header><text>The guidance issued under subsection (b) shall not apply to national security systems.</text></subsection><subsection id="id5cc6409955d24b5a810e3493265601ed"><enum>(h)</enum><header>Delegation of authority for certain systems</header><text>The authorities of the Director described in subsection (b) shall be delegated— </text><paragraph id="id8E1E57C26DB24C3ABDBE1057BD8F1AEC"><enum>(1)</enum><text>to the Secretary of Defense in the case of systems described in section 3553(e)(2); and </text></paragraph><paragraph id="id56CF417D008D4B08A86FED819418F216"><enum>(2)</enum><text>to the Director of National Intelligence in the case of systems described in 3553(e)(3).</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id95e2c232fe394bce96d288f45b1605c5"><enum>(b)</enum><header>Deadline for guidance</header><text>Not later than 180 days after the date of enactment of this Act, the Director shall issue the guidance required under section 3559A(b) of title 44, United States Code, as added by subsection (a). </text></subsection><subsection id="idd33995b8-b3e7-4941-8c34-c5f09b88a7e6"><enum>(c)</enum><header>Clerical amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding after the item relating to section 3559 the following:</text><quoted-block style="USC" id="ida08a9f5b-a4cb-4b88-910d-9c26375e8351" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="section" idref="id4CFA7FCCBE5B4C36A1F7A2B9B130E24E">3559A. Federal penetration testing.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id892140ad-08bd-42f0-ad80-26ce09e6f330"><enum>(d)</enum><header>Penetration testing by the Secretary of Homeland Security</header><text>Section 3553(b) of title 44, United States Code, as amended by section 101, is further amended—</text><paragraph id="idb5429dfc-21c2-4bde-aabe-a4d016e92a75"><enum>(1)</enum><text>in paragraph (8)(B), by striking <quote>and</quote> at the end;</text></paragraph><paragraph id="idb9269658-1307-4686-a173-bf853ded240d"><enum>(2)</enum><text>by redesignating paragraph (9) as paragraph (10); and</text></paragraph><paragraph id="idbadf0482-098d-475d-9955-fb58776cbeec"><enum>(3)</enum><text>by inserting after paragraph (8) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id090eb3c9-1ef4-4e87-961f-09ec9036096d" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id878318c6-e932-4af0-80ca-a0e19a03c6e2"><enum>(9)</enum><text>performing penetration testing with or without advance notice to, or authorization from, agencies, to identify vulnerabilities within Federal information systems; and</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section><section id="id8ac0efe9-c6c6-4290-b836-3e48c6b22cc4"><enum>205.</enum><header>Ongoing threat hunting program</header><subsection id="id6a0cb734-18f5-4b34-a908-2cd70aeb0e90"><enum>(a)</enum><header>Threat hunting program</header><paragraph id="idd27d01dd-4f45-48ee-854c-d3bee7f24c74"><enum>(1)</enum><header>In general</header><text>Not later than 540 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.</text></paragraph><paragraph id="idaed14bce-1f2e-407c-b5d1-724988e6aabf"><enum>(2)</enum><header>Plan</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish the program required under paragraph (1) that describes how the Director of the Cybersecurity and Infrastructure Security Agency plans to—</text><subparagraph id="idd8aa213d-62be-407c-9807-c5382e1b0dac"><enum>(A)</enum><text>determine the method for collecting, storing, accessing, and analyzing appropriate agency data;</text></subparagraph><subparagraph id="id72766359-9544-4e45-9b11-3100060753a2"><enum>(B)</enum><text>provide on-premises support to agencies;</text></subparagraph><subparagraph id="idcfa22088-7357-4ae3-b4a5-8eee33d9ca14"><enum>(C)</enum><text>staff threat hunting services;</text></subparagraph><subparagraph id="idbdb416d6-882f-417b-869b-2afb71372517"><enum>(D)</enum><text>allocate available human and financial resources to implement the plan; and</text></subparagraph><subparagraph id="id79084f13-b1ce-4cee-80f7-ebde945c9106"><enum>(E)</enum><text>provide input to the heads of agencies on the use of—</text><clause id="ide0f87131-6c04-4e69-9bf0-583dbfcf0067"><enum>(i)</enum><text>more stringent standards under section 11331(c)(1) of title 40, United States Code; and</text></clause><clause id="id88988633-827d-4a81-a4ea-7d3cab3f9754"><enum>(ii)</enum><text>additional cybersecurity procedures under section 3554 of title 44, United States Code.</text></clause></subparagraph></paragraph></subsection><subsection id="idd35a2fb4-085f-405e-bbe4-b46bfd5b26f0" commented="no"><enum>(b)</enum><header>Reports</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall submit to the appropriate congressional committees—</text><paragraph commented="no" id="ide51f7826-8a5c-4b72-b522-3ecefd72bbf1"><enum>(1)</enum><text>not later than 30 days after the date on which the Director of the Cybersecurity and Infrastructure Security Agency completes the plan required under subsection (a)(2), a report on the plan to provide threat hunting services to agencies;</text></paragraph><paragraph id="ide9e2cbae-e92f-4fae-b84f-8e2988e49315"><enum>(2)</enum><text>not less than 30 days before the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services under the program under subsection (a)(1), a report providing any updates to the plan developed under subsection (a)(2); and</text></paragraph><paragraph id="id35b455b0-69bb-4977-8357-0f3b4a0b587c"><enum>(3)</enum><text>not later than 1 year after the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services to agencies other than the Cybersecurity and Infrastructure Security Agency, a report describing lessons learned from providing those services.</text></paragraph></subsection></section><section id="idb10abbdc-108c-4af0-bc7c-43b1df5a7e70"><enum>206.</enum><header>Codifying vulnerability disclosure programs</header><subsection id="id81b60b6f-fbc1-49c5-b91c-4aaef24d468b"><enum>(a)</enum><header>In general</header><text><external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">Chapter 35</external-xref> of title 44, United States Code, is amended by inserting after <external-xref legal-doc="usc" parsable-cite="usc/44/3559A">section 3559A,</external-xref> as added by section 204 of this Act, the following:</text><quoted-block style="USC" display-inline="no-display-inline" id="idd2c7a600-04e7-46cf-a5fa-cf4e7e095f61" changed="added" reported-display-style="italic" committee-id="SSGA00"><section id="idbfd45c00-c084-4656-af18-aabb596f38b4"><enum>3559B.</enum><header>Federal vulnerability disclosure programs</header><subsection id="id1cd29b24-ca8b-4321-b0fb-7943c0b7ec7a"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id0d7a0a01-b25f-4480-8782-3c1404803db6"><enum>(1)</enum><header>Report</header><text>The term <term>report</term> means a vulnerability disclosure made to an agency by a reporter.</text></paragraph><paragraph id="id50c7002a-ecdd-42f5-991d-d87d944b3ff5"><enum>(2)</enum><header>Reporter</header><text>The term <term>reporter</term> means an individual that submits a vulnerability report pursuant to the vulnerability disclosure process of an agency.</text></paragraph></subsection><subsection id="id9d837eeb-fdad-450a-b973-20e31e8fe3f2"><enum>(b)</enum><header>Responsibilities of OMB</header><paragraph id="id9b1dd61d-8ebe-4ce5-bd98-4b939d75fbf9"><enum>(1)</enum><header>Limitation on legal action</header><text>The Director, in consultation with the Attorney General, shall issue guidance to agencies to not recommend or pursue legal action against a reporter or an individual that conducts a security research activity that the head of the agency determines—</text><subparagraph id="id253f6631-d0f8-4242-85b2-5152b84c49c5"><enum>(A)</enum><text>represents a good faith effort to follow the vulnerability disclosure policy of the agency developed under subsection (d)(2); and</text></subparagraph><subparagraph id="id888c648c-fd7a-4889-8d4f-9a736d43cc9d"><enum>(B)</enum><text>is authorized under the vulnerability disclosure policy of the agency developed under subsection (d)(2).</text></subparagraph></paragraph><paragraph id="ida2e68a41-1f0a-4ab7-8a58-688e823962ca"><enum>(2)</enum><header>Sharing information with CISA</header><text>The Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director, shall issue guidance to agencies on sharing relevant information in a consistent, automated, and machine readable manner with the Cybersecurity and Infrastructure Security Agency, including—</text><subparagraph id="id6068cb6f-f33b-458b-b7ad-cdb5e72e1144"><enum>(A)</enum><text>any valid or credible reports of newly discovered or not publicly known vulnerabilities (including misconfigurations) on Federal information systems that use commercial software or services;</text></subparagraph><subparagraph id="ida586a068-9112-4a36-a03a-88021c15b802"><enum>(B)</enum><text>information relating to vulnerability disclosure, coordination, or remediation activities of an agency, particularly as those activities relate to outside organizations—</text><clause id="ida792d656-d241-4beb-8172-bb9991091d94"><enum>(i)</enum><text>with which the head of the agency believes the Director of the Cybersecurity and Infrastructure Security Agency can assist; or</text></clause><clause id="id8cf110e3-bf13-44ff-bea1-3f99a0f2d028"><enum>(ii)</enum><text>about which the head of the agency believes the Director of the Cybersecurity and Infrastructure Security Agency should know; and</text></clause></subparagraph><subparagraph id="id1901478a-aeef-4996-bf6a-c1a5834fc00c"><enum>(C)</enum><text>any other information with respect to which the head of the agency determines helpful or necessary to involve the Cybersecurity and Infrastructure Security Agency.</text></subparagraph></paragraph><paragraph id="id7ac1af0c-4ec8-4c3d-93c6-d2ffb15c7716" commented="no"><enum>(3)</enum><header>Agency vulnerability disclosure policies</header><text>The Director shall issue guidance to agencies on the required minimum scope of agency systems covered by the vulnerability disclosure policy of an agency required under subsection (d)(2).</text></paragraph></subsection><subsection id="id55f5a204-298f-4e67-bd1f-b94ab0e2326c"><enum>(c)</enum><header>Responsibilities of CISA</header><text>The Director of the Cybersecurity and Infrastructure Security Agency shall—</text><paragraph id="id1dcac4cc-7348-4db9-a115-3663280647da"><enum>(1)</enum><text>provide support to agencies with respect to the implementation of the requirements of this section;</text></paragraph><paragraph id="idc07761d7-765f-4fa8-834e-26faff0448f5"><enum>(2)</enum><text>develop tools, processes, and other mechanisms determined appropriate to offer agencies capabilities to implement the requirements of this section; and</text></paragraph><paragraph id="id91f7956e-d559-4261-9935-0f05abcbb975"><enum>(3)</enum><text>upon a request by an agency, assist the agency in the disclosure to vendors of newly identified vulnerabilities in vendor products and services.</text></paragraph></subsection><subsection id="id90ab267d-767d-421e-a1f6-a8c37fc41374"><enum>(d)</enum><header>Responsibilities of agencies</header><paragraph id="id0c26245b-3579-4cc4-98d7-919565e32acf"><enum>(1)</enum><header>Public information</header><text>The head of each agency shall make publicly available, with respect to each internet domain under the control of the agency that is not a national security system—</text><subparagraph id="iddfb4555d-3f6d-4941-9bcb-ef6956712856"><enum>(A)</enum><text>an appropriate security contact; and</text></subparagraph><subparagraph id="id013b4dbb-ab40-4dc4-9184-1d883cc6ca10"><enum>(B)</enum><text>the component of the agency that is responsible for the internet accessible services offered at the domain.</text></subparagraph></paragraph><paragraph id="id2c8a66c6-af87-46ff-bc57-ad1e927cd3eb"><enum>(2)</enum><header>Vulnerability disclosure policy</header><text>The head of each agency shall develop and make publicly available a vulnerability disclosure policy for the agency, which shall—</text><subparagraph id="id7ed96a6c-2e86-4c07-b51d-d81840c61d28"><enum>(A)</enum><text>describe—</text><clause id="idff681c3b-2b21-4bf8-9f2b-053cda2646d7"><enum>(i)</enum><text>the scope of the systems of the agency included in the vulnerability disclosure policy;</text></clause><clause id="id4ac266be-b414-4398-9ce9-dcc7c18745d9"><enum>(ii)</enum><text>the type of information system testing that is authorized by the agency;</text></clause><clause id="id00e39778-0939-4d12-8a46-7d21c1790068"><enum>(iii)</enum><text>the type of information system testing that is not authorized by the agency; and</text></clause><clause id="idd545f69c-24ec-4fe9-8728-61bfe25416d0"><enum>(iv)</enum><text>the disclosure policy of the agency for sensitive information;</text></clause></subparagraph><subparagraph id="id98a3c7499ef24840b4eb29d238e28bf5"><enum>(B)</enum><text>with respect to a report to an agency, describe—</text><clause id="id55edbf0ec2cc435f853d9fa304031b56"><enum>(i)</enum><text>how the reporter should submit the report; and</text></clause><clause id="id01b0d61bf4e745f282a0133e6f20c49b"><enum>(ii)</enum><text>if the report is not anonymous, when the reporter should anticipate an acknowledgment of receipt of the report by the agency; </text></clause></subparagraph><subparagraph id="idaf99963069e740ba8531834c1513a624"><enum>(C)</enum><text>include any other relevant information; and</text></subparagraph><subparagraph id="idfeb7f786632b4455981e70919d924555"><enum>(D)</enum><text>be mature in scope, to cover all Federal information systems used or operated by that agency or on behalf of that agency.</text></subparagraph></paragraph><paragraph id="idaa3cceb3-d355-4b76-8e22-53d0c31f5e45"><enum>(3)</enum><header>Identified vulnerabilities</header><text>The head of each agency shall incorporate any vulnerabilities reported under paragraph (2) into the vulnerability management process of the agency in order to track and remediate the vulnerability.</text></paragraph></subsection><subsection id="idbad231ca-eb1e-442f-b368-e45a3967a81a"><enum>(e)</enum><header>Paperwork Reduction Act exemption</header><text>The requirements of subchapter I (commonly known as the <quote>Paperwork Reduction Act</quote>) shall not apply to a vulnerability disclosure program established under this section.</text></subsection><subsection id="ida1510e95-469e-430a-9967-a99b04bd4adb"><enum>(f)</enum><header>Congressional reporting</header><text>Not later than 90 days after the date of enactment of the <short-title>Federal Information Security Modernization Act of 2021</short-title>, and annually thereafter for a 3-year period, the Director shall provide to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs of the Senate</committee-name> and the <committee-name committee-id="">Committee on Oversight and Reform of the House of Representatives</committee-name> a briefing on the status of the use of vulnerability disclosure policies under this section at agencies, including, with respect to the guidance issued under subsection (b)(3), an identification of the agencies that are compliant and not compliant.</text></subsection><subsection id="id1826b922e7e14000957626b50dbfcf02"><enum>(g)</enum><header>Exemptions</header><text>The authorities and functions of the Director and Director of the Cybersecurity and Infrastructure Security Agency under this section shall not apply to national security systems.</text></subsection><subsection id="idC2F6C750DB024FC19A34C74BD2C60FAC"><enum>(h)</enum><header>Delegation of authority for certain systems</header><text>The authorities of the Director and the Director of the Cybersecurity and Infrastructure Security Agency described in this section shall be delegated— </text><paragraph id="idE69564DA113E40A29BB8266B51E7C65F"><enum>(1)</enum><text>to the Secretary of Defense in the case of systems described in section 3553(e)(2); and </text></paragraph><paragraph id="idB5C5EAE3B43D4BD79C4CD46F9057F4B6"><enum>(2)</enum><text>to the Director of National Intelligence in the case of systems described in section 3553(e)(3).</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idfca3fac3-836e-466a-8157-47a9f672f1e2"><enum>(b)</enum><header>Clerical amendment</header><text>The table of sections for <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44, United States Code, is amended by adding after the item relating to section 3559A, as added by section 204, the following:</text><quoted-block style="USC" id="id75b825b6-898f-4500-8557-11e73f887f9d" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="section" idref="id4CFA7FCCBE5B4C36A1F7A2B9B130E24E">3559B. Federal vulnerability disclosure programs.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section><section id="ide5684d3fad7e4f56b75dba6cd0e97ffb"><enum>207.</enum><header>Implementing presumption of compromise and least privilege principles</header><subsection id="id4bdc8be904034692811818fee0a6d279"><enum>(a)</enum><header>Guidance</header><text>Not later than 1 year after the date of enactment of this Act, the Director shall provide an update to the appropriate congressional committees on progress in increasing the internal defenses of agency systems, including—</text><paragraph id="id81aebb397800497cb59a74789ec7f7bb"><enum>(1)</enum><text>shifting away from <quote>trusted networks</quote> to implement security controls based on a presumption of compromise;</text></paragraph><paragraph id="id22e40b388ca9420bb87b72753d386791"><enum>(2)</enum><text>implementing principles of least privilege in administering information security programs;</text></paragraph><paragraph id="idde0bae0f38bf44ec9ecaa6667938975a"><enum>(3)</enum><text>limiting the ability of entities that cause incidents to move laterally through or between agency systems;</text></paragraph><paragraph id="idf1d3fdeb5f12468dbc7a3c864e48a0dd"><enum>(4)</enum><text>identifying incidents quickly;</text></paragraph><paragraph id="id89acd576afc34221b8e00ee67c76333c"><enum>(5)</enum><text>isolating and removing unauthorized entities from agency systems quickly;</text></paragraph><paragraph id="idef712e9810704f949a0e879eac011222"><enum>(6)</enum><text>otherwise increasing the resource costs for entities that cause incidents to be successful; and</text></paragraph><paragraph id="idc3251015893945bb91cf5be3a87c7ab9"><enum>(7)</enum><text>a summary of the agency progress reports required under subsection (b).</text></paragraph></subsection><subsection id="id02b50496e4764e499aa1080c1295de5c"><enum>(b)</enum><header>Agency progress reports</header><text>Not later than 1 year after the date of enactment of this Act, the head of each agency shall submit to the Director a progress report on implementing an information security program based on the presumption of compromise and least privilege principles, which shall include—</text><paragraph id="id249e1e2bd2d04451ad310cdaf1d285f7"><enum>(1)</enum><text>a description of any steps the agency has completed, including progress toward achieving requirements issued by the Director;</text></paragraph><paragraph id="id09e5c707d5bb443f987e1ee85554f783"><enum>(2)</enum><text>an identification of activities that have not yet been completed and that would have the most immediate security impact; and</text></paragraph><paragraph id="id44044096db5d469a9aa127f966432c78"><enum>(3)</enum><text>a schedule to implement any planned activities.</text></paragraph></subsection></section><section id="id8b0e41d840ae4395902d3df5effa3f05"><enum>208.</enum><header>Automation reports</header><subsection id="idd763fa23c6994651a96be8e3aa0ab982"><enum>(a)</enum><header>OMB report</header><text>Not later than 180 days after the date of enactment of this Act, the Director shall submit to the appropriate congressional committees a report on the use of automation under paragraphs (1), (5)(C) and (8)(B) of section 3554(b) of title 44, United States Code.</text></subsection><subsection id="id638258cae80d4f5586f224980af092d6"><enum>(b)</enum><header>GAO report</header><text>Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall perform a study on the use of automation and machine readable data across the Federal Government for cybersecurity purposes, including the automated updating of cybersecurity tools, sensors, or processes by agencies.</text></subsection></section><section id="ida9af080b73ed477baca48a97214a35aa"><enum>209.</enum><header>Extension of Federal acquisition security council</header><text display-inline="no-display-inline">Section 1328 of title 41, United States Code, is amended by striking <quote>the date that</quote> and all that follows and inserting <quote>December 31, 2026.</quote>.</text></section><section id="ida81471996a584d75940dabe4f8de9e29"><enum>210.</enum><header>Council of the Inspectors General on Integrity and Efficiency dashboard</header><subsection id="idac07d37cba7e47de8f8d92443e4d6ac9"><enum>(a)</enum><header>Dashboard required</header><text>Section 11(e)(2) of the Inspector General Act of 1978 (5 U.S.C. App.) is amended—</text><paragraph id="id29e239309cef4fe485d49882114e6626"><enum>(1)</enum><text>in subparagraph (A), by striking <quote>and</quote> at the end;</text></paragraph><paragraph id="id8418a520c05045318dffd446f13a6aa5"><enum>(2)</enum><text>by redesignating subparagraph (B) as subparagraph (C); and</text></paragraph><paragraph id="idc69774f40e9b458eb783bcc8720f2590"><enum>(3)</enum><text>by inserting after subparagraph (A) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id4448fc6f4416476ea065542478bc755c" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="ide56981bc076844bea2d1e09eda7b08ec"><enum>(B)</enum><text>that shall include a dashboard of open information security recommendations identified in the independent evaluations required by section 3555(a) of title 44, United States Code; and</text></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection></section></title><title id="idBA76D8C1347D4082B6AD3C5262A370EC" style="OLC" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>III</enum><header>Risk-based budget model</header><section id="id61d6ec96e759421ca9949058bbc78dd6"><enum>301.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text><paragraph id="idb9abc574126144f887ebac979deeefd3"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="ida1f9d9946c4e4721a27127ab912a8cbb"><enum>(A)</enum><text>the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate; and</text></subparagraph><subparagraph id="idebc31616daee4995836cd605ef5df6a1"><enum>(B)</enum><text>the Committee on Homeland Security and the Committee on Appropriations of the House of Representatives.</text></subparagraph></paragraph><paragraph id="id08d40eb4b6f24271b5c6671c61355e4b"><enum>(2)</enum><header>Covered agency</header><text>The term <term>covered agency</term> has the meaning given the term <term>executive agency</term> in section 133 of title 41, United States Code.</text></paragraph><paragraph id="idc0779233548642bca684e4f84409925a"><enum>(3)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Office of Management and Budget.</text></paragraph><paragraph id="idb62ac6aef9e24153a5166b5881a14b90"><enum>(4)</enum><header>Information technology</header><text>The term <term>information technology</term>—</text><subparagraph id="id8988a1772d7240efb349621f64718f86"><enum>(A)</enum><text>has the meaning given the term in section 11101 of title 40, United States Code; and</text></subparagraph><subparagraph id="id5ce7cce11c87401790c2837371c956df"><enum>(B)</enum><text>includes the hardware and software systems of a Federal agency that monitor and control physical equipment and processes of the Federal agency.</text></subparagraph></paragraph><paragraph id="id72a2f2e2ccd14415b4e2192b8341fc95"><enum>(5)</enum><header>Risk-based budget</header><text>The term <term>risk-based budget</term> means a budget—</text><subparagraph id="id6e90ed1cd5a34eeaa3efb19ed2183f1d"><enum>(A)</enum><text>developed by identifying and prioritizing cybersecurity risks and vulnerabilities, including impact on agency operations in the case of a cyber attack, through analysis of threat intelligence, incident data, and tactics, techniques, procedures, and capabilities of cyber threats; and</text></subparagraph><subparagraph id="ide009e326328946a0a8967519696951c8"><enum>(B)</enum><text>that allocates resources based on the risks identified and prioritized under subparagraph (A).</text></subparagraph></paragraph></section><section id="id8425fbd074984e3196cb527331f4167c"><enum>302.</enum><header>Establishment of risk-based budget model</header><subsection id="idae13440539584556ab47e663cee611b4"><enum>(a)</enum><header>In general</header><paragraph id="id9a6cfcb949da4aaab905f235db89ce2d"><enum>(1)</enum><header>Model</header><text>Not later than 1 year after the first publication of the budget submitted by the President under section 1105 of title 31, United States Code, following the date of enactment of this Act, the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director and in coordination with the Director of the National Institute of Standards and Technology, shall develop a standard model for creating a risk-based budget for cybersecurity spending.</text></paragraph><paragraph id="id69ecfdb9df1c4a929a5830460d801ad9"><enum>(2)</enum><header>Responsibility of director</header><text>Section 3553(a) of title 44, United States Code, as amended by section 101, is further amended by inserting after paragraph (6) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id6df3f96db0004ac4bfc3be24eed0cdc9" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id9bdbf288009a4b478ef00d94e17a909c"><enum>(7)</enum><text>developing a standard risk-based budget model to inform Federal agency cybersecurity budget development; and</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph><paragraph id="ideba7f555019943688711ef3518cfb002"><enum>(3)</enum><header>Contents of model</header><text>The model required to be developed under paragraph (1) shall—</text><subparagraph id="id81afec9eb866425489d8e99f00365899"><enum>(A)</enum><text>consider Federal and non-Federal cyber threat intelligence products, where available, to identify threats, vulnerabilities, and risks;</text></subparagraph><subparagraph id="ida5096baf8dbf40379394193241aeb4cb"><enum>(B)</enum><text>consider the impact of agency operations of compromise of systems, including the interconnectivity to other agency systems and the operations of other agencies;</text></subparagraph><subparagraph id="idc68420fa28fb4a408aae5b2c87925640"><enum>(C)</enum><text>indicate where resources should be allocated to have the greatest impact on mitigating current and future threats and current and future cybersecurity capabilities;</text></subparagraph><subparagraph id="id2e148fe05ddc4d459afb91e7ec7c2c90"><enum>(D)</enum><text>be used to inform acquisition and sustainment of—</text><clause id="id104bb4bf6fb04427b01354337e6610be"><enum>(i)</enum><text>information technology and cybersecurity tools;</text></clause><clause id="id8909559045b34f998818a93e751d707a"><enum>(ii)</enum><text>information technology and cybersecurity architectures;</text></clause><clause id="ida7f79dd83e364825bcfd4e71b90be37a"><enum>(iii)</enum><text>information technology and cybersecurity personnel; and</text></clause><clause id="id11ee14b91f03409a9db45867c34d612d"><enum>(iv)</enum><text>cybersecurity and information technology concepts of operations; and</text></clause></subparagraph><subparagraph id="id94a1e352563d4488a2fdb60f26e5f23b"><enum>(E)</enum><text>be used to evaluate and inform Government-wide cybersecurity programs of the Department of Homeland Security.</text></subparagraph></paragraph><paragraph id="idb70be624cbd74684866b064d053f7eca"><enum>(4)</enum><header>Required updates</header><text>Not less frequently than once every 3 years, the Director shall review, and update as necessary, the model required to be developed under this subsection.</text></paragraph><paragraph id="id130ef2b078ac448995511e1e589a02c8"><enum>(5)</enum><header>Publication</header><text>The Director shall publish the model required to be developed under this subsection, and any updates necessary under paragraph (4), on the public website of the Office of Management and Budget.</text></paragraph><paragraph id="id80164e65eae74a60afb60620f20118b3"><enum>(6)</enum><header>Reports</header><text>Not later than 1 year after the date of enactment of this Act, and annually thereafter for each of the 2 following fiscal years or until the date on which the model required to be developed under this subsection is completed, whichever is sooner, the Director shall submit a report to Congress on the development of the model.</text></paragraph></subsection><subsection id="id6447a9f9d4a8439583a87a9e57bcaac7"><enum>(b)</enum><header>Required use of risk-based budget model</header><paragraph id="ideca2ca02c21b4de0b81dfa0cd882bd99"><enum>(1)</enum><header>In general</header><text>Not later than 2 years after the date on which the model developed under subsection (a) is published, the head of each covered agency shall use the model to develop the annual cybersecurity and information technology budget requests of the agency.</text></paragraph><paragraph id="id8a0392638deb434db176d704ccccdef0"><enum>(2)</enum><header>Agency performance plans</header><text>Section 3554(d)(2) of title 44, United States Code, is amended by inserting <quote>and the risk-based budget model required under section 3553(a)(7)</quote> after <quote>paragraph (1)</quote>.</text></paragraph></subsection><subsection id="id6e7cafa7c6ff4d0db3d7e8a1e2f7866b"><enum>(c)</enum><header>Verification</header><paragraph id="idfbe6d312438144b6b236c274622e15d5"><enum>(1)</enum><header>In general</header><text>Section 1105(a)(35)(A)(i) of title 31, United States Code, is amended—</text><subparagraph id="idf862e9dc40ef4c15a31255ab7b40687b"><enum>(A)</enum><text>in the matter preceding subclause (I), by striking <quote>by agency, and by initiative area (as determined by the administration)</quote> and inserting <quote>and by agency</quote>;</text></subparagraph><subparagraph id="ida8d32d9c7023497bab1fb422ffb79dd1"><enum>(B)</enum><text>in subclause (III), by striking <quote>and</quote> at the end; and</text></subparagraph><subparagraph id="idf0ebd809e59f4b9e8dbd45a5ed307c12"><enum>(C)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="ide1455b595c3b448d907443d68cef0f4b" changed="added" reported-display-style="italic" committee-id="SSGA00"><subclause id="id8a692bbd21184c8da03cd463a8d8e394"><enum>(V)</enum><text>a validation that the budgets submitted were developed using a risk-based methodology; and</text></subclause><subclause id="id6b6f6bbe5d704b1783ef7f348d2f6461"><enum>(VI)</enum><text>a report on the progress of each agency on closing recommendations identified under the independent evaluation required by section 3555(a)(1) of title 44.</text></subclause><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="ida0931978cc5a4a9bba86b3dcd3ae2392"><enum>(2)</enum><header>Effective date</header><text>The amendments made by paragraph (1) shall take effect on the date that is 2 years after the date on which the model developed under subsection (a) is published.</text></paragraph></subsection><subsection id="idb35deefffa414735b7748d73c82f7f18"><enum>(d)</enum><header>Reports</header><paragraph id="idfd3d62a99cbe4800bcca07f466c1256d"><enum>(1)</enum><header>Independent evaluation</header><text>Section 3555(a)(2) of title 44, United States Code, is amended—</text><subparagraph id="id4728e6e0b48e416f81385986d439f261"><enum>(A)</enum><text>in subparagraph (B), by striking <quote>and</quote> at the end;</text></subparagraph><subparagraph id="id7a62fb87cd084487a1450f8e1bbdf4e2"><enum>(B)</enum><text>in subparagraph (C), by striking the period at the end and inserting <quote>; and</quote>; and</text></subparagraph><subparagraph id="id59a4763ec6bf4c688da372abeccc5f7d"><enum>(C)</enum><text>by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id73967006b9f44c55b5d45e09fb8578cc" changed="added" reported-display-style="italic" committee-id="SSGA00"><subparagraph id="idc115e50d09274d7b896017a0e0c7865d"><enum>(D)</enum><text>an assessment of how the agency implemented the risk-based budget model required under section 3553(a)(7) and an evaluation of whether the model mitigates agency cyber vulnerabilities.</text></subparagraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="id832e92b9995649b59d63d05cdbaa4423"><enum>(2)</enum><header>Assessment</header><text>Section 3553(c) of title 44, United States Code, as amended by section 101, is further amended by inserting after paragraph (5) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id33f7d1fa278d46249bf1db904bfc8954" changed="added" reported-display-style="italic" committee-id="SSGA00"><paragraph id="id8f51d986dd5e4a7ba58bcd72e7fe4c3f"><enum>(6)</enum><text>an assessment of—</text><subparagraph id="idf7bd88a0434e43acbe91f4c78c4a6720"><enum>(A)</enum><text>Federal agency implementation of the model required under subsection (a)(7);</text></subparagraph><subparagraph id="ide3c2d1c53a65426395272383cdb89a94"><enum>(B)</enum><text>how cyber vulnerabilities of Federal agencies changed from the previous year; and</text></subparagraph><subparagraph id="idf8c276c6fe6d41c895ab93c4fee7855d"><enum>(C)</enum><text>whether the model mitigates the cyber vulnerabilities of the Federal Government.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="ide1279245c0cc43ab8599766b4dddfde6"><enum>(e)</enum><header>GAO report</header><text>Not later than 3 years after the date on which the first budget of the President is submitted to Congress containing the validation required under section 1105(a)(35)(A)(i)(V) of title 31, United States Code, as amended by subsection (c), the Comptroller General of the United States shall submit to the appropriate congressional committees a report that includes—</text><paragraph id="idb0c7dda822e54d558014e00b057a44f5"><enum>(1)</enum><text>an evaluation of the success of covered agencies in developing risk-based budgets;</text></paragraph><paragraph id="idf0ce13e2719a4724a71173c9af83189d"><enum>(2)</enum><text>an evaluation of the success of covered agencies in implementing risk-based budgets;</text></paragraph><paragraph id="idbf82564ba93d4f9791edbeefab2f4a87"><enum>(3)</enum><text>an evaluation of whether the risk-based budgets developed by covered agencies mitigate cyber vulnerability, including the extent to which the risk-based budgets inform Federal Government-wide cybersecurity programs; and</text></paragraph><paragraph id="idf8d17040945d42bc85f11fefe93e4ccd" commented="no" display-inline="no-display-inline"><enum>(4)</enum><text>any other information relating to risk-based budgets the Comptroller General determines appropriate.</text></paragraph></subsection></section></title><title style="OLC" id="id6be91a28-5456-47b5-8e19-e05075ec9918" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>IV</enum><header>Pilot programs to enhance Federal cybersecurity</header><section id="idb880f204-10e6-4aff-8b89-7b9643bdf14d"><enum>401.</enum><header>Active cyber defensive study</header><subsection id="id950c6394-2f83-4e9b-bf51-78cca0c53f09"><enum>(a)</enum><header>Definition</header><text>In this section, the term <term>active defense technique</term>—</text><paragraph id="id50e222df-7893-4db5-8e65-c63256672333"><enum>(1)</enum><text>means an action taken on the systems of an entity to increase the security of information on the network of an agency by misleading an adversary; and</text></paragraph><paragraph id="id41163473-3e32-45be-93e8-33460e986a64"><enum>(2)</enum><text>includes a honeypot, deception, or purposefully feeding false or misleading data to an adversary when the adversary is on the systems of the entity.</text></paragraph></subsection><subsection id="idb5da2754f1c54de2a4e1511631e75256"><enum>(b)</enum><header>Study</header><text>Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in coordination with the Director, shall perform a study on the use of active defense techniques to enhance the security of agencies, which shall include—</text><paragraph id="id366852ecb4774f53908d0d509c05048e"><enum>(1)</enum><text>a review of legal restrictions on the use of different active cyber defense techniques in Federal environments, in consultation with the Department of Justice;</text></paragraph><paragraph id="idf381ed1484724299b94a6ffa0914d5b7"><enum>(2)</enum><text>an evaluation of—</text><subparagraph id="ida944d9bfe98a43ae9056c5b94d132037"><enum>(A)</enum><text>the efficacy of a selection of active defense techniques determined by the Director of the Cybersecurity and Infrastructure Security Agency; and</text></subparagraph><subparagraph id="id5e1af42e4dab401fa0d291a30002f0aa"><enum>(B)</enum><text>factors that impact the efficacy of the active defense techniques evaluated under subparagraph (A);</text></subparagraph></paragraph><paragraph id="id6acea7d9c8e24ba3915449dab885955d"><enum>(3)</enum><text>recommendations on safeguards and procedures that shall be established to require that active defense techniques are adequately coordinated to ensure that active defense techniques do not impede threat response efforts, criminal investigations, and national security activities, including intelligence collection; and</text></paragraph><paragraph id="idda0e32b2c81748c3ac25ab332019e4d6"><enum>(4)</enum><text>the development of a framework for the use of different active defense techniques by agencies.</text></paragraph></subsection></section><section id="ide28bd9bd-b880-470a-9369-73f95be82806"><enum>402.</enum><header>Security operations center as a service pilot</header><subsection id="id2ea889f5-5eca-4380-8859-4b9dfb94f9da"><enum>(a)</enum><header>Purpose</header><text>The purpose of this section is for the Cybersecurity and Infrastructure Security Agency to run a security operation center on behalf of another agency, alleviating the need to duplicate this function at every agency, and empowering a greater centralized cybersecurity capability. </text></subsection><subsection id="id59072d4e-2da1-4e39-bc59-0f1728e11ed5"><enum>(b)</enum><header>Plan</header><text>Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish a centralized Federal security operations center shared service offering within the Cybersecurity and Infrastructure Security Agency.</text></subsection><subsection id="id9bbfd027-8896-4c35-a0c0-2a4b9a7e8e02"><enum>(c)</enum><header>Contents</header><text>The plan required under subsection (b) shall include considerations for—</text><paragraph id="id3426c98e-c593-4cce-bf6a-b54e379da2ac"><enum>(1)</enum><text>collecting, organizing, and analyzing agency information system data in real time;</text></paragraph><paragraph id="id0ccabc11-bcd0-4ede-b2cb-ed47e93671b8"><enum>(2)</enum><text>staffing and resources; and</text></paragraph><paragraph id="id7ba59422-6d86-4b08-a09b-a1a84dd256b1"><enum>(3)</enum><text>appropriate interagency agreements, concepts of operations, and governance plans.</text></paragraph></subsection><subsection id="id722e4ba8-c1f1-4134-a74f-9bd3d2d70679"><enum>(d)</enum><header>Pilot program</header><paragraph id="id14667c90-3ec6-4429-8ce8-05649813d093"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date on which the plan required under subsection (b) is developed, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, shall enter into a 1-year agreement with not less than 2 agencies to offer a security operations center as a shared service.</text></paragraph><paragraph id="ide4e1084c-beb5-4fab-9e12-97e04161a701"><enum>(2)</enum><header>Additional agreements</header><text>After the date on which the briefing required under subsection (e)(1) is provided, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, may enter into additional 1-year agreements described in paragraph (1) with agencies.</text></paragraph></subsection><subsection id="id2c347965-f6e1-4142-b756-b4dea95bf4d8"><enum>(e)</enum><header>Briefing and report</header><paragraph id="id4adf98a7-6592-4fd3-af47-98960156f598"><enum>(1)</enum><header>Briefing</header><text>Not later than 260 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Oversight and Reform of the House of Representatives a briefing on the parameters of any 1-year agreements entered into under subsection (d)(1).</text></paragraph><paragraph id="ided460a16-db30-45c7-b938-5b737c40b516"><enum>(2)</enum><header>Report</header><text>Not later than 90 days after the date on which the first 1-year agreement entered into under subsection (d) expires, the Director of the Cybersecurity and Infrastructure Security Agency shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Oversight and Reform of the House of Representatives a report on—</text><subparagraph id="id06a737ad-6b58-44d1-963a-eac1e6d4f5d9"><enum>(A)</enum><text>the agreement; and</text></subparagraph><subparagraph id="id3d1bacf1-1f07-4b81-acf0-3bf7a2e3a2cb" commented="no" display-inline="no-display-inline"><enum>(B)</enum><text>any additional agreements entered into with agencies under subsection (d). </text></subparagraph></paragraph></subsection></section></title></legis-body><endorsement><action-date date="20221219">December 19, 2022</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

