<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H9C4974FC45BC4DBC91F05235C93987F5" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 5786 IH: To establish in the National Nuclear Security Administration a Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group.</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-09-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 5786</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230928">September 28, 2023</action-date><action-desc><sponsor name-id="C001112">Mr. Carbajal</sponsor> (for himself, <cosponsor name-id="B001298">Mr. Bacon</cosponsor>, and <cosponsor name-id="G000579">Mr. Gallagher</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To establish in the National Nuclear Security Administration a Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group.</official-title></form><legis-body id="HAE97C7208B5942D4BE60F1ABDCF17B52" style="OLC"> 
<section id="HFC98B1734A384922A79C05BAD832571E" section-type="section-one"><enum>1.</enum><header>Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group</header><text display-inline="no-display-inline">Subtitle A of title XXXII of the National Defense Authorization Act for Fiscal Year 2000 (<external-xref legal-doc="public-law" parsable-cite="pl/106/65">Public Law 106–65</external-xref>) is amended by adding at the end the following new section:</text> <quoted-block style="OLC" id="H5DDC295F9E394AFB87010176E63B93F9" display-inline="no-display-inline"> <section id="HDCF51E306B5745E980875667F1232495"><enum>3222.</enum><header>Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group</header> <subsection id="HEAF7FEAD6A894288803939B4D519C499"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">There is in the Administration a working group, to be known as the <quote>Cybersecurity Risk Inventory, Assessment, and Mitigation Working Group</quote>. </text></subsection>
<subsection id="H2293EBDB1A0C4319AB2FF9AF78AB7332"><enum>(b)</enum><header>Membership</header><text>Members of the working group shall include the Deputy Administrator for Defense Programs, the Associate Administrator for Information Management and Chief Information Officer, and staff from other offices as determined appropriate by the Deputy Administrator and Associate Administrator.</text></subsection> <subsection id="HD4F851E7E2DD41F1A830EB37A85C16A1"><enum>(c)</enum><header>Comprehensive Strategy</header><text>The working group shall prepare a comprehensive strategy for inventorying the range of National Nuclear Security Administration systems that are potentially at risk in the operational technology and nuclear weapons information technology environments, assessing the systems at risk, and implementing risk mitigation actions. Such strategy shall incorporate key elements of effective cybersecurity risk management strategies, as identified by the Government Accountability Office, including the specification of—</text>
<paragraph id="H2CEB56A71AD2453180D4DB8846C9AAFA"><enum>(1)</enum><text>goals, objectives, activities, and performance measures;</text></paragraph> <paragraph id="HA0F72BF44BC741A89456B5155CDAE82A"><enum>(2)</enum><text>organizational roles, responsibilities, and coordination;</text></paragraph>
<paragraph id="H427B26F12BB74BE99176F63A7B53D256"><enum>(3)</enum><text>necessary resources needed to implement the strategy over the next ten years; and</text></paragraph> <paragraph id="H9135739EC9664F5B9FAB0A39CAB93BC7"><enum>(4)</enum><text>detailed milestones and schedules for completion of tasks.</text></paragraph></subsection>
<subsection id="H34A99CC798684BEEAB44F4C0FC4EBF45"><enum>(d)</enum><header>Submission to Congress</header>
<paragraph id="H0CA7BBDA7C5A42F68F740673E83F1D37"><enum>(1)</enum><header>Briefing</header><text>Not later than 120 days after the date of the enactment of this Act, the members of the working group shall provide to the congressional defense committees a briefing on the plan of the working group plan to develop the strategy required under subsection (c).</text></paragraph> <paragraph id="HADE615FB064949C099A888B477038A07"><enum>(2)</enum><header>Submission of strategy</header><text>Not later than April 1, 2025, the working group shall submit the congressional defense committees a copy of the completed strategy.</text></paragraph></subsection>
<subsection id="HE2B54E78C070450FAEB52172F7978E05"><enum>(e)</enum><header>Termination</header><text>The working group shall terminate on the date that is five years after the date of the enactment of this section.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></section> </legis-body></bill>

