<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HA56FEBA759D348818710917224D0F69C" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 9290 IH: To direct the Chief Information Officer of the Department of Defense and the Director of the Defense Information Systems Agency to jointly provide to the Committees on Armed Services of the Senate and House of Representatives a briefing on the plan of the Department of Defense to transition away from the Joint Regional Security Stacks, and for other purposes.</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-08-02</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 9290</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20240802">August 2, 2024</action-date><action-desc><sponsor name-id="S001208">Ms. Slotkin</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Chief Information Officer of the Department of Defense and the Director of the Defense Information Systems Agency to jointly provide to the Committees on Armed Services of the Senate and House of Representatives a briefing on the plan of the Department of Defense to transition away from the Joint Regional Security Stacks, and for other purposes.</official-title></form><legis-body id="HB386B1E540ED4890B2B966AD0600CD72" style="OLC"><section id="H70D73C45F87643189FC21FEC5F576E9B" section-type="section-one"><enum>1.</enum><header>Briefing on Department of Defense plan to transition away from Joint Regional Security Stacks</header><subsection id="HCB40ECB8748044F3843902DE08A33374"><enum>(a)</enum><header>Findings</header><text display-inline="yes-display-inline">Congress makes the following findings:</text><paragraph id="HE4A38CA6F9814272B500BCE5232B4CCD"><enum>(1)</enum><text display-inline="yes-display-inline">the Department of Defense faces aggressive timelines to meet zero trust goals by 2027 that align to its Zero Trust Strategy; and</text></paragraph><paragraph id="HC039B0027DB046ABB19C6E199FFE5F67"><enum>(2)</enum><text>a central part of this evolution will be the migration away from the legacy Joint Regional Security Stacks.</text></paragraph></subsection><subsection id="HA5AE4B9CE4D44F97A501F487057C80E2"><enum>(b)</enum><header>Sense of Congress</header><text>It is the sense of Congress that—</text><paragraph id="H32D20A0AFB0B4AE4999677B87E9572EB"><enum>(1)</enum><text display-inline="yes-display-inline">it is paramount that the successor to the Joint Regional Security Stacks incorporates least privilege access, continuous trust verification, and continuous security inspection while protecting all data and securing all applications regardless of user location or device;</text></paragraph><paragraph id="HD6D5507E59A24AD49B1BB140059C1748"><enum>(2)</enum><text>in order to achieve goals within the specified timelines of the Department of Defense, the military departments, combatant commands, and other components of the Department should leverage scalable, IL–5 certified solutions that went through an open vendor selection process and comprehensive prototyping before production; and</text></paragraph><paragraph id="H9E215BC8C9D94C55A2178C7BF7D5E0C8"><enum>(3)</enum><text display-inline="yes-display-inline">if such components instead pursue their own bespoke solutions to this common need, they must plan to navigate the transition from the Joint Regional Security Stacks and certification timeline constraints without negatively affecting the resilience of the Department of Defense information networks.</text></paragraph></subsection><subsection id="HFC89A35D2E8046A99EC9990F418C45E2"><enum>(c)</enum><header>Briefing</header><text display-inline="yes-display-inline">Not later than 120 days after the date of the enactment of this Act, the Chief Information Officer of the Department of Defense and the Director of the Defense Information Systems Agency, shall jointly provide to the Committees on Armed Services of the Senate and House of Representatives a briefing on the plan of the Department of Defense to transition away from the Joint Regional Security Stacks, with a focus on how legacy seats will gain access to zero trust-aligned continuous trust verification and security inspection regardless of user location or device.</text></subsection></section></legis-body></bill> 

