<?xml version="1.0" encoding="UTF-8"?><BillSummaries>
    <item congress="117" measure-type="s" measure-number="3600" measure-id="id117s3600" originChamber="SENATE" orig-publish-date="2022-02-08" update-date="2022-03-14">
        <title>Strengthening American Cybersecurity Act of 2022</title>
        <summary summary-id="id117s3600v55" currentChamber="SENATE" update-date="2022-03-14">
            <action-date>2022-03-01</action-date>
            <action-desc>Passed Senate</action-desc>
            <summary-text><![CDATA[ <p><strong>Strengthening American Cybersecurity Act of 2022</strong></p> <p>This bill addresses cybersecurity threats against critical infrastructure and the federal government.</p> <p>The Cybersecurity and Infrastructure Security Agency (CISA) must perform ongoing and continuous assessments of federal risk posture.</p> <p> An agency, within a specified time frame, must (1) determine whether notice to any individual potentially affected by a breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected.</p> <p> Each agency must (1) provide information relating to a major incident to specified parties, and (2) develop specified training for individuals with access to federal information or information systems.</p> <p>The bill requires reporting and other actions to address cybersecurity incidents.</p> <p> Entities that own or operate critical infrastructure must report cyber incidents and ransom payments within specified time frames.</p> <p> The bill limits the use and disclosure of reported information.</p> <p> The bill establishes (1) an interagency council to standardize federal reporting of cybersecurity threats, (2) a task force on ransomware attacks, and (3) a pilot program to identify information systems vulnerable to such attacks.</p> <p>The bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA). </p> <p>FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing products and services.</p> <p> The bill establishes a FedRAMP Board to examine the operations of FedRAMP and the Federal Secure Cloud Advisory Committee.</p>]]></summary-text>
        </summary>
        <summary summary-id="id117s3600v00" currentChamber="SENATE" update-date="2022-03-12">
            <action-date>2022-02-08</action-date>
            <action-desc>Introduced in Senate</action-desc>
            <summary-text><![CDATA[ <p><strong>Strengthening American Cybersecurity Act of 2022</strong></p> <p>This bill addresses cybersecurity threats against critical infrastructure and the federal government.</p> <p>The Cybersecurity and Infrastructure Security Agency (CISA) must perform ongoing and continuous assessments of federal risk posture.</p> <p> An agency, within a specified time frame, must (1) determine whether notice to any individual potentially affected by a breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected.</p> <p> Each agency must (1) provide information relating to a major incident to specified parties, and (2) develop specified training for individuals with access to federal information or information systems.</p> <p>The bill requires reporting and other actions to address cybersecurity incidents.</p> <p> Entities that own or operate critical infrastructure must report cyber incidents and ransom payments within specified time frames.</p> <p> The bill limits the use and disclosure of reported information.</p> <p> The bill establishes (1) an interagency council to standardize federal reporting of cybersecurity threats, (2) a task force on ransomware attacks, and (3) a pilot program to identify information systems vulnerable to such attacks.</p> <p>The bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA). </p> <p>FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing products and services.</p> <p> The bill establishes a FedRAMP Board to examine the operations of FedRAMP and the Federal Secure Cloud Advisory Committee.</p>]]></summary-text>
        </summary>
    </item>
    <dublinCore xmlns:dc="http://purl.org/dc/elements/1.1/">
        <dc:format>text/xml</dc:format>
        <dc:language>EN</dc:language>
        <dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
        <dc:contributor>Congressional Research Service, Library of Congress</dc:contributor>
        <dc:description>This file contains bill summaries for federal legislation. A bill summary describes the most significant provisions of a piece of legislation and details the effects the legislative text may have on current law and federal programs. Bill summaries are authored by the Congressional Research Service (CRS) of the Library of Congress. As stated in Public Law 91-510 (2 USC 166 (d)(6)), one of the duties of CRS is "to prepare summaries and digests of bills and resolutions of a public general nature introduced in the Senate or House of Representatives". For more information, refer to the User Guide that accompanies this file.</dc:description>
    </dublinCore>
</BillSummaries>
