<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-House" bill-type="olc" dms-id="H978340F4D4164AA2847D118D00AAA00" public-private="public"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 4791 EH: Federal Agency Data Protection Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>0</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="no">IB</distribution-code> 
<congress display="yes">110th CONGRESS</congress> <session display="yes">2d Session</session> 
<legis-num>H. R. 4791</legis-num> 
<current-chamber display="no">IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<legis-type>AN ACT</legis-type> 
<official-title display="yes">To amend title 44, United States Code, to strengthen requirements for ensuring the effectiveness of information security controls over information resources that support Federal operations and assets, and for other purposes.</official-title> 
</form> 
<legis-body display-enacting-clause="yes-display-enacting-clause" id="H38F9DA573DF54B44AB901DD1A2701BA3" style="OLC"> 
<section id="HB3F561AD5A3B4298B9C3DB9BEAD6EA5" section-type="section-one"><enum>1.</enum><header>Short title; table of contents</header> 
<subsection id="HB9F496C6FA094F3F92C6AEFE45FF43A1"><enum>(a)</enum><header>Short title</header><text>This Act may be cited as the <quote><short-title>Federal Agency Data Protection Act</short-title></quote>.</text> </subsection>
<subsection id="HFF3E9B90D53F42AF80DC1DF22C6CEFEF"><enum>(b)</enum><header>Table of contents</header><text display-inline="yes-display-inline">The table of contents of this Act is as follows:</text> 
<toc container-level="legis-body-container" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration"> 
<toc-entry idref="HB3F561AD5A3B4298B9C3DB9BEAD6EA5" level="section">Sec. 1. Short title; table of contents.</toc-entry> 
<toc-entry idref="H77B16715AD354A259E462FFA37235635" level="section">Sec. 2. Purpose.</toc-entry> 
<toc-entry idref="H9B14270F84DF4453A7A38F8BB93892E0" level="section">Sec. 3. Definitions.</toc-entry> 
<toc-entry idref="H45C8BC1DB30E4467A5A98FDC495306E" level="section">Sec. 4. Authority of Director of Office of Management and Budget to establish information security policies and procedures.</toc-entry> 
<toc-entry idref="H8F547E5808CE463CB4389F00FFC57B35" level="section">Sec. 5. Responsibilities of Federal agencies for information security.</toc-entry> 
<toc-entry idref="H6332EE357BD34A62A42DA64616E64122" level="section">Sec. 6. Federal agency data breach notification requirements.</toc-entry> 
<toc-entry idref="HA5430EE0250C4139B903C69400AC35B5" level="section">Sec. 7. Protection of government computers from risks of peer-to-peer file sharing.</toc-entry> 
<toc-entry idref="HE42691B718D64387AE8D3674F394BAC0" level="section">Sec. 8. Annual independent audit.</toc-entry> 
<toc-entry idref="HF42FD193661244D182162656E0157647" level="section">Sec. 9. Best practices for privacy impact assessments.</toc-entry> 
<toc-entry idref="HBDEB7C218C3C40CEB5B9808765B619C4" level="section">Sec. 10. Implementation.</toc-entry> </toc> </subsection></section>
<section id="H77B16715AD354A259E462FFA37235635"><enum>2.</enum><header>Purpose</header><text display-inline="no-display-inline">The purpose of this Act is to protect personally identifiable information of individuals that is maintained in or transmitted by Federal agency information systems.</text> </section>
<section id="H9B14270F84DF4453A7A38F8BB93892E0"><enum>3.</enum><header>Definitions</header> 
<subsection id="H0D013EF56E604838B373C556828252CA"><enum>(a)</enum><header>Personally identifiable information and mobile digital device definitions</header><text display-inline="yes-display-inline"><external-xref legal-doc="usc" parsable-cite="usc/44/3542">Section 3542(b)</external-xref> of title 44, United States Code, is amended by adding at the end the following new paragraphs:</text> 
<quoted-block id="HD2734F754EED4D85B900FBB69500B199" style="OLC">
<paragraph id="H19DFE8186F864447908C6E8BE2183081"><enum>(4)</enum><text>The term <quote>personally identifiable information</quote>, with respect to an individual, means any information about the individual maintained by an agency, including information—</text> 
<subparagraph id="H8178755F05354899830584FBD224E080"><enum>(A)</enum><text>about the individual’s education, finances, or medical, criminal, or employment history;</text> </subparagraph>
<subparagraph id="H51BAFBD8A915421193914CE93523AEA3"><enum>(B)</enum><text>that can be used to distinguish or trace the individual’s identity, including name, social security number, date and place of birth, mother’s maiden name, or biometric records; or</text> </subparagraph>
<subparagraph id="H18E1EDC979A0411A88CA5915A68DBB4E"><enum>(C)</enum><text>that is otherwise linked or linkable to the individual.</text> </subparagraph></paragraph>
<paragraph id="H850CE7C978DA4255BE1DB9AB3100AB40"><enum>(5)</enum><text>The term <quote>mobile digital device</quote> includes any device that can store or process information electronically and is designed to be used in a manner not limited to a fixed location, including—</text> 
<subparagraph id="H7D1A18130EF54D3591003FEE162FC858"><enum>(A)</enum><text>processing devices such as laptop computers, communication devices, and other hand-held computing devices; and</text> </subparagraph>
<subparagraph id="HAEACF16AE20742F9A508FC1EC9100148"><enum>(B)</enum><text>storage devices such as portable hard drives, CD–ROMs, DVDs, and other portable electronic media.</text> </subparagraph></paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </subsection>
<subsection id="HC133D672FC054C4EBCDB39E1C12E3514"><enum>(b)</enum><header>Conforming amendments</header><text>Section 208 of the E-Government Act of 2002 (<external-xref legal-doc="public-law" parsable-cite="pl/107/347">Public Law 107–347</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/44/3501">44 U.S.C. 3501</external-xref> note) is amended—</text> 
<paragraph id="HEEE39D2F87AF4A20A6E200E2438E05D9"><enum>(1)</enum><text>in subsection (b)(1)(A)—</text> 
<subparagraph id="HEBD8356694414667B00094997149933E"><enum>(A)</enum><text>in clause (i), by striking <quote>information that is in an identifiable form</quote> and inserting <quote>personally identifiable information</quote>; and</text> </subparagraph>
<subparagraph id="H7AD96792A4324E36A03C3F0469D5FF52"><enum>(B)</enum><text>in clause (ii)(II), by striking <quote>information in an identifiable form permitting the physical or online contacting of a specific individual</quote> and inserting <quote>personally identifiable information</quote>;</text> </subparagraph></paragraph>
<paragraph id="HB531B878C67B44B9B7364C5E39E1884"><enum>(2)</enum><text>in subsection (b)(2)(B)(i), by striking <quote>information that is in an identifiable form</quote> and inserting <quote>personally identifiable information</quote>;</text> </paragraph>
<paragraph id="H1830D1787C504C6CAEC509222B40CD00"><enum>(3)</enum><text>in subsection (b)(3)(C), by striking <quote>information that is in an identifiable form</quote> and inserting <quote>personally identifiable information</quote>; and</text> </paragraph>
<paragraph id="H1DA40EF05F7A44D291797B89EAF88709"><enum>(4)</enum><text>in subsection (d), by striking the text and inserting <quote>In this section, the term <quote>personally identifiable information</quote> has the meaning given that term in <external-xref legal-doc="usc" parsable-cite="usc/44/3542">section 3542(b)(4)</external-xref> of title 44, United States Code.</quote>.</text> </paragraph></subsection></section>
<section id="H45C8BC1DB30E4467A5A98FDC495306E"><enum>4.</enum><header>Authority of Director of Office of Management and Budget to establish information security policies and procedures</header><text display-inline="no-display-inline"><external-xref legal-doc="usc" parsable-cite="usc/44/3543">Section 3543(a)</external-xref> of title 44, United States Code, is amended—</text> 
<paragraph id="HB75B08A4DC1740618D5F6F8F61A622F"><enum>(1)</enum><text display-inline="yes-display-inline">by inserting before the semicolon at the end of paragraph (5) the following:</text> 
<quoted-block display-inline="yes-display-inline" id="HA02DB203426040368DDE1CAF2DAEFADA" style="OLC"><text>, including plans and schedules, developed by the agency on the basis of priorities for addressing levels of identified risk, for conducting—</text>
<subparagraph id="H5B134C0D5A614669BE04B6CB26019596"><enum>(A)</enum><text display-inline="yes-display-inline">testing and evaluation, as required under section 3544(b)(5); and</text> </subparagraph>
<subparagraph id="H292C373EFA5843FAB300599926C9D711"><enum>(B)</enum><text>remedial action, as required under section 3544(b)(6), to address deficiencies identified by such testing and evaluation</text> </subparagraph> <after-quoted-block>; and</after-quoted-block></quoted-block> </paragraph>
<paragraph id="H884E57751D0741C1A775934D21822CB5"><enum>(2)</enum><text>by adding at the end the following:</text> 
<quoted-block id="H85C939F6CDC64C029171C65DDF7E003D" style="OLC">
<paragraph id="H9781B33C88254E58A6592CF929BD2F"><enum>(9)</enum><text>establishing minimum requirements regarding the protection of personally identifiable information maintained in or transmitted by mobile digital devices, including requirements for the use of technologies that efficiently and effectively render information unusable by unauthorized persons;</text> </paragraph>
<paragraph id="H235481F107C442A7839000E9EA6279C5"><enum>(10)</enum><text>requiring agencies to comply with—</text> 
<subparagraph id="H6F863E6EDE324A2299428B00D3A1ABF9"><enum>(A)</enum><text>minimally acceptable system configuration requirements consistent with best practices, including checklists developed under section 8(c) of the Cyber Security Research and Development Act (<external-xref legal-doc="public-law" parsable-cite="pl/107/305">Public Law 107–305</external-xref>; 116 Stat. 2378) by the Director of the National Institute of Standards and Technology; and</text> </subparagraph>
<subparagraph id="H603F90EC2C5A49B1974585302C78CC6C"><enum>(B)</enum><text>minimally acceptable requirements for periodic testing and evaluation of the implementation of such configuration requirements;</text> </subparagraph></paragraph>
<paragraph id="HEB48D4BFED2B4B98A7FADCC4941DA37C"><enum>(11)</enum><text>ensuring that agency contracts for (or involving or including) the provision of information technology products or services include requirements for contractors to meet minimally acceptable configuration requirements, as required under paragraph (10);</text> </paragraph>
<paragraph id="HA22CCA2A45D1439AA167E166280841D"><enum>(12)</enum><text>ensuring the establishment through regulation and guidance of contract requirements to ensure compliance with this subchapter with regard to providing information security for information and information systems used or operated by a contractor of an agency or other organization on behalf of the agency; and</text> </paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></section>
<section id="H8F547E5808CE463CB4389F00FFC57B35"><enum>5.</enum><header>Responsibilities of Federal agencies for information security</header><text display-inline="no-display-inline"><external-xref legal-doc="usc" parsable-cite="usc/44/3544">Section 3544(b)</external-xref> of title 44, United States Code, is amended—</text> 
<paragraph id="HD8108697C53148A2A6C172611795B546"><enum>(1)</enum><text>in paragraph (2)(D)(iii), by striking <quote>as determined by the agency</quote> and inserting <quote>as required by the Director under section 3543(a)(10)</quote>;</text> </paragraph>
<paragraph id="H0B9B9334720C4A1D8F1244224B95C141"><enum>(2)</enum><text>in paragraph (5)—</text> 
<subparagraph id="HBAE0950C8A7F44878F46C7244D467600"><enum>(A)</enum><text>by inserting after <quote>annually</quote> the following: <quote>and as approved by the Director</quote>;</text> </subparagraph>
<subparagraph id="HAA14DF992FE64EC0BD00E5E43E54B97B"><enum>(B)</enum><text>by striking <quote>and</quote> at the end of subparagraph (A);</text> </subparagraph>
<subparagraph id="H2B6A09D55F974526A187113ED4929E67"><enum>(C)</enum><text>by redesignating subparagraph (B) as subparagraph (D); and</text> </subparagraph>
<subparagraph id="H7040A8E782FC480CB55BB61D2EC51600"><enum>(D)</enum><text>by inserting after subparagraph (A) the following:</text> 
<quoted-block id="HE0FB82DAD8614FAF91E22164300459BE" style="OLC">
<subparagraph id="H93E8424CA24844BFB62628C2FD0FBA2"><enum>(B)</enum><text>shall include testing and evaluation of system configuration requirements as required under section 3543(a)(10);</text> </subparagraph>
<subparagraph id="H780D6CB69DAA485CB388AE28AFE4DAFC"><enum>(C)</enum><text display-inline="yes-display-inline">shall include testing of systems operated by a contractor of the agency or other organization on behalf of the agency, which testing requirement may be satisfied by independent testing, evaluation, or audit of such systems; and</text> </subparagraph> <after-quoted-block>;</after-quoted-block></quoted-block> </subparagraph></paragraph>
<paragraph id="H188A3A9BB3F04FFA8C03FB4748A64464"><enum>(3)</enum><text>by striking <quote>and</quote> at the end of paragraph (7);</text> </paragraph>
<paragraph id="HC3FCBDE893074BB495457DF7001543AA"><enum>(4)</enum><text>by striking the period at the end of paragraph (8) and inserting a semicolon; and</text> </paragraph>
<paragraph id="H3D5F77C1112D4ABC8BE5575347D2AE65"><enum>(5)</enum><text>by adding at the end the following:</text> 
<quoted-block id="H0A4F4A8D59394FD9A0579ED8F7341C66" style="OLC">
<paragraph id="H7147F6F0342B4784AD7F04FD92D66E0"><enum>(9)</enum><text>plans and procedures for ensuring the adequacy of information security protections for systems maintaining or transmitting personally identifiable information, including requirements for—</text> 
<subparagraph id="H74AD03CB4BD046668572623921D788E4"><enum>(A)</enum><text>maintaining a current inventory of systems maintaining or transmitting such information;</text> </subparagraph>
<subparagraph id="H3DDF869161274387BBDE6E1E31FE7739"><enum>(B)</enum><text>implementing information security requirements for mobile digital devices maintaining or transmitting such information, as required by the Director (including the use of technologies rendering data unusable by unauthorized persons); and</text> </subparagraph>
<subparagraph id="H1EDBD9E2BD0445F2B4AA4CA0E2677FF6"><enum>(C)</enum><text>developing, implementing, and overseeing remediation plans to address vulnerabilities in information security protections for such information;</text> </subparagraph></paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></section>
<section id="H6332EE357BD34A62A42DA64616E64122"><enum>6.</enum><header>Federal agency data breach notification requirements</header> 
<subsection id="H9634163AE0FC46D19B839F8C650477D5"><enum>(a)</enum><header>Authority of director of Office of Management and Budget To establish data breach policies</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3543">Section 3543(a)</external-xref> of title 44, United States Code, as amended by section 4, is further amended—</text> 
<paragraph id="H3C5DD387889F44C890062DF719832E00"><enum>(1)</enum><text>by striking <quote>and</quote> at the end of paragraph (7);</text> </paragraph>
<paragraph id="H132982BC8EB84365BDC083CC14B65E3"><enum>(2)</enum><text>in paragraph (8)—</text> 
<subparagraph id="H6E04C79216E04090AB8509CA7D0FE2B"><enum>(A)</enum><text>by striking <quote>and</quote> at the end of subparagraph (D);</text> </subparagraph>
<subparagraph id="H5DD9B9142FF14F6FA8D1A81DAFA8855F"><enum>(B)</enum><text>by striking the period and inserting <quote>; and</quote> at the end of subparagraph (E); and</text> </subparagraph>
<subparagraph id="H88B1DBFBEBDF4FA09B30E3F66B829F9B"><enum>(C)</enum><text>by adding at the end the following new subparagraph:</text> 
<quoted-block id="H08222CA148E0401EA1791EF4BA000833" style="OLC">
<subparagraph id="H1B53895C4D194493A81427567D081B00"><enum>(F)</enum><text>a summary of the breaches of information security reported by agencies to the Director and the Federal information security incident center pursuant to paragraph (13);</text> </subparagraph> <after-quoted-block>; and</after-quoted-block></quoted-block> </subparagraph></paragraph>
<paragraph id="H3B10E45691114F749612AB18FCAEC25B"><enum>(3)</enum><text>by adding at the end the following:</text> 
<quoted-block id="HB8FE4A723CF84C9C92DAD3A89F60C047" style="OLC">
<paragraph id="H45D1F9AF90F64AEE851241451BE7263C"><enum>(13)</enum><text display-inline="yes-display-inline">establishing policies, procedures, and standards for agencies to follow in the event of a breach of data security involving the disclosure of personally identifiable information, specifically including—</text> 
<subparagraph id="H62D75C3DA3D542629372F7DAA2068F02"><enum>(A)</enum><text>a requirement for timely notice to be provided to those individuals whose personally identifiable information could be compromised as a result of such breach, except no notice shall be required if the breach does not create a reasonable risk—</text> 
<clause id="HBE76D4F25A944239AB2E2EFD68D86D8C"><enum>(i)</enum><text>of identity theft, fraud, or other unlawful conduct regarding such individual; or</text> </clause>
<clause id="HEB0F466E0C404FBF89A43DD09C687B26"><enum>(ii)</enum><text>of other harm to the individual;</text> </clause></subparagraph>
<subparagraph id="HCAA7E01F0F76466A8C765D2C82B00878"><enum>(B)</enum><text>guidance on determining how timely notice is to be provided;</text> </subparagraph>
<subparagraph id="H5E64AACF567545D2AC292EB198B2EA3"><enum>(C)</enum><text>guidance regarding whether additional special actions are necessary and appropriate, including data breach analysis, fraud resolution services, identify theft insurance, and credit protection or monitoring services; and</text> </subparagraph>
<subparagraph id="HC363001632494503AE03BDECC90000C3"><enum>(D)</enum><text>a requirement for timely reporting by the agencies of such breaches to the Director and Federal information security center.</text> </subparagraph></paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></subsection>
<subsection id="HB4E1267FCC684D7498E0ABF32706E246"><enum>(b)</enum><header>Authority of chief information officer To develop and maintain inventories</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3544">Section 3544(a)(3)</external-xref> of title 44, United States Code, is amended—</text> 
<paragraph id="HFD070CA2B9B54934B94437014683BAD1"><enum>(1)</enum><text>by inserting after <quote>authority to ensure compliance with</quote> the following: <quote>and, to the extent determined necessary and explicitly authorized by the head of the agency, to enforce</quote>;</text> </paragraph>
<paragraph id="H30C392BCCCAC4CA6AFB0150900946D73"><enum>(2)</enum><text>by striking <quote>and</quote> at the end of subparagraph (D);</text> </paragraph>
<paragraph id="HB09DB783AD6C4AF7984BC339C38DDB"><enum>(3)</enum><text>by inserting <quote>and</quote> at the end of subparagraph (E); and</text> </paragraph>
<paragraph id="HE16804B709AE412D9DE4E7C11900DEC9"><enum>(4)</enum><text>by adding at the end the following:</text> 
<quoted-block id="H06AD27A6CC164B62883F7E86DB97CE2E" style="OLC">
<subparagraph id="H868FE900401E4831983216FA77DF28A0"><enum>(F)</enum><text>developing and maintaining an inventory of all personal computers, laptops, or any other hardware containing personally identifiable information;</text> </subparagraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></subsection>
<subsection id="H10702372761942FD8877A9C9D7AF55DF"><enum>(c)</enum><header>Inclusion of data breach notification</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3544">Section 3544(b)</external-xref> of title 44, United States Code, as amended by section 5, is further amended by adding at the end the following:</text> 
<quoted-block id="HF80C46DF643C4B93ABF052032E787D59" style="OLC">
<paragraph id="HDDB4BA9F57B945BC9637DB6207E48D90"><enum>(10)</enum><text>procedures for notifying individuals whose personally identifiable information may have been compromised or accessed following a breach of information security; and</text> </paragraph>
<paragraph id="H17F0D780AFE2483092DF9DF7DBE0EBB9"><enum>(11)</enum><text>procedures for timely reporting of information security breaches involving personally identifiable information to the Director and the Federal information security incident center.</text> </paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </subsection>
<subsection id="HBB2C899987FA4442A16308B142B12100"><enum>(d)</enum><header>Authority of Agency Chief Human Capital Officers To Assess Federal Personal Property</header><text display-inline="yes-display-inline"><external-xref legal-doc="usc" parsable-cite="usc/5/1402">Section 1402(a)</external-xref> of title 5, United States Code, is amended—</text> 
<paragraph id="HAC5860A363D9461E00F158B235BA00A8"><enum>(1)</enum><text>by striking <quote>, and</quote> at the end of paragraph (5) and inserting a semicolon;</text> </paragraph>
<paragraph id="H2B07E32593364F2FA0B34E55E49983E5"><enum>(2)</enum><text>by striking the period and inserting <quote>; and</quote> at the end of paragraph (6); and</text> </paragraph>
<paragraph id="H02C908ECAF564F65AC1C9408645E7919"><enum>(3)</enum><text>by adding at the end the following:</text> 
<quoted-block display-inline="no-display-inline" id="HDF51082C9C784F51B2B31DADB74240C9" style="USC">
<paragraph id="H0F54D1B9CC2A4200B2FBA02504B975FC"><enum>(7)</enum><text display-inline="yes-display-inline">prescribing policies and procedures for exit interviews of employees, including a full accounting of all Federal personal property that was assigned to the employee during the course of employment.</text> </paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></subsection></section>
<section id="HA5430EE0250C4139B903C69400AC35B5"><enum>7.</enum><header>Protection of government computers from risks of peer-to-peer file sharing</header> 
<subsection id="HCF6929DD53064C4D85DC03AC68B3002D"><enum>(a)</enum><header>Plans required</header><text>As part of the Federal agency responsibilities set forth in sections <external-xref legal-doc="usc" parsable-cite="usc/44/3544">3544</external-xref> and <external-xref legal-doc="usc" parsable-cite="usc/44/3545">3545</external-xref> of title 44, United States Code, the head of each agency shall develop and implement a plan to ensure the security and privacy of information collected or maintained by or on behalf of the agency from the risks posed by certain peer-to-peer file sharing programs.</text> </subsection>
<subsection id="H63E598CD23BB49A595C6C00755623915"><enum>(b)</enum><header>Contents of plans</header><text>Such plans shall set forth appropriate methods, including both technological (such as the use of software and hardware) and nontechnological methods (such as employee policies and user training), to achieve the goal of securing and protecting such information from the risks posed by peer-to-peer file sharing programs.</text> </subsection>
<subsection id="HE03AD3BA00824B35A534A03D25520653"><enum>(c)</enum><header>Implementation of plans</header><text>The head of each agency shall—</text> 
<paragraph id="HEE08125CE4E94801A364AAF733A9C690"><enum>(1)</enum><text>develop and implement the plan required under this section as expeditiously as possible, but in no event later than six months after the date of the enactment of this Act; and</text> </paragraph>
<paragraph id="H09B0FB9953D04EAFA6ED429C8C2980D4"><enum>(2)</enum><text>review and revise the plan periodically as necessary.</text> </paragraph></subsection>
<subsection id="H41315554A34741C9B249190775D25633"><enum>(d)</enum><header>Review of plans</header><text>Not later than 18 months after the date of the enactment of this Act, the Comptroller General shall—</text> 
<paragraph id="H60E39D446FF44181AC4D4DCF92E204EF"><enum>(1)</enum><text>review the adequacy of the agency plans required by this section; and</text> </paragraph>
<paragraph id="H7E9CBA6CBC6B4E9E8B227DBE40887180"><enum>(2)</enum><text>submit to the Committee on Oversight and Government Reform of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the results of the review, together with any recommendations the Comptroller General considers appropriate.</text> </paragraph></subsection>
<subsection id="H4A0A9924740842389D44C925D76667E1"><enum>(e)</enum><header>Definitions</header><text>In this section:</text> 
<paragraph id="H041F41DD13694AB7BA55BA18E18C6D64"><enum>(1)</enum><header>Peer-to-peer file sharing program</header><text>The term <quote>peer-to-peer file sharing program</quote> means computer software that allows the computer on which such software is installed (A) to designate files available for transmission to another such computer, (B) to transmit files directly to another such computer, and (C) to request the transmission of files from another such computer. The term does not include the use of such software for file sharing between, among, or within Federal, State, or local government agencies in order to perform official agency business.</text> </paragraph>
<paragraph id="H14559EE85C564B329900AA369E5C0062"><enum>(2)</enum><header>Agency</header><text>The term <quote>agency</quote> has the meaning provided by <external-xref legal-doc="usc" parsable-cite="usc/44/3502">section 3502</external-xref> of title 44, United States Code.</text> </paragraph></subsection></section>
<section id="HE42691B718D64387AE8D3674F394BAC0"><enum>8.</enum><header>Annual independent audit</header> 
<subsection id="H271A34D11BB148219823495389644DE5"><enum>(a)</enum><header>Requirement for audit instead of evaluation</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3545">Section 3545</external-xref> of title 44, United States Code, is amended—</text> 
<paragraph id="H474A6E8364EB4839B51C3CEF75680183"><enum>(1)</enum><text>in the section heading, by striking <quote><header-in-text level="section" style="USC">evaluation</header-in-text></quote> and inserting <quote><header-in-text level="section" style="USC">audit</header-in-text></quote> ; and</text> </paragraph>
<paragraph id="H742E74C360604CD5AF7EBA83A8D5A6B8"><enum>(2)</enum><text>in paragraphs (1) and (2) of subsection (a), by striking <quote>evaluation</quote> and inserting <quote>audit</quote> both places it appears.</text> </paragraph></subsection>
<subsection id="HCC89873BCC2841AEB5A9965507219BA6"><enum>(b)</enum><header>Additional specific requirements for audits</header><text>Section 3545(a) of such title is amended—</text> 
<paragraph id="H43A73A19266B4CFE91C7E526628CAD14"><enum>(1)</enum><text>in paragraph (2)—</text> 
<subparagraph id="H370F30173A37401899DC00E39B326BDF"><enum>(A)</enum><text>in subparagraph (A), by striking <quote>subset of the agency’s information systems;</quote> and inserting the following:</text> 
<quoted-block display-inline="yes-display-inline" id="H9C3DD186772E4D299112C1A9A4C319D" style="OLC"><text>subset of—</text>
<clause id="H43BF5ACE1CDD4B1A8BBBE55696AD91D1" indent="up1"><enum>(i)</enum><text>the information systems used or operated by the agency; and</text> </clause>
<clause id="HFEFE3FF2A0A447A5ABBDD1372B44530" indent="up1"><enum>(ii)</enum><text>the information systems used, operated, or supported on behalf of the agency by a contractor of the agency, any subcontractor (at any tier) of such a contractor, or any other entity;</text> </clause> <after-quoted-block>; </after-quoted-block></quoted-block> </subparagraph>
<subparagraph id="H3A2699E3F1AD4850BA4B11981EEADC23"><enum>(B)</enum><text>in subparagraph (B), by striking <quote>and</quote> at the end;</text> </subparagraph>
<subparagraph id="HCB66AD173970455B9D551C8D26E423E6"><enum>(C)</enum><text>in subparagraph (C), by striking the period and inserting <quote>; and</quote>; and</text> </subparagraph>
<subparagraph id="H408F16BDF7CD495D862C6CF47999D265"><enum>(D)</enum><text>by adding at the end the following new subparagraph:</text> 
<quoted-block display-inline="no-display-inline" id="H7507ACDCC38A4CF1B34E80A6E0FA7FA" style="OLC">
<subparagraph id="H5B92EDAAD3ED4C2D804CBD733F53538D" indent="up1"><enum>(D)</enum><text display-inline="yes-display-inline">a conclusion whether the agency’s information security controls are effective, including an identification of any significant deficiencies in such controls.</text> </subparagraph> <after-quoted-block>; and</after-quoted-block></quoted-block> </subparagraph></paragraph>
<paragraph id="HE110E8ED7A724433AF054C66492F238B"><enum>(2)</enum><text>by adding at the end the following new paragraph:</text> 
<quoted-block id="H172C49FE05224D36B46427002F9CBABB" style="OLC">
<paragraph id="HE5FA67367E664133B8C45DD8DF000063" indent="up1"><enum>(3)</enum><text>Each audit under this section shall conform to generally accepted government auditing standards.</text> </paragraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></subsection>
<subsection id="HEC9AABE800FB455EA2C500F59A28532"><enum>(c)</enum><header>Conforming amendments</header> 
<paragraph id="H765EB4CCEB284A50008791FAE07D6B1"><enum>(1)</enum><text>Each of the following provisions of <external-xref legal-doc="usc" parsable-cite="usc/44/3545">section 3545</external-xref> of title 44, United States Code, is amended by striking <quote>evaluation</quote> and inserting <quote>audit</quote> each place it appears:</text> 
<subparagraph id="H91CAAF53F19B46B49201ADA883DDCCB4"><enum>(A)</enum><text>Subsection (b)(1).</text> </subparagraph>
<subparagraph id="HCEAB42ECE5714CE9A11206F6B57DA277"><enum>(B)</enum><text>Subsection (b)(2).</text> </subparagraph>
<subparagraph id="H721ABFE6F3624796AA38C49857767627"><enum>(C)</enum><text>Subsection (c).</text> </subparagraph>
<subparagraph id="H57F33E14793C4A188C94F1C46BC26817"><enum>(D)</enum><text>Subsection (e)(1).</text> </subparagraph>
<subparagraph id="HF74DF815CAFF4823A66EE94EB4680684"><enum>(E)</enum><text>Subsection (e)(2).</text> </subparagraph></paragraph>
<paragraph id="H3E32AB6319D74DC093CA46859E564840"><enum>(2)</enum><text>Section 3545(d) of such title is amended to read as follows:</text> 
<quoted-block display-inline="no-display-inline" id="HF11A0D0343B848EAABAAEAAC461E0102" style="OLC">
<subsection id="HD6548D95EFD0432586D0593F34962FDE"><enum>(d)</enum><header>Existing audits</header><text>The audit required by this section may be based in whole or in part on an audit relating to programs or practices of the applicable agency.</text> </subsection> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph>
<paragraph id="H0A67346D411B44C68F007985A78928D"><enum>(3)</enum><text>Section 3545(f) of such title is amended by striking <quote>evaluators</quote> and inserting <quote>auditors</quote>.</text> </paragraph>
<paragraph id="H2E2EA8D3F91142E4AF7C744D808D7B50"><enum>(4)</enum><text>Section 3545(g)(1) of such title is amended by striking <quote>evaluations</quote> and inserting <quote>audits</quote>.</text> </paragraph>
<paragraph id="HD68A78B754A04DD59152D2C0F86FCF5"><enum>(5)</enum><text>Section 3545(g)(3) of such title is amended by striking <quote>Evaluations</quote> and inserting <quote>Audits</quote>.</text> </paragraph>
<paragraph id="H14E8B590C81D4CE6B071EEDD57820012"><enum>(6)</enum><text>Section 3543(a)(8)(A) of such title is amended by striking <quote>evaluations</quote> and inserting <quote>audits</quote>.</text> </paragraph>
<paragraph id="H303ED159839F420783B580FDA427602D"><enum>(7)</enum><text>Section 3544(b)(5)(D) of such title (as redesignated by section 5(2)(C)) is amended by striking <quote>a evaluation</quote> and inserting <quote>an audit</quote>.</text> </paragraph></subsection></section>
<section id="HF42FD193661244D182162656E0157647"><enum>9.</enum><header>Best practices for privacy impact assessments</header><text display-inline="no-display-inline">Section 208(b)(3) of the E-Government Act of 2002 (<external-xref legal-doc="public-law" parsable-cite="pl/107/347">Public Law 107–347</external-xref>; <external-xref legal-doc="usc" parsable-cite="usc/44/3501">44 U.S.C. 3501</external-xref> note) is amended—</text> 
<paragraph id="HFBDD9DF2F3864E358800F8F1F1BB16B7"><enum>(1)</enum><text>in subparagraph (B), by striking <quote>and</quote> at the end;</text> </paragraph>
<paragraph id="H904B5172BC4C4A478664CD33E5A7C361"><enum>(2)</enum><text>in subparagraph (C), by striking the period and inserting <quote>; and</quote>, and</text> </paragraph>
<paragraph id="H68DE79E48804464B00D3EC19C5D7B1E1"><enum>(3)</enum><text>by adding at the end the following:</text> 
<quoted-block id="H2C83F5519BAB455E8177D7AD942DE891" style="OLC">
<subparagraph id="H35B8E906BADF442C81FE557905D749BD"><enum>(D)</enum><text>develop best practices for agencies to follow in conducting privacy impact assessments.</text> </subparagraph> <after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></section>
<section id="HBDEB7C218C3C40CEB5B9808765B619C4"><enum>10.</enum><header>Implementation</header><text display-inline="no-display-inline">Except as otherwise specifically provided in this Act, implementation of this Act and the amendments made by this Act shall begin not later than 90 days after the date of the enactment of this Act.</text> </section>
</legis-body> <attestation><attestation-group><attestation-date date="20080603" chamber="House">Passed the House of Representatives June 3, 2008.</attestation-date><attestor display="no">Lorraine C. Miller,</attestor><role>Clerk.</role></attestation-group></attestation>
<endorsement display="yes"></endorsement>
</bill> 


