<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-House" bill-type="olc" dms-id="H6E78028986D446728BEFCCFFC9D553E" public-private="public"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 5983 EH: Homeland Security Network Defense and Accountability Act of 2008</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>0</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="no">I</distribution-code> 
<congress display="yes">110th CONGRESS</congress> <session display="yes">2d Session</session> 
<legis-num>H. R. 5983</legis-num> 
<current-chamber display="no">IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<legis-type>AN ACT</legis-type> 
<official-title display="yes">To amend the Homeland Security Act of 2002 to enhance the information security of the Department of Homeland Security, and for other purposes.</official-title> 
</form> 
<legis-body display-enacting-clause="yes-display-enacting-clause" style="OLC" id="H7C293C1A89374C34BC2C101B356EF011">
<section id="H9949929503984F13B4D86284069A941" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline"> This Act may be cited as the <quote><short-title>Homeland Security Network Defense and Accountability Act of 2008</short-title></quote>.</text></section>
<section id="H993419A87C8A469384FFD34D815DA68F"><enum>2.</enum><header>Authority of Chief Information Officer; qualifications for appointment</header><text display-inline="no-display-inline">Section 703(a) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343(a)</external-xref>) is amended—</text>
<paragraph id="H6E2912793F1440FE957E20B639589B49"><enum>(1)</enum><text>by inserting before the first sentence the following:</text>
<quoted-block style="OLC" id="HCA7DA7FFD5074CF998A0962401488E27" display-inline="no-display-inline">
<paragraph id="H6DE1594ED4D1447A9C1FF3F2E7514F00"><enum>(1)</enum><header>Authorities and duties</header><text display-inline="yes-display-inline">The Secretary shall delegate to the Chief Information Officer such authority necessary for the development, approval, implementation, integration, and oversight of policies, procedures, processes, activities, funding, and systems of the Department relating to the management of information and information infrastructure for the Department, including the management of all related mission applications, information resources, and personnel. </text></paragraph>
<paragraph id="H193836545ADE4D9490F3525B3926E774"><enum>(2)</enum><header>Line authority</header></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></paragraph>
<paragraph id="HC5B0FB7580A147BAB1E5A9C3DC4CD56D"><enum>(2)</enum><text>by adding at the end the following new paragraphs:</text>
<quoted-block id="H900ACC35EE6F461F952449E82115AD1" style="OLC">
<paragraph id="H53B9A9620F844349879E10B719B1C75C"><enum>(3)</enum><header>Qualifications for appointment</header><text>An individual may not be appointed as Chief Information Officer unless the individual has—</text>
<subparagraph id="H606298AE6935426EAEDBAC1F304475EE"><enum>(A)</enum><text>demonstrated ability in and knowledge of information technology and information security; and</text></subparagraph>
<subparagraph id="H909CAD320B474E2BB628F9CB10FDE301"><enum>(B)</enum><text>not less than 5 years of executive leadership and management experience in information technology and information security in the public or private sector.</text></subparagraph></paragraph>
<paragraph id="H5B916755C7E64A8CB41105D12E8F75BB"><enum>(4)</enum><header>Functions</header><text>The Chief Information Officer shall—</text>
<subparagraph id="HBB7BBC13466642419BD1314353E332C"><enum>(A)</enum><text>establish and maintain an incident response team that provides a continuous, real-time capability within the Department of Homeland Security to—</text>
<clause id="HAC534F56A62D47688E1DF8B62B73D266"><enum>(i)</enum><text>detect, respond to, contain, investigate, attribute, and mitigate any computer incident, as defined by the National Institute of Standards and Technology, that could violate or pose an imminent threat of violation of computer security policies, acceptable use policies, or standard security practices of the Department; and</text></clause>
<clause id="HC4F8F3BC2E5D4F2C916EAEF71EF13C83"><enum>(ii)</enum><text>deliver timely notice of any incident to individuals responsible for information infrastructure of the Department, and to the United States Computer Emergency Readiness Team;</text></clause></subparagraph>
<subparagraph id="H34B4C3E1683741C6A9412257910066D8"><enum>(B)</enum><text>establish, maintain, and update a network architecture, including a diagram detailing how security controls are positioned throughout the information infrastructure of the Department to maintain the confidentiality, integrity, availability, accountability, and assurance of electronic information; and</text></subparagraph>
<subparagraph id="HFD158CA956E3483494E0C3886364BB00"><enum>(C)</enum><text>ensure that vulnerability assessments are conducted on a regular basis for any Department information infrastructure connected to the Internet or another external network, and that vulnerabilities are mitigated in a timely fashion.</text></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></section>
<section id="H34CBAC5A88D54A0B83B3439D6C9107A0"><enum>3.</enum><header>Attack-based testing protocols</header><text display-inline="no-display-inline">Section 703 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343</external-xref>) is amended by adding at the end the following new subsection:</text>
<quoted-block id="HEC1CB70103A643ECA7FE00940079AB4" style="OLC">
<subsection id="HC0F655F51F90422C0097595140E36FA0"><enum>(c)</enum><header>Attack-based testing protocols</header><text>The Chief Information Officer, in consultation with the Inspector General, the Assistant Secretary for Cybersecurity, and the heads of other appropriate Federal agencies, shall—</text>
<paragraph id="H3EBC68705DC6491891C95375B6D646C0"><enum>(1)</enum><text>establish security control testing protocols that ensure that the Department’s information infrastructure is effectively protected against known attacks against and exploitations of Federal and contractor information infrastructure;</text></paragraph>
<paragraph id="H22AFFD4B27584F288853A23315ACDE8E"><enum>(2)</enum><text>oversee the deployment of such protocols throughout the information infrastructure of the Department; and</text></paragraph>
<paragraph id="HD6B41578962543EBAF88BD7D066B7D71"><enum>(3)</enum><text>update such protocols on a regular basis.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></section>
<section id="H8F0F9EEBCCBC41B4BFD55D831300A440"><enum>4.</enum><header>Inspector General reviews of information infrastructure</header><text display-inline="no-display-inline">Section 703 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343</external-xref>) is further amended by adding at the end the following new subsection:</text>
<quoted-block style="OLC" id="HDCAD1B48DBBA42A184E9B7D925AF7B25" display-inline="no-display-inline">
<subsection id="HD2EE70349EA247E9B7FF531120EAB500"><enum>(d)</enum><header>Inspector General reviews</header>
<paragraph id="HC966CFE494E140939FC74848E8E88FCF"><enum>(1)</enum><header>In general</header><text>The Inspector General of the Department shall use authority under the Inspector General Act of 1978 (5 App. U.S.C.) to conduct announced and unannounced performance reviews and programmatic reviews of the information infrastructure of the Department to determine the effectiveness of security policies and controls of the Department.</text></paragraph>
<paragraph id="H839301EBA3E84E1BBFA882A9C532400"><enum>(2)</enum><header>Performance reviews</header><text>Performance reviews under this subsection shall test and validate a system’s security controls using the protocols created under subsection (c), beginning not later than 270 days after the date of enactment of the <short-title>Homeland Security Network Defense and Accountability Act of 2008</short-title>.</text></paragraph>
<paragraph id="H2FAF33F1962C4535AAD716CA27920000"><enum>(3)</enum><header>Programmatic reviews</header><text>Programmatic reviews under this subsection shall—</text>
<subparagraph id="HCC562DBCE2A740A6B3AF159100BAAA42"><enum>(A)</enum><text>determine whether an agency of the Department is complying with policies, processes, and procedures established by the Chief Information Officer; and</text></subparagraph>
<subparagraph id="HD6C96AF2E9384B85B7AC1B726E521885"><enum>(B)</enum><text display-inline="yes-display-inline">focus on risk assessment, risk management, and risk mitigation, with primary regard to the implementation of best practices such as authentication, access control (including remote access), intrusion detection and prevention, data protection and integrity, and any other controls that the Inspector General considers necessary.</text></subparagraph></paragraph>
<paragraph id="HDD1E320997B942A49212F7F7AB745F0"><enum>(4)</enum><header>Information security report</header><text>The Inspector General shall submit a security report containing the results of each review under this subsection and prioritized recommendations for improving security controls based on that review, including recommendations regarding funding changes and personnel management, to—</text>
<subparagraph id="HA09934FF31B248E399A0A3DD8E403FA"><enum>(A)</enum><text>the Secretary;</text></subparagraph>
<subparagraph id="HE4B969BA6EFD4D98BE6FB5A6C774FF83"><enum>(B)</enum><text>the Chief Information Officer; and</text></subparagraph>
<subparagraph id="H5CBCC2C859FD41EFB9E8B4AEB3647F00"><enum>(C)</enum><text>the head of the Department component that was the subject of the review, and other appropriate individuals responsible for the information infrastructure of such agency.</text></subparagraph></paragraph>
<paragraph id="HE6FE100D943E43B19B950000FD692D8C"><enum>(5)</enum><header>Corrective action report</header><text></text>
<subparagraph id="HA026A1D28F1E4B5E9BBD35D1D1758E87"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Within 60 days after receiving a security report under paragraph (4), the head of the Department component that was the subject of the review and the Chief Information Officer shall jointly submit a corrective action report to the Secretary and the Inspector General.</text></subparagraph>
<subparagraph id="HA5ECC143EB994E0688BDC8A5DBBDBAF7"><enum>(B)</enum><header>Contents</header><text>The corrective action report—</text>
<clause id="H5299E95D09814973963492F85FA2B279"><enum>(i)</enum><text>shall contain a plan for addressing recommendations and mitigating vulnerabilities contained in the security report, including a timeline and budget for implementing such plan; and</text></clause>
<clause id="HB9891714F025436200A4D200ED29D208"><enum>(ii)</enum><text display-inline="yes-display-inline">shall note any matters in disagreement between the head of the Department component and the Chief Information Officer.</text></clause></subparagraph></paragraph>
<paragraph id="H22D73D792E9649469692609C2546C4D9"><enum>(6)</enum><header>Reports to Congress</header>
<subparagraph id="H8122562D9F3149248E8BFECE37F0A5D9"><enum>(A)</enum><header>Annual reports</header><text display-inline="yes-display-inline">In conjunction with the reporting requirements of <external-xref legal-doc="usc" parsable-cite="usc/44/3545">section 3545</external-xref> of title 44, United States Code, the Inspector General shall submit an annual report to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate—</text>
<clause id="H953C3A3971E04DA0BB6C072053B84D54"><enum>(i)</enum><text>summarizing the performance and programmatic reviews performed during the preceding fiscal year, the results of those reviews, and any actions that remain to be taken under plans included in corrective action reports under paragraph (5); and</text></clause>
<clause id="HC53D63AA085241E6A384F8EC32D26B98"><enum>(ii)</enum><text>describing the effectiveness of the testing protocols developed under subsection (c) in reducing successful exploitations of the Department’s information infrastructure.</text></clause></subparagraph>
<subparagraph id="HBFA850C036D640EC8C4FE18BA008BD6"><enum>(B)</enum><header>Security reports and corrective action reports</header><text>The Inspector General shall make all security reports and corrective action reports available to any member of the Committee on Homeland Security of the House of Representatives, any member of the Committee on Homeland Security and Governmental Affairs of the Senate, and the Comptroller General of the United States, upon request.</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></section>
<section id="HEA68FC233608426CAFEF525E1CED1CC7"><enum>5.</enum><header>Information infrastructure defined</header><text display-inline="no-display-inline">Section 703 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343</external-xref>) is further amended by adding at the end the following:</text>
<quoted-block style="OLC" id="HCBCC5989C02F4FA1A4BC7102E7C977B" display-inline="no-display-inline">
<subsection id="H466D80E5D01B4178BDD556CAE3FB6184"><enum>(e)</enum><header>Information infrastructure defined</header><text display-inline="yes-display-inline">In this section, the term <term>information infrastructure</term> means systems and assets used in processing, transmitting, receiving, or storing information electronically.</text></subsection><after-quoted-block>.</after-quoted-block></quoted-block></section>
<section id="HF5ADAC8B63384AB8BB09941605002614"><enum>6.</enum><header>Network service providers</header>
<subsection id="HD7FE2EB61DD046B8B8CCA57BA110E31"><enum>(a)</enum><header>In general</header><text>Subtitle D of title VIII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/391">6 U.S.C. 391 et seq.</external-xref>) is amended by adding at the end the following new section:</text>
<quoted-block style="OLC" id="H4E6FEEECCB934EE98F239CE3E96BEAA3" display-inline="no-display-inline">
<section id="HF7FB5A7C96AF461FA776A5E652CA5865"><enum>836.</enum><header>Requirements for network service providers</header>
<subsection id="H7A3CDB08978A44EF8734DB5E855620A8"><enum>(a)</enum><header>Compatibility determination</header><text display-inline="yes-display-inline">Before entering into or renewing a covered contract, the Secretary, acting through the Chief Information Officer, must determine that the contractor has an internal information systems security policy that complies with the Department’s information security requirements for risk assessment, risk management, and risk mitigation, with primary regard to the implementation of best practices such as authentication, access control (including remote access), intrusion detection and prevention, data protection and integrity, and any other policies that the Secretary considers necessary to ensure the security of the Department’s information infrastructure.</text> </subsection>
<subsection id="HC4CE5074997148D1BEC53E2896532C64"><enum>(b)</enum><header>Contract requirements regarding security</header><text>The Secretary shall include in each covered contract provisions requiring the contractor to—</text>
<paragraph id="H7955F1065F4E429F8ED61635005F1443"><enum>(1)</enum><text>implement and regularly update the internal information systems security policy required under subsection (a);</text></paragraph>
<paragraph id="H4850F0B1DF8B4AF9BB33286432A0E66B"><enum>(2)</enum><text display-inline="yes-display-inline">maintain the capability to provide contracted services on a continuing and ongoing basis to the Department in the event of unplanned or disruptive event; and </text></paragraph>
<paragraph id="HEDF320C89A6149768200565127D1A47"><enum>(3)</enum><text>deliver timely notice of any internal computer incident, as defined by the National Institute of Standards and Technology, that could violate or pose an imminent threat of violation of computer security policies, acceptable use policies, or standard security practices at the Department, to the United States Computer Emergency Readiness Team and the incident response team established under section 703(a)(4).</text></paragraph></subsection>
<subsection id="HA80AC7E04B6746AFAD11FE371232C9B7"><enum>(c)</enum><header>Contract requirements regarding subcontracting</header><text>The Secretary shall include in each covered contract—</text>
<paragraph id="HEF075FFBCC3C4AB6A625D73E6D842F91"><enum>(1)</enum><text>a requirement that the contractor develop and implement a plan for the award of subcontracts, as appropriate, to small business concerns and disadvantaged business concerns in accordance with other applicable requirements, including the terms of such plan, as appropriate; and</text></paragraph>
<paragraph id="H7586E55B6D0744FB87F354B3E1136328"><enum>(2)</enum><text>a requirement that the contractor submit to the Secretary, during performance of the contract, periodic reports describing the extent to which the contractor has complied with such plan, including specification (by total dollar amount and by percentage of the total dollar value of the contract) of the value of subcontracts awarded at all tiers of subcontracting to small business concerns, including socially and economically disadvantaged small businesses concerns, small business concerns owned and controlled by service-disabled veterans, HUBZone small business concerns, small business concerns eligible to be awarded contracts pursuant to section 8(a) of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/637">15 U.S.C. 637(a)</external-xref>), and Historically Black Colleges and Universities and Hispanic-serving institutions, tribal colleges and universities, and other minority institutions.</text></paragraph></subsection>
<subsection id="H89B39E5456A84BD88B002DA949580073"><enum>(d)</enum><header>Existing contracts</header><text display-inline="yes-display-inline">The Secretary shall, to the extent practicable under the terms of existing contracts, require each contractor who provides covered information services under a contract in effect on the date of the enactment of the <short-title>Homeland Security Network Defense and Accountability Act of 2008</short-title> to comply with the requirements described in subsection (b).</text></subsection>
<subsection id="H50E072E1C4EB43C7A63F80817F5962D3"><enum>(e)</enum><header>Definitions</header><text>For purposes of this section:</text>
<paragraph id="H277A52620F7946C1BE88FA7C98FD128E"><enum>(1)</enum><header>Socially and economically disadvantaged small businesses concern, small business concern owned and controlled by service-disabled veterans, and HUBZone small business concern</header><text>The terms <term>socially and economically disadvantaged small businesses concern</term>, <term>small business concern owned and controlled by service-disabled veterans</term>, and <term>HUBZone small business concern</term> have the meanings given such terms under the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/631">15 U.S.C. 631 et seq.</external-xref>).</text></paragraph>
<paragraph id="H7605D728B3C34ECAACC76EDB8E27B48B"><enum>(2)</enum><header>Contractor</header><text>The term <term>contractor</term> includes each subcontractor of a contractor.</text></paragraph>
<paragraph id="H22104223DDCF4C7E8F481F4EEA00A2D"><enum>(3)</enum><header>Covered contract</header><text display-inline="yes-display-inline">The term <term>covered contract</term> means a contract entered into or renewed after the date of the enactment of the <short-title>Homeland Security Network Defense and Accountability Act of 2008</short-title> for the provision of covered information services.</text></paragraph>
<paragraph id="H57029ED13DDC41C6A19ED0CC7BDACBC"><enum>(4)</enum><header>Covered information services</header><text display-inline="yes-display-inline">The term <term>covered information services</term> means creation, management, maintenance, control, or operation of information networks or Internet Web sites for the Department.</text></paragraph>
<paragraph id="H00E71EEBD2C84C32A763A99340B215A6"><enum>(5)</enum><header>Historically Black colleges and universities</header><text>The term <term>Historically Black Colleges and Universities</term> means part B institutions under title III of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1061">20 U.S.C. 1061</external-xref>).</text></paragraph>
<paragraph id="H67CE4B8A8CDA4005B1CBB54D2BB87D22"><enum>(6)</enum><header>Hispanic-serving institution</header><text>The term <term>Hispanic-serving institution</term> has the meaning given such term under title V of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1101a">20 U.S.C. 1101a(a)(5)</external-xref>).</text></paragraph>
<paragraph id="HB27B2FB74B614057BF391C7604ABFDC"><enum>(7)</enum><header>Information infrastructure</header><text>The term <term>information infrastructure</term> has the meaning that term has under section 703.</text></paragraph>
<paragraph id="H5779C77DAE9B4BFBB4C385002C05AAA9"><enum>(8)</enum><header>Tribal colleges and universities</header><text>The term <term>tribal colleges and universities</term> has the meaning given such term under the Tribally Controlled College or University Assistance Act of 1978 (<external-xref legal-doc="usc" parsable-cite="usc/25/1801">25 U.S.C. 1801 et seq.</external-xref>).</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection>
<subsection id="HFEC7AA7377E04751BF1E7D2C15005854"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of such Act is amended by inserting after the item relating to section 835 the following new item:</text>
<quoted-block style="OLC" id="H58048118C72F4E37BA02B1F398C1294" display-inline="no-display-inline">
<toc container-level="quoted-block-container" quoted-block="no-quoted-block" lowest-level="section" idref="H4E6FEEECCB934EE98F239CE3E96BEAA3" regeneration="yes-regeneration" lowest-bolded-level="division-lowest-bolded">
<toc-entry idref="HF7FB5A7C96AF461FA776A5E652CA5865" level="section">Sec. 836. Requirements for network service providers.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection>
<subsection id="H4B1B7B2AE58C43948DFBC5AB356D99B"><enum>(c)</enum><header>Report</header><text display-inline="yes-display-inline">Within 90 days after the date of enactment of this Act, the Secretary of Homeland Security shall transmit to the Committee on Homeland Security of the House of Representatives and the Homeland Security and Governmental Affairs Committee of the Senate a report describing—</text>
<paragraph id="HF90545817F3D41C7B6BFA39E1C004900"><enum>(1)</enum><text>the progress in implementing requirements issued by the Office of Management and Budget for encryption, authentication, Internet Protocol version 6, and Trusted Internet Connections, including a timeline for completion;</text></paragraph>
<paragraph id="HDEC5EDA84A0E4FBB959F15EF28EA2B11"><enum>(2)</enum><text>a plan, including an estimated budget and a timeline, to investigate breaches against the Department of Homeland Security’s information infrastructure for purposes of counterintelligence assessment, attribution, and response; </text></paragraph>
<paragraph id="HA96EE0A7E51A40C8B2BE0A61FFFA5C"><enum>(3)</enum><text>a proposal to increase threat information sharing with cleared and uncleared contractors and provide specialized damage assessment training to private sector information security professionals; and</text></paragraph>
<paragraph id="H93D43E4577234BE0B3A8E1DDE0A9C603"><enum>(4)</enum><text>a process to coordinate the Department of Homeland Security’s information infrastructure protection activities.</text></paragraph></subsection></section>
<section id="HBB6EA147E1A54642B342561DD056ECE1"><enum>7.</enum><header>Rule of construction</header><text display-inline="no-display-inline">Nothing in this Act shall be construed as affecting in any manner the application of the Federal Information Management Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/44/3541">44 U.S.C. 3541 et seq.</external-xref>), to the Department of Homeland Security, including all requirements and deadlines in that Act.</text></section>
</legis-body> <attestation><attestation-group><attestation-date date="20080729" chamber="House">Passed the House of Representatives July 30, 2008.</attestation-date><attestor display="no">Lorraine C. Miller,</attestor><role>Clerk.</role></attestation-group></attestation>
<endorsement display="yes"></endorsement>
</bill> 


