<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 1105</calendar>
		<congress>110th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 3474</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20080911">September 11, 2008</action-date>
			<action-desc><sponsor name-id="S277">Mr. Carper</sponsor> (for himself,
			 <cosponsor name-id="S210">Mr. Lieberman</cosponsor>, <cosponsor name-id="S252">Ms. Collins</cosponsor>, and <cosponsor name-id="S291">Mr.
			 Coleman</cosponsor>) introduced the following bill; which was read twice and
			 referred to the
			 <committee-name added-display-style="italic" committee-id="SSGA00" deleted-display-style="strikethrough">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<action stage="Reported-in-Senate">
			<action-date>October 1 (legislative day, September 17),
			 2008</action-date>
			<action-desc>Reported by <sponsor name-id="S210">Mr.
			 Lieberman</sponsor>, without amendment</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend title 44, United States Code, to enhance
		  information security of the Federal Government, and for other
		  purposes.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Federal Information Security
			 Management Act of 2008</short-title></quote> or the <quote><short-title>FISMA Act of 2008</short-title></quote>.</text>
		</section><section id="idAB378F06581045608DE5D50163CDE864"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">Section 3542(b) of title 44, United States
			 Code, is amended by adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="id49178C238F0944F0A364468C8C411F9F" style="OLC">
				<paragraph id="ID145b71feac11475a8d32c98a3c67ec40"><enum>(4)</enum><text>The term
				<term>adequate security</term> means security commensurate with the risk and
				magnitude of harm resulting from the loss, misuse, or unauthorized access to or
				modification of information.</text>
				</paragraph><paragraph id="IDaaccd0967fdc4ec9935c25778795e584"><enum>(5)</enum><text>The term
				<term>incident</term> means an occurrence that actually or potentially
				jeopardizes the confidentiality, integrity, or availability of an information
				system or the information the system processes, stores, or transmits or that
				constitutes a violation or imminent threat of violation of security policies,
				security procedures, or acceptable use policies.</text>
				</paragraph><paragraph id="idDDFA7958B2C84CEF97E722547390D30D"><enum>(6)</enum><text>The term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on in processing, transmitting, receiving,
				or storing information
				electronically.</text>
				</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="HE42691B718D64387AE8D3674F394BAC0"><enum>3.</enum><header>Annual
			 independent audit</header>
			<subsection id="H271A34D11BB148219823495389644DE5"><enum>(a)</enum><header>Requirement for
			 audit instead of evaluation</header><text><external-xref legal-doc="usc" parsable-cite="usc/44/3545">Section 3545</external-xref> of title 44, United
			 States Code, is amended—</text>
				<paragraph id="H474A6E8364EB4839B51C3CEF75680183"><enum>(1)</enum><text>in the section
			 heading, by striking <quote><header-in-text level="section" style="OLC">evaluation</header-in-text></quote> and inserting
			 <quote><header-in-text level="section" style="OLC">audit</header-in-text></quote> ; and</text>
				</paragraph><paragraph id="H742E74C360604CD5AF7EBA83A8D5A6B8"><enum>(2)</enum><text>in paragraphs (1)
			 and (2) of subsection (a), by striking <quote>evaluation</quote> and inserting
			 <quote>audit</quote> both places that term appears.</text>
				</paragraph></subsection><subsection id="HCC89873BCC2841AEB5A9965507219BA6"><enum>(b)</enum><header>Additional
			 specific requirements for audits</header><text>Section 3545(a) of such title is
			 amended—</text>
				<paragraph id="H43A73A19266B4CFE91C7E526628CAD14"><enum>(1)</enum><text>in paragraph
			 (2)—</text>
					<subparagraph id="H370F30173A37401899DC00E39B326BDF"><enum>(A)</enum><text>in subparagraph
			 (A), by striking <quote>subset of the agency’s information systems;</quote> and
			 inserting the following:</text>
						<quoted-block display-inline="yes-display-inline" id="H9C3DD186772E4D299112C1A9A4C319D" style="OLC">
							<text>subset
			 of—</text><clause id="idBDD7548B5C6E4052AAE8B429E5ABD071"><enum>(i)</enum><text>the information
				systems used or operated by the agency; and</text>
							</clause><clause id="id3558A301377248DBB5894E9274F5D979"><enum>(ii)</enum><text>the information
				systems used, operated, or supported on behalf of the agency by a contractor of
				the agency, any subcontractor (at any tier) of such a contractor, or any other
				entity;</text>
							</clause><after-quoted-block>;
				</after-quoted-block></quoted-block>
					</subparagraph><subparagraph id="H3A2699E3F1AD4850BA4B11981EEADC23"><enum>(B)</enum><text>in subparagraph
			 (B), by striking <quote>and</quote> at the end;</text>
					</subparagraph><subparagraph id="HCB66AD173970455B9D551C8D26E423E6"><enum>(C)</enum><text>in subparagraph
			 (C), by striking the period and inserting <quote>; and</quote>; and</text>
					</subparagraph><subparagraph id="H408F16BDF7CD495D862C6CF47999D265"><enum>(D)</enum><text>by adding at the
			 end the following new subparagraph:</text>
						<quoted-block display-inline="no-display-inline" id="idA5D041E848DF4AD49F3B2D94B091DCDC" style="OLC">
							<subparagraph id="id374CA23FC9404389918957169EC0A633"><enum>(D)</enum><text>a conclusion as
				to whether the agency’s information security controls are effective, including
				an identification of any significant deficiencies identified in such
				controls.</text>
							</subparagraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
					</subparagraph></paragraph><paragraph id="HE110E8ED7A724433AF054C66492F238B"><enum>(2)</enum><text>by adding at the
			 end the following:</text>
					<quoted-block display-inline="no-display-inline" id="H172C49FE05224D36B46427002F9CBABB" style="OLC">
						<paragraph id="id56532764393C4985BE77F00712EC1E80"><enum>(3)</enum><text>Each audit under
				this section shall conform to generally accepted government auditing
				standards.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HEC9AABE800FB455EA2C500F59A28532"><enum>(c)</enum><header>Technical and
			 conforming amendments</header>
				<paragraph id="H765EB4CCEB284A50008791FAE07D6B1"><enum>(1)</enum><text>Each of the
			 following provisions of
			 <external-xref legal-doc="usc" parsable-cite="usc/44/3545">section
			 3545</external-xref> of title 44, United States Code, is amended by striking
			 <quote>evaluation</quote> and inserting <quote>audit</quote> each place it
			 appears:</text>
					<subparagraph id="H91CAAF53F19B46B49201ADA883DDCCB4"><enum>(A)</enum><text>Subsection
			 (b)(1).</text>
					</subparagraph><subparagraph id="HCEAB42ECE5714CE9A11206F6B57DA277"><enum>(B)</enum><text>Subsection
			 (b)(2).</text>
					</subparagraph><subparagraph id="H721ABFE6F3624796AA38C49857767627"><enum>(C)</enum><text>Subsection
			 (c).</text>
					</subparagraph><subparagraph id="H57F33E14793C4A188C94F1C46BC26817"><enum>(D)</enum><text>Subsection
			 (e)(1).</text>
					</subparagraph><subparagraph id="HF74DF815CAFF4823A66EE94EB4680684"><enum>(E)</enum><text>Subsection
			 (e)(2).</text>
					</subparagraph></paragraph><paragraph id="H3E32AB6319D74DC093CA46859E564840"><enum>(2)</enum><text>Section 3545(d) of
			 such title is amended to read as follows:</text>
					<quoted-block display-inline="no-display-inline" id="HF11A0D0343B848EAABAAEAAC461E0102" style="OLC">
						<subsection id="HD6548D95EFD0432586D0593F34962FDE"><enum>(d)</enum><header>Existing
				information</header><text>The audit required by this section may include
				consideration of relevant audits, evaluations, reports, or other information
				relating to programs or practices of the applicable
				agency.</text>
						</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph><paragraph id="H0A67346D411B44C68F007985A78928D"><enum>(3)</enum><text>Section 3545(f) of
			 such title is amended by striking <quote>evaluators</quote> and inserting
			 <quote>auditors</quote>.</text>
				</paragraph><paragraph id="H2E2EA8D3F91142E4AF7C744D808D7B50"><enum>(4)</enum><text>Section 3545(g)(1)
			 of such title is amended by striking <quote>evaluations</quote> and inserting
			 <quote>audits</quote>.</text>
				</paragraph><paragraph id="HD68A78B754A04DD59152D2C0F86FCF5"><enum>(5)</enum><text>Section 3545(g)(3)
			 of such title is amended by striking <quote>Evaluations</quote> and inserting
			 <quote>Audits</quote>.</text>
				</paragraph><paragraph id="H14E8B590C81D4CE6B071EEDD57820012"><enum>(6)</enum><text>Section
			 3543(a)(8)(A) of such title is amended by striking <quote>evaluations</quote>
			 and inserting <quote>audits</quote>.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="H303ED159839F420783B580FDA427602D"><enum>(7)</enum><text>Section
			 3544(b)(5)(B) of such title is amended by striking <quote>a evaluation</quote>
			 and inserting <quote>an audit, evaluation, report, or other information
			 relating to programs or practices of the applicable agency</quote>.</text>
				</paragraph></subsection></section><section id="id39E356ABC32546108511BE3AAAB9ACE2"><enum>4.</enum><header>Chief
			 Information Security Officer and Chief Information Security Officer
			 Council</header>
			<subsection id="id758AACAAC081492795294106BC14350E"><enum>(a)</enum><header>Delegations to
			 Chief Information Security Officer</header><text>Section 3544(a) of title 44,
			 United States Code, is amended—</text>
				<paragraph id="id5D40F02D6A624F81AC2EF0F383482076"><enum>(1)</enum><text>in paragraph
			 (3)—</text>
					<subparagraph id="id061E04309743427F911EA5EB74A43FEC"><enum>(A)</enum><text>in the matter
			 preceding subparagraph (A)—</text>
						<clause id="id3AB8F1AD5B96412591DCBA73CF085280"><enum>(i)</enum><text>by
			 striking <quote>Chief Information Officer established under section
			 3506</quote> and inserting <quote>Chief Information Security Officer designated
			 under section 3548</quote>; and</text>
						</clause><clause commented="no" display-inline="no-display-inline" id="id9C897FB1153E472FAC09EE1C946BBE77"><enum>(ii)</enum><text display-inline="yes-display-inline">by striking <quote>ensure
			 compliance</quote> and inserting <quote>enforce compliance</quote>;</text>
						</clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idD23CF810F31343C7B5FD5C352EFCE970"><enum>(B)</enum><text>by striking
			 subparagraph (A); and</text>
					</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idE48C0E6255F14BE6BD7D4A29D1E67DC1"><enum>(C)</enum><text>by redesignating
			 subparagraphs (B) through (E) as subparagraphs (A) through (D),
			 respectively;</text>
					</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id014D97CA930F45CD8E4B3BCD71590CD9"><enum>(2)</enum><text>in paragraph (4),
			 by inserting <quote>and cleared</quote> after <quote>trained</quote>;
			 and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id83C68FCFBE33404B915E8134FCDB45F4"><enum>(3)</enum><text>in paragraph (5),
			 by striking <quote>Chief Information Officer</quote> and inserting <quote>Chief
			 Information Security Officer</quote>.</text>
				</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id18121F77EA3548309CB7E5C2708C98D7"><enum>(b)</enum><header>Chief
			 Information Security Officer and Chief Information Security Officer
			 Council</header><text>Chapter 35 of title 44, United States Code, is
			 amended—</text>
				<paragraph commented="no" display-inline="no-display-inline" id="idFACA8E7D16FD4029A8C4F2FF142679BD"><enum>(1)</enum><text>by redesignating
			 sections 3548 and 3549 as sections 3553 and 3554, respectively; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4D4DDE6E95814C47A80AF0790B18F529"><enum>(2)</enum><text>by inserting
			 after section 3547 the following:</text>
					<quoted-block display-inline="no-display-inline" id="idBEE6B5F67471408FBE2354D21F8E849C" style="USC">
						<section commented="no" display-inline="no-display-inline" id="id63BC2A8FDBDA482887EA1173E190272A"><enum>3548.</enum><header>Chief
				Information Security Officers</header>
							<subsection commented="no" display-inline="no-display-inline" id="id002E8DB44D69488F950DF5C0CE14008D"><enum>(a)</enum><header>Designations</header><paragraph commented="no" display-inline="yes-display-inline" id="idF8231B97DEEF46E0976CCD141E674067"><enum>(1)</enum><text>Except as provided
				under paragraph (2), the head of each agency shall designate a Chief
				Information Security Officer who with such agency head shall carry out the
				responsibilities of the agency under this subchapter. An individual may not
				serve as the Chief Information Officer and the Chief Information Security
				Officer for an agency at the same time. The Chief Information Security Officer
				shall report directly to the Chief Information Officer to carry out such
				responsibilities.</text>
								</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idBAFB130FE55F4F14AF7BF1CF2FC03E4C" indent="up1"><enum>(2)</enum><text>The Secretary of Defense and the
				Secretary of each military department may each designate Chief Information
				Security Officers who with the Secretary making the designation shall carry out
				the responsibilities of the applicable department under this subchapter. An
				individual may not serve as the Chief Information Officer and the Chief
				Information Security Officer for a department at the same time. The Secretary
				shall provide for the Chief Information Security Officer to report to the
				applicable Chief Information Officer to carry out such responsibilities. If
				more than 1 Chief Information Security Officer is designated, the respective
				duties of the Chief Information Security Officers shall be clearly
				delineated.</text>
								</paragraph></subsection><subsection id="id6CC0240469894F0FA943E6D4B4C85AAA"><enum>(b)</enum><header>Qualifications
				and general duties</header><text>A Chief Information Security Officer
				shall—</text>
								<paragraph id="ID4600B6C732834C2E9D4E618448AAAAD3"><enum>(1)</enum><text>possess necessary
				qualifications, including education, professional certifications, training,
				experience, and the security clearance required to administer the functions
				described under this subchapter; and</text>
								</paragraph><paragraph id="ID4B83BA6EB81C4DBEBA54BA486A7B3DE5"><enum>(2)</enum><text>have information
				security duties as the primary duty of that official.</text>
								</paragraph></subsection><subsection id="ID1f270cd8224f404ea97555e7f77d6aa7"><enum>(c)</enum><header>Responsibilities</header><text display-inline="yes-display-inline">A Chief Information Security Officer for an
				agency shall have the mission, budget, resources, and authority necessary
				to—</text>
								<paragraph id="ID3afee759433a43229b6f270d74c188d5"><enum>(1)</enum><text>oversee the
				establishment and maintenance of an incident response capability that on a
				continuous basis can—</text>
									<subparagraph id="IDcb0605258b61459c85a6a40678ed7bb3"><enum>(A)</enum><text>detect, report,
				respond to, contain, investigate, attribute, and mitigate any network,
				computer, or data security incident that impairs adequate security, in
				accordance with policy provided by the Office of Management and Budget, in
				consultation with the Chief Information Security Officer Council, and guidance
				from the National Institute of Standards and Technology;</text>
									</subparagraph><subparagraph id="ID8312582bcd124da3a8de12d4f1df90e3"><enum>(B)</enum><text>collaborate with
				other public and private sector incident response resources to address
				incidents that extend beyond the agency; and</text>
									</subparagraph><subparagraph id="idF7084FD9AEA04942BF35E6861633603C"><enum>(C)</enum><text>not later than 24
				hours after discovery of any incident described under subparagraph (A) unless
				otherwise directed by policy of the Office of Management and Budget, provide
				notice to the appropriate supporting information security operating center,
				inspector general, and the United States Computer Emergency Readiness
				Team;</text>
									</subparagraph></paragraph><paragraph id="ID3c2a69cece3a471cb258074b837ccdc5"><enum>(2)</enum><text>collaborate with
				the Chief Information Officer to establish, maintain, and update an enterprise
				network, system, storage, and security architecture framework documentation to
				be submitted quarterly to the United States Computer Emergency Readiness Team,
				that includes—</text>
									<subparagraph id="id56E2A64141E1439F9746B8CB42426EE2"><enum>(A)</enum><text>documentation of
				how technical, managerial, and operational security controls are implemented
				throughout the agency's information infrastructure; and</text>
									</subparagraph><subparagraph id="idEB20BE3E13D34CC48CB48D0315CFA17A"><enum>(B)</enum><text>documentation of
				how the controls described under subparagraph (A) maintain the appropriate
				level of confidentiality, integrity, and availability of electronic information
				and information systems based on National Institute of Standards and Technology
				guidance and Chief Information Security Officers Council recommended
				approaches;</text>
									</subparagraph></paragraph><paragraph id="IDd4011a5b810846b895fc5d3b1ab597f7"><enum>(3)</enum><text>ensure
				that—</text>
									<subparagraph id="idFFD5AE6E6CC749E2A2BA93198F95F8F7"><enum>(A)</enum><text>risk assessments
				are conducted on a periodic basis;</text>
									</subparagraph><subparagraph id="id2654334C1E55408EACBA4AE332F5C71C"><enum>(B)</enum><text>penetration tests
				are conducted commensurate with risk (as defined by the National Institute of
				Standards and Technology) for an agency's information infrastructure;
				and</text>
									</subparagraph><subparagraph id="id5E0B6A116EBC40E197D5937B71590B1A"><enum>(C)</enum><text>information
				security vulnerabilities are mitigated in a timely fashion;</text>
									</subparagraph></paragraph><paragraph id="id1B32ADC21BAB4CA6918835F10E489D12"><enum>(4)</enum><text>ensure that
				annual information technology security awareness and role-based training for
				agency employees and contractors is conducted;</text>
								</paragraph><paragraph id="ID57a7719d1474415ab61699eed1a0bb53"><enum>(5)</enum><text>create, maintain,
				and manage an information security performance measurement system that aligns
				with agency goals and budget process; and</text>
								</paragraph><paragraph id="IDb5bfee7b99ec48f4974fab26b7c1431b"><enum>(6)</enum><text>direct and manage
				information technology security programs and functions within all subordinate
				agency organizations (including components, bureaus, offices, and other
				organizations within the agency).</text>
								</paragraph></subsection><subsection id="IDeb8ede921a2549bdaadccac755d044da"><enum>(d)</enum><header>Continuous
				Technical Monitoring for malicious activity of Agency Network and Information
				System</header><paragraph commented="no" display-inline="yes-display-inline" id="id10176C20AC9E4DD68549D3305A541E25"><enum>(1)</enum><text>Each agency shall
				establish a mechanism that allows the Chief Information Security Officer of the
				agency to detect, monitor, correlate, and analyze, the security of any
				information system that is connected to the agency's information infrastructure
				on a continuous basis through automated monitoring.</text>
								</paragraph><paragraph id="IDc165c460c6e94a1e9e85a7699d3d3571" indent="up1"><enum>(2)</enum><text>The Chief Information Security
				Officer of an agency shall be responsible for and have the authority to assure
				that any information system connected to the network (directly or indirectly)
				that does not comply with security policies and standards, or has been
				compromised, is denied access and use of the agency network until the
				information system meets or exceeds accepted security policies and standards
				established by—</text>
									<subparagraph id="idD55D93542DF54D419B3BFC948DB54CA2"><enum>(A)</enum><text>the National Institute of Standards
				and Technology;</text>
									</subparagraph><subparagraph id="id4A4895DEB6B2404AAE29A80DFDDD91A8"><enum>(B)</enum><text>the Office of Management and Budget;
				and</text>
									</subparagraph><subparagraph id="idC7B7ED6D719546169DFFB6CE0A57867B"><enum>(C)</enum><text>the applicable agency.</text>
									</subparagraph></paragraph><paragraph id="ID86e38a70e35d45a1a4ef74d4392928e8" indent="up1"><enum>(3)</enum><text>After notification to the applicable
				agency’s Chief Information Officer, the Chief Information Security Officer of
				an agency may prevent access to any information system or individual that is
				using or attempts to use the agency information infrastructure if information
				security policies and procedures have not been followed or implemented.</text>
								</paragraph><paragraph commented="no" id="idFFA80C3273394DE8A57AA8CAC57B1636" indent="up1"><enum>(4)</enum><text>If the Chief Information Security
				Officer recognizes a network, computer, or data security incident that impairs
				adequate security of an interagency information system, the Chief Information
				Security Officer shall notify the managing agency, agency inspector general,
				and the United States Computer Emergency Readiness Team within 24 hours after
				discovery of an incident as defined by policy of the Office of Management and
				Budget.</text>
								</paragraph></subsection><subsection id="ID145ee4123a35494ab0e26ba461a9f53b"><enum>(e)</enum><header>Operational
				Evaluation</header><paragraph commented="no" display-inline="yes-display-inline" id="id37222DE0F9B64D449BD4BF28BB836E09"><enum>(1)</enum><text>The Chief Information
				Security Officer of an agency in consultation with the agency Chief Information
				Officer, with recommendations from the Chief Information Security Officers
				Council and in consultation with the Secretary of Homeland Security and the
				heads of other appropriate Federal agencies, shall—</text>
									<subparagraph id="ID992b80bed11043ad90f7fbea80dd0c79" indent="up1"><enum>(A)</enum><text>establish security control testing
				protocols that ensure that the information infrastructure of the agency,
				including contractor information systems operating on behalf of the agency are
				effectively protected against known vulnerabilities, attacks, and
				exploitations;</text>
									</subparagraph><subparagraph id="IDe5e5dc9e2ab24b83a7eb51b3d4c0dab7" indent="up1"><enum>(B)</enum><text>oversee the deployment of such
				protocols throughout the information infrastructure of the agency; and</text>
									</subparagraph><subparagraph id="ID1d543d8f3f14458db6c01c3d26594e5e" indent="up1"><enum>(C)</enum><text>update and test such protocols on a
				recurring basis.</text>
									</subparagraph></paragraph><paragraph id="ID85f45e8defa64edd83785a23325b8dcb" indent="up1"><enum>(2)</enum><text>After consideration of best practices
				and recommendations for operational evaluations established by the Chief
				Information Security Officer Council and in consultation with the heads of
				appropriate agencies, the Department of Homeland Security shall no less than
				annually—</text>
									<subparagraph id="IDc06083e6c09b427186f7055c26a5f229"><enum>(A)</enum><text>conduct an operational evaluation of
				the information infrastructure of each agency for known vulnerabilities,
				attacks, and exploitations of Federal networks on a frequent and recurring
				basis;</text>
									</subparagraph><subparagraph id="ID434c6b7c21cc4fe086e615681f1f55e8"><enum>(B)</enum><text>evaluate the ability of each agency to
				monitor, detect, correlate, analyze, report, and respond to breaches in
				information security policies and practices;</text>
									</subparagraph><subparagraph id="ID742ec0021cea40f09320cac035c57d7f"><enum>(C)</enum><text>report to the agency head, the Chief
				Information Officer, and the Chief Information Security Officer of the
				applicable agency the findings of the operational evaluation; and</text>
									</subparagraph><subparagraph id="ID1af4fecaf16b409686cbde9ed499fbf5"><enum>(D)</enum><text>in consultation with the Chief
				Information Officer and the Chief Information Security Officer of the
				applicable agency, assist with mitigating exploited vulnerabilities, attacks,
				and exploitations.</text>
									</subparagraph></paragraph><paragraph id="IDfb6488bf835347419178cbfa3c6e9f1c" indent="up1"><enum>(3)</enum><text>Not later than 30 days after
				receiving an operational evaluation under paragraph (2), the Chief Information
				Security Officer of an agency shall provide the Chief Information Officer and
				the agency head a plan for addressing recommendations and mitigating
				vulnerabilities contained in the security reports identified under paragraph
				(2), including a timeline and budget for implementing such plan.</text>
								</paragraph></subsection><subsection id="idA7F94562ECE54AE6BF008D8A9BC3C003"><enum>(f)</enum><header>National
				security systems</header><text>Subsections (c), (d), and (e) shall not apply to
				any national security system as defined under section 3542(b)(2) so long as
				that system is evaluated in a manner consistent with processes described under
				subsection (e)(2) (A) through (D) of this section.</text>
							</subsection></section><section id="IDf5277d0ae1bd449eb5d392fb66aa61c2"><enum>3549.</enum><header>Chief
				Information Security Officer Council</header>
							<subsection id="IDbd957c141c154c698b2e3e26d45a7e48"><enum>(a)</enum><header>Establishment</header><text>There
				is established in the executive branch a Chief Information Security Officers
				Council (in this section referred to as the <quote>Council</quote>).</text>
							</subsection><subsection id="ID7d39a48d67f64fcc8a6f434cb1ae5b2b"><enum>(b)</enum><header>Membership</header><text>The
				members of the Council shall be full-time senior government employees. The
				members shall be as follows:</text>
								<paragraph id="IDbe8d3d747c784f3aaeb768f0acb991b9"><enum>(1)</enum><text>The Administrator
				of the Office of Electronic Government of the Office of Management and
				Budget.</text>
								</paragraph><paragraph id="IDfb8098f6cbc645ae89cf7d1e19508c8d"><enum>(2)</enum><text>The Chief
				Information Security Officer of each agency described under section 901(b) of
				title 31.</text>
								</paragraph><paragraph id="ID47ba643cb6f84cc28bccb68f567d728c"><enum>(3)</enum><text>The Chief
				Information Security Officer of the Department of the Army, the Department of
				the Navy, and the Department of the Air Force, if chief information officers
				have been designated for such departments under section 3506(a)(2)(B).</text>
								</paragraph><paragraph id="idF872FDB6F5EC426EBE052D5EF51ECC71"><enum>(4)</enum><text>A representative
				from the Office of the Director of National Intelligence.</text>
								</paragraph><paragraph id="ID66f5f018f11845afb5e56f47c970b0aa"><enum>(5)</enum><text>A representative
				from the United States Strategic Command.</text>
								</paragraph><paragraph id="ID8592b0108e274919b1a481d6c58d4e40"><enum>(6)</enum><text>A representative
				from the United States Computer Emergency Readiness Team.</text>
								</paragraph><paragraph id="IDef26138a0dea4c44a9fd7c3000568e41"><enum>(7)</enum><text>A representative
				from the Intelligence Community Incident Response Center.</text>
								</paragraph><paragraph id="ID03af8d3cd9f444e09df3fab7e069b47f"><enum>(8)</enum><text>A representative
				from the Committee on National Security Systems.</text>
								</paragraph><paragraph id="ID41c8d36c93ba4c3eb4a0894567f90fc0"><enum>(9)</enum><text>Any other officer
				or employee of the United States designated by the chairperson.</text>
								</paragraph></subsection><subsection id="IDa4b063669e434917a58285c7658fef21"><enum>(c)</enum><header>Co-Chairpersons
				and Vice Chairpersons</header><paragraph commented="no" display-inline="yes-display-inline" id="id94EFFD21453F4F79B7604D93CA0A0CB8"><enum>(1)</enum><text>The Director of the
				National Cyber Security Center shall act as chairperson of the Council. The
				Administrator of the Office of Electronic Government of the Office of
				Management and Budget shall act as co-chairperson of the Council.</text>
								</paragraph><paragraph id="id8DC6300DA9DB4B10BAD233F8B000A3C0" indent="up1"><enum>(2)</enum><text>The vice chairperson of the Council
				shall be selected by the Council from among its members. The vice chairperson
				shall serve a 1-year term and may serve multiple terms. The vice chairperson
				shall serve as a liaison to the Chief Information Officer, Council Committee on
				National Security Systems, and other councils or committees as appointed by the
				chairperson.</text>
								</paragraph></subsection><subsection id="ID763d039de4444702b9032d715d2408f3"><enum>(d)</enum><header>Functions</header><paragraph commented="no" display-inline="yes-display-inline" id="id81705CFECB8246BA9A56B850CC0F669A"><enum>(1)</enum><text>The Council shall be
				the principal interagency forum for establishing best practices and
				recommendations for operational evaluations that use attack-based testing
				protocols established under section 3548(e).</text>
								</paragraph><paragraph id="ID0cfabe484ca24aafa2d079926a925ff0" indent="up1"><enum>(2)</enum><text>The Council shall—</text>
									<subparagraph id="ID92208fe56af0468e85fb4a359e6ffaec"><enum>(A)</enum><text>share experiences and innovative
				approaches relating to information sharing and information security best
				practices, penetration testing regimes, and incident response
				mitigation;</text>
									</subparagraph><subparagraph id="IDc65288dab05d44858f32a8c6cb2c6e0d"><enum>(B)</enum><text>promote the development and use of
				standard performance measures for agency information security that—</text>
										<clause id="id88E6E59E8DBC4004BEB7EE62493CF237"><enum>(i)</enum><text>are outcome-based;</text>
										</clause><clause id="idBB9A820F3403464F8045F20FA49A2C18"><enum>(ii)</enum><text>focus on risk management;</text>
										</clause><clause id="idB17A2B3C7C5C4E9A94FA90AE3CE98AE2"><enum>(iii)</enum><text>align with the business and
				program goals of the agency;</text>
										</clause><clause id="idAC79AC8B740F4AB787B3D841F915F5AA"><enum>(iv)</enum><text>measure improvements in the agency
				security posture over time; and</text>
										</clause><clause id="id2CA8F43ADCF449FE9D1838E2BD6578A9"><enum>(v)</enum><text>reduce burdensome compliance
				measures;</text>
										</clause></subparagraph><subparagraph id="id0955CBBD9C0F4F60B9C8736AAE4AC3E9"><enum>(C)</enum><text>develop and recommend to the Office of
				Management and Budget the necessary qualifications to be established for Chief
				Information Security Officers to be capable of administering the functions
				described under this subchapter including education, training, and
				experience;</text>
									</subparagraph><subparagraph id="id53B1449AFCCD42799EE784869847EE80"><enum>(D)</enum><text>enhance information system
				certification and accreditation processes by establishing a prioritized
				baseline of information security measures and controls that can be continuously
				monitored through automated mechanisms; and</text>
									</subparagraph><subparagraph id="id571CE5BF825F46B390B9E92406ACCB51"><enum>(E)</enum><text>submit proposed enhancements to the
				Office of Management and Budget.</text>
									</subparagraph></paragraph></subsection></section><section id="idBEB0B4F906B244DBB9506B8AC9ABFDC3"><enum>3550.</enum><header>Requirements
				for contracts relating to agency information and information systems</header>
							<subsection id="ID12f16936d952486094033027f650db2b"><enum>(a)</enum><header>In
				general</header><paragraph commented="no" display-inline="yes-display-inline" id="idCDA9C70484EB43A58E0DEAA3FD4A1723"><enum>(1)</enum><text>Not later than 180 days
				after the date of enactment of the <short-title>Federal
				Information Security Management Act of 2008</short-title>, the Director of the
				Office of Management and Budget, in consultation with the Director of the
				National Institutes of Standards and Technology, shall promulgate information
				security regulations governing contracts (including task or delivery orders
				issued pursuant to contracts) between the Federal Government and any
				individual, corporation, partnership, organization, or other entity that
				interfaces with an information system of an agency or collects, stores,
				operates, or maintains information on behalf of the agency.</text>
								</paragraph><paragraph id="idC17D80AC8BC74CEA96B65E39E132D32F" indent="up1"><enum>(2)</enum><text>Regulations promulgated under this
				subsection shall specify requirements concerning—</text>
									<subparagraph id="IDa6ff531916dd4aef8bbeb2e3b9b35424"><enum>(A)</enum><text>adequacy and effectiveness of the
				security of information systems;</text>
									</subparagraph><subparagraph id="ID8d60a9aad07840ee8c0733a6b505d8a4"><enum>(B)</enum><text>the collection and transmission of
				information, including personally identifiable information; and</text>
									</subparagraph><subparagraph id="IDbdc1582a194e4b6c9a31e0fd46af88ab"><enum>(C)</enum><text>procedures in the event of a security
				incident.</text>
									</subparagraph></paragraph></subsection><subsection id="IDbfd197efeded48dfb06e96c7695350d2"><enum>(b)</enum><header>Compliance</header><text>Notwithstanding
				any other provision of law, effective 180 days after the issuance of
				regulations under subsection (a), no agency may enter into a contract (or issue
				a task or delivery orders under a contract), or otherwise enter into an
				agreement, with an individual, corporation, partnership, organization, or other
				entity that interfaces with an information system of an agency or collects,
				stores, operates, or maintains information on behalf of the agency, unless the
				requirements of the contract or agreement are in compliance with such
				regulations.</text>
							</subsection><subsection id="ID263961d42fd54dc9b4d9640b93c41162"><enum>(c)</enum><header>Security
				requirements</header><text>Notwithstanding any other provision of law,
				effective 3 years after the issuance of regulations under subsection (a), no
				agency may enter into a contract (or issue a task or delivery order under
				contract), or otherwise enter into an agreement, with an individual,
				corporation, partnership, organization, or other entity for commercial off the
				shelf items, including hardware and software that does not conform to the
				security requirements in such regulations.</text>
							</subsection></section><section id="id5C236C14DDE74E48A73E21BE2B877E76"><enum>3551.</enum><header>Reports to
				Congress</header>
							<subsection id="id2441491BF1AE42A58A1EE92056ACA9C7"><enum>(a)</enum><header>Annual
				reports</header><paragraph commented="no" display-inline="yes-display-inline" id="id69D86B013ABE43539FAD5D374F828DB8"><enum>(1)</enum><text>On March 1 of each
				year, the Department of Homeland Security shall submit a report on operational
				evaluations and testing protocols to—</text>
									<subparagraph id="id49A8DF708C034FFAABA225CFEC2DF027" indent="up1"><enum>(A)</enum><text>the Committee on Homeland Security and
				Governmental Affairs of the Senate;</text>
									</subparagraph><subparagraph id="id3FF828C808C543E596E879BBF582355D" indent="up1"><enum>(B)</enum><text>the Committee on Oversight and
				Government Reform and the Committee on Homeland Security of the House of
				Representatives;</text>
									</subparagraph><subparagraph id="idCCB75ADE1B1D42ABABD390DDE0D87D4D" indent="up1"><enum>(C)</enum><text>the Select Committee on Intelligence
				of the Senate;</text>
									</subparagraph><subparagraph id="id7428E93EAE38496481D511A584252B21" indent="up1"><enum>(D)</enum><text>the Permanent Select Committee on
				Intelligence of the House of Representatives;</text>
									</subparagraph><subparagraph id="idB7EAB9FD5C054CD7B309784B5F9D88B0" indent="up1"><enum>(E)</enum><text>the Government Accountability Office;
				and</text>
									</subparagraph><subparagraph id="idDE94E015D5854627871F50BA152D5DAE" indent="up1"><enum>(F)</enum><text>the President’s Council on Integrity
				and Efficiency and the Executive Council on Integrity and Efficiency.</text>
									</subparagraph></paragraph><paragraph id="id27D9654B0AC7475D8A6E2DF74807CF38" indent="up1"><enum>(2)</enum><text>Each report submitted under this
				subsection shall—</text>
									<subparagraph id="idE6DB572BB7FB49CDBE6ED2072DB66F5A"><enum>(A)</enum><text>provide detailed information on the
				operational evaluations of each agency performed during the preceding fiscal
				year, the results of such evaluations, and any actions that remain to be taken
				under plans included in corrective action reports under section
				3548(e)(3);</text>
									</subparagraph><subparagraph id="idCAF4B1CFEAE144F2A4D2B950B9BC6A59"><enum>(B)</enum><text>describe the effectiveness of the
				testing protocols developed under section 3548(e)(1) in mitigating the risks
				associated with known vulnerabilities, attacks, and exploitations of the
				information infrastructure of each agency;</text>
									</subparagraph><subparagraph id="id6AF53479E88549478E178FAE1C5021C7"><enum>(C)</enum><text>describe the information security
				posture of the Federal Government, including—</text>
										<clause id="id0B04260F25A44CA8963A175315AD4B08"><enum>(i)</enum><text>the risks to the confidentiality,
				integrity, and availability of information governmentwide; and</text>
										</clause><clause id="id21C79D6EDB8C4CE6A2BE9D24F4233CD5"><enum>(ii)</enum><text>a plan of action and milestones to
				mitigate the risks governmentwide;</text>
										</clause></subparagraph><subparagraph id="idE7F7B047B6FB4774A9FC2906A46B14C1"><enum>(D)</enum><text>include any recommendations for
				relevant executive branch action and congressional oversight; and</text>
									</subparagraph><subparagraph id="id8A7B73CC9ED14593849D52C8B5AFC6B4"><enum>(E)</enum><text>include an unclassified and classified
				report of the operational evaluation.</text>
									</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id379C2B03F78D470F95E2D5679FA8ED5E"><enum>(b)</enum><header>Security
				reports and corrective action reports</header><text>The agency head and
				inspector general of each agency shall make all information security reports
				and information security corrective action reports available upon request
				to—</text>
								<paragraph commented="no" display-inline="no-display-inline" id="id1E11F05A04A5454C9BAA21A92F32C98A"><enum>(1)</enum><text>the Secretary of
				Homeland Security for purposes of completing the requirements under subsection
				(a); and</text>
								</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idDAEBE986ECF043A59FD703F755ECC87D"><enum>(2)</enum><text>the Comptroller
				General of the United
				States.</text>
								</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id4BB2DBABC42A4A5A9DE50360C4AD8C76"><enum>(c)</enum><header>Technical and
			 conforming amendments</header><text>The table of sections for chapter 35 of
			 title 44, United States Code, is amended by striking the items relating to
			 sections 3548 and 3549 and inserting the following:</text>
				<quoted-block id="idb4500f42-d48b-476b-9793-3b3b3d48b561" style="USC">
					<toc>
						<toc-entry level="section">Sec. </toc-entry>
						<toc-entry idref="id63BC2A8FDBDA482887EA1173E190272A" level="section">3548. Chief Information Security Officers.</toc-entry>
						<toc-entry idref="IDf5277d0ae1bd449eb5d392fb66aa61c2" level="section">3549. Chief Information Security Officer Council.</toc-entry>
						<toc-entry idref="idBEB0B4F906B244DBB9506B8AC9ABFDC3" level="section">3550. Requirements for contracts relating to agency information
				and information systems.</toc-entry>
						<toc-entry idref="id5C236C14DDE74E48A73E21BE2B877E76" level="section">3551. Reports to Congress.</toc-entry>
						<toc-entry level="section">3552. Authorization of
				appropriations.</toc-entry>
						<toc-entry level="section">3553. Effect on existing
				law.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body>
	<endorsement>
		<action-date>October 1 (legislative day, September 17),
		  2008</action-date>
		<action-desc>Reported without amendment</action-desc>
	</endorsement>
</bill>
