<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H4F479C6FD8AE40909CA11E153DD5EA33" public-private="public" bill-type="olc"> 
<form> 
<distribution-code display="yes">I</distribution-code> 
<congress>111th CONGRESS</congress>
<session>2d Session</session>
<legis-num>H. R. 5247</legis-num> 
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<action> 
<action-date date="20100506">May 6, 2010</action-date> 
<action-desc><sponsor name-id="L000559">Mr. Langevin</sponsor> (for himself, <cosponsor name-id="M001157">Mr. McCaul</cosponsor>, <cosponsor name-id="R000568">Mr. Rodriguez</cosponsor>, <cosponsor name-id="R000576">Mr. Ruppersberger</cosponsor>, <cosponsor name-id="C001067">Ms. Clarke</cosponsor>, <cosponsor name-id="S000030">Ms. Loretta Sanchez of California</cosponsor>, <cosponsor name-id="M001172">Ms. Markey of Colorado</cosponsor>, and <cosponsor name-id="S000510">Mr. Smith of Washington</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HGO00">Committee on Oversight and Government Reform</committee-name>, and in addition to the Committees on <committee-name committee-id="HAS00">Armed Services</committee-name> and <committee-name committee-id="">Select Intelligence (Permanent Select)</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc>
</action> 
<legis-type>A BILL</legis-type> 
<official-title>To establish a National Cyberspace Office, and for other purposes.</official-title> 
</form> 
<legis-body id="H26CA0F854CCB4A2FAC1FC32F8184EE2A" style="OLC"> 
<section id="H7B895E1B6C904027BFE6760F083A386C" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Executive Cyberspace Authorities Act of 2010</short-title></quote>.</text></section> 
<section id="H975F4F12689E48E7A90C25A6C2D8FC62"><enum>2.</enum><header>National Cyberspace Office</header> 
<subsection id="H892C6A38E01E472A85A102179670EE83"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">There is established within the Executive Office of the President an office to be known as the National Cyberspace Office.</text></subsection> 
<subsection id="HBBD4BBE3A6FA42D39791F8ECAE7E0774"><enum>(b)</enum><header>Director</header><text display-inline="yes-display-inline">There shall be at the head of the National Cyberspace Office a Director, who shall be appointed by the President by and with the advice and consent of the Senate. The Director of the National Cyberspace Office shall administer all functions under this section and collaborate to the extent practicable with the heads of appropriate agencies, the private sector, and international partners. The National Cyberspace Office shall serve as the principal office for coordinating issues relating to achieving an assured, reliable, secure, and survivable information infrastructure and related capabilities for the Federal Government.</text></subsection> 
<subsection id="H1B2986553E8048968D5AECB4E437606D"><enum>(c)</enum><header>Authority and functions of the Director of the National Cyberspace Office</header> 
<paragraph id="H756A686C54F94C1A8BA9EC4D62A61038"><enum>(1)</enum><header>Duties of the Director</header><text display-inline="yes-display-inline">The Director of the National Cyberspace Office shall—</text> 
<subparagraph id="H1F7E8DE98F0148E8B781070643E0D451"><enum>(A)</enum><text>oversee agency information security policies and practices, including—</text> 
<clause id="HC9AB886E1AD24909A6BDE97E81C422F2"><enum>(i)</enum><text display-inline="yes-display-inline">developing and overseeing the implementation of policies, principles, standards, and guidelines on information security, including through ensuring timely agency adoption of and compliance with such policies, principles, standards, and guidelines;</text></clause> 
<clause id="HE13A1D5E1FB44ED9ABF16011D827920F"><enum>(ii)</enum><text display-inline="yes-display-inline">reviewing at least annually, and approving or disapproving, each agency budget relating to the protection of information technology submitted pursuant to <internal-xref idref="H67D633B394054AAC8C9DEE45BEA28309" legis-path="2.(d)">subsection (d)</internal-xref>;</text> </clause> 
<clause id="H50B9D079A13F4D9F87BFC6EC3E860D04"><enum>(iii)</enum><text display-inline="yes-display-inline">coordinating the development of standards and guidelines under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) with agencies and offices operating or exercising control of national security systems (including the National Security Agency) to assure, to the maximum extent feasible, that such standards and guidelines are complementary with standards and guidelines developed for national security systems;</text></clause> 
<clause id="HF39ED82446B84EE989CB64E9AFE8B537"><enum>(iv)</enum><text display-inline="yes-display-inline">coordinating information security policies and procedures with related information resources management policies and procedures;</text></clause> 
<clause id="HD3F18E9290074A8995DB44B21607156E" commented="no"><enum>(v)</enum><text display-inline="yes-display-inline">overseeing the operation of the Federal information security incident center required under section 3546 of title 44, United States Code; and</text></clause> 
<clause id="H13F4C1F96F6A4677950227BC38725627"><enum>(vi)</enum><text display-inline="yes-display-inline">reporting to Congress not later than March 1 of each year on agency compliance with the requirements of this Act, including—</text> 
<subclause id="H2B6C847917B940A6AA0E29FAC8156AF9" commented="no"><enum>(I)</enum><text display-inline="yes-display-inline">a summary of the findings of the independent evaluation required by section 3545 of title 44, United States Code;</text></subclause> 
<subclause id="H6BB42CFF012A45B38CC3B5831CD5A56C"><enum>(II)</enum><text display-inline="yes-display-inline">an assessment of the development, promulgation, and adoption of, and compliance with, standards developed under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3);</text></subclause> 
<subclause id="HE0CF338632794F34AC2B554FAC249EE0"><enum>(III)</enum><text display-inline="yes-display-inline">significant deficiencies in agency information security practices;</text></subclause> 
<subclause id="HD1F2227BA9E843D9876E86766DC36272"><enum>(IV)</enum><text display-inline="yes-display-inline">planned remedial action to address such deficiencies; and</text></subclause> 
<subclause id="HD08905C0964D49079DEE3A3768C282C5"><enum>(V)</enum><text display-inline="yes-display-inline">a summary of, and the views of the Director on, the report prepared by the National Institute of Standards and Technology under section 20(d)(10) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3);</text></subclause></clause></subparagraph> 
<subparagraph id="HBD35B1177A494C749977EFA5DD3D5CEF" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">encourage public-private working groups with representatives from relevant agencies and industry partners to increase information sharing and policy coordination efforts in order to reduce vulnerabilities in the national information infrastructure;</text></subparagraph> 
<subparagraph id="HD82415E9BEC9402DB4D9B43B84FFBB12" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">coordinate the defense of information infrastructure operated by agencies in the case of a large-scale attack on information technology, as determined by the Director;</text></subparagraph> 
<subparagraph id="HBC8C204854C248969EB85C3732B045D2" commented="no"><enum>(D)</enum><text display-inline="yes-display-inline">establish a national strategy, in consultation with the Department of State, the United States Trade Representative, and the National Institute of Standards and Technology, to engage with the international community to set the policies, principles, standards, or guidelines for information security; and</text></subparagraph> 
<subparagraph id="H1E584B7B2E95439C92A2A07D6C3BBFC4" commented="no"><enum>(E)</enum><text display-inline="yes-display-inline">coordinate information security training for Federal employees with the Office of Personnel Management.</text></subparagraph></paragraph> 
<paragraph id="HDC4194C581814236BFCB727ADC261CB2"><enum>(2)</enum><header>Consultation</header><text display-inline="yes-display-inline">The head of each agency shall consult with the Director regarding information security policies and practices.</text></paragraph> 
<paragraph id="H0794A19E81C840CB9B22DDAE855D8B3F" commented="no" display-inline="no-display-inline"><enum>(3)</enum><header>Experts and consultants</header><text display-inline="yes-display-inline">The Director may procure temporary and intermittent services under section 3109(b) of title 5, United States Code.</text></paragraph> 
<paragraph id="HF9B689A295AF4F62A589A2A71DB97445" commented="no"><enum>(4)</enum><header>Membership on the National Security Council</header><text display-inline="yes-display-inline">Section 101(a) of the National Security Act of 1947 (50 U.S.C. 402(a)) is amended—</text> 
<subparagraph id="H1AD711016B9A4B53B495DFF551219845" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">by redesignating paragraphs (7) and (8) as paragraphs (8) and (9), respectively; and</text></subparagraph> 
<subparagraph id="HD55662555435400DA4D0AD04DA4723CA" commented="no"><enum>(B)</enum><text>by inserting after paragraph (6) the following:</text> 
<quoted-block style="OLC" id="H9F00E6E316554F7E99DE0C419115011D" display-inline="no-display-inline"> 
<paragraph id="H168EDF46D37447CBA3A021ABC55E1B14" commented="no"><enum>(7)</enum><text display-inline="yes-display-inline">the Director of the National Cyberspace Office;</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph> </subsection> 
<subsection id="H67D633B394054AAC8C9DEE45BEA28309"><enum>(d)</enum><header>Budget approval</header> 
<paragraph id="H745ED8B987FF496BABBFB5566B391E01"><enum>(1)</enum><header>Submission of budget</header><text display-inline="yes-display-inline">The head of each agency shall submit to the Director of the National Cyberspace Office a budget each year for the following fiscal year relating to the protection of information technology for such agency, by a date determined by the Director that is before the submission of such budget by the head of the agency to the Office of Management and Budget.</text></paragraph> 
<paragraph id="H7098E5D0FAAD4521814095A6A6EB4190"><enum>(2)</enum><header>Budget approval</header><text>The Director shall review and approve or disapprove the budget before the submission of such budget by the head of the agency to the Office of Management and Budget.</text></paragraph> 
<paragraph id="HE27EA3E8BC884579BC3A752EEF405B9B"><enum>(3)</enum><header>Budget disapproval</header><text>If the Director disapproves a budget under paragraph (2), the Director shall transmit recommendations to the head of the agency for such budget.</text></paragraph> 
<paragraph id="HA7C75889FED64B378AE7AF70731C22D6" commented="no"><enum>(4)</enum><header>Budget submission requirements</header><text display-inline="yes-display-inline">Each budget submitted by the head of an agency pursuant to <internal-xref idref="H745ED8B987FF496BABBFB5566B391E01" legis-path="2.(d)(1)">paragraph (1)</internal-xref> shall include—</text> 
<subparagraph id="H38C57D24F4F54834AF72A71D5515E940" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline">a review of any threats to information technology for such agency;</text></subparagraph> 
<subparagraph id="HA9A7BE81E3CB42C6A1D7512E54BA55C5" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">a plan to secure the information infrastructure for such agency based on threats to information technology, using the National Institute of Standards and Technology guidelines and recommendations;</text></subparagraph> 
<subparagraph id="H8489F00F82A74E2B845E803438797864" commented="no"><enum>(C)</enum><text display-inline="yes-display-inline">a review of compliance by such agency with any previous year plan described in subparagraph (B); and</text></subparagraph> 
<subparagraph id="HEFAA7AC0A042448AAD6C31D5E945C567" commented="no"><enum>(D)</enum><text display-inline="yes-display-inline">a report on the development of the credentialing process to enable secure authentication of identity and authorization for access to the information infrastructure of such agency.</text></subparagraph></paragraph> 
<paragraph id="H1473418B801E41EE84D00609730E3538" commented="no"><enum>(5)</enum><header>Cyber security performance</header><text display-inline="yes-display-inline">The National Cyberspace Office may recommend to the President that awards and bonuses be withheld for any agency that failed to make adequate efforts to secure the information infrastructure of such agency.</text></paragraph></subsection> 
<subsection id="H51F21D583AE948F2BEEE2C2C64A7CBFF"><enum>(e)</enum><header>National Security Systems</header><text display-inline="yes-display-inline">Except for the authority described in clauses (iii) and (vi) of subsection (c)(1)(A), the authorities of the Director of the National Cyberspace Office under this section shall not apply to national security systems.</text></subsection> 
<subsection id="HCC56A95E6E9448AE8B409829A38B393D"><enum>(f)</enum><header>Department of Defense and Central Intelligence Agency Systems</header> 
<paragraph id="H8A763A80EF264B6AA0069CB8BD47A9F5"><enum>(1)</enum><header>Delegation of authority</header><text display-inline="yes-display-inline">The authority of the Director of the National Cyberspace Office described in subparagraphs (A)(i) and (C) of subsection (c)(1) shall be delegated to the Secretary of Defense in the case of systems described in paragraph (2) and to the Director of Central Intelligence in the case of systems described in paragraph (3).</text></paragraph> 
<paragraph id="HE310965B184245F0A34E58029FA0CC62"><enum>(2)</enum><header>Department of Defense</header><text display-inline="yes-display-inline">The systems described in this paragraph are systems that are operated by the Department of Defense, a contractor of the Department of Defense, or another entity on behalf of the Department of Defense that processes any information the unauthorized access, use, disclosure, disruption, modification, or destruction of which would have a debilitating impact on the mission of the Department of Defense.</text></paragraph> 
<paragraph id="HFBB5CF4C9D1F4B88821CC28079D518B4"><enum>(3)</enum><header>Central Intelligence Agency</header><text display-inline="yes-display-inline">The systems described in this paragraph are systems that are operated by the Central Intelligence Agency, a contractor of the Central Intelligence Agency, or another entity on behalf of the Central Intelligence Agency that processes any information the unauthorized access, use, disclosure, disruption, modification, or destruction of which would have a debilitating impact on the mission of the Central Intelligence Agency.</text></paragraph></subsection> 
<subsection id="HD15A9829108F4DDDB4103F19298CFC9D"><enum>(g)</enum><header>Conforming amendments</header><text display-inline="yes-display-inline">Title 44, United States Code, is amended—</text> 
<paragraph id="HBC8741806B6348DEB5DF0A7227B06BA8"><enum>(1)</enum><text>in section 3546(a), by striking <quote>Director</quote> and inserting <quote>Director of the National Cyberspace Office</quote>; and</text></paragraph> 
<paragraph id="H3CABA4E0B32844429485B8321D136E24"><enum>(2)</enum><text display-inline="yes-display-inline">in section 3545(e)—</text> 
<subparagraph id="H19E38650EA6644FBBA2FD2A2AAECB846"><enum>(A)</enum><text>in paragraph (1), by inserting <quote>and the Director of the National Cyberspace Office</quote> after <quote>submit to the Director</quote>; and</text></subparagraph> 
<subparagraph id="HCD1A028762544F208BF44893C86EF010"><enum>(B)</enum><text display-inline="yes-display-inline">in paragraph (2), by inserting <quote>and the Director of the National Cyberspace Office</quote> after <quote>the Director</quote>.</text></subparagraph></paragraph></subsection></section> 
<section id="HA9E1709111A0424F86DB5656B9378C60"><enum>3.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text> 
<paragraph id="HB22BD2B1B8B44F98AA1B9AF306A6D994"><enum>(1)</enum><header>Agency</header><text>The term <term>agency</term> has the meaning given that term in section 3502 of title 44, United States Code.</text></paragraph> 
<paragraph id="H8DF60317DCBE483F8CEBD18EA8397543"><enum>(2)</enum><header>Information infrastructure</header><text display-inline="yes-display-inline">The term <term>information infrastructure</term> means the underlying framework that information systems and assets rely on in processing, storing, or transmitting information electronically. </text></paragraph> 
<paragraph id="H20C3C05C2BDB49FBAA22EE4AE893647B"><enum>(3)</enum><header>Information resources management</header><text display-inline="yes-display-inline">The term <term>information resources management</term> has the meaning given that term in section 3502 of title 44, United States Code. </text></paragraph> 
<paragraph id="HD4429DC08F0C4DCB9D3828C5DF86918F"><enum>(4)</enum><header>Information security</header><text display-inline="yes-display-inline">The term <term>information security</term> has the meaning given that term in section 3542 of title 44, United States Code.</text></paragraph> 
<paragraph id="H99DA31A9A0444622AFEC69366AF9EB26"><enum>(5)</enum><header>Information technology</header><text>The term <term>information technology</term> has the meaning given that term in section 11101 of title 40, United States Code.</text></paragraph> 
<paragraph id="HCF96DE1EE2B04E318C6D74DC80347FA6"><enum>(6)</enum><header>National security system</header><text display-inline="yes-display-inline">The term <term>national security system</term> has the meaning given that term in section 3542 of title 44, United States Code.</text> </paragraph></section> 
</legis-body> 
</bill> 

