<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 921</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20090428">April 28, 2009</action-date>
			<action-desc><sponsor name-id="S277">Mr. Carper</sponsor> introduced
			 the following bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend chapter 35 of title 44, United States Code, to
		  recognize the interconnected nature of the Internet and agency networks,
		  improve situational awareness of Government cyberspace, enhance information
		  security of the Federal Government, unify policies, procedures, and guidelines
		  for securing information systems and national security systems, establish
		  security standards for Government purchased products and services, and for
		  other purposes.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>United States Information and
			 Communications Enhancement Act of 2009</short-title></quote> or the
			 <quote><short-title>U.S. ICE Act of
			 2009</short-title></quote>.</text>
		</section><section id="IDe000424beddc4a0badf2018264c28250"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">The Congress finds the following:</text>
			<paragraph id="ID668f58417e0c4ce0bcdd8526148ef55b"><enum>(1)</enum><text>The development
			 of an interconnected global information infrastructure has significantly
			 enhanced the productivity, prosperity, and collaboration of people, business,
			 and governments worldwide.</text>
			</paragraph><paragraph id="ID1340330196644c148229a846ee357708"><enum>(2)</enum><text>The information
			 infrastructure of the United States is a strategic national resource vital to
			 our democracy, economy, and security.</text>
			</paragraph><paragraph id="ID42153572351f40ac909b63b33f4b60f3"><enum>(3)</enum><text>The Federal
			 Government must increasingly rely on a trusted and resilient information
			 infrastructure to effectively and efficiently communicate with and deliver
			 services to citizens, enhance economic prosperity, defend the Nation from
			 attack, and recover from natural disasters.</text>
			</paragraph><paragraph id="ID1f480ed19a0f4d4e8927cf4f1c6cae33"><enum>(4)</enum><text>Since 2002 the
			 Federal Government has experienced multiple high-profile breaches that resulted
			 in the theft of sensitive information amounting to more than the entire print
			 collection contained in the Library of Congress, including personally
			 identifiable information, advanced scientific research, and prenegotiated
			 United States diplomatic positions.</text>
			</paragraph><paragraph id="ID39a5d8c6b0a54eb989e7cfdbb7a33c0b"><enum>(5)</enum><text>On March 12, 2008
			 witnesses testified before a hearing held by the Subcommittee on Federal
			 Financial Management, Government Information, Federal Services, and
			 International Security of the Committee on Homeland Security and Governmental
			 Affairs of the Senate that—</text>
				<subparagraph id="id6559AE33F908418D925DCE80FBE9F2C4"><enum>(A)</enum><text>implementation of
			 the Federal Information Security Management Act of 2002 (Public Law 107–296;
			 116 Stat. 2135) wastes agency resources on paperwork exercise instead of
			 security;</text>
				</subparagraph><subparagraph id="id5C50A584C75F484B9B6BA4B6C22B41BF"><enum>(B)</enum><text>agencies do not
			 fully understand what information they hold, who has access to that
			 information, and whether the information has been compromised; and</text>
				</subparagraph><subparagraph id="id0746E7AADAEF47D8B9F8DB81D3B8607C"><enum>(C)</enum><text>agencies lack
			 effective coordination for mitigating and responding to cyber-related
			 incidents.</text>
				</subparagraph></paragraph><paragraph id="ID99b7cf08e58d465b89b3c1448f50e392"><enum>(6)</enum><text>The Federal
			 Information Security Management Act of 2002 (Public Law 107–296; 116 Stat.
			 2135) needs to be amended to increase the coordination of agency activities to
			 enhance situational awareness throughout the Federal Government using more
			 effective enterprise-wide automated monitoring, detection, and response
			 capabilities.</text>
			</paragraph></section><section id="id20CAE4669B5546CB8789B4911B4D5BE6"><enum>3.</enum><header>Coordination of
			 Federal Information Policy</header><text display-inline="no-display-inline">Chapter 35 of title 44, United States Code,
			 is amended by striking subchapters II and III and inserting the
			 following:</text>
			<quoted-block display-inline="no-display-inline" id="id151DFFC8551942009F08F3929DAE1BCB" style="USC">
				<subchapter id="idA46F1CEDCE84495DBA31C213EDF97874"><enum>II</enum><header>Information
				security</header>
					<section id="id73CCC29494D94776810170DDDCCD9936"><enum>3551.</enum><header>Definitions</header>
						<subsection id="ID9ea18e91ce074e0c89eb9d4f7ff5d836"><enum>(a)</enum><text>Except as
				provided under subsection (b), the definitions under section 3502 shall apply
				to this subchapter.</text>
						</subsection><subsection id="ID873343f1a5f94d34b86b7fc448cc05ff"><enum>(b)</enum><text>In this
				subchapter:</text>
							<paragraph id="id3BD1CA4E239F44B88390E050156FA1A0"><enum>(1)</enum><text>The term
				<term>adequate security</term> means security commensurate with the risk and
				magnitude of harm resulting from the loss, misuse, or unauthorized access to,
				or modification, of information.</text>
							</paragraph><paragraph id="idEA7DBA3AED3D4847A14DC1ADB51225FA"><enum>(2)</enum><text>The term
				<term>Director</term> means the Director of the National Office for
				Cyberspace.</text>
							</paragraph><paragraph id="id4B58940B216C404DBF2B7DD07E24DD43"><enum>(3)</enum><text>The term
				<term>incident</term> means an occurrence that actually or potentially
				jeopardizes the confidentiality, integrity, or availability of an information
				system or the information the system processes, stores, or transmits or that
				constitutes a violation or imminent threat of violation of security policies,
				security procedures, or acceptable use policies.</text>
							</paragraph><paragraph id="idE44EBB4DFA654844A67729E1C1891D1E"><enum>(4)</enum><text>The term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on in processing, transmitting, receiving,
				or storing information electronically.</text>
							</paragraph><paragraph id="IDcb5c60332aab455c9d1cc5fd78583cbd"><enum>(5)</enum><text>The term
				<term>information security</term> means protecting information and information
				systems from unauthorized access, use, disclosure, disruption, modification, or
				destruction in order to provide—</text>
								<subparagraph id="ID4ca459a9218542ef8d680cf099b24c32"><enum>(A)</enum><text>integrity, which
				means guarding against improper information modification or destruction, and
				includes ensuring information nonrepudiation and authenticity;</text>
								</subparagraph><subparagraph id="ID13023997969843a8a984ecc7df6acfab"><enum>(B)</enum><text>confidentiality,
				which means preserving authorized restrictions on access and disclosure,
				including means for protecting personal privacy and proprietary information;
				and</text>
								</subparagraph><subparagraph id="ID2263320d45a845a1932daa77fd79028c"><enum>(C)</enum><text>availability,
				which means ensuring timely and reliable access to and use of
				information.</text>
								</subparagraph></paragraph><paragraph id="id5BF057DB15EE410785D7C583D095F3C3"><enum>(6)</enum><text>The term
				<term>information technology</term> has the meaning given that term in section
				11101 of title 40.</text>
							</paragraph><paragraph id="ID9a19e5c620124dbb8223efbb21f9d0db"><enum>(7)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="id2DEA375ECA8F43FDA82138C3751EEDE2"><enum>(A)</enum><text>The term <term>national
				security system</term> means any information system (including any
				telecommunications system) used or operated by an agency or by a contractor of
				an agency, or other organization on behalf of an agency—</text>
									<clause id="ID5540aefa26e14c269911600aca3ab906" indent="up1"><enum>(i)</enum><text>the function, operation, or use of
				which—</text>
										<subclause id="ID2fd57480587a45059ace48ada7298219"><enum>(I)</enum><text>involves intelligence activities;</text>
										</subclause><subclause id="ID07fd47014e004ae5926e77b492996311"><enum>(II)</enum><text>involves cryptologic activities related
				to national security;</text>
										</subclause><subclause id="IDd5a45fd5453d42ddbb8a726d77de0727"><enum>(III)</enum><text>involves command and control of
				military forces;</text>
										</subclause><subclause id="ID9a204f8c758f4de3b1ebb4cb44b4a6df"><enum>(IV)</enum><text>involves equipment that is an integral
				part of a weapon or weapons system; or</text>
										</subclause><subclause id="ID815fe74c715f465ab8666b79f3e3f851"><enum>(V)</enum><text>subject to subparagraph (B), is critical
				to the direct fulfillment of military or intelligence missions; or</text>
										</subclause></clause><clause id="ID0b95e4f1a63c4bf18fdf4c2d0b738934" indent="up1"><enum>(ii)</enum><text>is protected at all times by
				procedures established for information that have been specifically authorized
				under criteria established by an Executive order or an Act of Congress to be
				kept classified in the interest of national defense or foreign policy.</text>
									</clause></subparagraph><subparagraph id="IDac53cdf0cc31470880e05b5f543b1ad5" indent="up1"><enum>(B)</enum><text>Subparagraph (A)(i)(V) does not
				include a system that is to be used for routine administrative and business
				applications (including payroll, finance, logistics, and personnel management
				applications).</text>
								</subparagraph></paragraph></subsection></section><section id="IDca3cbab08a154f99b1ab586c2143917e"><enum>3552.</enum><header>National
				Office for Cyberspace</header>
						<subsection id="IDf83bdea60bcb470ea2410817e9ef2410"><enum>(a)</enum><text>There is
				established within the Executive Office of the President an office to be known
				as the National Office for Cyberspace.</text>
						</subsection><subsection id="IDeb968d07a6ff45f88f6c5b4d4bd76219"><enum>(b)</enum><text>There shall be at
				the head of the Office a Director who shall be appointed by the President, by
				and with the advice and consent of the Senate. The Director of the National
				Office for Cyberspace shall administer all functions under this subchapter and
				collaborate to the extent practicable with the heads of the appropriate
				agencies, the private sector, and international partners. The Office shall
				serve as the principal office for coordinating issues relating to achieving an
				assured, reliable, secure, and survivable global information and communications
				infrastructure and related capabilities.</text>
						</subsection></section><section id="ID413f00e1044e4b46a11e63945ac07d04"><enum>3553.</enum><header>Authority and
				functions of the National Office for Cyberspace</header>
						<subsection id="ID59b0885284d446858f097e6418193392"><enum>(a)</enum><text>The Director
				shall develop and implement a comprehensive national cyberspace strategy to
				ensure a trusted and resilient communications and information infrastructures
				that—</text>
							<paragraph id="ID3fcd535624da4a608cd4e8e32d1d7e0b"><enum>(1)</enum><text>enhances economic
				prosperity and facilitates market leadership for the United States information
				and communications industry;</text>
							</paragraph><paragraph id="IDdbe0cec622c045c0858fc45ad6ee21ea"><enum>(2)</enum><text>deters, prevents,
				detects, defends against, responds to, and remediates interruptions and damage
				to United States information and communications infrastructure;</text>
							</paragraph><paragraph id="IDeb36356ec76b4e0c9f6bc8b6a3ed0c7f"><enum>(3)</enum><text>ensures United
				States capabilities to operate in cyberspace in support of national goals;
				and</text>
							</paragraph><paragraph id="ID2a65040e1b3a41bfb7090263accc6304"><enum>(4)</enum><text>protects privacy
				rights and preserving civil liberties of United States persons.</text>
							</paragraph></subsection><subsection id="ID95d09fba8d3446a48877586a4e35a784"><enum>(b)</enum><text>Notwithstanding
				any provision of law, regulation, rule, or policy to the contrary, the National
				Office for Cyberspace may—</text>
							<paragraph id="IDa7511043c3b84231870f97df4ad19df1"><enum>(1)</enum><text>direct the
				sponsorship of the security clearances for Federal officers and employees
				(including experts and consultants employed under section 3109) whose
				responsibilities involve critical infrastructure in the interest of national
				security; and</text>
							</paragraph><paragraph id="ID236f207ebb64429fabb0cfee6841aaa7"><enum>(2)</enum><text>employ experts
				and consultants under section 3109 for cyber security-related work.</text>
							</paragraph></subsection><subsection id="ID9dc87c8f2aec436ea9d4e1c4b52c0f5a"><enum>(c)</enum><text>With respect to
				responsibilities with the Federal Government, the National Office for
				Cyberspace shall—</text>
							<paragraph id="ID7089852a60cd419f9ec60f9076370d88"><enum>(1)</enum><text>provide
				recommendations to agencies on measures that shall be required to be
				implemented to mitigate vulnerabilities, attacks, and exploitations discovered
				as a result of activities required pursuant to this section;</text>
							</paragraph><paragraph id="ID1184a3dbcc3f4abeaeaa24c02027d472"><enum>(2)</enum><text>oversee the
				implementation of policies, principles, standards, and guidelines on
				information security, including through ensuring timely agency adoption of and
				compliance with standards promulgated under section 3556;</text>
							</paragraph><paragraph id="ID73c409b10e574f828e7e9f229862c4ca"><enum>(3)</enum><text>to the extent
				practicable—</text>
								<subparagraph id="idF5AAA43D23E04178B65A5A77AE3AE554"><enum>(A)</enum><text>prioritize the
				policies, principles, standards, and guidelines developed under section 3556
				based upon the threat, vulnerability and consequences of an information
				security incident; and</text>
								</subparagraph><subparagraph id="ID2d5138f2de52412fa32dc43b535c96a0"><enum>(B)</enum><text>develop guidance
				that requires agencies to actively monitor the effective implementation of
				policies, principles, standards, and guidelines developed under section
				3556;</text>
								</subparagraph></paragraph><paragraph id="ID6b85e795021c413bbafe8c99e61da67d"><enum>(4)</enum><text>require agencies,
				consistent with the standards promulgated under such section 3556 and the
				requirements of this subchapter, to identify and provide information security
				protections commensurate with the risk and magnitude of the harm resulting from
				the unauthorized access, use, disclosure, disruption, modification, or
				destruction of—</text>
								<subparagraph id="IDa401a5cbd617430d90afb06b3f8dfeb2"><enum>(A)</enum><text>information
				collected or maintained by or on behalf of an agency; or</text>
								</subparagraph><subparagraph id="ID0edb91e0cf07487ea1d3a1169b840406"><enum>(B)</enum><text>information
				systems used or operated by an agency or by a contractor of an agency or other
				organization on behalf of an agency;</text>
								</subparagraph></paragraph><paragraph id="ID2ac08f651cfc4593bb18e314acf2302a"><enum>(5)</enum><text>coordinate and
				ensure that the development of standards and guidelines under section 20 of the
				National Institute of Standards and Technology Act (15 U.S.C. 278g–3) and
				standards and guidelines developed for national security systems are, to the
				maximum extent practicable, complementary and unified;</text>
							</paragraph><paragraph id="IDd7f0aa300d0845388c42aeb21342b143"><enum>(6)</enum><text>oversee agency
				compliance with the requirements of this subchapter, including coordinating
				with the Office of Management and Budget to use any authorized action under
				section 11303 of title 40, to enforce accountability for compliance with such
				requirements;</text>
							</paragraph><paragraph id="ID3409a471f4904c59bec5b8982953dce1"><enum>(7)</enum><text>review at least
				annually, and approving or disapproving, agency information security programs
				required under section 3554(b); and</text>
							</paragraph><paragraph id="IDc26dfa6c2bd449fb8b5d36eca6ac40ba"><enum>(8)</enum><text>coordinate
				information security policies and procedures with related information resources
				management policies and procedures.</text>
							</paragraph></subsection><subsection id="ID270d95317a754ec7a7fc0bfc2966d337"><enum>(d)</enum><paragraph commented="no" display-inline="yes-display-inline" id="idA766F2B8613B40F18F6261CD1BAE2A91"><enum>(1)</enum><text>After consultation with
				the appropriate agencies, the Director shall oversee the effective
				implementation of governmentwide operational evaluations on a frequent and
				recurring basis to evaluate whether agencies effectively—</text>
								<subparagraph id="ID871717102db1441c8154d6dce7ec8634" indent="up1"><enum>(A)</enum><text>monitor, detect, analyze, protect,
				report, and respond against known vulnerabilities, attacks, and
				exploitations;</text>
								</subparagraph><subparagraph id="ID16c34c0f98ad47af98b5e8d086e168e5" indent="up1"><enum>(B)</enum><text>report to and collaborate with the
				appropriate public and private security operation centers and law enforcement
				agencies; and</text>
								</subparagraph><subparagraph id="IDd43af0e87a114044929a7e41b325c35f" indent="up1"><enum>(C)</enum><text>mitigate the risk posed by previous
				successful exploitations in a timely fashion and in order to prevent future
				vulnerabilities, attacks, and exploitations.</text>
								</subparagraph></paragraph><paragraph id="IDd5c652422b914d6184b73cade10115dd" indent="up1"><enum>(2)</enum><text>Not later than 30 days after
				receiving an operational evaluation under this subsection, the Director shall
				ensure agencies evaluated under paragraph (1) develop a plan for addressing
				recommendations and mitigating vulnerabilities contained in the security
				reports identified under paragraph (1), including a timeline and budget for
				implementing such plan.</text>
							</paragraph></subsection><subsection id="IDa1bf0fd0d3da4eb0a6eefa2c9bf4e79a"><enum>(e)</enum><text>Not later than
				March 1 of each year, the Director shall submit a report to Congress on the
				overall information security posture of the communications and information
				infrastructure of the United States, including—</text>
							<paragraph id="idE33723C183A54CA5BC5A85DBD78F118C"><enum>(1)</enum><text>the evaluations
				conducted under subsection (d) for the United States Government;</text>
							</paragraph><paragraph id="ID035f5cf251084ff6a3dd1ac5b763617f"><enum>(2)</enum><text>a detailed
				assessment of the overall resiliency of the communications and information
				infrastructure effectiveness of the United States and the United States
				Government including the ability to monitor, detect, mitigate, and respond to
				an incident;</text>
							</paragraph><paragraph id="IDadc9315c12b545fbbe824b9205cc0dac"><enum>(3)</enum><text>a detailed
				assessment the information security effectiveness of each agency, including the
				ability to monitor, detect, mitigate, collaborate, and respond to an
				incident;</text>
							</paragraph><paragraph id="ID42d855fe5cfd430ab288830fb7d4e41d"><enum>(4)</enum><text>a detailed
				assessment of operational evaluations performed during the preceding fiscal
				year, the results of such evaluations, and any actions that remain to be taken
				under plans included in corrective action reports under subsection (d);</text>
							</paragraph><paragraph id="ID9ddb962bb15d42cd9339df56d23e8d2c"><enum>(5)</enum><text>a detailed
				assessment of the development, promulgation, and adoption of, and compliance
				with, standards developed under section 20 of the National Institute of
				Standards and Technology Act (15 U.S.C. 278g–3) and promulgated under section
				3554, and recommendations for enhancement;</text>
							</paragraph><paragraph id="ID83e7a4d197ad477f9044e449b77354bf"><enum>(6)</enum><text>a detailed
				assessment of significant deficiencies in the information security and
				reporting practices of the Federal Government as applicable to each
				agency;</text>
							</paragraph><paragraph id="IDf2afae4de2c34ae09d4a20b903a80341"><enum>(7)</enum><text>planned remedial
				action to address deficiencies described under paragraph (6), including an
				associated budget and recommendations for relevant executive and legislative
				branch actions;</text>
							</paragraph><paragraph id="ID328b2c0fce9f41b88cb7b991e4d9a8fc"><enum>(8)</enum><text>a summary of the
				results of the independent evaluations under section 3555; and</text>
							</paragraph><paragraph id="id45CFCF0033DA4C9B8844E0C816E4EE70"><enum>(9)</enum><text>a detailed
				assessment of the effectiveness of reporting to the National Cyber
				Investigative Joint Task Force under section 3554.</text>
							</paragraph></subsection><subsection commented="no" id="ID7dd7c80c0ad14b3fa58bbdea7d8abed1"><enum>(f)</enum><text>Evaluations and
				any other descriptions of information systems under the authority and control
				of the Director of National Intelligence or of National Foreign Intelligence
				Programs systems under the authority and control of the Secretary of Defense
				shall be made available to Congress only through the appropriate oversight
				committees of Congress, in accordance with applicable laws.</text>
						</subsection><subsection id="IDab370a81ab35406ca7d95746d9f7e871"><enum>(g)</enum><paragraph commented="no" display-inline="yes-display-inline" id="id159A6FCD59C045319C285107B6FD5236"><enum>(1)</enum><text>In collaboration with
				the private sector and in coordination with the Director of the Office of
				Management and Budget, the National Institute of Standards and Technology, and
				the General Service Administration, the Director shall develop and implement
				policy, guidance, and regulations that cost effectively enhance the security of
				the Federal Government, including policy, guidance, and regulations
				that—</text>
								<subparagraph id="ID44f3913d1fe54189b49ec874297a144f"><enum>(A)</enum><text>to the extent
				practicable, standardize security requirements (also known as <quote>lock-down
				configurations</quote>) of commercial off-the-shelf products and services
				(including cloud products and services) purchased by the Federal
				Government;</text>
								</subparagraph><subparagraph id="ID61a2210cbe564c18b067e7471a18256e"><enum>(B)</enum><text>to the extent
				practicable, obtain products and services with security configuration baselines
				consistent with available security standards and configurations and guidelines
				developed by the National Institute of Standards and Technology;</text>
								</subparagraph><subparagraph id="ID9bc15c828db2488d846f741ce2b42b70"><enum>(C)</enum><text>incentivize
				agencies to purchase standard products and services through the General Service
				Administration in order to reduce the vulnerabilities and costs associated with
				custom products and services; and</text>
								</subparagraph><subparagraph id="id464E085E9F28471F8127F63A860A7870"><enum>(D)</enum><text>enable purchasing
				decisions to reasonably and appropriately account for significant supply chain
				security risks associated with any particular product or service.</text>
								</subparagraph></paragraph><paragraph id="IDb5155d7b9eed48199b762023403da677" indent="up1"><enum>(2)</enum><text>Not later than 180 days after the
				date of enactment of the <short-title>United States
				Information and Communications Enhancement Act of 2009</short-title>, and
				annually thereafter, the Director shall submit a report to Congress that
				includes—</text>
								<subparagraph id="id1319ACDDBAEC4662A81F82A391B2E7F7"><enum>(A)</enum><text>a description of the cost savings and
				security enhancements that can be achieved by using the purchasing power of the
				Federal Government; and</text>
								</subparagraph><subparagraph id="id0FFFD69846A84788A3654CBE4438D7B3"><enum>(B)</enum><text>recommendations for legislative or
				executive branch actions necessary to achieve such cost savings.</text>
								</subparagraph></paragraph></subsection></section><section id="ID866813ffd52941d2b70f99d216d1890e"><enum>3554.</enum><header>Agency
				responsibilities</header>
						<subsection id="IDb825c7e10e5a44138aeff4e91c7b094e"><enum>(a)</enum><text>The head of each
				agency shall—</text>
							<paragraph id="IDc7231b804a7748cb915abd33f3499455"><enum>(1)</enum><text>be responsible
				for—</text>
								<subparagraph id="ID394b0fd63ea94f5d82451fb4dd6d0917"><enum>(A)</enum><text>providing
				information security protections commensurate with the risk and magnitude of
				the harm resulting from unauthorized access, use, disclosure, disruption,
				modification, or destruction of—</text>
									<clause id="ID8f32ffcc8f4a4a728aebdb3811d78a65"><enum>(i)</enum><text>information
				collected or maintained by or on behalf of the agency; and</text>
									</clause><clause id="ID81b9237a3cd04c99b698e26bb7f15765"><enum>(ii)</enum><text>information
				systems used or operated by an agency or by a contractor of an agency or other
				organization on behalf of an agency;</text>
									</clause></subparagraph><subparagraph id="ID6f30efc6feb14cb8b24d2e4cbd1f2d74"><enum>(B)</enum><text>complying with
				the requirements of this subchapter and related policies, procedures,
				standards, and guidelines, including—</text>
									<clause id="ID5fbc0296278f44678d7361164915219b"><enum>(i)</enum><text>information
				security standards promulgated under section 3556;</text>
									</clause><clause id="IDc4d7aca76dd344d4aa1df6070c1c26d9"><enum>(ii)</enum><text>information
				security standards and guidelines for national security systems issued in
				accordance with law and as directed by the President; and</text>
									</clause><clause id="id7E24B3A19F6543FA8A0055F16C3AAB68"><enum>(iii)</enum><text>ensuring the
				standards implemented for information systems and national security systems
				under the agency head are complementary and uniform, to the extent practicable;
				and</text>
									</clause></subparagraph><subparagraph id="ID1e2d5cd542124e41bacbdd0b6d4a6c88"><enum>(C)</enum><text>ensuring that
				information security management processes are integrated with agency strategic
				and operational planning processes;</text>
								</subparagraph></paragraph><paragraph id="IDcdae870ed30740cb8db7def5d036c507"><enum>(2)</enum><text>ensure that
				senior agency officials provide information security for the information and
				information systems that support the operations and assets under their control,
				including through—</text>
								<subparagraph id="ID9a5918eb6a2d4987bd8422ccd581c68d"><enum>(A)</enum><text>assessing the
				risk and magnitude of the harm that could result from the unauthorized access,
				use, disclosure, disruption, modification, or destruction of such information
				or information systems;</text>
								</subparagraph><subparagraph id="IDbb62b33379e846a1af9cd0efc1a4f4e8"><enum>(B)</enum><text>determining the
				levels of information security appropriate to protect such information and
				information systems in accordance with standards promulgated under section
				3556, for information security classifications and related requirements;</text>
								</subparagraph><subparagraph id="ID36575d1ecbd34c32a62a55d1401c2f66"><enum>(C)</enum><text>implementing
				policies and procedures to cost effectively reduce risks to an acceptable
				level; and</text>
								</subparagraph><subparagraph id="ID5ffad6dc1b7c4eb28d303f5108805f09"><enum>(D)</enum><text>continuously
				testing and evaluating information security controls and techniques to ensure
				that they are effectively implemented;</text>
								</subparagraph></paragraph><paragraph id="IDb550fe98a924459289151c1b2c945f58"><enum>(3)</enum><text>delegate to an
				agency official designated as the Chief Information Security Officer the
				authority to ensure and enforce compliance with the requirements imposed on the
				agency under this subchapter, including—</text>
								<subparagraph id="ID3ab02975253f4139b3ff66d2b7599b32"><enum>(A)</enum><text>overseeing the
				establishment and maintenance of a security operations capability that on an
				automated and continuous basis can—</text>
									<clause id="ID0ac1501765ad4bdba08e715473d9efb0"><enum>(i)</enum><text>detect, report,
				respond to, contain, and mitigate incidents that impair adequate security of
				the information and information infrastructure, in accordance with policy
				provided by the Director, in consultation with the Chief Information Officers
				Council, and guidance from the National Institute of Standards and
				Technology;</text>
									</clause><clause id="ID25cf7c777dba41e2ba81c99bc45d7e6b"><enum>(ii)</enum><text>collaborate with
				the National Office for Cyberspace and appropriate public and private sector
				security operations centers to address incidents that impact the security of
				information and information infrastructure that extend beyond the control of
				the agency; and</text>
									</clause><clause id="ID7138fa1ff2ff4cdba95b4455d2129257"><enum>(iii)</enum><text>not later than
				24 hours after discovery of any incident described under subparagraph (A),
				unless otherwise directed by policy of the National Office for Cyberspace,
				provide notice to the appropriate security operations center, the National
				Cyber Investigative Joint Task Force, and inspector general;</text>
									</clause></subparagraph><subparagraph id="ID0b83f06269fc4c779dfc72ccf1d31abb"><enum>(B)</enum><text>collaborating
				with the Administrator for E-Government and the Chief Information Officer to
				establish, maintain, and update an enterprise network, system, storage, and
				security architecture framework documentation to be submitted quarterly to the
				National Office for Cyberspace and the appropriate security operations center,
				that includes—</text>
									<clause id="ID306f7c9bce0d427a8466732dbbf962a7"><enum>(i)</enum><text>documentation of
				how technical, managerial, and operational security controls are implemented
				throughout the agency’s information infrastructure; and</text>
									</clause><clause id="IDba0cbc9f8c414fe4a6998f9d2a80a993"><enum>(ii)</enum><text>documentation of
				how the controls described under subparagraph (A) maintain the appropriate
				level of confidentiality, integrity, and availability of information and
				information systems based on—</text>
										<subclause id="idEBC744CB5934480493F1BC9213965831"><enum>(I)</enum><text>the policy of the
				Director;</text>
										</subclause><subclause id="idF2D2C1CEA99F4104B959C4840D213CEE"><enum>(II)</enum><text>the National
				Institute of Standards and Technology guidance; and</text>
										</subclause><subclause id="id088D1B5D3528419798BB9B890EC444CC"><enum>(III)</enum><text>the Chief
				Information Officers Council recommended approaches;</text>
										</subclause></clause></subparagraph><subparagraph id="ID5c1668542e684112b6b747c22915f96c"><enum>(C)</enum><text>developing,
				maintaining, and overseeing an agency wide information security program as
				required by subsection (b);</text>
								</subparagraph><subparagraph id="IDa6676dc4bf2e4ceb941173f572238f5c"><enum>(D)</enum><text>developing,
				maintaining, and overseeing information security policies, procedures, and
				control techniques to address all applicable requirements, including those
				issued under sections 3553 and 3556;</text>
								</subparagraph><subparagraph id="IDeb1d8c1dde1a4896999e09cd2c019d72"><enum>(E)</enum><text>training and
				overseeing personnel with significant responsibilities for information security
				with respect to such responsibilities; and</text>
								</subparagraph><subparagraph id="IDa6487c064d674980860048b88f61a867"><enum>(F)</enum><text>assisting senior
				agency officials concerning their responsibilities under paragraph (2);</text>
								</subparagraph></paragraph><paragraph id="IDdc9162d839874acfb03ddf8d7c9e3612"><enum>(4)</enum><text>ensure that the
				agency has trained and cleared personnel sufficient to assist the agency in
				complying with the requirements of this subchapter and related policies,
				procedures, standards, and guidelines;</text>
							</paragraph><paragraph id="ID50d8b3cd8e3d489da34be10cd800eb9c"><enum>(5)</enum><text>ensure that the
				agency Chief Information Security Officer, in coordination with other senior
				agency officials, reports biannually to the agency head on the effectiveness of
				the agency information security program, including progress of remedial
				actions; and</text>
							</paragraph><paragraph id="IDcb64e8a6a1734160a444c87ab05b4170"><enum>(6)</enum><text>ensure that the
				Chief Information Security Officer possesses necessary qualifications,
				including education, professional certifications, training, experience, and the
				security clearance required to administer the functions described under this
				subchapter; and has information security duties as the primary duty of that
				official.</text>
							</paragraph></subsection><subsection id="IDfc756ca913e94be9a2a96a14a5348155"><enum>(b)</enum><text>Each agency shall
				develop, document, and implement an agencywide information security program,
				approved by the Director under section 3553(a)(5), to provide information
				security for the information and information systems that support the
				operations and assets of the agency, including those provided or managed by
				another agency, contractor, or other source, that includes—</text>
							<paragraph id="ID45ec11f304bc475184d85fdf73d9bc37"><enum>(1)</enum><text>periodic
				assessments—</text>
								<subparagraph id="idA1A77369E7974B7296EE6183346DE318"><enum>(A)</enum><text>of the risk and
				magnitude of the harm that could result from the unauthorized access, use,
				disclosure, disruption, modification, or destruction of information and
				information systems that support the operations and assets of the agency;
				and</text>
								</subparagraph><subparagraph id="id82BFC1A2DB8C4935B7B216144BE984B0"><enum>(B)</enum><text>that recommend a
				prioritized description of which data and applications should be removed or
				migrated to more secure networks or standards;</text>
								</subparagraph></paragraph><paragraph id="IDbac990bd74964872b645f070302981d2"><enum>(2)</enum><text>penetration tests
				commensurate with risk (as defined by the National Institute of Standards and
				Technology and the National Office for Cyberspace) for agency information
				systems;</text>
							</paragraph><paragraph id="ID48788e883297412da959a15e6b173ae6"><enum>(3)</enum><text>information
				security vulnerabilities are mitigated based on the risk posed to the
				agency;</text>
							</paragraph><paragraph id="IDf0ea14c9b21f4acf9ec5448d6da24b2c"><enum>(4)</enum><text>policies and
				procedures that—</text>
								<subparagraph id="ID0db06330fb0d4d4c94ac337c1986b3a3"><enum>(A)</enum><text>are based on the
				risk assessments required by paragraph (1);</text>
								</subparagraph><subparagraph id="ID31e689436ab54f4c9a096e2fcc27f741"><enum>(B)</enum><text>cost effectively
				reduce information security risks to an acceptable level;</text>
								</subparagraph><subparagraph id="IDbadaa804e7d74ee987877e7144629765"><enum>(C)</enum><text>ensure that
				information security is addressed throughout the life cycle of each agency
				information system; and</text>
								</subparagraph><subparagraph id="IDdc5de091d53a42049c2cbd8728cce125"><enum>(D)</enum><text>ensure compliance
				with—</text>
									<clause id="IDd1c5b75ad15b4520b487a559ca7d1ec7"><enum>(i)</enum><text>the requirements
				of this subchapter;</text>
									</clause><clause id="ID55d4e309b1474d5c98b8f0935b3d496c"><enum>(ii)</enum><text>policies and
				procedures as may be prescribed by the Director, and information security
				standards promulgated under section 3556;</text>
									</clause><clause id="IDac0c412f1ffd4680a5e9df68e40f3374"><enum>(iii)</enum><text>minimally
				acceptable system configuration requirements, as determined by the Director;
				and</text>
									</clause><clause id="ID057cf206a2f54b34af041d45ed74aeb5"><enum>(iv)</enum><text>any other
				applicable requirements, including standards and guidelines for national
				security systems issued in accordance with law and as directed by the
				President;</text>
									</clause></subparagraph></paragraph><paragraph id="ID86ebc91197ea415d8950e432371c5c47"><enum>(5)</enum><text>subordinate plans
				for providing adequate information security for networks, facilities, and
				systems or groups of information systems, as appropriate;</text>
							</paragraph><paragraph id="ID43d46ca086c74a15943386ecebc92c65"><enum>(6)</enum><text>role-based
				security awareness training to inform personnel with access to the agency
				network, including contractors and other users of information systems that
				support the operations and assets of the agency, of—</text>
								<subparagraph id="ID6c238c1c9d0642349c9f3dac22fe79b1"><enum>(A)</enum><text>information
				security risks associated with their activities; and</text>
								</subparagraph><subparagraph id="ID92dd96dfe1c84328929238d70aa88a7e"><enum>(B)</enum><text>their
				responsibilities in complying with agency policies and procedures designed to
				reduce these risks;</text>
								</subparagraph></paragraph><paragraph id="ID226adccb85d04b5dbc2e5d916e9957f5"><enum>(7)</enum><text>to the extent
				practicable, automated and continuous technical monitoring for testing, and
				evaluation of the effectiveness and compliance of information security
				policies, procedures, and practices, including—</text>
								<subparagraph id="ID1b4a97a4f499448182b4d6c86492c9e0"><enum>(A)</enum><text>management,
				operational, and technical controls of every information system identified in
				the inventory required under section 3505(b); and</text>
								</subparagraph><subparagraph id="ID74d454353abf47aca434adb8f22ea5a0"><enum>(B)</enum><text>management,
				operational, and technical controls relied on for an evaluation under section
				3555;</text>
								</subparagraph></paragraph><paragraph id="ID12ec163679d0459687e0635d7ca45ce6"><enum>(8)</enum><text>a process for
				planning, implementing, evaluating, and documenting remedial action to address
				any deficiencies in the information security policies, procedures, and
				practices of the agency;</text>
							</paragraph><paragraph id="ID3ddb44c312964f47a8d438cd5c433344"><enum>(9)</enum><text>to the extent
				practicable, continuous technical monitoring for detecting, reporting, and
				responding to security incidents, consistent with standards and guidelines
				issued by the Director, including—</text>
								<subparagraph id="IDe2937e5cf78b4b0985b9e5193b992678"><enum>(A)</enum><text>mitigating risks
				associated with such incidents before substantial damage is done;</text>
								</subparagraph><subparagraph id="IDccb05dce9de046e0a6d7fc26fe64faa9"><enum>(B)</enum><text>notifying and
				consulting with the appropriate security operations response center; and</text>
								</subparagraph><subparagraph id="ID528d35f567e344a1be84c1f91505ccea"><enum>(C)</enum><text>notifying and
				consulting with, as appropriate—</text>
									<clause id="IDe352bbbaa389457098ee8ed458a3a07d"><enum>(i)</enum><text>law enforcement
				agencies and relevant Offices of Inspectors General;</text>
									</clause><clause id="IDf738249fd47847deb0a4d0a6d6a02c3c"><enum>(ii)</enum><text>the National
				Office for Cyberspace; and</text>
									</clause><clause id="ID0c3545892cf746bd97870c617fb48ffe"><enum>(iii)</enum><text>any other
				agency or office, in accordance with law or as directed by the President;
				and</text>
									</clause></subparagraph></paragraph><paragraph id="ID34811b5d39604bc08ee79ec8d8a84614"><enum>(10)</enum><text>plans and
				procedures to ensure continuity of operations for information systems that
				support the operations and assets of the agency.</text>
							</paragraph></subsection><subsection id="ID12636ba0c80e472fb3067a4ce0a369bb"><enum>(c)</enum><text>Each agency
				shall—</text>
							<paragraph id="IDc4e6782f72fd4083a2f7904cca21bac9"><enum>(1)</enum><text>submit an annual
				report on the adequacy and effectiveness of information security policies,
				procedures, and practices, and compliance with the requirements of this
				subchapter, including compliance with each requirement of subsection (b)
				to—</text>
								<subparagraph id="idABCA01D96AF54B549A065DD9128799D3"><enum>(A)</enum><text>the National
				Office for Cyberspace;</text>
								</subparagraph><subparagraph id="id549A4E5096A4439F91D361CCF204DA57"><enum>(B)</enum><text>the Committee on
				Homeland Security and Governmental Affairs of the Senate;</text>
								</subparagraph><subparagraph id="id1153D46A02D742618D99EDBABBCA8E50"><enum>(C)</enum><text>the Committee on
				Commerce, Science, and Transportation of the Senate;</text>
								</subparagraph><subparagraph id="id4DBE009B328542DB85F48F85FC8E00E6"><enum>(D)</enum><text>the Committee on
				Government Oversight and Reform of the House of Representatives;</text>
								</subparagraph><subparagraph id="id5353841C6F084C909B0A26DDEF532634"><enum>(E)</enum><text>the Committee on
				Homeland Security of the House of Representatives;</text>
								</subparagraph><subparagraph id="idD63A0B73CB414FFC99CB5E5FFB9E7F65"><enum>(F)</enum><text>other appropriate
				authorization and appropriations committees of Congress; and</text>
								</subparagraph><subparagraph id="id099F2E65069E4E0EB95C8BED932BF829"><enum>(G)</enum><text>the Comptroller
				General.</text>
								</subparagraph></paragraph><paragraph id="ID7ac35019d9344b4dbdcd4f9acceb4040"><enum>(2)</enum><text>address the
				adequacy and effectiveness of information security policies, procedures, and
				practices in plans and reports relating to—</text>
								<subparagraph id="IDc907dc7948244a8899eab3c1691b6e8c"><enum>(A)</enum><text>annual agency
				budgets;</text>
								</subparagraph><subparagraph id="ID7f387cfe29c8403d8be8c636dfb01f4e"><enum>(B)</enum><text>information
				resources management of this subchapter;</text>
								</subparagraph><subparagraph id="ID91d2556d30ff42c580ef71837a9b7581"><enum>(C)</enum><text>information
				technology management under this chapter;</text>
								</subparagraph><subparagraph id="ID1b5b0927be3f4adaa98f940a954ee297"><enum>(D)</enum><text>program
				performance under sections 1105 and 1115 through 1119 of title 31, and sections
				2801 and 2805 of title 39;</text>
								</subparagraph><subparagraph id="IDf4f65d3ded6e40899d75978dffaf98a6"><enum>(E)</enum><text>financial
				management under chapter 9 of title 31, and the Chief Financial Officers Act of
				1990 (31 U.S.C. 501 note; Public Law 101–576) (and the amendments made by that
				Act);</text>
								</subparagraph><subparagraph id="ID1d45e9cc4f6a425586f731d4fa80d89b"><enum>(F)</enum><text>financial
				management systems under the Federal Financial Management Improvement Act (31
				U.S.C. 3512 note);</text>
								</subparagraph><subparagraph id="IDa66ce9711f9f4ffcb2dabe4dd0f62dc3"><enum>(G)</enum><text>internal
				accounting and administrative controls under section 3512 of title 31;
				and</text>
								</subparagraph><subparagraph id="id21413B8BA4B642E486EE1145DCD006B0"><enum>(H)</enum><text>performance
				ratings, salaries, and bonuses provided to the Chief Information Security
				Officer and supporting personnel taking into account program performance;
				and</text>
								</subparagraph></paragraph><paragraph id="ID02c4d5e45e574386b37a49bcb6b131af"><enum>(3)</enum><text>report any
				significant deficiency in a policy, procedure, or practice identified under
				paragraph (1) or (2)—</text>
								<subparagraph id="ID92864a0ee7074af492b87fdc9bb7e78b"><enum>(A)</enum><text>as a material
				weakness in reporting under section 3512 of title 31; and</text>
								</subparagraph><subparagraph id="ID1ea2108092a9489d904a8000c63b92b2"><enum>(B)</enum><text>if relating to
				financial management systems, as an instance of a lack of substantial
				compliance under the Federal Financial Management Improvement Act (31 U.S.C.
				3512 note).</text>
								</subparagraph></paragraph></subsection><subsection id="ID03a066f00ae049b080682088e6116b51"><enum>(d)</enum><paragraph commented="no" display-inline="yes-display-inline" id="idCB054D271FAA456081FCDE1A71076A4B"><enum>(1)</enum><text>In addition to the
				requirements of subsection (c), each agency, in consultation with the National
				Office for Cyberspace, shall include as part of the performance plan required
				under section 1115 of title 31 a description of—</text>
								<subparagraph id="idD1B3BFD29FEB4075B5D6F0465EDC1135" indent="up1"><enum>(A)</enum><text>the time periods; and</text>
								</subparagraph><subparagraph id="id7BC247B3E31F495A95920AE1C59CED77" indent="up1"><enum>(B)</enum><text>the resources, including budget,
				staffing, and training, that are necessary to implement the program required
				under subsection (b).</text>
								</subparagraph></paragraph><paragraph id="id136AA53094524105A38E81AA324B4D5D" indent="up1"><enum>(2)</enum><text>The description under paragraph (1)
				shall be based on the risk assessments required under subsection (b)(2)(1) and
				operational evaluations required under section 3553(d).</text>
							</paragraph></subsection><subsection id="ID05efacd7139741e9943488afdf1ec582"><enum>(e)</enum><text>Each agency shall
				provide the public with timely notice and opportunities for comment on proposed
				information security policies and procedures to the extent that such policies
				and procedures affect communication with the public.</text>
						</subsection></section><section id="ID6806476753984ca882c9957827821128"><enum>3555.</enum><header>Annual
				independent evaluation</header>
						<subsection id="ID68af5229eff9416fb2ac2b1e9b58c678"><enum>(a)</enum><paragraph commented="no" display-inline="yes-display-inline" id="id1D079F93D61447B8A7ED24D725D622CD"><enum>(1)</enum><text>Each year each agency
				shall have performed an independent evaluation of the information security
				program and practices of that agency to determine the effectiveness of such
				program and practices.</text>
							</paragraph><paragraph id="idED62B38B6FE648BFB6AC97A80198EACE" indent="up1"><enum>(2)</enum><text>Each evaluation under this section
				shall consist of—</text>
								<subparagraph id="id825EE838DA1D4F589D140FE528032A44"><enum>(A)</enum><text>testing of the effectiveness of
				information security policies, procedures, and practices of a representative
				subset of the information systems of the agency; and</text>
								</subparagraph><subparagraph id="id29C5A22EF4754B649D9B2A0123D3D394"><enum>(B)</enum><text>an assessment (made on the basis of
				the results of the testing) of compliance with—</text>
									<clause id="idDC223A1E35D041B1AEC2808F40E8303E"><enum>(i)</enum><text>the requirements of this
				subchapter; and</text>
									</clause><clause id="id6835BB359E0C4812847CFBD68973640E"><enum>(ii)</enum><text>related information security
				policies, procedures, standards, and guidelines.</text>
									</clause></subparagraph></paragraph></subsection><subsection id="ID5d37b87629224d2fb29ecf706668d001"><enum>(b)</enum><paragraph commented="no" display-inline="yes-display-inline" id="idC800D21D7C134999AE0409F5CA6EC6A1"><enum>(1)</enum><text>For each agency with an
				Inspector General appointed under the Inspector General Act of 1978 (5 U.S.C.
				App.) or any other law, the annual evaluation required by this section shall be
				performed by the Inspector General or by an independent external auditor, as
				determined by the Inspector General of the agency.</text>
							</paragraph><paragraph id="ID0f733e98a79b4393bfed3f36892c5050" indent="up1"><enum>(2)</enum><text>For each agency to which paragraph
				(1) does not apply, the head of the agency shall engage an independent external
				auditor to perform the evaluation.</text>
							</paragraph></subsection><subsection id="ID5f82831a4dbf4ff4a6dadee8e348ceb2"><enum>(c)</enum><text>The evaluation
				required by this section may be based in whole or in part on an audit,
				evaluation, or report relating to programs or practices of the applicable
				agency.</text>
						</subsection><subsection id="IDc155b67256be42a9b616524fcdb717e0"><enum>(d)</enum><text>Each year, not
				later than such date established by the Director, the head of each agency shall
				submit to the Director the results of the evaluation required under this
				section.</text>
						</subsection><subsection id="ID19a8d1f877534fab94177d265360abd4"><enum>(e)</enum><text>Agencies and
				evaluators shall take appropriate steps to ensure the protection of information
				which, if disclosed, may adversely affect information security. Such
				protections shall be commensurate with the risk and comply with all applicable
				laws and regulations.</text>
						</subsection><subsection id="ID0733f437bba348c69dfde81f6d0b42e9"><enum>(f)</enum><text>The Comptroller
				General shall—</text>
							<paragraph id="id3E83FF7A80AA4F158D8AF3D7E731D468"><enum>(1)</enum><text>not later than
				180 days after the date of enactment of the United States Communications and
				Information Enhancement Act of 2009 and after collaboration with the Director
				and the Inspectors General, develop and deliver standards for independent
				evaluations as required under this section that are risk-based and cost
				effective;</text>
							</paragraph><paragraph id="id19EF35EDBE2A4DF5BFAC64BB8F23A688"><enum>(2)</enum><text>periodically
				evaluate and report to Congress on—</text>
								<subparagraph id="ID8358c94a3a724e3da05177eea023257e"><enum>(A)</enum><text>the adequacy and
				effectiveness of agency information security policies and practices; and</text>
								</subparagraph><subparagraph id="ID99a34f47554346d3aa4045e8b57b532e"><enum>(B)</enum><text>the
				implementation of the requirements of this subchapter.</text>
								</subparagraph></paragraph></subsection></section><section id="IDb09b1a5db70840f8b8df0e233b7fad3f"><enum>3556.</enum><header>Responsibilities
				for Federal information systems standards</header>
						<subsection id="ID83bd36a1d607464c93ac2eb0b13df9a9"><enum>(a)</enum><paragraph commented="no" display-inline="yes-display-inline" id="id41C538F95A7347838BBB4800B5834204"><enum>(1)</enum><text>The Secretary of
				Commerce shall, on the basis of standards and guidelines developed by the
				National Institute of Standards and Technology under paragraphs (2) and (3) of
				section 20(a) of the National Institute of Standards and Technology Act (15
				U.S.C. 278g–3(a)), prescribe standards and guidelines pertaining to information
				systems, including national security systems.</text>
							</paragraph><paragraph id="idB9B56BD135BB48658273C021389B8E52" indent="up1"><enum>(2)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="id1EA467E196B24BFF853984073B48C5B5"><enum>(A)</enum><text>Standards prescribed
				under subsection (a)(1) shall include information security standards
				that—</text>
									<clause id="idAE80444C19BE44F79985E48253052A5E" indent="up1"><enum>(i)</enum><text>to the extent practicable, are unified
				with standards and guidelines developed for information systems and national
				security systems to ensure the adequacy and effectiveness of information
				security and information sharing;</text>
									</clause><clause id="id292321A632294F619A92EEB0C7312F59" indent="up1"><enum>(ii)</enum><text>provide minimum information security
				requirements as determined under section 20(b) of the National Institute of
				Standards and Technology Act (15 U.S.C. 278g–3(b)); and</text>
									</clause><clause id="idE1A01C6224B74AD1BA854EBA7F5EF779" indent="up1"><enum>(iii)</enum><text>are otherwise necessary to improve
				the security of information and information systems, including information
				stored by third parties on behalf of the Federal Government.</text>
									</clause></subparagraph><subparagraph id="id0DAF0763BDEC4675979F39DA0A41AAD1" indent="up1"><enum>(B)</enum><text>Information security standards
				described in subparagraph (A) shall be compulsory and binding.</text>
								</subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="ID93cf21437bbe42eda1752b3fe1949586"><enum>(b)</enum><text>The President may
				disapprove or modify the standards and guidelines referred to in subsection
				(a)(1) if the President determines such action to be in the public interest.
				The President's authority to disapprove or modify such standards and guidelines
				may not be delegated. Notice of such disapproval or modification shall be
				published promptly in the Federal Register. Upon receiving notice of such
				disapproval or modification, the Secretary of Commerce shall immediately
				rescind or modify such standards or guidelines as directed by the
				President.</text>
						</subsection><subsection id="IDf5345b868ced4c5cb45ba8774740f538"><enum>(c)</enum><text>To ensure fiscal
				and policy consistency, the Secretary shall exercise the authority conferred by
				this section subject to direction by the President and in coordination with the
				Director of the Office of Management and Budget and the National Office for
				Cyberspace.</text>
						</subsection><subsection id="ID10cc2495e3dd40d1a57ea83b7b0b6d54"><enum>(d)</enum><text>The National
				Office for Cyberspace and the head of an agency may employ standards for the
				cost effective information security for information systems within or under the
				supervision of that agency that are more stringent than the standards the
				Secretary prescribes under this section if the more stringent standards—</text>
							<paragraph id="ID2746724b920042fbbe889197bac0be05"><enum>(1)</enum><text>contain at least
				the applicable standards made compulsory and binding by the Secretary;
				and</text>
							</paragraph><paragraph id="IDe4e15b5ed9e947e5b4516196b95ed80d"><enum>(2)</enum><text>are otherwise
				consistent with policies and guidelines issued under section 3553.</text>
							</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="IDc962b17afd6e4f18b3719be1347a502b"><enum>(e)</enum><text>The decision by
				the Secretary regarding the promulgation of any standard under this section
				shall occur not later than 6 months after the submission of the proposed
				standard to the Secretary by the National Institute of Standards and
				Technology, as provided under section 20 of the National Institute of Standards
				and Technology Act (15 U.S.C.
				278g–3).</text>
						</subsection></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="IDd5b221c19f854a628f2f504bb1f0811d"><enum>4.</enum><header>Authority and
			 responsibility of the United States Computer Emergency Readiness Team in
			 relation to Federal agencies</header>
			<subsection id="id8F6F77DF77404E07A6752C5F89CA7DE5"><enum>(a)</enum><header>Definition</header><text>In
			 this section:</text>
				<paragraph id="id6E5FCE7B99B345AE9E9E362F803A4DD6"><enum>(1)</enum><text>The term
			 <term>agency</term> has the meaning given under section 3502(1) of title 44,
			 United States Code.</text>
				</paragraph><paragraph id="id50EAB02DE57B432EAF58DC7C36CB63FE"><enum>(2)</enum><text>The term
			 <term>US–CERT </term> means the United States Computer Emergency Readiness
			 Team.</text>
				</paragraph></subsection><subsection id="ID9bb8978d7fdc4c44bebd116ec57a5356"><enum>(b)</enum><header>Purposes</header><text>The
			 purposes of this section are to recognize that US–CERT—</text>
				<paragraph id="id1BBF60FE86FA497BBEF95C914C67DD29"><enum>(1)</enum><text>is charged with
			 providing response support and defense against cyber attacks for agencies and
			 information sharing and collaboration with State and local government,
			 industry, and international partners;</text>
				</paragraph><paragraph id="id1EB8F91533FB40D9A61032BAC2F8A4FA"><enum>(2)</enum><text>interacts with
			 agencies, industry, the research community, State and local governments, and
			 others to disseminate reasoned and actionable cyber security information to the
			 public;</text>
				</paragraph><paragraph id="id522A912DF6BE44018338DA087CC8AC5E"><enum>(3)</enum><text>provides a way
			 for citizens, businesses, and other institutions to communicate and coordinate
			 directly with the United States Government about cyber security; and</text>
				</paragraph><paragraph id="id119DC7808F7643E5B9F2EE9C574B14F4"><enum>(4)</enum><text>has continually
			 enhanced its ability to monitor, detect, and respond to information security
			 incidents that affect the Federal Government.</text>
				</paragraph></subsection><subsection id="idEE4C921A8CE348C19C3E6C8E679B7C47"><enum>(c)</enum><header>Coordination
			 with US–CERT</header><text>The head of each agency shall ensure that the Chief
			 Information Officer, Chief Information Security Officer, and security
			 operations centers under the direction of that agency head shall establish
			 policies, procedures, and guidance to effectively coordinate with the Director
			 of US–CERT in a timely fashion to detect, report, respond to, contain, and
			 mitigate incidents that impair adequate security of the information and
			 information infrastructure.</text>
			</subsection><subsection id="IDd03ddb0ed23b447aabf550696aaeba28"><enum>(d)</enum><header>Review and
			 approval</header><text>In coordination with the Administrator for Electronic
			 Government and Information Technology, the Director of the National Office for
			 Cyberspace shall review and approve the policies, procedures, and guidance
			 established in subparagraph (c) to ensure that US–CERT has the capability to
			 effectively and efficiently detect, correlate, respond to, contain, and
			 mitigate incidents that impair the adequate security of the information and
			 information infrastructure of more than 1 agency. To the extent practicable,
			 the capability shall be continuous and technically automated.</text>
			</subsection><subsection id="ID6d1866eeb6314c4da7eb0c872ad66f68"><enum>(e)</enum><header>Security
			 clearances; experts and consultants</header><text>Notwithstanding any provision
			 of law, regulation, rule, or policy to the contrary, the Director of US–CERT
			 may—</text>
				<paragraph id="ID49a1c9d0ff0c4f4cb3a2c2ebb37e012c"><enum>(1)</enum><text>direct the
			 sponsorship of the security clearances for Federal officers and employees
			 (including experts and consultants employed under section 3109) whose
			 responsibilities involve critical infrastructure in the interest of national
			 security; and</text>
				</paragraph><paragraph id="ID83cc4923d027439f93a25d452caf3909"><enum>(2)</enum><text>employ experts
			 and consultants under section 3109 for cyber security-related work.</text>
				</paragraph></subsection></section><section id="ID82ee36a3e96144c0be34b8026e256ad1"><enum>5.</enum><header>Authority and
			 responsibility of Departments not related to military functions</header>
			<subsection id="idE3A2B236830A4699B91F71608060EDEE"><enum>(a)</enum><header>Definitions</header><text>In
			 this section:</text>
				<paragraph id="id94BA56C3436C4D70A41953FB8C2414F2"><enum>(1)</enum><header>Agency</header><text>The
			 term <term>agency</term>—</text>
					<subparagraph id="id75603BCE00914EB1BF0B382AB6FAF8EE"><enum>(A)</enum><text>means—</text>
						<clause id="id025BBE3B11B64EE1BA7F7CCBFCEFAA15"><enum>(i)</enum><text>an
			 Executive department defined under section 101 of title 5, United States Code;
			 and</text>
						</clause><clause id="id21E3B58E089144C5AAA63852978FCB41"><enum>(ii)</enum><text>an
			 Executive agency that has multiple components which have separate and distinct
			 enterprise architectures; and</text>
						</clause></subparagraph><subparagraph id="id92A2B38023A443D09418F16E09BD5E9C"><enum>(B)</enum><text>shall not
			 include—</text>
						<clause id="idD11D11D45CA64F51974766687694C195"><enum>(i)</enum><text>the
			 Department of Defense; or</text>
						</clause><clause id="idE6934471811D4CC6B0EDB375B890CE13"><enum>(ii)</enum><text>any component of
			 an Executive agency that is performing any national security function,
			 including military intelligence.</text>
						</clause></subparagraph></paragraph><paragraph id="idA70796E981944A4389C1D6452969F546"><enum>(2)</enum><header>Executive
			 agency</header><text>The term <term>Executive agency</term> has the meaning
			 given under section 105 of title 5, United States Code.</text>
				</paragraph></subsection><subsection id="IDb43f861748b24ab1b376e10c836623e8"><enum>(b)</enum><header>Purpose</header><text>The
			 purpose of this section is to recognize that—</text>
				<paragraph id="id6CA5AB997F544B4284506C89E60B9B70"><enum>(1)</enum><text>agencies have
			 developed and maintained separate and distinct enterprise architectures that
			 inhibit the ability of an agency to ensure that components of that agency have
			 effectively implemented security policies, procedures, and practices;</text>
				</paragraph><paragraph id="ID500c70ca95e44f7d8c321478a902db83"><enum>(2)</enum><text>the separate and
			 distinct enterprise architectures have in many instances been at the detriment
			 of securing the agency information infrastructure (the civilian cyberspace) and
			 exposed that infrastructure to unnecessary risk for an extended period of time;
			 and</text>
				</paragraph><paragraph id="ID473b8df10f2e485e80d205d710739003"><enum>(3)</enum><text>a more uniform
			 agency enterprise architecture will be more efficient and effective for the
			 purposes of information sharing and ensuring the appropriate confidentiality,
			 integrity, and availability of information and information systems.</text>
				</paragraph></subsection><subsection id="IDcfe3b9c437024e5e88a326d48a0cb10c"><enum>(c)</enum><header>Agency
			 coordination</header>
				<paragraph id="id0BF2FC08AE934E60A94DB874CA53F433"><enum>(1)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the head of each agency shall ensure that components of that agency shall
			 establish an automated reporting mechanism that allows the Chief Information
			 Security Officer and security operations center at the total agency level to
			 implement and monitor the implementation of appropriate security policies,
			 procedures, and controls of agency components.</text>
				</paragraph><paragraph commented="no" id="ID6c0c8bfb6ff844219f81ec6782f7e83c"><enum>(2)</enum><header>Approval and
			 coordination</header><text>The activities conducted under paragraph (1) shall
			 be—</text>
					<subparagraph commented="no" id="id891304421FBC449AA070540E2E8D4587"><enum>(A)</enum><text>approved by the
			 Director of the National Office for Cyberspace; and</text>
					</subparagraph><subparagraph commented="no" id="id1FCA2F29BE82412D896153B5FF93FBD0"><enum>(B)</enum><text>to the extent
			 practicable, in coordination and complementary with activities—</text>
						<clause commented="no" id="id8103AD65442241EAA328C82FCF66B7E6"><enum>(i)</enum><text>described under
			 section 4; and</text>
						</clause><clause commented="no" id="id7DA1BA96C06540029490FA57901AA090"><enum>(ii)</enum><text>conducted by the
			 Administrator for E-Government and Information Technology.</text>
						</clause></subparagraph></paragraph></subsection></section><section id="id7A55CFF1CB1C44B79DA4E5E0C1FEE192"><enum>6.</enum><header>Technical and
			 conforming amendments</header>
			<subsection id="id8874545E20D9468CA71BFA87F6C2E99E"><enum>(a)</enum><header>Table of
			 sections</header><text>The table of sections for chapter 35 of title 44, United
			 States Code, is amended by striking the matter relating to subchapters II and
			 III and inserting the following:</text>
				<quoted-block display-inline="no-display-inline" id="idB0799A3074324879A261924087D0FE89" style="OLC">
					<toc>
						<toc-entry idref="idA46F1CEDCE84495DBA31C213EDF97874" level="subchapter">SUBCHAPTER II—Information security</toc-entry>
						<toc-entry idref="id73CCC29494D94776810170DDDCCD9936" level="section">Sec. 3551. Definitions.</toc-entry>
						<toc-entry idref="IDca3cbab08a154f99b1ab586c2143917e" level="section">Sec. 3552. National Office for Cyberspace.</toc-entry>
						<toc-entry idref="ID413f00e1044e4b46a11e63945ac07d04" level="section">Sec. 3553. Authority and functions of the National Office for
				Cyberspace.</toc-entry>
						<toc-entry idref="ID866813ffd52941d2b70f99d216d1890e" level="section">Sec. 3554. Agency responsibilities.</toc-entry>
						<toc-entry idref="ID6806476753984ca882c9957827821128" level="section">Sec. 3555. Annual independent evaluation.</toc-entry>
						<toc-entry idref="IDb09b1a5db70840f8b8df0e233b7fad3f" level="section">Sec. 3556. Responsibilities for Federal information systems
				standards.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="id89F18E2848864D4E9B13DFE2421446F8"><enum>(b)</enum><header>Other
			 references</header>
				<paragraph id="idEE2ECCBFE2E64C108ECFE4546EFCD84C"><enum>(1)</enum><text>Section
			 1001(c)(1)(A) of the Homeland Security Act of 2002 (6 U.S.C. 511(c)(1)(A)) is
			 amended by striking <quote>section 3532(3)</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
				</paragraph><paragraph id="id7598996942ED447DB7D8518CDE5AB33A"><enum>(2)</enum><text>Section
			 2222(j)(6) of title 10, United States Code, is amended by striking
			 <quote>section 3542(b)(2))</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
				</paragraph><paragraph id="id2C54F1D88EB145F8ACBD820FFE81EE07"><enum>(3)</enum><text>Section
			 2223(c)(3) of title 10, United States Code, is amended, by striking
			 <quote>section 3542(b)(2))</quote> and inserting <quote>section
			 3551(b)</quote>.</text>
				</paragraph><paragraph id="id48D85116BB2741F890C9DD833EF4A191"><enum>(4)</enum><text>Section 2315 of
			 title 10, United States Code, is amended by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3551(b)</quote>.</text>
				</paragraph><paragraph id="id495DD205D3D24D85B2460645BEA9893B"><enum>(5)</enum><text>Section 20(a)(2)
			 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is
			 amended by striking <quote>section 3532(b)(2)</quote> and inserting
			 <quote>section 3551(b)</quote>.</text>
				</paragraph><paragraph id="id9BD9C7253E3C48FFA45434F87967DC7A"><enum>(6)</enum><text>Section 8(d)(1)
			 of the Cyber Security Research and Development Act (15 U.S.C. 7406(d)(1)) is
			 amended by striking <quote>section 3534(b)</quote> and inserting <quote>section
			 3554(b)</quote>.</text>
				</paragraph></subsection></section><section id="idEC96875D2F934451BE4B7AFBCE56D99A"><enum>7.</enum><header>Effective
			 date</header><text display-inline="no-display-inline">This Act (including the
			 amendments made by this Act) shall take effect 30 days after the date of
			 enactment of this Act.</text>
		</section></legis-body>
</bill>
