<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HCE365AEE1DBE48079BA125A3C1D02A4B" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 1136</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20110316">March 16, 2011</action-date>
			<action-desc><sponsor name-id="L000559">Mr. Langevin</sponsor> (for
			 himself, <cosponsor name-id="B000208">Mr. Bartlett</cosponsor>,
			 <cosponsor name-id="R000576">Mr. Ruppersberger</cosponsor>,
			 <cosponsor name-id="S000030">Ms. Loretta Sanchez of California</cosponsor>,
			 <cosponsor name-id="A000210">Mr. Andrews</cosponsor>, and
			 <cosponsor name-id="D000327">Mr. Dicks</cosponsor>) introduced the following
			 bill; which was referred to the <committee-name committee-id="HGO00">Committee
			 on Oversight and Government Reform</committee-name>, and in addition to the
			 Committee on <committee-name committee-id="HHM00">Homeland
			 Security</committee-name>, for a period to be subsequently determined by the
			 Speaker, in each case for consideration of such provisions as fall within the
			 jurisdiction of the committee concerned</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend chapter 35 of title 44, United States Code, to
		  create the National Office for Cyberspace, to revise requirements relating to
		  Federal information security, and for other purposes.</official-title>
	</form>
	<legis-body id="HE1FD46A0FA164578A66427C3EF6B3CA8" style="OLC">
		<section id="H6530B84F66964E3EB40368E620C18A40" section-type="section-one"><enum>1.</enum><header>Short title</header>
			<subsection id="H9CB61CB1A1A54B9FB80751A9E3A3E067"><enum>(a)</enum><header>Short
			 title</header><text display-inline="yes-display-inline">This Act may be cited
			 as the <quote><short-title>Executive Cyberspace
			 Coordination Act of 2011</short-title></quote>.</text>
			</subsection><subsection commented="no" id="H3DE1B7E7E8214E7D988BF9C58C224073"><enum>(b)</enum><header>Table of
			 contents</header><text display-inline="yes-display-inline">The table of
			 contents for this Act is as follows:</text>
				<toc container-level="legis-body-container" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration">
					<toc-entry idref="H6530B84F66964E3EB40368E620C18A40" level="section">Sec. 1. Short title.</toc-entry>
					<toc-entry idref="HFD9BE589A08149D98702A555EDA490A3" level="title">Title I—Federal information security amendments</toc-entry>
					<toc-entry idref="H373A7BB5ADB741519CB384A9C1EE8C3D" level="section">Sec. 101. Coordination of Federal information
				policy.</toc-entry>
					<toc-entry idref="H838FDE1B3C284890942D8924A2B34138" level="section">Sec. 102. Information security acquisition
				requirements.</toc-entry>
					<toc-entry idref="H0D55C4D352274EA89A59F7511F1BFFAA" level="section">Sec. 103. Technical and conforming amendments.</toc-entry>
					<toc-entry idref="H4677CEF0080B46139B6A1E152A91D606" level="section">Sec. 104. Effective date.</toc-entry>
					<toc-entry idref="H8F786A8D0A804D62BC1D8711AA9DB7FF" level="title">Title II—Federal Chief Technology Officer</toc-entry>
					<toc-entry idref="H68941CFD901E4F208E7A96778C44A003" level="section">Sec. 201. Office of the Chief Technology Officer.</toc-entry>
					<toc-entry idref="HAC1B35212ABC434DAA23074AAB2526CF" level="title">Title III—Strengthening Cybersecurity for Critical
				Infrastructure</toc-entry>
					<toc-entry idref="H92F168B960414B28963DAD9086BDEAA7" level="section">Sec. 301. Definitions.</toc-entry>
					<toc-entry idref="H41F4B360DD9E46938B45BC0DFDC3C12F" level="section">Sec. 302. Authority of Secretary.</toc-entry>
				</toc>
			</subsection></section><title id="HFD9BE589A08149D98702A555EDA490A3"><enum>I</enum><header>Federal
			 information security amendments</header>
			<section id="H373A7BB5ADB741519CB384A9C1EE8C3D"><enum>101.</enum><header>Coordination of
			 Federal information policy</header><text display-inline="no-display-inline">Chapter 35 of title 44, United States Code,
			 is amended by striking subchapters II and III and inserting the
			 following:</text>
				<quoted-block display-inline="no-display-inline" id="H3F02B290A4F942589B4A2B0831DA6E53" style="USC">
					<subchapter id="HBB65D1E5EEBC4A95987D1DCD98A01260"><enum>II</enum><header>Information
				security</header>
						<section id="HFFA5EBBC5CAB45E3A8EB793073455D44"><enum>3551.</enum><header>Purposes</header><text display-inline="no-display-inline">The purposes of this subchapter are
				to—</text>
							<paragraph id="HE7A37DBE804B4851BB6390FF8337A907"><enum>(1)</enum><text>provide a
				comprehensive framework for ensuring the effectiveness of information security
				controls over information resources that support Federal operations and
				assets;</text>
							</paragraph><paragraph id="H3B4B1BA43A3E4ACF97222724EDFE9AE7"><enum>(2)</enum><text>recognize the
				highly networked nature of the current Federal computing environment and
				provide effective Governmentwide management and oversight of the related
				information security risks, including coordination of information security
				efforts throughout the civilian, national security, and law enforcement
				communities;</text>
							</paragraph><paragraph id="H001C9E3A75B74FDA9B70B0784C6DD005"><enum>(3)</enum><text>provide for
				development and maintenance of minimum controls required to protect Federal
				information and information infrastructure;</text>
							</paragraph><paragraph id="H2C37F491166C43F590AB400DC0108A5B"><enum>(4)</enum><text>provide a
				mechanism for improved oversight of Federal agency information security
				programs;</text>
							</paragraph><paragraph id="H089CD65278A34481A35E5E9BF3062043"><enum>(5)</enum><text>acknowledge that
				commercially developed information security products offer advanced, dynamic,
				robust, and effective information security solutions, reflecting market
				solutions for the protection of critical information infrastructures important
				to the national defense and economic security of the Nation that are designed,
				built, and operated by the private sector; and</text>
							</paragraph><paragraph id="HC6E07DB2C4814D6D9AFF8CC56C1A57B6"><enum>(6)</enum><text>recognize that the
				selection of specific technical hardware and software information security
				solutions should be left to individual agencies from among commercially
				developed products.</text>
							</paragraph></section><section display-inline="no-display-inline" id="HDDBE874C42CF46D9A135A8874456B23C" section-type="subsequent-section"><enum>3552.</enum><header>Definitions</header>
							<subsection id="HFAC0B36646B94FCD998BB69B5C5E685B"><enum>(a)</enum><header>Section 3502
				definitions</header><text>Except as provided under subsection (b), the
				definitions under section 3502 shall apply to this subchapter.</text>
							</subsection><subsection id="HE0C67CC8EAE64E159C2386DA96273AB5"><enum>(b)</enum><header>Additional
				definitions</header><text>In this subchapter:</text>
								<paragraph id="H36E820E53CD0444DB9FEB2CE112E49AF"><enum>(1)</enum><text>The term
				<term>adequate security</term> means security that complies with the
				regulations promulgated under section 3554 and the standards promulgated under
				section 3558.</text>
								</paragraph><paragraph id="H7FFC8EA17D53411692EFA9C244FAA4B5"><enum>(2)</enum><text>The term
				<term>incident</term> means an occurrence that actually or potentially
				jeopardizes the confidentiality, integrity, or availability of an information
				system, information infrastructure, or the information the system processes,
				stores, or transmits or that constitutes a violation or imminent threat of
				violation of security policies, security procedures, or acceptable use
				policies.</text>
								</paragraph><paragraph id="H6199D2DC5CC844F4B2279D981872A9E9"><enum>(3)</enum><text>The term
				<term>information infrastructure</term> means the underlying framework that
				information systems and assets rely on in processing, storing, or transmitting
				information electronically.</text>
								</paragraph><paragraph id="H910F48132540436B8A2FBC82E8C5FDD9"><enum>(4)</enum><text>The term
				<term>information security</term> means protecting information and information
				infrastructure from unauthorized access, use, disclosure, disruption,
				modification, or destruction in order to provide—</text>
									<subparagraph id="H4A5F75CAD2C843AC90933031CCC58283"><enum>(A)</enum><text>integrity, which
				means guarding against improper information modification or destruction, and
				includes ensuring information nonrepudiation and authenticity;</text>
									</subparagraph><subparagraph id="HDB077F8DDB08454C8988FB7123C16AD7"><enum>(B)</enum><text>confidentiality,
				which means preserving authorized restrictions on access and disclosure,
				including means for protecting personal privacy and proprietary information;</text>
									</subparagraph><subparagraph id="HAB85AC1DA25E415A93C6B5EAEA0D5E36"><enum>(C)</enum><text>availability,
				which means ensuring timely and reliable access to and use of information;
				and</text>
									</subparagraph><subparagraph id="H5F4F8679AACA42F0872429A7D2B1C6F5"><enum>(D)</enum><text display-inline="yes-display-inline">authentication, which means using digital
				credentials to assure the identity of users and validate access of such
				users.</text>
									</subparagraph></paragraph><paragraph id="H09FBC60CF0F246ACA30D13D08F4AA9FB"><enum>(5)</enum><text>The term
				<term>information technology</term> has the meaning given that term in section
				11101 of title 40.</text>
								</paragraph><paragraph id="HEA984A5DD0FF4458908B9C65ECAE0489"><enum>(6)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="H304A9EB87FB94ADEBB147AE9CDE29CB5"><enum>(A)</enum><text>The term <term>national
				security system</term> means any information infrastructure (including any
				telecommunications system) used or operated by an agency or by a contractor of
				an agency, or other organization on behalf of an agency—</text>
										<clause id="HAC3C4E1D1B914588AC1D0CED50B1FE2C" indent="up1"><enum>(i)</enum><text>the function, operation, or use of
				which—</text>
											<subclause id="H5BCFB24B05364B3FBA077D43069D3B34"><enum>(I)</enum><text>involves intelligence activities;</text>
											</subclause><subclause id="HA896BF2CDD0C492D99514F8E750A99EB"><enum>(II)</enum><text>involves cryptologic activities related
				to national security;</text>
											</subclause><subclause id="H2BAC665D24D6421C9625D5B8F5480275"><enum>(III)</enum><text>involves command and control of
				military forces;</text>
											</subclause><subclause id="H140A3F14A3484438BF106811BBC0DA07"><enum>(IV)</enum><text>involves equipment that is an integral
				part of a weapon or weapons system; or</text>
											</subclause><subclause id="HC3F8BDE1AB6146CC88B578E4B43F4D0A"><enum>(V)</enum><text>subject to subparagraph (B), is critical
				to the direct fulfillment of military or intelligence missions; or</text>
											</subclause></clause><clause id="HEA0DF161E1514DA5A4EBAAF1F667C1BC" indent="up1"><enum>(ii)</enum><text>is protected at all times by
				procedures established for information that have been specifically authorized
				under criteria established by an Executive order or an Act of Congress to be
				kept classified in the interest of national defense or foreign policy.</text>
										</clause></subparagraph><subparagraph id="HCCE06DDA3EA9455F8FB3DEB09158D548" indent="up1"><enum>(B)</enum><text>Subparagraph (A)(i)(V) does not
				include a system that is to be used for routine administrative and business
				applications (including payroll, finance, logistics, and personnel management
				applications).</text>
									</subparagraph></paragraph></subsection></section><section id="H431551C7121C4659A36AF151144607B3"><enum>3553.</enum><header>National
				Office for Cyberspace</header>
							<subsection id="HF887ACE3344947E3BC85378E38CE9FDF"><enum>(a)</enum><header>Establishment</header><text>There
				is established within the Executive Office of the President an office to be
				known as the National Office for Cyberspace.</text>
							</subsection><subsection id="H51F684512F2A4B4282D07851CAD52DCE"><enum>(b)</enum><header>Director</header>
								<paragraph id="HC36A0DD5725E4A6DB19B71AD1DA37EEB"><enum>(1)</enum><header>In
				general</header><text>There shall be at the head of the National Office for
				Cyberspace a Director, who shall be appointed by the President by and with the
				advice and consent of the Senate. The Director of the National Office for
				Cyberspace shall administer all functions designated to such Director under
				this subchapter and collaborate to the extent practicable with the heads of
				appropriate agencies, the private sector, and international partners. The
				Office shall serve as the principal office for coordinating issues relating to
				cyberspace, including achieving an assured, reliable, secure, and survivable
				information infrastructure and related capabilities for the Federal Government,
				while promoting national economic interests, security, and civil
				liberties.</text>
								</paragraph><paragraph id="HB164947EBD7343DE862D490F7139B9A5"><enum>(2)</enum><header>Basic
				pay</header><text display-inline="yes-display-inline">The Director of the
				National Office for Cyberspace shall be paid at the rate of basic pay for level
				III of the Executive Schedule.</text>
								</paragraph></subsection><subsection id="HC9BF8551A6FF4B12B5410258D9B67E10"><enum>(c)</enum><header>Staff</header><text display-inline="yes-display-inline">The Director of the National Office for
				Cyberspace may appoint and fix the pay of additional personnel as the Director
				considers appropriate.</text>
							</subsection><subsection id="H81203EE7F78A4FB690FF45F3B1AB64F6"><enum>(d)</enum><header>Experts and
				consultants</header><text display-inline="yes-display-inline">The Director of
				the National Office for Cyberspace may procure temporary and intermittent
				services under section 3109(b) of title 5.</text>
							</subsection></section><section id="H0848FCFF9F44438FA3F17EDA36941B3D"><enum>3554.</enum><header>Federal
				Cybersecurity Practice Board</header>
							<subsection id="H6539075E298341ED969C8E0F19DEB56A"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">Within the National Office for Cyberspace,
				there shall be established a board to be known as the <quote>Federal
				Cybersecurity Practice Board</quote> (in this section referred to as the
				<quote>Board</quote>).</text>
							</subsection><subsection id="HBECC1D739EF04AF083CC87FA22018858"><enum>(b)</enum><header>Members</header><text>The
				Board shall be chaired by the Director of the National Office for Cyberspace
				and consist of not more than 10 members, with at least one representative
				from—</text>
								<paragraph id="HD0487728535B48F0B40AE24C480554C6"><enum>(1)</enum><text>the Office of
				Management and Budget;</text>
								</paragraph><paragraph id="H472D55F70F544DD0B24D42EA2247D161"><enum>(2)</enum><text>civilian
				agencies;</text>
								</paragraph><paragraph id="H841E91B5E5764605A721732B0E6E8AFE"><enum>(3)</enum><text>the Department of
				Defense;</text>
								</paragraph><paragraph id="H26A045185FEC4F0FA417EA3A1459F659"><enum>(4)</enum><text>the Federal law
				enforcement community;</text>
								</paragraph><paragraph id="HD79766CAF52C48668CE46D73CA14A78F"><enum>(5)</enum><text>the Federal Chief
				Technology Office; and</text>
								</paragraph><paragraph id="H5B847869325E425EA42784BC53842422"><enum>(6)</enum><text>such additional
				military and civilian agencies as the Director considers appropriate.</text>
								</paragraph></subsection><subsection id="H313E09073439478E9EF07CCE9823F91F"><enum>(c)</enum><header>Responsibilities</header>
								<paragraph id="HC52415156C1E406D85AC92E51C65D538"><enum>(1)</enum><header>Development of
				policies and procedures</header><text>Subject to the authority, direction, and
				control of the Director of the National Office for Cyberspace, the Board shall
				be responsible for developing and periodically updating information security
				policies and procedures relating to the matters described in paragraph (2). In
				developing such policies and procedures, the Board shall require that all
				matters addressed in the policies and procedures are consistent, to the maximum
				extent practicable and in accordance with applicable law, among the civilian,
				military, intelligence, and law enforcement communities.</text>
								</paragraph><paragraph id="H63055142143F43EBB1ABC8ED3300CED7"><enum>(2)</enum><header>Specific matters
				covered in policies and procedures</header>
									<subparagraph id="HB07F5103AE284760A38B6DBF8D6406B7"><enum>(A)</enum><header>Minimum security
				controls</header><text>The Board shall be responsible for developing and
				periodically updating information security policies and procedures relating to
				minimum security controls for information technology, in order to—</text>
										<clause id="H7635CE6F3F9E4603817D1527BEB69AD2"><enum>(i)</enum><text>provide
				Governmentwide protection of Government-networked computers against common
				attacks; and</text>
										</clause><clause id="H41D01E1127674F26923DEE424D70FC39"><enum>(ii)</enum><text>provide
				agencywide protection against threats, vulnerabilities, and other risks to the
				information infrastructure within individual agencies.</text>
										</clause></subparagraph><subparagraph id="HA0ADF34418524730BFE92F321371D167"><enum>(B)</enum><header>Measures of
				effectiveness</header><text display-inline="yes-display-inline">The Board shall
				be responsible for developing and periodically updating information security
				policies and procedures relating to measurements needed to assess the
				effectiveness of the minimum security controls referred to in
				<internal-xref idref="HB07F5103AE284760A38B6DBF8D6406B7" legis-path="3554.(c)(2)(A)">subparagraph (A)</internal-xref>. Such measurements
				shall include a risk scoring system to evaluate risk to information security
				both Governmentwide and within contractors of the Federal Government.</text>
									</subparagraph><subparagraph id="H40B060B7A0A140BC8C02CA53E68BC925"><enum>(C)</enum><header>Products and
				services</header><text display-inline="yes-display-inline">The Board shall be
				responsible for developing and periodically updating information security
				policies, procedures, and minimum security standards relating to criteria for
				products and services to be used in agency information systems and information
				infrastructure that will meet the minimum security controls referred to in
				<internal-xref idref="HB07F5103AE284760A38B6DBF8D6406B7" legis-path="3554.(c)(2)(A)">subparagraph (A)</internal-xref>. In carrying out
				this subparagraph, the Board shall act in consultation with the Office of
				Management and Budget and the General Services Administration.</text>
									</subparagraph><subparagraph id="H9CB8D38D8E6C46F1AA68EF5B571ABD42"><enum>(D)</enum><header>Remedies</header><text display-inline="yes-display-inline">The Board shall be responsible for
				developing and periodically updating information security policies and
				procedures relating to methods for providing remedies for security deficiencies
				identified in agency information infrastructure.</text>
									</subparagraph></paragraph><paragraph id="H2F97C812DD83444499315E931714FCAF"><enum>(3)</enum><header>Additional
				considerations</header><text display-inline="yes-display-inline">The Board
				shall also consider—</text>
									<subparagraph id="H3594E29694BF4AC484D250D1ECC76504"><enum>(A)</enum><text display-inline="yes-display-inline">opportunities to engage with the
				international community to set policies, principles, training, standards, or
				guidelines for information security;</text>
									</subparagraph><subparagraph id="H981B4C1058FC46B09AEAA45CCAFA0220"><enum>(B)</enum><text>opportunities to
				work with agencies and industry partners to increase information sharing and
				policy coordination efforts in order to reduce vulnerabilities in the national
				information infrastructure; and</text>
									</subparagraph><subparagraph id="H9918F469E5F94429A27374F220480618"><enum>(C)</enum><text>options necessary
				to encourage and maintain accountability of any agency, or senior agency
				official, for efforts to secure the information infrastructure of such
				agency.</text>
									</subparagraph></paragraph><paragraph id="HDB5CD29A2B6043C1918410BD847CF811"><enum>(4)</enum><header>Relationship to
				other standards</header><text>The policies and procedures developed under
				<internal-xref idref="HC52415156C1E406D85AC92E51C65D538" legis-path="3554.(c)(1)">paragraph (1)</internal-xref> are supplemental to the
				standards promulgated by the Director of the National Office for Cyberspace
				under section 3558.</text>
								</paragraph><paragraph id="H455E685B65F04469AC2C6E9ACF42DC10"><enum>(5)</enum><header>Recommendations
				for regulations</header><text>The Board shall be responsible for making
				recommendations to the Director of the National Office for Cyberspace on
				regulations to carry out the policies and procedures developed by the Board
				under
				<internal-xref idref="HC52415156C1E406D85AC92E51C65D538" legis-path="3554.(c)(1)">paragraph (1)</internal-xref>.</text>
								</paragraph></subsection><subsection id="HA0FFBEC5A0284B4DB6C6C984DB5CB449"><enum>(d)</enum><header>Regulations</header><text>The
				Director of the National Office for Cyberspace, in consultation with the
				Director of the Office of Management and the Administrator of General Services,
				shall promulgate and periodically update regulations to carry out the policies
				and procedures developed by the Board under subsection (c).</text>
							</subsection><subsection id="H754035EC39724DD4A4F2F178938B8E9C"><enum>(e)</enum><header>Annual
				Report</header><text>The Director of the National Office for Cyberspace shall
				provide to Congress a report containing a summary of agency progress in
				implementing the regulations promulgated under this section as part of the
				annual report to Congress required under section 3555(a)(8).</text>
							</subsection><subsection id="H022069E0775144DA862972FC3A1CD166"><enum>(f)</enum><header>No disclosure by
				Board required</header><text display-inline="yes-display-inline">The Board is
				not required to disclose under section 552 of title 5 information submitted by
				agencies to the Board regarding threats, vulnerabilities, and risks.</text>
							</subsection></section><section display-inline="no-display-inline" id="HB218F6E4931E4C4A8B8E367394716929"><enum>3555.</enum><header>Authority and
				functions of the Director of the National Office for Cyberspace</header>
							<subsection id="HCD88C29BA69F441B98ECE15E8AF47784"><enum>(a)</enum><header>In
				General</header><text>The Director of the National Office for Cyberspace shall
				oversee agency information security policies and practices, including—</text>
								<paragraph id="H9EA714D96A88413FB3F925AFE4AD42B1"><enum>(1)</enum><text>developing and
				overseeing the implementation of policies, principles, standards, and
				guidelines on information security, including through ensuring timely agency
				adoption of and compliance with standards promulgated under section
				3558;</text>
								</paragraph><paragraph id="H685D024C9707478FAB87A86C32D9118A"><enum>(2)</enum><text>requiring
				agencies, consistent with the standards promulgated under section 3558 and
				other requirements of this subchapter, to identify and provide information
				security protections commensurate with the risk and magnitude of the harm
				resulting from the unauthorized access, use, disclosure, disruption,
				modification, or destruction of—</text>
									<subparagraph id="H9930B790BFCE44658A505694A3B8C61F"><enum>(A)</enum><text>information
				collected or maintained by or on behalf of an agency; or</text>
									</subparagraph><subparagraph id="H8AC640DF583943238811D6B446A16182"><enum>(B)</enum><text>information
				infrastructure used or operated by an agency or by a contractor of an agency or
				other organization on behalf of an agency;</text>
									</subparagraph></paragraph><paragraph id="HDD7EA250D77B4344880E27D5584AE30C"><enum>(3)</enum><text>coordinating the
				development of standards and guidelines under section 20 of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3) with agencies and
				offices operating or exercising control of national security systems (including
				the National Security Agency) to assure, to the maximum extent feasible, that
				such standards and guidelines are complementary with standards and guidelines
				developed for national security systems;</text>
								</paragraph><paragraph id="HCBF27016005D479780144EA7475747E2"><enum>(4)</enum><text>overseeing agency
				compliance with the requirements of this subchapter, including through any
				authorized action under section 11303 of title 40, to enforce accountability
				for compliance with such requirements;</text>
								</paragraph><paragraph id="H92E32E7F5B6145EC9B47F365CB0AD029"><enum>(5)</enum><text>reviewing at least
				annually, and approving or disapproving, agency information security programs
				required under section 3556(b);</text>
								</paragraph><paragraph id="H6FB57CE20A7C4018A607033B83AA972B"><enum>(6)</enum><text>coordinating
				information security policies and procedures of the Federal Government with
				related information resources management policies and procedures on the
				security and resiliency of cyberspace;</text>
								</paragraph><paragraph id="HAF0AADDEDFC54EDC8449028B40CC7E4C"><enum>(7)</enum><text>overseeing the
				operation of the Federal information security incident center required under
				section 3559;</text>
								</paragraph><paragraph id="H58A7544191AC45B8A62275679DB5F62B"><enum>(8)</enum><text>reporting to
				Congress no later than March 1 of each year on agency compliance with the
				requirements of this subchapter, including—</text>
									<subparagraph id="HF3756A6FCAE84E1D911173FE55ECD041"><enum>(A)</enum><text>a summary of the
				findings of audits required by section 3557;</text>
									</subparagraph><subparagraph id="H953184A66DD3487389ADE3E056760F80"><enum>(B)</enum><text>an assessment of
				the development, promulgation, and adoption of, and compliance with, standards
				developed under section 20 of the National Institute of Standards and
				Technology Act (15 U.S.C. 278g–3) and promulgated under section 3558;</text>
									</subparagraph><subparagraph id="H7AED3F9744E34F5D847FA4A87B9972E7"><enum>(C)</enum><text>significant
				deficiencies in agency information security practices;</text>
									</subparagraph><subparagraph id="H4148D3F05A2A476EA737CB9801CAA9B1"><enum>(D)</enum><text>planned remedial
				action to address such deficiencies; and</text>
									</subparagraph><subparagraph id="HA6030EA649DF494E9707881C6E722875"><enum>(E)</enum><text>a summary of, and
				the views of the Director of the National Office for Cyberspace on, the report
				prepared by the National Institute of Standards and Technology under section
				20(d)(10) of the National Institute of Standards and Technology Act (15 U.S.C.
				278g–3);</text>
									</subparagraph></paragraph><paragraph id="H8BBE988207884751A30FE7EA3D48F27A"><enum>(9)</enum><text display-inline="yes-display-inline">coordinating the defense of information
				infrastructure operated by agencies in the case of a large-scale attack on
				information infrastructure, as determined by the Director;</text>
								</paragraph><paragraph commented="no" id="H09E99A7BB3AD4BA680FA6221B8AF1BD2"><enum>(10)</enum><text display-inline="yes-display-inline">establishing a national strategy not later
				than 120 days after the date of the enactment of this section;</text>
								</paragraph><paragraph id="H8A637CCAEFFC4EC392A31B1D11C32180"><enum>(11)</enum><text display-inline="yes-display-inline">coordinating information security training
				for Federal employees with the Office of Personnel Management;</text>
								</paragraph><paragraph commented="no" id="H4C464A368DEA45719919CE9F5C44007D"><enum>(12)</enum><text display-inline="yes-display-inline">ensuring the adequacy of protections for
				privacy and civil liberties in carrying out the responsibilities of the
				Director under this subchapter;</text>
								</paragraph><paragraph commented="no" id="HF7B27C37A1C141D6907FF41BA5973B17"><enum>(13)</enum><text display-inline="yes-display-inline">making recommendations that the Director
				determines are necessary to ensure risk-based security of the Federal
				information infrastructure and information infrastructure that is owned,
				operated, controlled, or licensed for use by, or on behalf of, the Department
				of Defense, a military department, or another element of the intelligence
				community to—</text>
									<subparagraph commented="no" id="HAF1B12BC02454E1D946C428CFE6B9203"><enum>(A)</enum><text>the Director of
				the Office of Management and Budget;</text>
									</subparagraph><subparagraph commented="no" id="H47513BB1E1634520A06E849E80FD555F"><enum>(B)</enum><text>the head of an
				agency; or</text>
									</subparagraph><subparagraph commented="no" id="H26AC5C79BA7346DDB5A5C281F5679DD5"><enum>(C)</enum><text>to Congress with
				regard to the reprogramming of funds;</text>
									</subparagraph></paragraph><paragraph commented="no" id="H3D8AA0B954D948B3B2C6C0BF90E17A18"><enum>(14)</enum><text>ensuring, in
				consultation with the Administrator of the Office of Information and Regulatory
				Affairs, that the efforts of agencies relating to the development of
				regulations, rules, requirements, or other actions applicable to the national
				information infrastructure are complementary;</text>
								</paragraph><paragraph commented="no" id="H21B18EC3F1BC40CCAC0139120A99E77F"><enum>(15)</enum><text>when directed by
				the President, carrying out the responsibilities for national security and
				emergency preparedness communications described in section 706 of the
				Communications Act of 1934 (47 U.S.C. 606) to ensure integration and
				coordination; and</text>
								</paragraph><paragraph commented="no" id="H8BFDF0E69E854C76B5899B62B75891B8"><enum>(16)</enum><text>as assigned by
				the President, other duties relating to the security and resiliency of
				cyberspace.</text>
								</paragraph></subsection><subsection commented="no" id="HA53D41F721674E10BF0E4895EA330E6C"><enum>(b)</enum><header>Recruitment
				program</header><text display-inline="yes-display-inline">Not later than 1 year
				after appointment, the Director of the National Office for Cyberspace shall
				establish a national program to conduct competitions and challenges that
				instruct United States students in cybersecurity education and computer
				literacy.</text>
							</subsection><subsection id="HB44E35608C2D4C1C8EF81ACD74DBA6C0"><enum>(c)</enum><header>Budget oversight
				and reporting</header><paragraph commented="no" display-inline="yes-display-inline" id="HED9C689C429C4DA4BB14D6B55DD7C9A4"><enum>(1)</enum><text display-inline="yes-display-inline">The head of each agency shall submit to the
				Director of the National Office for Cyberspace a budget each year for the
				following fiscal year relating to the protection of information infrastructure
				for such agency, by a date determined by the Director that is before the
				submission of such budget by the head of the agency to the Office of Management
				and Budget.</text>
								</paragraph><paragraph id="HFC7FA53A6D3A4E5DB0364E240532EA67" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">The Director shall review and offer a
				non-binding approval or disapproval of each agency’s annual budget to each such
				agency before the submission of such budget by the head of the agency to the
				Office of Management and Budget.</text>
								</paragraph><paragraph id="H45AA52EE0D89467287BC4FAAFE16795E" indent="up1"><enum>(3)</enum><text>If the Director offers a non-binding
				disapproval of an agency’s budget, the Director shall transmit recommendations
				to the head of such agency for strengthening its proposed budget with regard to
				the protection of such agency’s information infrastructure.</text>
								</paragraph><paragraph id="H9CEEA0144AD145D29B15CC9A01933880" indent="up1"><enum>(4)</enum><text display-inline="yes-display-inline">Each budget submitted by the head of an
				agency pursuant to paragraph (1) shall include—</text>
									<subparagraph id="HB2619FE4BFAF46058D6D53BD2B6E338B"><enum>(A)</enum><text>a review of any threats to information
				technology for such agency;</text>
									</subparagraph><subparagraph id="HDAB91538F1B8455AA58AEC7E26812FDB"><enum>(B)</enum><text>a plan to secure the information
				infrastructure for such agency based on threats to information technology,
				using the National Institute of Standards and Technology guidelines and
				recommendations;</text>
									</subparagraph><subparagraph id="H5A9CE680ABC04D2C88D989F2BDF4B6D9"><enum>(C)</enum><text>a review of compliance by such agency
				with any previous year plan described in subparagraph (B); and</text>
									</subparagraph><subparagraph id="H5BE8334049A74C95B497B5120954BCA3"><enum>(D)</enum><text>a report on the development of the
				credentialing process to enable secure authentication of identity and
				authorization for access to the information infrastructure of such
				agency.</text>
									</subparagraph></paragraph><paragraph id="HE8F85FAA27BE419B89562339AB396141" indent="up1"><enum>(5)</enum><text display-inline="yes-display-inline">The Director of the National Office for
				Cyberspace may recommend to the President monetary penalties or incentives
				necessary to encourage and maintain accountability of any agency, or senior
				agency official, for efforts to secure the information infrastructure of such
				agency.</text>
								</paragraph></subsection></section><section display-inline="no-display-inline" id="HE285EC7C6BA6491DA5E7CC617707D4E9" section-type="subsequent-section"><enum>3556.</enum><header>Agency
				responsibilities</header>
							<subsection id="H68101AE5B3D74A6389E0592FED3E7C63"><enum>(a)</enum><header>In
				general</header><text display-inline="yes-display-inline">The head of each
				agency shall—</text>
								<paragraph id="H0EF0ED09F34A4F529D32A78AA1DA2FA0"><enum>(1)</enum><text>be responsible
				for—</text>
									<subparagraph id="HD5C4B2C51CFC4B5CB5D412BB2BA3E3BA"><enum>(A)</enum><text>providing
				information security protections commensurate with the risk and magnitude of
				the harm resulting from unauthorized access, use, disclosure, disruption,
				modification, or destruction of—</text>
										<clause id="HD402003BF4E244EA8BA75AB1D4AB330F"><enum>(i)</enum><text>information
				collected or maintained by or on behalf of the agency; and</text>
										</clause><clause id="HB664FF5FB2E643FB97ED7FCC7F8957AD"><enum>(ii)</enum><text display-inline="yes-display-inline">information infrastructure used or operated
				by an agency or by a contractor of an agency or other organization on behalf of
				an agency;</text>
										</clause></subparagraph><subparagraph id="H948C546E7C0047B9AA60C634CA701E06"><enum>(B)</enum><text>complying with the
				requirements of this subchapter and related policies, procedures, standards,
				and guidelines, including—</text>
										<clause id="H7CCA4ACA39CB4C3C9964CEE655B9E34D"><enum>(i)</enum><text>the regulations
				promulgated under section 3554 and the information security standards
				promulgated under section 3558;</text>
										</clause><clause id="H5977025608B84953B837FAC8679866B3"><enum>(ii)</enum><text>information
				security standards and guidelines for national security systems issued in
				accordance with law and as directed by the President; and</text>
										</clause><clause id="H31FE57A607C447508A3D6F7C821740EA"><enum>(iii)</enum><text display-inline="yes-display-inline">ensuring the standards implemented for
				information infrastructure and national security systems under the agency head
				are complementary and uniform, to the extent practicable; and</text>
										</clause></subparagraph><subparagraph id="H142E8F3C1ECA453E9C789EB810E0EE92"><enum>(C)</enum><text>ensuring that
				information security management processes are integrated with agency strategic
				and operational planning processes;</text>
									</subparagraph></paragraph><paragraph id="H579C46FD2C4748E28D46BFA465EE8F7D"><enum>(2)</enum><text display-inline="yes-display-inline">ensure that senior agency officials provide
				information security for the information and information infrastructure that
				support the operations and assets under their control, including
				through—</text>
									<subparagraph id="HF3D35E855CD94A4E9AF94134E88A0AEF"><enum>(A)</enum><text display-inline="yes-display-inline">assessing the risk and magnitude of the
				harm that could result from the unauthorized access, use, disclosure,
				disruption, modification, or destruction of such information or information
				infrastructure;</text>
									</subparagraph><subparagraph id="HD79AA8C41FB34B5D93C7C77A81814375"><enum>(B)</enum><text display-inline="yes-display-inline">determining the levels of information
				security appropriate to protect such information and information infrastructure
				in accordance with regulations promulgated under section 3554 and standards
				promulgated under section 3558, for information security classifications and
				related requirements;</text>
									</subparagraph><subparagraph id="H2B34070E806C48C7A1513BF9153EAEC5"><enum>(C)</enum><text>implementing
				policies and procedures to cost effectively reduce risks to an acceptable
				level; and</text>
									</subparagraph><subparagraph id="HC6AE56F2BC9B47C6BDDCF6DD0E970AA5"><enum>(D)</enum><text>continuously
				testing and evaluating information security controls and techniques to ensure
				that they are effectively implemented;</text>
									</subparagraph></paragraph><paragraph id="HF420B4B27F394FDAA3F0E482A0B93735"><enum>(3)</enum><text display-inline="yes-display-inline">delegate to an agency official, designated
				as the <quote>Chief Information Security Officer</quote>, under the authority
				of the agency Chief Information Officer the responsibility to oversee agency
				information security and the authority to ensure and enforce compliance with
				the requirements imposed on the agency under this subchapter, including—</text>
									<subparagraph id="H2E454752777244F48CB2ACE1580DEE26"><enum>(A)</enum><text>overseeing the
				establishment and maintenance of a security operations capability on an
				automated and continuous basis that can—</text>
										<clause id="HDC42187A97D14C6088936E372AA5FBFF"><enum>(i)</enum><text display-inline="yes-display-inline">assess the state of compliance of all
				networks and systems with prescribed controls issued pursuant to section 3558
				and report immediately any variance therefrom and, where appropriate and with
				the approval of the agency Chief Information Officer, shut down systems that
				are found to be non-compliant;</text>
										</clause><clause id="HE8126B7DCBD942D399219D9FD8E529B1"><enum>(ii)</enum><text>detect, report,
				respond to, contain, and mitigate incidents that impair adequate security of
				the information and information infrastructure, in accordance with policy
				provided by the Director of the National Office for Cyberspace, in consultation
				with the Chief Information Officers Council, and guidance from the National
				Institute of Standards and Technology;</text>
										</clause><clause id="H396F0E24B0EA44EC82D4E446D0C4B5B6"><enum>(iii)</enum><text>collaborate with
				the National Office for Cyberspace and appropriate public and private sector
				security operations centers to address incidents that impact the security of
				information and information infrastructure that extend beyond the control of
				the agency; and</text>
										</clause><clause id="HE1096161378448C987D8F376E22DFCA3"><enum>(iv)</enum><text>not later than 24
				hours after discovery of any incident described under subparagraph (A)(ii),
				unless otherwise directed by policy of the National Office for Cyberspace,
				provide notice to the appropriate security operations center, the National
				Cyber Investigative Joint Task Force, and the Inspector General of the
				agency;</text>
										</clause></subparagraph><subparagraph display-inline="no-display-inline" id="H5B4A6D6E609F454F9AD44BD210B16AD1"><enum>(B)</enum><text>developing,
				maintaining, and overseeing an agency wide information security program as
				required by subsection (b);</text>
									</subparagraph><subparagraph id="HA93FEF65053C4526950F52761E99D25C"><enum>(C)</enum><text>developing,
				maintaining, and overseeing information security policies, procedures, and
				control techniques to address all applicable requirements, including those
				issued under sections 3555 and 3558;</text>
									</subparagraph><subparagraph id="HDD601CE6004E402FAB65D5CFB1A8E456"><enum>(D)</enum><text>training and
				overseeing personnel with significant responsibilities for information security
				with respect to such responsibilities; and</text>
									</subparagraph><subparagraph id="H68138E04AB16491F9DBF5D43044C594A"><enum>(E)</enum><text>assisting senior
				agency officials concerning their responsibilities under paragraph (2);</text>
									</subparagraph></paragraph><paragraph display-inline="no-display-inline" id="HAB2DF8CC75014184B2275CA7C7802DBD"><enum>(4)</enum><text>ensure that the
				agency has trained and cleared personnel sufficient to assist the agency in
				complying with the requirements of this subchapter and related policies,
				procedures, standards, and guidelines;</text>
								</paragraph><paragraph id="H016DB0CB5488491A865D772516F2D11C"><enum>(5)</enum><text>ensure that the
				Chief Information Security Officer, in coordination with other senior agency
				officials, reports biannually to the agency head on the effectiveness of the
				agency information security program, including progress of remedial actions;
				and</text>
								</paragraph><paragraph id="H33FCF33C799040689A77A324A9BC14F1"><enum>(6)</enum><text display-inline="yes-display-inline">ensure that the Chief Information Security
				Officer possesses necessary qualifications, including education, professional
				certifications, training, experience, and the security clearance required to
				administer the functions described under this subchapter; and has information
				security duties as the primary duty of that official.</text>
								</paragraph></subsection><subsection display-inline="no-display-inline" id="HB2ECDF0430414C558A6AF72582E02D18"><enum>(b)</enum><header>Agency
				program</header><text display-inline="yes-display-inline">Each agency shall
				develop, document, and implement an agencywide information security program,
				approved by the Director of the National Office for Cyberspace under section
				3555(a)(5), to provide information security for the information and information
				infrastructure that support the operations and assets of the agency, including
				those provided or managed by another agency, contractor, or other source, that
				includes—</text>
								<paragraph id="H379869AB61BF4D87A38F2336B7BE92CC"><enum>(1)</enum><text display-inline="yes-display-inline">continuous automated technical monitoring
				of information infrastructure used or operated by an agency or by a contractor
				of an agency or other organization on behalf of an agency to assure conformance
				with regulations promulgated under section 3554 and standards promulgated under
				section 3558;</text>
								</paragraph><paragraph id="H59FB1D0A133E4B34A4FE1DD29B662A4F"><enum>(2)</enum><text display-inline="yes-display-inline">testing of the effectiveness of security
				controls that are commensurate with risk (as defined by the National Institute
				of Standards and Technology and the National Office for Cyberspace) for agency
				information infrastructure;</text>
								</paragraph><paragraph id="H39E77B3E8B0148278A9648F467AA4702"><enum>(3)</enum><text>policies and
				procedures that—</text>
									<subparagraph id="H09F52A61B96A4F6B8BB9A81223E0E39A"><enum>(A)</enum><text display-inline="yes-display-inline">mitigate and remediate, to the extent
				practicable, information security vulnerabilities based on the risk posed to
				the agency;</text>
									</subparagraph><subparagraph id="H92BE2CFC95654664AE19A501DBD64333"><enum>(B)</enum><text>cost effectively
				reduce information security risks to an acceptable level;</text>
									</subparagraph><subparagraph id="HBA9D6C788D48454394F7E284D55F0791"><enum>(C)</enum><text display-inline="yes-display-inline">ensure that information security is
				addressed throughout the life cycle of each agency information system and
				information infrastructure;</text>
									</subparagraph><subparagraph id="H754615C87B41428DAC26B6D1FA4DF014"><enum>(D)</enum><text>ensure compliance
				with—</text>
										<clause id="HFB88CDF1C65B44EE8BC69CF9BD44B470"><enum>(i)</enum><text>the requirements
				of this subchapter;</text>
										</clause><clause id="H3BF90DD505924DE8A65B922E53391FC7"><enum>(ii)</enum><text>policies and
				procedures as may be prescribed by the Director of the National Office for
				Cyberspace, and information security standards promulgated under section
				3558;</text>
										</clause><clause id="HB24FA5D7ADD847B383521D60406AE698"><enum>(iii)</enum><text>minimally
				acceptable system configuration requirements, as determined by the Director of
				the National Office for Cyberspace; and</text>
										</clause><clause id="H2019804CE43A421BB37D6A5E3C66454F"><enum>(iv)</enum><text display-inline="yes-display-inline">any other applicable requirements,
				including—</text>
											<subclause id="HA48D4C653C514BB88A2D95C0DF11C130"><enum>(I)</enum><text>standards and
				guidelines for national security systems issued in accordance with law and as
				directed by the President;</text>
											</subclause><subclause id="HBB716985500A4F459689AE0E250A87B6"><enum>(II)</enum><text>the policy of the
				Director of the National Office for Cyberspace;</text>
											</subclause><subclause id="HC057FCC42E3747E9AF2B5EFFB022AFD3"><enum>(III)</enum><text>the National
				Institute of Standards and Technology guidance; and</text>
											</subclause><subclause id="HCB0661DE09924D39B1BC59533EEF360B"><enum>(IV)</enum><text>the Chief
				Information Officers Council recommended approaches;</text>
											</subclause></clause></subparagraph><subparagraph id="H6616501FB7DC4C0B8A1C220B029CA6C7"><enum>(E)</enum><text>develop, maintain,
				and oversee information security policies, procedures, and control techniques
				to address all applicable requirements, including those issued under sections
				3555 and 3558; and</text>
									</subparagraph><subparagraph id="H4BD5275592D948D294AC858CC1E2E85C"><enum>(F)</enum><text>ensure the
				oversight and training of personnel with significant responsibilities for
				information security with respect to such responsibilities;</text>
									</subparagraph></paragraph><paragraph id="H5198A3BCBD664CABB96A4DC1A263E31D"><enum>(4)</enum><text>ensuring that the
				agency has trained and cleared personnel sufficient to assist the agency in
				complying with the requirements of this subchapter and related policies,
				procedures, standards, and guidelines;</text>
								</paragraph><paragraph id="H5EA03DBF747E4DD68408B508CC71605C"><enum>(5)</enum><text>to the extent
				practicable, automated and continuous technical monitoring for testing, and
				evaluation of the effectiveness and compliance of information security
				policies, procedures, and practices, including—</text>
									<subparagraph id="H7603760251504460824F1B147FD9F25F"><enum>(A)</enum><text display-inline="yes-display-inline">management, operational, and technical
				controls of every information infrastructure identified in the inventory
				required under section 3505(b); and</text>
									</subparagraph><subparagraph id="HDCA77C8C0C02467F99978F2B2EF783DA"><enum>(B)</enum><text>management,
				operational, and technical controls relied on for an evaluation under section
				3556;</text>
									</subparagraph></paragraph><paragraph id="H1AF11FC760934D46A47F9B9AC841C879"><enum>(6)</enum><text>a process for
				planning, implementing, evaluating, and documenting remedial action to address
				any deficiencies in the information security policies, procedures, and
				practices of the agency;</text>
								</paragraph><paragraph id="H9B8B9E2383164297B8556E60C4A89C5E"><enum>(7)</enum><text>to the extent
				practicable, continuous automated technical monitoring for detecting,
				reporting, and responding to security incidents, consistent with standards and
				guidelines issued by the Director of the National Office for Cyberspace,
				including—</text>
									<subparagraph id="H81DB68087FFB42E7AEBA39FA3B47BBF9"><enum>(A)</enum><text>mitigating risks
				associated with such incidents before substantial damage is done;</text>
									</subparagraph><subparagraph id="H1B150E4B96AD400A8B3D600D656E130D"><enum>(B)</enum><text>notifying and
				consulting with the appropriate security operations response center; and</text>
									</subparagraph><subparagraph id="H6C450C7947544737BDFCC0F2CEFCC257"><enum>(C)</enum><text>notifying and
				consulting with, as appropriate—</text>
										<clause id="H7F14ADEE7CEF4165A80E18FE963F11A5"><enum>(i)</enum><text>law enforcement
				agencies and relevant Offices of Inspectors General;</text>
										</clause><clause id="H6589F13133FE4C1A89EACB1AA7596EB9"><enum>(ii)</enum><text>the National
				Office for Cyberspace; and</text>
										</clause><clause id="H6E2C961E30F84129A0B8E074846C6B2D"><enum>(iii)</enum><text>any other agency
				or office, in accordance with law or as directed by the President; and</text>
										</clause></subparagraph></paragraph><paragraph display-inline="no-display-inline" id="H32DC9D0ED84941D7B6E04E8580E58616"><enum>(8)</enum><text display-inline="yes-display-inline">plans and procedures to ensure continuity
				of operations for information infrastructure that support the operations and
				assets of the agency.</text>
								</paragraph></subsection><subsection display-inline="no-display-inline" id="H84CADC342E3B48E89D85E91B21ACE689"><enum>(c)</enum><header>Agency
				reporting</header><text>Each agency shall—</text>
								<paragraph id="H90C3A360ABAB40628FB97EE203A77BA0"><enum>(1)</enum><text>submit an annual
				report on the adequacy and effectiveness of information security policies,
				procedures, and practices, and compliance with the requirements of this
				subchapter, including compliance with each requirement of subsection (b)
				to—</text>
									<subparagraph id="H069D5B45DD1147008F4DCE988F85DC59"><enum>(A)</enum><text>the National
				Office for Cyberspace;</text>
									</subparagraph><subparagraph id="H14F9F5E27F99461880031C09DC0CE97E"><enum>(B)</enum><text>the Committee on
				Homeland Security and Governmental Affairs of the Senate;</text>
									</subparagraph><subparagraph id="HFA2E1D72C2EB4122A24E0F6C20D75D51"><enum>(C)</enum><text>the Committee on
				Oversight and Government Reform of the House of Representatives;</text>
									</subparagraph><subparagraph id="H2859B3E8665C449788058390C955C09C"><enum>(D)</enum><text>other appropriate
				authorization and appropriations committees of Congress; and</text>
									</subparagraph><subparagraph id="H817673E4A2014309803D5D6531D46807"><enum>(E)</enum><text>the Comptroller
				General;</text>
									</subparagraph></paragraph><paragraph id="HA6764639A68B4546AF92B8EDE047837A"><enum>(2)</enum><text>address the
				adequacy and effectiveness of information security policies, procedures, and
				practices in plans and reports relating to—</text>
									<subparagraph id="HA6D5B3E7B9554552B9C2DE60DBC9AF75"><enum>(A)</enum><text>annual agency
				budgets;</text>
									</subparagraph><subparagraph id="H61F9E151CCC84F3EAACA14A788B4FDB5"><enum>(B)</enum><text>information
				resources management of this subchapter;</text>
									</subparagraph><subparagraph id="H3FAF689331BC4E40A959C76C39EB691D"><enum>(C)</enum><text>information
				technology management under this chapter;</text>
									</subparagraph><subparagraph id="H0F588D80D4E84CF0A71C6BAC792EEB2C"><enum>(D)</enum><text>program
				performance under sections 1105 and 1115 through 1119 of title 31, and sections
				2801 and 2805 of title 39;</text>
									</subparagraph><subparagraph id="H077353C3B2664DB29ABA8F200C5A29CD"><enum>(E)</enum><text>financial
				management under chapter 9 of title 31, and the Chief Financial Officers Act of
				1990 (31 U.S.C. 501 note; Public Law 101–576) (and the amendments made by that
				Act);</text>
									</subparagraph><subparagraph id="HD22F2DC8C48544DD8A06E38A07C097B9"><enum>(F)</enum><text>financial
				management systems under the Federal Financial Management Improvement Act (31
				U.S.C. 3512 note); and</text>
									</subparagraph><subparagraph id="H11D7A05E7439402E814F8394AEE52C06"><enum>(G)</enum><text>internal
				accounting and administrative controls under section 3512 of title 31;
				and</text>
									</subparagraph></paragraph><paragraph id="H6EE5D4F582DA48C7A2C5F0865B78B459"><enum>(3)</enum><text>report any
				significant deficiency in a policy, procedure, or practice identified under
				paragraph (1) or (2)—</text>
									<subparagraph id="HE6889E00BFC54251B3C79CA76F5059CC"><enum>(A)</enum><text>as a material
				weakness in reporting under section 3512 of title 31; and</text>
									</subparagraph><subparagraph id="H307FD71DB014409B9A4DD4C36C0F42F9"><enum>(B)</enum><text>if relating to
				financial management systems, as an instance of a lack of substantial
				compliance under the Federal Financial Management Improvement Act (31 U.S.C.
				3512 note).</text>
									</subparagraph></paragraph></subsection><subsection display-inline="no-display-inline" id="HD54C8795B8684588A40B70502786111A"><enum>(d)</enum><header>Performance
				plan</header><paragraph commented="no" display-inline="yes-display-inline" id="H959F4EC1F7304F2C98F61C6B92086661"><enum>(1)</enum><text>In
				addition to the requirements of subsection (c), each agency, in consultation
				with the National Office for Cyberspace, shall include as part of the
				performance plan required under section 1115 of title 31 a description of the
				resources, including budget, staffing, and training, that are necessary to
				implement the program required under subsection (b).</text>
								</paragraph><paragraph id="HF3829B3927A24F5CAA5DAD93E19FCB64" indent="up1"><enum>(2)</enum><text>The description under paragraph (1)
				shall be based on the risk assessments required under subsection (a)(2).</text>
								</paragraph></subsection><subsection id="H059AA7C5AFDD421FA45533A4FA8C3253"><enum>(e)</enum><header>Public notice
				and comment</header><text>Each agency shall provide the public with timely
				notice and opportunities for comment on proposed information security policies
				and procedures to the extent that such policies and procedures affect
				communication with the public.</text>
							</subsection></section><section display-inline="no-display-inline" id="HE4B6077A95F543419698DFBE1EBAAEB5" section-type="subsequent-section"><enum>3557.</enum><header>Annual independent
				audit</header>
							<subsection id="H751B7530BA8E4239B8ADC826F571882F"><enum>(a)</enum><header>In
				general</header><paragraph commented="no" display-inline="yes-display-inline" id="H19FF2430F0A9456A8575BD3B1AAA04C2"><enum>(1)</enum><text>Each year each agency
				shall have performed an independent audit of the information security program
				and practices of that agency to determine the effectiveness of such program and
				practices.</text>
								</paragraph><paragraph id="HC66C3D22ED4E438DAED50D97CDF9B0AD" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">Each audit under this section shall
				include—</text>
									<subparagraph id="H97C79526FCBF424691E4F52B37AD43EC"><enum>(A)</enum><text display-inline="yes-display-inline">testing of the effectiveness of the
				information infrastructure of the agency for automated, continuous monitoring
				of the state of compliance of its information infrastructure with regulations
				promulgated under section 3554 and standards promulgated under section 3558 in
				a representative subset of—</text>
										<clause id="HE08DD2B4F7EE4FF192B9AB738ED03A61"><enum>(i)</enum><text display-inline="yes-display-inline">the information infrastructure used or
				operated by the agency; and</text>
										</clause><clause id="H709BC230121D4726A24A614E587E9F79"><enum>(ii)</enum><text display-inline="yes-display-inline">the information infrastructure used,
				operated, or supported on behalf of the agency by a contractor of the agency, a
				subcontractor (at any tier) of such contractor, or any other entity;</text>
										</clause></subparagraph><subparagraph id="HA660DA4B265246299BBC832BE3020DE1"><enum>(B)</enum><text>an assessment (made on the basis of
				the results of the testing) of compliance with—</text>
										<clause id="H22BD52F1087E443DBD2EBF876ADF691B"><enum>(i)</enum><text>the requirements of this
				subchapter; and</text>
										</clause><clause id="H940C27D527D74EC4A0DA4B9EB1DC6FE5"><enum>(ii)</enum><text>related information security
				policies, procedures, standards, and guidelines;</text>
										</clause></subparagraph><subparagraph id="H8576830D976946749834322DD8487C8D"><enum>(C)</enum><text>separate assessments, as appropriate,
				regarding information security relating to national security systems;
				and</text>
									</subparagraph><subparagraph id="H6E53E8CFBAB94D29980588048FCF1A90"><enum>(D)</enum><text>a conclusion regarding whether the
				information security controls of the agency are effective, including an
				identification of any significant deficiencies in such controls.</text>
									</subparagraph></paragraph><paragraph id="H98CEA1E9DBC1487F962A2DAB91EDAE2D" indent="up1"><enum>(3)</enum><text>Each audit under this section shall
				be performed in accordance with applicable generally accepted Government
				auditing standards.</text>
								</paragraph></subsection><subsection display-inline="no-display-inline" id="HEDD1EFB05CC7458F91B2C927F29B7523"><enum>(b)</enum><header>Independent
				auditor</header><text>Subject to subsection (c)—</text>
								<paragraph id="H904B60B8B0A448AAABA5E59EC2E96CCA"><enum>(1)</enum><text>for each agency
				with an Inspector General appointed under the Inspector General Act of 1978 or
				any other law, the annual audit required by this section shall be performed by
				the Inspector General or by an independent external auditor, as determined by
				the Inspector General of the agency; and</text>
								</paragraph><paragraph id="H0EB67FABCA884D43BEF781A3B524EF3A"><enum>(2)</enum><text>for each agency to
				which paragraph (1) does not apply, the head of the agency shall engage an
				independent external auditor to perform the audit.</text>
								</paragraph></subsection><subsection display-inline="no-display-inline" id="HE885C4CDB206470FBE63E63EEEFF4FD4"><enum>(c)</enum><header>National
				security systems</header><text>For each agency operating or exercising control
				of a national security system, that portion of the audit required by this
				section directly relating to a national security system shall be
				performed—</text>
								<paragraph id="H5DEC425531B043DA841122A9DAC8173B"><enum>(1)</enum><text>only by an entity
				designated head; and</text>
								</paragraph><paragraph id="HA49FB013A3264DDDA333E23C42EB5653"><enum>(2)</enum><text>in such a manner
				as to ensure appropriate protection for information associated with any
				information security vulnerability in such system commensurate with the risk
				and in accordance with all applicable laws.</text>
								</paragraph></subsection><subsection id="HE7B006BDE5E24ADA8A6733CED4CD3310"><enum>(d)</enum><header>Existing
				audits</header><text>The audit required by this section may be based in whole
				or in part on another audit relating to programs or practices of the applicable
				agency.</text>
							</subsection><subsection id="H1C3E471F1BA04C83A8F82EF0162B33DA"><enum>(e)</enum><header>Agency
				reporting</header><paragraph commented="no" display-inline="yes-display-inline" id="H5D7E71192F964B7192C05BC7DF9E904C"><enum>(1)</enum><text>Each year, not later
				than such date established by the Director of the National Office for
				Cyberspace, the head of each agency shall submit to the Director the results of
				the audit required under this section.</text>
								</paragraph><paragraph id="H160F9B2A2080485D958AF2F83576E3EA" indent="up1"><enum>(2)</enum><text>To the extent an audit required under
				this section directly relates to a national security system, the results of the
				audit submitted to the Director of the National Office for Cyberspace shall
				contain only a summary and assessment of that portion of the audit directly
				relating to a national security system.</text>
								</paragraph></subsection><subsection id="H55D077A3EA014B24A26273005A5162DC"><enum>(f)</enum><header>Protection of
				information</header><text>Agencies and auditors shall take appropriate steps to
				ensure the protection of information which, if disclosed, may adversely affect
				information security. Such protections shall be commensurate with the risk and
				comply with all applicable laws and regulations.</text>
							</subsection><subsection id="H5A302B4D7B6941D0B597F367A74CD80C"><enum>(g)</enum><header>National Office
				for Cyberspace reports to congress</header><paragraph commented="no" display-inline="yes-display-inline" id="H71E9E31FCBD94891898A8917F442AD36"><enum>(1)</enum><text>The Director of the
				National Office for Cyberspace shall summarize the results of the audits
				conducted under this section in the annual report to Congress required under
				section 3555(a)(8).</text>
								</paragraph><paragraph id="H90D9A7A359EC40F58330248EF619569D" indent="up1"><enum>(2)</enum><text display-inline="yes-display-inline">The Director’s report to Congress under
				this subsection shall summarize information regarding information security
				relating to national security systems in such a manner as to ensure appropriate
				protection for information associated with any information security
				vulnerability in such system commensurate with the risk and in accordance with
				all applicable laws.</text>
								</paragraph><paragraph id="H23D3ECDBCD864CE5899205303C025B45" indent="up1"><enum>(3)</enum><text display-inline="yes-display-inline">Audits and any other descriptions of
				information infrastructure under the authority and control of the Director of
				Central Intelligence or of National Foreign Intelligence Programs systems under
				the authority and control of the Secretary of Defense shall be made available
				to Congress only through the appropriate oversight committees of Congress, in
				accordance with applicable laws.</text>
								</paragraph></subsection><subsection id="H29D1C0074EA24D8EAA9D9D5A1C1AF900"><enum>(h)</enum><header>Comptroller
				general</header><text display-inline="yes-display-inline">The Comptroller
				General shall periodically evaluate and report to Congress on—</text>
								<paragraph id="H949597F0066F4FF890844C089776453D"><enum>(1)</enum><text>the adequacy and
				effectiveness of agency information security policies and practices; and</text>
								</paragraph><paragraph id="HF42B2331960F4B5D8702F7787469748B"><enum>(2)</enum><text>implementation of
				the requirements of this subchapter.</text>
								</paragraph></subsection><subsection id="H84DC85F6E1D341DF81973759DFF71355"><enum>(i)</enum><header>Contractor
				audits</header><text display-inline="yes-display-inline">Each year each
				contractor that operates, uses, or supports an information system or
				information infrastructure on behalf of an agency and each subcontractor of
				such contractor—</text>
								<paragraph id="HACB85E52913E4B899D027D11BE865796"><enum>(1)</enum><text>shall conduct an
				audit using an independent external auditor in accordance with subsection (a),
				including an assessment of compliance with the applicable requirements of this
				subchapter; and</text>
								</paragraph><paragraph id="H08BA0EB5DFD642479DAED5BAEF80A919"><enum>(2)</enum><text>shall submit the
				results of such audit to such agency not later than such date established by
				the Agency.</text>
								</paragraph></subsection></section><section display-inline="no-display-inline" id="H8B26A75FBE1E4DB2977884F2DC8AB4D8" section-type="subsequent-section"><enum>3558.</enum><header>Responsibilities
				for Federal information systems standards</header>
							<subsection id="H96C457C115AF42FBA57C4E576F980265"><enum>(a)</enum><header>Requirement To
				Prescribe Standards</header>
								<paragraph id="HB783F333CA784A8D9172C579884A30D2"><enum>(1)</enum><header>In
				general</header>
									<subparagraph id="H74A134DF35A744368E2416A49C2A267E"><enum>(A)</enum><header>Requirement</header><text display-inline="yes-display-inline">Except as provided under paragraph (2), the
				Secretary of Commerce shall, on the basis of proposed standards developed by
				the National Institute of Standards and Technology pursuant to paragraphs (2)
				and (3) of section 20(a) of the National Institute of Standards and Technology
				Act (15 U.S.C. 278g–3(a)) and in consultation with the Secretary of Homeland
				Security, promulgate information security standards pertaining to Federal
				information systems.</text>
									</subparagraph><subparagraph id="H28D1BC5131904D0BB32804EBF2B30DEA"><enum>(B)</enum><header>Required
				standards</header><text>Standards promulgated under subparagraph (A) shall
				include—</text>
										<clause id="HD3CD0794178E479DA8030107B58057A9"><enum>(i)</enum><text>standards that
				provide minimum information security requirements as determined under section
				20(b) of the National Institute of Standards and Technology Act (15 U.S.C.
				278g–3(b)); and</text>
										</clause><clause id="HC040F9ED86104D93AC388347FB1C96D6"><enum>(ii)</enum><text display-inline="yes-display-inline">such standards that are otherwise necessary
				to improve the efficiency of operation or security of Federal information
				systems.</text>
										</clause></subparagraph><subparagraph id="H4DB4B8D37AB6472583307ADD262E291A"><enum>(C)</enum><header>Required
				standards binding</header><text>Information security standards described under
				subparagraph (B) shall be compulsory and binding.</text>
									</subparagraph></paragraph><paragraph id="H06C1704C8D4C44E29226B6C4ABF0AB26"><enum>(2)</enum><header>Standards and
				guidelines for national security systems</header><text>Standards and guidelines
				for national security systems, as defined under section 3552(b), shall be
				developed, promulgated, enforced, and overseen as otherwise authorized by law
				and as directed by the President.</text>
								</paragraph></subsection><subsection id="HC5D8778DCBF045B3B05112DFAD2EA7EA"><enum>(b)</enum><header>Application of
				More Stringent Standards</header><text>The head of an agency may employ
				standards for the cost-effective information security for all operations and
				assets within or under the supervision of that agency that are more stringent
				than the standards promulgated by the Secretary of Commerce under this section,
				if such standards—</text>
								<paragraph id="HA91B7782F5AC46279CCCDFC2F9F43D51"><enum>(1)</enum><text>contain, at a
				minimum, the provisions of those applicable standards made compulsory and
				binding by the Secretary; and</text>
								</paragraph><paragraph id="H1BF6B68A12C54A9EA4963F1543CC686B"><enum>(2)</enum><text>are otherwise
				consistent with policies and guidelines issued under section 3555.</text>
								</paragraph></subsection><subsection id="HFFA3D02A45ED474182300A0045346B16"><enum>(c)</enum><header>Requirements
				Regarding Decisions by the Secretary</header>
								<paragraph id="H94578EF67A214E34A2B9D36D3BA6B2BD"><enum>(1)</enum><header>Deadline</header><text>The
				decision regarding the promulgation of any standard by the Secretary of
				Commerce under subsection (b) shall occur not later than 6 months after the
				submission of the proposed standard to the Secretary by the National Institute
				of Standards and Technology, as provided under section 20 of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3).</text>
								</paragraph><paragraph id="H5480940A12294EFDA78D8CCFFF30D704"><enum>(2)</enum><header>Notice and
				comment</header><text>A decision by the Secretary of Commerce to significantly
				modify, or not promulgate, a proposed standard submitted to the Secretary by
				the National Institute of Standards and Technology, as provided under section
				20 of the National Institute of Standards and Technology Act (15 U.S.C.
				278g–3), shall be made after the public is given an opportunity to comment on
				the Secretary’s proposed decision.</text>
								</paragraph></subsection></section><section display-inline="no-display-inline" id="H1F4D88CBFD4D4E5183E127851D9E3E39" section-type="subsequent-section"><enum>3559.</enum><header>Federal information
				security incident center</header>
							<subsection id="H42A0B5D5F42549D4979621645C1B285F"><enum>(a)</enum><header>In
				General</header><text>The Director of the National Office for Cyberspace shall
				ensure the operation of a central Federal information security incident center
				to—</text>
								<paragraph id="HFC863AC54CA84B87AD7ED0A6ADA329FC"><enum>(1)</enum><text display-inline="yes-display-inline">provide timely technical assistance to
				operators of agency information systems and information infrastructure
				regarding security incidents, including guidance on detecting and handling
				information security incidents;</text>
								</paragraph><paragraph id="HF306893F33EA4CBCAD023342FA14A89E"><enum>(2)</enum><text>compile and
				analyze information about incidents that threaten information security;</text>
								</paragraph><paragraph id="H6082048EC5A04F43A88D6A77551F5EB7"><enum>(3)</enum><text display-inline="yes-display-inline">inform operators of agency information
				systems and information infrastructure about current and potential information
				security threats, and vulnerabilities; and</text>
								</paragraph><paragraph id="H0391B50B78E54B718B532B7067E79A0E"><enum>(4)</enum><text>consult with the
				National Institute of Standards and Technology, agencies or offices operating
				or exercising control of national security systems (including the National
				Security Agency), and such other agencies or offices in accordance with law and
				as directed by the President regarding information security incidents and
				related matters.</text>
								</paragraph></subsection><subsection id="H5EF5EC1F1654444FB939CAC4355FBB4F"><enum>(b)</enum><header>National
				Security Systems</header><text>Each agency operating or exercising control of a
				national security system shall share information about information security
				incidents, threats, and vulnerabilities with the Federal information security
				incident center to the extent consistent with standards and guidelines for
				national security systems, issued in accordance with law and as directed by the
				President.</text>
							</subsection><subsection id="HD15E9E183757459F9341685AA35FBA7B"><enum>(c)</enum><header>Review and
				approval</header><text>In coordination with the Administrator for Electronic
				Government and Information Technology, the Director of the National Office for
				Cyberspace shall review and approve the policies, procedures, and guidance
				established in this subchapter to ensure that the incident center has the
				capability to effectively and efficiently detect, correlate, respond to,
				contain, mitigate, and remediate incidents that impair the adequate security of
				the information systems and information infrastructure of more than one agency.
				To the extent practicable, the capability shall be continuous and technically
				automated.</text>
							</subsection></section><section id="HF97F699002464E4DA849C5D2E89EFFDC"><enum>3560.</enum><header>National
				security systems</header><text display-inline="no-display-inline">The head of
				each agency operating or exercising control of a national security system shall
				be responsible for ensuring that the agency—</text>
							<paragraph id="H5883512B03084ADF8438C56016CC32DB"><enum>(1)</enum><text>provides
				information security protections commensurate with the risk and magnitude of
				the harm resulting from the unauthorized access, use, disclosure, disruption,
				modification, or destruction of the information contained in such
				system;</text>
							</paragraph><paragraph id="HE4BFA740B0C9422AB1A133A1F10863B6"><enum>(2)</enum><text>implements
				information security policies and practices as required by standards and
				guidelines for national security systems, issued in accordance with law and as
				directed by the President; and</text>
							</paragraph><paragraph id="H93C9842724564F14AAED1EEDE6957182"><enum>(3)</enum><text>complies with the
				requirements of this
				subchapter.</text>
							</paragraph></section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="H838FDE1B3C284890942D8924A2B34138"><enum>102.</enum><header>Information
			 security acquisition requirements</header><text display-inline="no-display-inline">Chapter 113 of title 40, United States Code,
			 is amended by adding at the end of subchapter II the following new
			 section:</text>
				<quoted-block display-inline="no-display-inline" id="H6302B192BC3A419C9F85109B04B14C04" style="USC">
					<section id="HAD9E486D50F342E0BAA97A6CCBD8E968"><enum>11319.</enum><header>Information
				security acquisition requirements.</header>
						<subsection id="H47838A5F522A4A47A8977D1EBC6F15EC"><enum>(a)</enum><header>Prohibition</header><text display-inline="yes-display-inline">Notwithstanding any other provision of law,
				beginning one year after the date of the enactment of the
				<short-title>Executive Cyberspace Coordination Act of
				2011</short-title>, no agency may enter into a contract, an order under a
				contract, or an interagency agreement for—</text>
							<paragraph id="H25C2A69C4F84448398A73CD1FA55EF7A"><enum>(1)</enum><text>the collection,
				use, management, storage, or dissemination of information on behalf of the
				agency;</text>
							</paragraph><paragraph id="H165E76B445FD4679A1332A76789CC8E5"><enum>(2)</enum><text display-inline="yes-display-inline">the use or operation of an information
				system or information infrastructure on behalf of the agency; or</text>
							</paragraph><paragraph id="H8FF824A5DB784252815FE14079F05DD6"><enum>(3)</enum><text>information
				technology;</text>
							</paragraph><continuation-text continuation-text-level="subsection">unless
				such contract, order, or agreement includes requirements to provide effective
				information security that supports the operations and assets under the control
				of the agency, in compliance with the policies, standards, and guidance
				developed under subsection (b), and otherwise ensures compliance with this
				section.</continuation-text></subsection><subsection id="H099AEF92930947C7824631675460633D"><enum>(b)</enum><header>Coordination of
				secure acquisition policies</header>
							<paragraph id="H44C88393CAAD4F2CA07E45911BAF0B99"><enum>(1)</enum><header>In
				general</header><text>The Director of the Office of Management and Budget, in
				consultation with the Director of the National Institute of Standards and
				Technology, the Director of the National Office for Cyberspace, and the
				Administrator of General Services, shall oversee the development and
				implementation of policies, standards, and guidance, including through
				revisions to the Federal Acquisition Regulation and the Department of Defense
				supplement to the Federal Acquisition Regulation, to cost effectively enhance
				agency information security, including—</text>
								<subparagraph id="H05D8ABE83E34452A8FB798EB8872B8D3"><enum>(A)</enum><text>minimum
				information security requirements for agency procurement of information
				technology products and services; and</text>
								</subparagraph><subparagraph id="H2DF3351ACD504028816073B51B972E6A"><enum>(B)</enum><text>approaches for
				evaluating and mitigating significant supply chain security risks associated
				with products or services to be acquired by agencies.</text>
								</subparagraph></paragraph><paragraph id="H721B4B10904D4E85B1BB8DE7E46BE048"><enum>(2)</enum><header>Report</header><text display-inline="yes-display-inline">Not later than two years after the date of
				the enactment of the <short-title>Executive Cyberspace
				Coordination Act of 2011</short-title>, the Director of the Office of
				Management and Budget shall submit to Congress a report describing—</text>
								<subparagraph id="HDB5FE5386EA744D89908035DACFAE3B9"><enum>(A)</enum><text>actions taken to
				improve the information security associated with the procurement of products
				and services by the Federal Government; and</text>
								</subparagraph><subparagraph id="H8B2A2EDBED404B4EB14CFBB9868D0E6D"><enum>(B)</enum><text>plans for
				overseeing and coordinating efforts of agencies to use best practice approaches
				for cost-effectively purchasing more secure products and services.</text>
								</subparagraph></paragraph></subsection><subsection id="HB4405F3711494C3AB88118B35D592F24"><enum>(c)</enum><header>Vulnerability
				assessments of major systems</header>
							<paragraph id="H54A4686246CA47468BD9A3F78F7BD935"><enum>(1)</enum><header>Requirement for
				initial vulnerability assessments</header><text display-inline="yes-display-inline">The Director of the Office of Management
				and Budget shall require each agency to conduct an initial vulnerability
				assessment for any major system and its significant items of supply prior to
				the development of the system. The initial vulnerability assessment of a major
				system and its significant items of supply shall include use of an
				analysis-based approach to—</text>
								<subparagraph id="H3942A3CEDE654B65BB5C10DE08AEBD69"><enum>(A)</enum><text>identify
				vulnerabilities;</text>
								</subparagraph><subparagraph id="H11A6D059D12945769E237B9E6F3F5146"><enum>(B)</enum><text>define
				exploitation potential;</text>
								</subparagraph><subparagraph id="HC040A4711C2D4E8EB7781D066AEBF7C1"><enum>(C)</enum><text>examine the
				system's potential effectiveness;</text>
								</subparagraph><subparagraph id="HE164E14E8BDD4AADB85E15D62BCE9DBD"><enum>(D)</enum><text>determine overall
				vulnerability; and</text>
								</subparagraph><subparagraph id="H4021DEC86B0B4DF8949DC3EE20EAC49C"><enum>(E)</enum><text>make
				recommendations for risk reduction.</text>
								</subparagraph></paragraph><paragraph id="HA6F79CB792894002BB3B0DA856D9B712"><enum>(2)</enum><header>Subsequent
				vulnerability assessments</header>
								<subparagraph id="H64661310985D4FC9B317B9C099233FD1"><enum>(A)</enum><text display-inline="yes-display-inline">The Director shall require a subsequent
				vulnerability assessment of each major system and its significant items of
				supply within a program if the Director determines that circumstances warrant
				the issuance of an additional vulnerability assessment.</text>
								</subparagraph><subparagraph id="HE8CDC64B5DF74CD5B8ED07DCF62082E2"><enum>(B)</enum><text>Upon the request
				of a congressional committee, the Director may require a subsequent
				vulnerability assessment of a particular major system and its significant items
				of supply within the program.</text>
								</subparagraph><subparagraph id="HE63FC81AD26F48FFA2DFD05591BC15C1"><enum>(C)</enum><text>Any subsequent
				vulnerability assessment of a major system and its significant items of supply
				shall include use of an analysis-based approach and, if applicable, a
				testing-based approach, to monitor the exploitation potential of such system
				and reexamine the factors described in subparagraphs (A) through (E) of
				paragraph (1).</text>
								</subparagraph></paragraph><paragraph id="H3299A52BDEC9437F95236094408A3F2A"><enum>(3)</enum><header>Congressional
				oversight</header><text>The Director shall provide to the appropriate
				congressional committees a copy of each vulnerability assessment conducted
				under paragraph (1) or (2) not later than 10 days after the date of the
				completion of such assessment.</text>
							</paragraph></subsection><subsection id="H0D75B403E142405D98488FFA13752CC3"><enum>(d)</enum><header>Definitions</header><text>In
				this section:</text>
							<paragraph id="H06A0F057B6D94A928F07EB53C1BE3F2D"><enum>(1)</enum><header>Item of
				supply</header><text>The term <term>item of supply</term>—</text>
								<subparagraph id="H4C86CAD8C5654792BB20DC1CE4703D23"><enum>(A)</enum><text>means any
				individual part, component, subassembly, assembly, or subsystem integral to a
				major system, and other property which may be replaced during the service life
				of the major system, including a spare part or replenishment part; and</text>
								</subparagraph><subparagraph id="HBEB8E63649704580A4C8D340677070C0"><enum>(B)</enum><text>does not include
				packaging or labeling associated with shipment or identification of an
				item.</text>
								</subparagraph></paragraph><paragraph id="H3B5EC0D1598C4C77988AC670AA185C88"><enum>(2)</enum><header>Vulnerability
				assessment</header><text>The term <term>vulnerability assessment</term> means
				the process of identifying and quantifying vulnerabilities in a major system
				and its significant items of supply.</text>
							</paragraph><paragraph id="H0BCB40A777D642168908578682087AD6"><enum>(3)</enum><header>Major
				system</header><text>The term <term>major system</term> has the meaning given
				that term in section 4 of the Office of Federal Procurement Policy Act (41
				U.S.C.
				403).</text>
							</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</section><section id="H0D55C4D352274EA89A59F7511F1BFFAA"><enum>103.</enum><header>Technical and
			 conforming amendments</header>
				<subsection id="H95DA2867F9DF44A3828807022B12A6CA"><enum>(a)</enum><header>Table of
			 sections in title 44</header><text display-inline="yes-display-inline">The
			 table of sections for chapter 35 of title 44, United States Code, is amended by
			 striking the matter relating to subchapters II and III and inserting the
			 following:</text>
					<quoted-block display-inline="no-display-inline" id="H05E9FDC3CD274B84BF2F69C6FAAD6BA6" style="USC">
						<toc regeneration="yes-regeneration">
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="subchapter">Subchapter II—Information security</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3551. Purposes.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3552. Definitions.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3553. National Office for Cyberspace.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3554. Federal Cybersecurity Practice Board.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3555. Authority and functions of the Director of the National
				Office for Cyberspace.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3556. Agency responsibilities.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3557. Annual independent audit.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3558. Responsibilities for Federal information systems
				standards.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3559. Federal information security incident center.</toc-entry>
							<toc-entry idref="HE1FD46A0FA164578A66427C3EF6B3CA8" level="section">3560. National security
				systems.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="H810C909D593246FD8B696BF36EE7F287"><enum>(b)</enum><header>Table of
			 sections in title 40</header><text display-inline="yes-display-inline">The
			 table of sections for chapter 113 of title 40, United States Code, is amended
			 by inserting after the item relating to section 11318 the following new
			 item:</text>
					<quoted-block display-inline="no-display-inline" id="HB70EE8D8F4C8451F80F5AD09A5330755" style="USC">
						<toc regeneration="no-regeneration">
							<toc-entry level="section">Sec. 11319. Information security
				acquisition
				requirements.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="HBE28CB57BDFB4F6B926E2C08E8699974"><enum>(c)</enum><header>Other
			 references</header>
					<paragraph id="H61DBB479265E45EF92BBB8409C56B9A5"><enum>(1)</enum><text>Section
			 1001(c)(1)(A) of the Homeland Security Act of 2002 (6 U.S.C. 511(c)(1)(A)) is
			 amended by striking <quote>section 3532(3)</quote> and inserting <quote>section
			 3552(b)</quote>.</text>
					</paragraph><paragraph id="H4B3154A0F7504792877C438183BBEE5C"><enum>(2)</enum><text>Section 2222(j)(6)
			 of title 10, United States Code, is amended by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3552(b)</quote>.</text>
					</paragraph><paragraph id="HC22F1D9A96984034A83E02ACB0F56799"><enum>(3)</enum><text>Section 2223(c)(3)
			 of title 10, United States Code, is amended, by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3552(b)</quote>.</text>
					</paragraph><paragraph id="H14EF0CE7C470484AB16501072BCC3C53"><enum>(4)</enum><text>Section 2315 of
			 title 10, United States Code, is amended by striking <quote>section
			 3542(b)(2))</quote> and inserting <quote>section 3552(b)</quote>.</text>
					</paragraph><paragraph id="H2AFE636ACAF14C68A33B28920CC081AB"><enum>(5)</enum><text>Section 20 of the
			 National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is
			 amended—</text>
						<subparagraph id="H930052B3AF41429FBBDEAA787A9DD7D8"><enum>(A)</enum><text>in subsections
			 (a)(2) and (e)(5), by striking <quote>section 3532(b)(2)</quote> and inserting
			 <quote>section 3552(b)</quote>;</text>
						</subparagraph><subparagraph id="H46D3F83B0DC14AD1BDC1A5FF331F682F"><enum>(B)</enum><text>in subsection
			 (e)(2), by striking <quote>section 3532(1)</quote> and inserting <quote>section
			 3552(b)</quote>; and</text>
						</subparagraph><subparagraph id="HFA12D72287294CC6B31C2A65F937063B"><enum>(C)</enum><text>in subsections
			 (c)(3) and (d)(1), by striking <quote>section 11331 of title 40</quote> and
			 inserting <quote>section 3558 of title 44</quote>.</text>
						</subparagraph></paragraph><paragraph id="H0249C372869C4FABA6483B491E2E41AA"><enum>(6)</enum><text>Section 8(d)(1) of
			 the Cyber Security Research and Development Act (15 U.S.C. 7406(d)(1)) is
			 amended by striking <quote>section 3534(b)</quote> and inserting <quote>section
			 3556(b)</quote>.</text>
					</paragraph></subsection><subsection id="HD0F3ACD13BBF4D06832E8F30702702DB"><enum>(d)</enum><header>Repeal</header>
					<paragraph id="H37073545FC2C4310B8CC3035F83314FC"><enum>(1)</enum><text>Subchapter III of
			 chapter 113 of title 40, United States Code, is repealed.</text>
					</paragraph><paragraph id="H98994CDB6F42470D915260E1E858A1BD"><enum>(2)</enum><text>The table of
			 sections for chapter 113 of such title is amended by striking the matter
			 relating to subchapter III.</text>
					</paragraph></subsection><subsection id="H4087D13EA02547158A784E3878F94332"><enum>(e)</enum><header>Executive
			 schedule pay rate</header><text display-inline="yes-display-inline">Section
			 5314 of title 5, United States Code, is amended by adding at the end the
			 following:</text>
					<quoted-block display-inline="no-display-inline" id="H59E2CE67EE274BC2A33EB609DD0E3956" style="USC"><list level="paragraph">
							<list-item>Director of the National Office for
				  Cyberspace.</list-item></list>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection commented="no" id="H723A8EBB02CF48E7A7D246CF0688D9C6"><enum>(f)</enum><header>Membership on
			 the National Security Council</header><text display-inline="yes-display-inline">Section 101(a) of the National Security Act
			 of 1947 (50 U.S.C. 402(a)) is amended—</text>
					<paragraph commented="no" id="H38B28BD460ED4F20AB76EA284C7CF5DD"><enum>(1)</enum><text display-inline="yes-display-inline">by redesignating paragraphs (7) and (8) as
			 paragraphs (8) and (9), respectively; and</text>
					</paragraph><paragraph commented="no" id="HFADE81DEF9D74929858793236E5A5860"><enum>(2)</enum><text>by inserting after
			 paragraph (6) the following:</text>
						<quoted-block display-inline="no-display-inline" id="HC4839C54805E4F3193F9935D37F2EA47" style="OLC">
							<paragraph commented="no" id="H84C3EBBF48A7400FBD7421E1F438280C"><enum>(7)</enum><text display-inline="yes-display-inline">the Director of the National Office for
				Cyberspace;</text>
							</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection></section><section id="H4677CEF0080B46139B6A1E152A91D606"><enum>104.</enum><header>Effective
			 date</header>
				<subsection id="H20ACD7CC23464FE2B1E101B26156E0BD"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Unless otherwise
			 specified in this section, this title (including the amendments made by this
			 title) shall take effect 30 days after the date of enactment of this
			 Act.</text>
				</subsection><subsection id="H9E37C99A3E45408B851A895AC5CF81AA"><enum>(b)</enum><header>National Office
			 for Cyberspace</header><text display-inline="yes-display-inline">Section 3553
			 of title 44, United States Code, as added by section 101 of this title, shall
			 take effect 180 days after the date of enactment of this Act.</text>
				</subsection><subsection id="H8A07D99DEDFE43348E8A449118BD7D13"><enum>(c)</enum><header>Federal
			 Cybersecurity Practice Board</header><text>Section 3554 of title 44, United
			 States Code, as added by section 101 of this title, shall take effect one year
			 after the date of enactment of this Act.</text>
				</subsection></section></title><title id="H8F786A8D0A804D62BC1D8711AA9DB7FF"><enum>II</enum><header>Federal Chief
			 Technology Officer</header>
			<section id="H68941CFD901E4F208E7A96778C44A003"><enum>201.</enum><header>Office of the
			 Chief Technology Officer</header>
				<subsection id="HC04D69ACAD3B47198124E73DD623C723"><enum>(a)</enum><header>Establishment
			 and staff</header>
					<paragraph id="HE2ABA38B3CFA4B3D89A6C4DDF4926287"><enum>(1)</enum><header>Establishment</header>
						<subparagraph id="H602A16AF87CA4673B73A155E387770ED"><enum>(A)</enum><header>In
			 general</header><text>There is established in the Executive Office of the
			 President an Office of the Federal Chief Technology Officer (in this section
			 referred to as the <quote>Office</quote>).</text>
						</subparagraph><subparagraph id="HECC2B6865875428681258FC165678922"><enum>(B)</enum><header>Head of the
			 Office</header>
							<clause id="H465EAB6574B04393A56DD3E2254EE8C3"><enum>(i)</enum><header>Federal Chief
			 Technology Officer</header><text>The President shall appoint a Federal Chief
			 Technology Officer (in this section referred to as the <quote>Federal
			 CTO</quote>) who shall be the head of the Office.</text>
							</clause><clause id="HDC415BD6F1FF48F59565B93CE0A03EBF"><enum>(ii)</enum><header>Compensation</header><text>Section
			 5314 of title 5, United States Code, is amended by adding at the end the
			 following:</text>
								<quoted-block display-inline="no-display-inline" id="HC1C647BF31594A63B3D9F11A79D62E98" style="USC"><list level="paragraph">
										<list-item>Federal Chief Technology
				  Officer.</list-item></list>
									<after-quoted-block>.</after-quoted-block></quoted-block>
							</clause></subparagraph></paragraph><paragraph id="HDA6B1AEE2B744A7FB33F4F031BFDF5B8"><enum>(2)</enum><header>Staff of the
			 Office</header><text display-inline="yes-display-inline">The President may
			 appoint additional staff members to the Office.</text>
					</paragraph></subsection><subsection id="H4C6832A67EE04D51BA1D85A399AC3DF9"><enum>(b)</enum><header>Duties of the
			 office</header><text>The functions of the Federal CTO are the following:</text>
					<paragraph id="H77B7BA29F5784073B67EA46B1A4BF6E6"><enum>(1)</enum><text display-inline="yes-display-inline">Undertake fact-gathering, analysis, and
			 assessment of the Federal Government’s information technology infrastructures,
			 information technology strategy, and use of information technology, and provide
			 advice on such matters to the President, heads of Federal departments and
			 agencies, and government chief information officers and chief technology
			 officers.</text>
					</paragraph><paragraph id="H299A79580A00476A8EABDEBE199C134A"><enum>(2)</enum><text>Lead an
			 interagency effort, working with the chief technology and chief information
			 officers of each of the Federal departments and agencies, to develop and
			 implement a planning process to ensure that they use best-in-class
			 technologies, share best practices, and improve the use of technology in
			 support of Federal Government requirements.</text>
					</paragraph><paragraph id="H964F1B3DC23F45E2B285BDFB9D04EA4F"><enum>(3)</enum><text display-inline="yes-display-inline">Advise the President on information
			 technology considerations with regard to Federal budgets and with regard to
			 general coordination of the research and development programs of the Federal
			 Government for information technology-related matters.</text>
					</paragraph><paragraph id="HF2179F61D88C46C5A690EF35434ACED2"><enum>(4)</enum><text>Promote
			 technological innovation in the Federal Government, and encourage and oversee
			 the adoption of robust cross-governmental architectures and standards-based
			 information technologies, in support of effective operational and management
			 policies, practices, and services across Federal departments and agencies and
			 with the public and external entities.</text>
					</paragraph><paragraph id="H2B039A48CEDE4CDE82B4BAD02A7C8891"><enum>(5)</enum><text>Establish
			 cooperative public-private sector partnership initiatives to achieve knowledge
			 of technologies available in the marketplace that can be used for improving
			 governmental operations and information technology research and development
			 activities.</text>
					</paragraph><paragraph id="HE184FDFAB82F46AEBCAB83A5D7E293CF"><enum>(6)</enum><text>Gather timely and
			 authoritative information concerning significant developments and trends in
			 information technology, and in national priorities, both current and
			 prospective, and analyze and interpret the information for the purpose of
			 determining whether the developments and trends are likely to affect
			 achievement of the priority goals of the Federal Government.</text>
					</paragraph><paragraph id="H620318C5BFEE41738AB199D6595D2136"><enum>(7)</enum><text display-inline="yes-display-inline">Develop, review, revise, and recommend
			 criteria for determining information technology activities warranting Federal
			 support, and recommend Federal policies designed to advance the development and
			 maintenance of effective and efficient information technology capabilities,
			 including human resources, at all levels of government, academia, and industry,
			 and the effective application of the capabilities to national needs.</text>
					</paragraph><paragraph id="HB913B3CC8A4A411CBAB4260184444389"><enum>(8)</enum><text display-inline="yes-display-inline">Any other functions and activities that the
			 President may assign to the Federal CTO.</text>
					</paragraph></subsection><subsection id="HA94FDEBD495A4A96B631C3FEED8FCC5E"><enum>(c)</enum><header>Policy Planning;
			 Analysis and Advice</header><text display-inline="yes-display-inline">The
			 Office shall serve as a source of analysis and advice for the President and
			 heads of Federal departments and agencies with respect to major policies,
			 plans, and programs of the Federal Government in accordance with the functions
			 described in
			 <internal-xref idref="H4C6832A67EE04D51BA1D85A399AC3DF9" legis-path="201.(b)">subsection (b)</internal-xref>.</text>
				</subsection><subsection display-inline="no-display-inline" id="H8229E0B372E345459D2087F43B0C145B"><enum>(d)</enum><header>Coordination of
			 the Office with other entities</header>
					<paragraph id="HED10F402E02A4D97987C08D873299E1E"><enum>(1)</enum><header>Federal CTO on
			 Domestic Policy Council</header><text>The Federal CTO shall be a member of the
			 Domestic Policy Council.</text>
					</paragraph><paragraph id="HEB00C826FAF349E68B57BE10E1EA117A"><enum>(2)</enum><header>Federal CTO on
			 Cyber Security Practice Board</header><text>The Federal CTO shall be a member
			 of the Federal Cybersecurity Practice Board.</text>
					</paragraph><paragraph id="HCBD9192405174B81840D835A2D5C06E1"><enum>(3)</enum><header>Obtain
			 information from agencies</header><text display-inline="yes-display-inline">The
			 Office may secure, directly from any department or agency of the United States,
			 information necessary to enable the Federal CTO to carry out this section. On
			 request of the Federal CTO, the head of the department or agency shall furnish
			 the information to the Office, subject to any applicable limitations of Federal
			 law.</text>
					</paragraph><paragraph id="H514028F1CBE947418D621DF82BD85C32"><enum>(4)</enum><header>Staff of Federal
			 Agencies</header><text>On request of the Federal CTO, to assist the Office in
			 carrying out the duties of the Office, the head of any Federal department or
			 agency may detail personnel, services, or facilities of the department or
			 agency to the Office.</text>
					</paragraph></subsection><subsection id="H93E1B63377BA413FB4FE52F58D0B375E"><enum>(e)</enum><header>Annual
			 Report</header>
					<paragraph id="HD712F3C77FEB41A5AE3643288DF118C8"><enum>(1)</enum><header>Publication and
			 Contents</header><text>The Federal CTO shall publish, in the Federal Register
			 and on a public Internet website of the Federal CTO, an annual report that
			 includes the following:</text>
						<subparagraph id="H173B6BDEC1EC4C4E81102299D9279DCE"><enum>(A)</enum><text>Information on
			 programs to promote the development of technological innovations.</text>
						</subparagraph><subparagraph id="H7497BEEB265E47188FC5AC41DE9B3AFD"><enum>(B)</enum><text>Recommendations
			 for the adoption of policies to encourage the generation of technological
			 innovations.</text>
						</subparagraph><subparagraph id="HFC6758D9599C469DAC8E3A0111F6A2D4"><enum>(C)</enum><text>Information on the
			 activities and accomplishments of the Office in the year covered by the
			 report.</text>
						</subparagraph></paragraph><paragraph id="H0C6E4E6F07294CA5A3C9A46B9D0F0A2A"><enum>(2)</enum><header>Submission</header><text display-inline="yes-display-inline">The Federal CTO shall submit each report
			 under paragraph (1) to—</text>
						<subparagraph id="H797FE45D05654630A6D39D23ED874041"><enum>(A)</enum><text>the
			 President;</text>
						</subparagraph><subparagraph id="HE2E047ED6133441E9C189AC7A1C8C709"><enum>(B)</enum><text>the Committee on
			 Oversight and Government Reform of the House of Representatives;</text>
						</subparagraph><subparagraph id="H3E361270AD2F43F5A87C3977759C1A83"><enum>(C)</enum><text>the Committee on
			 Science and Technology of the House of Representatives; and</text>
						</subparagraph><subparagraph id="H4619CA6E1DC34191888B24E81DE7F716"><enum>(D)</enum><text>the Committee on
			 Commerce, Science, and Transportation of the Senate.</text>
						</subparagraph></paragraph></subsection></section></title><title id="HAC1B35212ABC434DAA23074AAB2526CF"><enum>III</enum><header>Strengthening
			 Cybersecurity for Critical Infrastructure</header>
			<section id="H92F168B960414B28963DAD9086BDEAA7"><enum>301.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="HE3BC19C2C3E04378BB843AC1D2551B61"><enum>(1)</enum><header>Critical
			 information infrastructure</header><text display-inline="yes-display-inline">The term <term>critical information
			 infrastructure</term> means the electronic information and communications
			 systems, software, and assets that control, protect, process, transmit,
			 receive, program, or store information in any form, including data, voice, and
			 video, relied upon by critical infrastructure, industrial control systems such
			 as supervisory control and data acquisition systems, and programmable logic
			 controllers. This shall also include such systems of the Federal
			 Government.</text>
				</paragraph><paragraph id="HCD7249392BA34B89BEA93E95EDF66E73"><enum>(2)</enum><header>Secretary</header><text display-inline="yes-display-inline">The term <term>Secretary</term> means the
			 Secretary of Homeland Security.</text>
				</paragraph></section><section id="H41F4B360DD9E46938B45BC0DFDC3C12F"><enum>302.</enum><header>Authority of
			 Secretary</header>
				<subsection id="HB2236B9657CD494FA1F07ED79BEFCA30"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The Secretary shall
			 have primary authority, in consultation with the Director of the National
			 Office for Cyberspace and the Federal Cyberspace Practice Board, in the
			 executive branch of the Federal Government in creation, verification, and
			 enforcement of measures with respect to the protection of critical information
			 infrastructure, including promulgating risk-informed information security
			 practices and standards applicable to critical information infrastructures that
			 are not owned by or under the direct control of the Federal Government. The
			 Secretary should consult with appropriate private sector entities, including
			 private owners and operators of the affected infrastructure, to carry out this
			 section.</text>
				</subsection><subsection id="H0D45CFFAA05743549F3B5BD1D3B46A3C"><enum>(b)</enum><header>Other Federal
			 agencies</header><text display-inline="yes-display-inline">In establishing
			 measures with respect to the protection of critical information infrastructure
			 the Secretary shall—</text>
					<paragraph id="H76AB9C61B7604520B47621D372D1270C"><enum>(1)</enum><text display-inline="yes-display-inline">consult with the Secretary of Commerce, the
			 Secretary of Defense, the National Institute of Standards and Technology, and
			 other sector specific Federal regulatory agencies in exercising the authority
			 referred to in subsection (a); and</text>
					</paragraph><paragraph id="HF54195598C50488BB2BD7E86CD018906"><enum>(2)</enum><text>coordinate, though
			 the Executive Office of the President, with sector specific Federal regulatory
			 agencies, including the Federal Energy Regulatory Commission, in establishing
			 enforcement mechanisms under the authority referred to in subsection
			 (a).</text>
					</paragraph></subsection><subsection id="H69D93DDB01D0496D8D5D440BF1053C47"><enum>(c)</enum><header>Auditing
			 authority</header><text display-inline="yes-display-inline">The Secretary
			 may—</text>
					<paragraph id="H817C647A892042F6A0EF9A5AC8B5B79D"><enum>(1)</enum><text display-inline="yes-display-inline">conduct such audits as are necessary to
			 ensure that appropriate measures are taken to secure critical information
			 infrastructure;</text>
					</paragraph><paragraph id="HAE1A5DEA49CA4C209F189B9BC6B80C69"><enum>(2)</enum><text>issue such
			 subpoenas as are necessary to determine compliance with Federal regulatory
			 requirements for securing critical information infrastructure; and</text>
					</paragraph><paragraph id="H9E243C80C3894B698C8FE94A67EB9712"><enum>(3)</enum><text display-inline="yes-display-inline">authorize sector specific Federal
			 regulatory agencies to undertake such audits.</text>
					</paragraph></subsection></section></title></legis-body>
</bill>
