<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-LIP22081-NXY-GY-R22"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S3618 IS: Federal Cybersecurity Oversight Act of 2022</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-02-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 3618</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220209">February 9, 2022</action-date><action-desc><sponsor name-id="S247">Mr. Wyden</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend the Federal Cybersecurity Enhancement Act of 2015 to require Federal agencies to obtain exemptions from certain cybersecurity requirements in order to avoid compliance with those requirements, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Federal Cybersecurity Oversight Act of 2022</short-title></quote>.</text></section><section id="id40A0F8991F9F49F2B79BAAD35754CE31"><enum>2.</enum><header>Federal cybersecurity requirements</header><subsection id="idE245D5AE717A429D8EADC2C67BC678CC"><enum>(a)</enum><header>Exemption from Federal requirements</header><text display-inline="yes-display-inline">Section 225(b)(2) of the Federal Cybersecurity Enhancement Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1523">6 U.S.C. 1523(b)(2)</external-xref>) is amended to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id2484B0C34D844863982200D9B094085B"><paragraph id="idFD75A940B4BC445F9DB9B46DC4E90958"><enum>(2)</enum><header>Exception</header><subparagraph id="id5F9CFAF8548141C1BC4C8ECE883A22E7"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">A particular requirement under paragraph (1) shall not apply to an agency information system of an agency if—</text><clause id="idC782E08B73BD403DA8732CAAE9D5D2B8"><enum>(i)</enum><text display-inline="yes-display-inline">with respect to the agency information system, the head of the agency submits to the Director an application for an exemption from the particular requirement, in which the head of the agency personally certifies to the Director with particularity that—</text><subclause id="id0FF1AEA4F17E47D7A04EA6CE53046F9B"><enum>(I)</enum><text display-inline="yes-display-inline">operational requirements articulated in the certification and related to the agency information system would make it excessively burdensome to implement the particular requirement;</text></subclause><subclause id="idB2C030D38AE144179792F786CB556791"><enum>(II)</enum><text>the particular requirement is not necessary to secure the agency information system or agency information stored on or transiting the agency information system; and</text></subclause><subclause id="id99FB623428C44BFB9EA320D176E7CB37"><enum>(III)</enum><text>the agency has taken all necessary steps to secure the agency information system and agency information stored on or transiting the agency information system;</text></subclause></clause><clause id="idF523E630C82147929FCA798FFE60A2AC"><enum>(ii)</enum><text>the head of the agency or the designee of the head of the agency has submitted the certification described in clause (i) to the appropriate congressional committees and any other congressional committee with jurisdiction over the agency; and</text></clause><clause id="id324EFFD3A5504C91A4303336C52487F5"><enum>(iii)</enum><text>the Director grants the exemption from the particular requirement.</text></clause></subparagraph><subparagraph id="id11C169079D274F1992A58351C1864F34"><enum>(B)</enum><header>Duration of exemption</header><clause id="id125924F37D214626ABE5379ABC98B35A"><enum>(i)</enum><header>In general</header><text>An exemption granted under subparagraph (A) shall expire on the date that is 1 year after the date on which the Director granted the exemption.</text></clause><clause id="id4152A97524E94AC7AAF5ABFFA2451CB6"><enum>(ii)</enum><header>Renewal</header><text>Upon the expiration of an exemption granted to an agency under subparagraph (A), the head of the agency may apply for an additional exemption.</text></clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idB80BF1B810514941BC75956FE58827B8"><enum>(b)</enum><header>Report on exemptions</header><text>Section 3554(c)(1)(A) of title 44, United States Code, is amended—</text><paragraph id="id0B5BC083CFA7478CB29B5F0A4EF6B5A9"><enum>(1)</enum><text>in clause (iii), by striking <quote>and</quote> at the end;</text></paragraph><paragraph id="id385D946EEEF94D45B4CD2B40C3EECD86"><enum>(2)</enum><text>by redesignating clause (iv) as clause (v); and</text></paragraph><paragraph id="idDBF6393C5ECA4B6B8664A7A49EDACEE2"><enum>(3)</enum><text>by inserting after clause (iii) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id18A3959D173E47CBAAC99A78105695A8"><clause id="id8348F37DCC134036A5CFC3874181D127"><enum>(iv)</enum><text>with respect to any exemption the Director of the Office of Management and Budget has granted the agency under section 225(b)(2) of the Federal Cybersecurity Enhancement Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1523">6 U.S.C. 1523(b)(2)</external-xref>) that is effective on the date of submission of the report—</text><subclause id="id29D5CAB2EF354CD5A6111EF0BEA184D3"><enum>(I)</enum><text>an identification of each particular requirement from which any agency information system (as defined in section 2210 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/660">6 U.S.C. 660</external-xref>)) is exempted; and</text></subclause><subclause id="idCEAE08C3CE7C4F5B91687FA590B43534"><enum>(II)</enum><text>for each requirement identified under subclause (I)—</text><item id="idA1BAF0EFC9BA4A738BCF09A3E72B4713"><enum>(aa)</enum><text>an identification of the agency information system described in subclause (I) exempted from the requirement; and</text></item><item id="idCC36E9A8B36A455797F203AABE472F57"><enum>(bb)</enum><text>an estimate of the date on which the agency will to be able to comply with the requirement; and</text></item></subclause></clause><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="idF74569D1098E4A1E92EFB16377C67973"><enum>(c)</enum><header>Effective date</header><text>This Act and the amendments made by this Act shall take effect on the date that is 1 year after the date of enactment of this Act.</text></subsection></section></legis-body></bill> 

