<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HE909A32B4FAB4ED0A4B86F45681A95C9" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 4265 IH: ITAA</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2023-06-21</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4265</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20230621">June 21, 2023</action-date><action-desc><sponsor name-id="R000579">Mr. Ryan</sponsor> introduced the following bill; which was referred to the <committee-name committee-id="HAS00">Committee on Armed Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Comptroller General of the United States to conduct a study and submit a report about the effectiveness of the procedural safeguards used by the Secretary of Defense to protect classified information from insider threats, and for other purposes.</official-title></form><legis-body id="H53DDDE84A3124156B77D474568585F92" style="OLC"> 
<section id="H68779EA211AC4AB9B04C42B43961EA0E" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Insider Threat Assessment Act</short-title></quote> or <quote>ITAA</quote>.</text></section> <section id="H39DB49565ADF4411A421A6389A711951"><enum>2.</enum><header>GAO study on protecting classified information from insider threats within the Department of Defense</header> <subsection id="H807633FB82EB4734920955A56A3C3A93"><enum>(a)</enum><header>Study</header><text display-inline="yes-display-inline">The Comptroller General of the United States shall conduct a study to assess the ability of the Secretary of Defense to mitigate insider threats to classified information and systems in which classified information is stored within the Department of Defense, including—</text> 
<paragraph id="HEDBB1CB5CE0742D0B308EC30662B4988"><enum>(1)</enum><text display-inline="yes-display-inline">the extent to which the Secretary takes timely action to address each security deficiency identified in each annual report submitted pursuant to the policy of the Director of National Intelligence titled the <quote>National Insider Threat Policy and Minimum Standards for Executive Branch Insider Threat Programs</quote> to the head of an executive agency by a designated senior official regarding the process or status of an insider threat program;</text></paragraph> <paragraph id="H2362A412CDD94B3EA05D30186610DD15"><enum>(2)</enum><text>the extent to which the Secretary uses information system security controls (including audits, limited access controls, and configuration management) for systems in which classified information is stored;</text></paragraph> 
<paragraph id="H614CA0C4A0344703B029197246C34C60"><enum>(3)</enum><text display-inline="yes-display-inline">the extent to which the Secretary uses controls to limit the ability of individuals who are eligible for access to classified information in accordance with Executive Order 12968 (60 Fed. Reg. 40245; relating to access to classified information), or any successor thereto, and Executive Order 10865 (25 Fed. Reg. 1583; relating to safeguarding classified information within industry), or any successor thereto, from removing such classified information from a system or facility in which such classified information is stored; and </text></paragraph> <paragraph id="H5B551059A9D2400F818A6B712C999355"><enum>(4)</enum><text>any other related matters that the Comptroller General deems appropriate.</text></paragraph> </subsection> 
<subsection id="H6DC222D9DA954217AEC512684F8B98CA"><enum>(b)</enum><header>Preliminary briefing; final report</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Comptroller General shall—</text> <paragraph id="HAB85FFAFB33248D8A4571E0EA6BB641C"><enum>(1)</enum><text>provide to the Committee on Armed Services of the House of Representatives a briefing regarding the preliminary findings of the study conducted under subsection (a); and</text></paragraph> 
<paragraph id="H916508F9E0EF49D8AA426CDA690162F7"><enum>(2)</enum><text display-inline="yes-display-inline">submit to such Committee a final report regarding the findings of the study conducted under subsection (a) at such time and in such format as is mutually agreed upon by such Committee and the Comptroller General at the time of the briefing described in paragraph (1). </text></paragraph></subsection> <subsection id="H2D59FA7AD78442F0A88E69DC356594F9" commented="no"><enum>(c)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text> 
<paragraph id="HECBBB9F419C34BDFBE4586E92213404E" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">The term <term>designated senior official</term> means, with respect to an insider threat program, an individual designated by the head of an executive agency to be principally responsible within such agency for establishing a process to gather, integrate, centrally analyze, and respond to information from counterintelligence, security, information assurance, human resources, law enforcement, and other relevant sources with information indicative of a potential insider threat.</text></paragraph> <paragraph id="H9031A785C59C4E1D9E95A5CA3778A0BE"><enum>(2)</enum><text>The term <term>executive agency</term> has the meaning given to such term in section 105 of title 5, United States Code.</text></paragraph> 
<paragraph id="H74616A64700648C2B1C4F970A6F724EE" commented="no"><enum>(3)</enum><text>The term <term>insider threat</term> means, with respect to the Department of Defense, a threat presented by a person who—</text> <subparagraph id="H53033A891DBA4DDFB15AC44FB8C0E48C" commented="no"><enum>(A)</enum><text display-inline="yes-display-inline"> has, or once had, authorized access to information, a facility, a network, a person, or a resource of the Department; and</text></subparagraph> 
<subparagraph id="HCD75F4B830C4408FB968C7099562EC74" commented="no"><enum>(B)</enum><text display-inline="yes-display-inline">wittingly, or unwittingly, commits—</text> <clause id="HF215D05515BA46C691F7D11CFE8482CA" commented="no"><enum>(i)</enum><text display-inline="yes-display-inline">an act in contravention of law or policy that resulted in, or might result in, harm through the loss or degradation of government or company information, resources, or capabilities; or </text></clause> 
<clause id="H97CEF51BA26C4BBA9683DE6FF537175C" commented="no"><enum>(ii)</enum><text>a destructive act, which may include physical harm to another in the workplace.</text></clause></subparagraph></paragraph> <paragraph id="HD16AB014D04F4460A9E97FEEAFF6FF25" commented="no"><enum>(4)</enum><text display-inline="yes-display-inline">The term <term>insider threat program</term> means a program of an executive agency established to deter, detect, and mitigate insider threats within the agency in accordance with the policy set out by the Insider Threat Task Force established under Executive Order 13587 (<external-xref legal-doc="usc" parsable-cite="usc/50/3161">50 U.S.C. 3161</external-xref> note; relating to procedures to access classified information).</text></paragraph></subsection> </section> 
</legis-body></bill>


