[Congressional Record Volume 161, Number 90 (Monday, June 8, 2015)]
[Senate]
[Page S3879]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1844. Mr. BENNET submitted an amendment intended to be proposed to 
amendment SA 1463 proposed by Mr. McCain to the bill H.R. 1735, to 
authorize appropriations for fiscal year 2016 for military activities 
of the Department of Defense, for military construction, and for 
defense activities of the Department of Energy, to prescribe military 
personnel strengths for such fiscal year, and for other purposes; which 
was ordered to lie on the table, as follows:

       At the end of title X, add the following:

         Subtitle H--Federal Cybersecurity Workforce Assessment

     SECTION 1091. SHORT TITLE.

       This subtitle may be cited as the ``Federal Cybersecurity 
     Workforce Assessment Act''.

     SEC. 1092. DEFINITIONS.

       In this subtitle:
       (1) Appropriate congressional committees.--The term 
     ``appropriate congressional committees'' means--
       (A) the Committee on Armed Services of the Senate;
       (B) the Committee on Homeland Security and Governmental 
     Affairs of the Senate;
       (C) the Committee on Armed Services in the House of 
     Representatives;
       (D) the Committee on Homeland Security of the House of 
     Representatives; and
       (E) the Committee on Oversight and Government Reform of 
     House of Representatives.
       (2) Cybersecurity work category; data element code; 
     specialty area.--The terms ``Cybersecurity Work Category'', 
     ``Data Element Code'', and ``Specialty Area'' have the 
     meanings given such terms in the Office of Personnel 
     Management's Guide to Data Standards.
       (3) Director.--The term ``Director'' means the Director of 
     the Office of Personnel Management.
       (4) Secretary.--The term ``Secretary'' means the Secretary 
     of Homeland Security.

     SEC. 1093. NATIONAL CYBERSECURITY WORKFORCE MEASUREMENT 
                   INITIATIVE.

       (a) In General.--The head of each Federal agency shall--
       (1) identify all positions within the agency that require 
     the performance of information technology, cybersecurity, or 
     other cyber-related functions;
       (2) determine the primary Cybersecurity Work Category and 
     Specialty Area of such positions; and
       (3) assign the corresponding Data Element Code, which shall 
     be added to the National Initiative for Cybersecurity 
     Education's National Cybersecurity Workforce Framework 
     report, in accordance with subsection (b).
       (b) Employment Codes.--
       (1) Procedures.--Not later than 90 days after the date of 
     the enactment of this Act, the head of each Federal agency 
     shall establish procedures--
       (A) to identify open positions that include information 
     technology, cybersecurity, or other cyber-related functions 
     (as defined in the Office of Personnel Management's Guide to 
     Data Standards); and
       (B) to assign the appropriate employment code to each such 
     position, using agreed standards and definitions.
       (2) Code assignments.--Not later than 9 months after the 
     date of the enactment of this Act, the head of each Federal 
     agency shall assign the appropriate employment code to each 
     employee within the agency who carries out information 
     technology, cybersecurity, or other cyber-related functions.
       (c) Progress Report.--Not later than 1 year after the date 
     of the enactment of this Act, the Director shall submit a 
     progress report on the implementation of this section to the 
     appropriate congressional committees.

     SEC. 1094. IDENTIFICATION OF CYBERSECURITY SPECIALTY AREAS OF 
                   CRITICAL NEED.

       (a) In General.--Beginning not later than 1 year after the 
     date on which the employment codes are assigned to employees 
     pursuant to section 1093(b)(2), and annually through 2021, 
     the head of each Federal agency, in consultation with the 
     Director and the Secretary, shall--
       (1) identify information technology, cybersecurity, or 
     other cyber-related Specialty Areas of critical need in the 
     agency's workforce; and
       (2) submit a report to the Director that--
       (A) describes the information technology, cybersecurity, or 
     other cyber-related Specialty Areas identified under 
     paragraph (1); and
       (B) substantiates the critical need designations.
       (b) Guidance.--The Director shall provide Federal agencies 
     with timely guidance for identifying information technology, 
     cybersecurity, or other cyber-related Specialty Areas of 
     critical need, including--
       (1) current Cybersecurity Work Categories and Specialty 
     Areas with acute skill shortages; and
       (2) information technology, cybersecurity, or other cyber-
     related Specialty Areas with emerging skill shortages.
       (c) Information Technology, Cybersecurity, or Other Cyber-
     related Critical Needs Report.--Not later than 18 months 
     after the date of the enactment of this Act, the Director, in 
     consultation with the Secretary, shall--
       (1) identify Specialty Areas of critical need for 
     information technology, cybersecurity, or other cyber-related 
     workforce across all Federal agencies; and
       (2) submit a progress report on the implementation of this 
     section to the appropriate congressional committees.

     SEC. 1095. GOVERNMENT ACCOUNTABILITY OFFICE STATUS REPORTS.

       The Comptroller General of the United States shall--
       (1) analyze and monitor the implementation of sections 1093 
     and 1094; and
       (2) not later than 3 years after the date of the enactment 
     of this Act, submit a report to the appropriate congressional 
     committees that describes the status of such implementation.
                                 ______