[Congressional Record Volume 161, Number 95 (Monday, June 15, 2015)]
[Senate]
[Pages S4164-S4165]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2036. Mr. TESTER (for himself and Mr. Kaine) submitted an 
amendment intended to be proposed to amendment SA 1463 proposed by Mr. 
McCain to the bill H.R. 1735, to authorize appropriations for fiscal 
year 2016 for military activities of the Department of Defense, for 
military construction, and for defense activities of the Department of 
Energy, to prescribe military personnel strengths for such fiscal year, 
and for other purposes; which was ordered to lie on the table; as 
follows:

       At the end of subtitle G of title X, add the following:

     SEC. 1085. REFORM AND IMPROVEMENT OF PERSONNEL SECURITY, 
                   INSIDER THREAT DETECTION AND PREVENTION, AND 
                   PHYSICAL SECURITY.

       (a) Personnel Security and Insider Threat Protection in 
     Department of Defense.--
       (1) Plans and schedules.--Consistent with the Memorandum of 
     the Secretary of Defense

[[Page S4165]]

     dated March 18, 2014, regarding the recommendations of the 
     reviews of the Washington Navy Yard shooting, the Secretary 
     of Defense shall develop plans and schedules--
       (A) to implement a continuous evaluation capability for the 
     national security population for which clearance 
     adjudications are conducted by the Department of Defense 
     Central Adjudication Facility, in coordination with the 
     Suitability Executive Agent, the Security Executive Agent, 
     and the Director of the Office of Management and Budget;
       (B) to produce a Department-wide insider threat strategy 
     and implementation plan, which includes--
       (i) resourcing for the Defense Insider Threat Management 
     and Analysis Center (DITMAC) and component insider threat 
     programs, and
       (ii) alignment of insider threat protection programs with 
     continuous evaluation capabilities and processes for 
     personnel security;
       (C) to centralize the authority, accountability, and 
     programmatic integration responsibilities, including fiscal 
     control, for personnel security and insider threat protection 
     under the Under Secretary of Defense for Intelligence;
       (D) to align the Department's consolidated Central 
     Adjudication Facility under the Under Secretary of Defense 
     for Intelligence;
       (E) to develop a defense security enterprise reform 
     investment strategy to ensure a consistent, long-term focus 
     on funding to strengthen all of the Department's security and 
     insider threat programs, policies, functions, and information 
     technology capabilities, including detecting threat behaviors 
     conveyed in the cyber domain, in a manner that keeps pace 
     with evolving threats and risks;
       (F) to resource and expedite deployment of the Identity 
     Management Enterprise Services Architecture (IMESA); and
       (G) to implement the recommendations contained in the study 
     conducted by the Director of Cost Analysis and Program 
     Evaluation required by section 907 of the National Defense 
     Authorization Act for Fiscal Year 2014 (Public Law 113-66; 10 
     U.S.C. 1564 note), including, specifically, the 
     recommendations to centrally manage and regulate Department 
     of Defense requests for personnel security background 
     investigations.
       (2) Reporting requirement.--Not later than 180 days after 
     the date of the enactment of this Act, the Secretary of 
     Defense shall submit to the appropriate committees of 
     Congress a report describing the plans and schedules required 
     under paragraph (1).
       (b) Physical and Logical Access.--Not later than 270 days 
     after the date of the enactment of this Act--
       (1) the Secretary of Defense shall define physical and 
     logical access standards, capabilities, and processes 
     applicable to all personnel with access to Department of 
     Defense installations and information technology systems, 
     including--
       (A) periodic or regularized background or records checks 
     appropriate to the type of physical or logical access 
     involved, the security level, the category of individuals 
     authorized, and the level of access to be granted;
       (B) standards and methods for verifying the identity of 
     individuals seeking access; and
       (C) electronic attribute-based access controls that are 
     appropriate for the type of access and facility or 
     information technology system involved;
       (2) the Director of the Office of Management and Budget and 
     the Chair of the Performance Accountability Council, in 
     coordination with the Secretary of Defense and the 
     Administrator of General Services, and in consultation with 
     representatives from stakeholder organizations, shall design 
     a capability to share and apply electronic identity 
     information across the Government to enable real-time, risk-
     managed physical and logical access decisions; and
       (3) the Director of the Office of Management and Budget, in 
     conjunction with the Director of the Office of Personnel 
     Management and in consultation with representatives from 
     stakeholder organizations, shall establish investigative and 
     adjudicative standards for the periodic or regularized 
     reevaluation of the eligibility of an individual to retain 
     credentials issued pursuant to Homeland Security Presidential 
     Directive 12 (dated August 27, 2004), as appropriate, but not 
     less frequently than the authorization period of the issued 
     credentials.
       (c) Security Enterprise Management.--Not later than 180 
     days after the date of enactment of this Act, the Director of 
     the Office of Management and Budget shall--
       (1) formalize the Security, Suitability, and Credentialing 
     Line of Business;
       (2) submit a report to the appropriate congressional 
     committee that describes plans--
       (A) for oversight by the Office of Management and Budget of 
     activities of the executive branch of the Government for 
     personnel security, suitability, and credentialing;
       (B) to designate enterprise shared services to optimize 
     investments;
       (C) to define and implement data standards to support 
     common electronic access to critical Government records; and
       (D) to reduce the burden placed on Government data 
     providers by centralizing requests for records access and 
     ensuring proper sharing of the data with appropriate 
     investigative and adjudicative elements.
       (d) Reciprocity Management.--Not later than 2 years after 
     the date of enactment of this Act, the Chair of the 
     Performance Accountability Council shall ensure that--
       (1) a centralized system is available to serve as the 
     reciprocity management system for the Federal Government; and
       (2) the centralized system described in paragraph (1) is 
     aligned with, and incorporates results from, continuous 
     evaluation and other enterprise reform initiatives.
       (e) Reporting Requirements Implementation.--Not later than 
     180 days after the date of enactment of this Act, the Chair 
     of the Performance Accountability Council, in coordination 
     with the Security Executive Agent, the Suitability Executive 
     Agent, and the Secretary of Defense, shall jointly develop a 
     plan to--
       (1) implement the Security Executive Agent Directive on 
     common, standardized employee and contractor security 
     reporting requirements;
       (2) establish and implement uniform reporting requirements 
     for employees and Federal contractors, according to risk, 
     relative to the safety of the workforce and protection of the 
     most sensitive information of the Government; and
       (3) ensure that reported information is shared 
     appropriately.
       (f) Definitions.--In this section--
       (1) the term ``appropriate committees of Congress'' means--
       (A) the congressional defense committees;
       (B) the Select Committee on Intelligence and the Committee 
     on Homeland Security and Governmental Affairs of the Senate; 
     and
       (C) the Permanent Select Committee on Intelligence, the 
     Committee on Oversight and Government Reform, and the 
     Committee on Homeland Security of the House of 
     Representatives;
       (2) the term ``Performance Accountability Council'' means 
     the Suitability and Security Clearance Performance 
     Accountability Council established under Executive Order 
     13467 (73 Fed. Reg. 38103), or any successor thereto; and
       (3) the terms ``Security Executive Agent'' and 
     ``Suitability Executive Agent'' mean the Security Executive 
     Agent and the Suitability Executive Agent, respectively, 
     established under Executive Order 13467 (73 Fed. Reg. 38103), 
     or any successor thereto.
                                 ______