[Congressional Record Volume 161, Number 125 (Tuesday, August 4, 2015)]
[Senate]
[Pages S6303-S6304]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2558. Mr. BENNET (for himself and Mr. Portman) submitted an
amendment intended to be proposed by him to the bill S. 754, to improve
cybersecurity in the United States through enhanced sharing of
information about cybersecurity threats, and for other purposes; which
was ordered to lie on the table; as follows:
At the end, add the following:
TITLE II--FEDERAL CYBERSECURITY WORKFORCE ASSESSMENT
SECTION 201. SHORT TITLE.
This title may be cited as the ``Federal Cybersecurity
Workforce Assessment Act''.
SEC. 202. DEFINITIONS.
In this title:
(1) Appropriate congressional committees.--The term
``appropriate congressional committees'' means--
(A) the Committee on Armed Services of the Senate;
(B) the Committee on Homeland Security and Governmental
Affairs of the Senate;
(C) the Committee on Armed Services in the House of
Representatives;
(D) the Committee on Homeland Security of the House of
Representatives; and
(E) the Committee on Oversight and Government Reform of
House of Representatives.
(2) Director.--The term ``Director'' means the Director of
the Office of Personnel Management.
(3) Roles.--The term ``roles'' has the meaning given the
term in the National Initiative for Cybersecurity Education's
Cybersecurity Workforce Framework.
SEC. 203. NATIONAL CYBERSECURITY WORKFORCE MEASUREMENT
INITIATIVE.
(a) In General.--The head of each Federal agency shall--
(1) identify all positions within the agency that require
the performance of information technology, cybersecurity, or
other cyber-related functions; and
(2) assign the corresponding employment code, which shall
be added to the National Initiative for Cybersecurity
Education's National Cybersecurity Workforce Framework, in
accordance with subsection (b).
(b) Employment Codes.--
(1) Procedures.--
(A) Coding structure.--Not later than 180 days after the
date of the enactment of this Act, the Secretary of Commerce,
acting through the National Institute of Standards and
Technology, shall update the National Initiative for
Cybersecurity Education's Cybersecurity Workforce Framework
to include a corresponding coding structure.
(B) Identification of civilian cyber personnel.--Not later
than 9 months after the date of enactment of this Act, the
Director, in coordination with the Director of National
Intelligence, shall establish procedures to implement the
National Initiative for Cybersecurity Education's coding
structure to identify all Federal civilian positions that
require the performance of information technology,
cybersecurity, or other cyber-related functions.
(C) Identification of non-civilian cyber personnel.--Not
later than 18 months after the date of enactment of this Act,
the Secretary of Defense shall establish procedures to
implement the National Initiative for Cybersecurity
Education's coding structure to identify all Federal non-
civilian positions that require the performance of
information technology, cybersecurity or other cyber-related
functions.
(D) Baseline assessment of existing cybersecurity
workforce.--Not later than 3 months after the date on which
the procedures are developed under subparagraphs (B) and (C),
respectively, the head of each Federal agency shall submit to
the appropriate congressional committees of jurisdiction a
report that identifies--
(i) the percentage of personnel with information
technology, cybersecurity, or other cyber-related job
functions who currently hold the appropriate industry-
recognized certifications as identified in the National
Initiative for Cybersecurity Education's Cybersecurity
Workforce Framework;
(ii) the level of preparedness of other civilian and non-
civilian cyber personnel without existing credentials to pass
certification exams; and
(iii) a strategy for mitigating any gaps identified in
clause (i) or (ii) with the appropriate training and
certification for existing personnel.
(E) Procedures for assigning codes.--Not later than 3
months after the date on which the procedures are developed
under subparagraphs (B) and (C), respectively, the head of
each Federal agency shall establish procedures--
(i) to identify all encumbered and vacant positions with
information technology, cybersecurity, or other cyber-related
functions
[[Page S6304]]
(as defined in the National Initiative for Cybersecurity
Education's coding structure); and
(ii) to assign the appropriate employment code to each such
position, using agreed standards and definitions.
(2) Code assignments.--Not later than 1 year after the date
after the procedures are established under paragraph (1)(E),
the head of each Federal agency shall complete assignment of
the appropriate employment code to each position within the
agency with information technology, cybersecurity, or other
cyber-related functions.
(c) Progress Report.--Not later than 180 days after the
date of enactment of this Act, the Director shall submit a
progress report on the implementation of this section to the
appropriate congressional committees.
SEC. 204. IDENTIFICATION OF CYBER-RELATED ROLES OF CRITICAL
NEED.
(a) In General.--Beginning not later than 1 year after the
date on which the employment codes are assigned to employees
pursuant to section 203(b)(2), and annually through 2022, the
head of each Federal agency, in consultation with the
Director and the Secretary of Homeland Security, shall--
(1) identify information technology, cybersecurity, or
other cyber-related roles of critical need in the agency's
workforce; and
(2) submit a report to the Director that--
(A) describes the information technology, cybersecurity, or
other cyber-related roles identified under paragraph (1); and
(B) substantiates the critical need designations.
(b) Guidance.--The Director shall provide Federal agencies
with timely guidance for identifying information technology,
cybersecurity, or other cyber-related roles of critical need,
including--
(1) current information technology, cybersecurity, and
other cyber-related roles with acute skill shortages; and
(2) information technology, cybersecurity, or other cyber-
related roles with emerging skill shortages.
(c) Cybersecurity Needs Report.--Not later than 2 years
after the date of the enactment of this Act, the Director, in
consultation with the Secretary of Homeland Security, shall--
(1) identify critical needs for information technology,
cybersecurity, or other cyber-related workforce across all
Federal agencies; and
(2) submit a progress report on the implementation of this
section to the appropriate congressional committees.
SEC. 205. GOVERNMENT ACCOUNTABILITY OFFICE STATUS REPORTS.
The Comptroller General of the United States shall--
(1) analyze and monitor the implementation of sections 203
and 204; and
(2) not later than 3 years after the date of the enactment
of this Act, submit a report to the appropriate congressional
committees that describes the status of such implementation.
______