[Congressional Record Volume 165, Number 102 (Tuesday, June 18, 2019)]
[Senate]
[Page S3689]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 670. Mr. WARNER submitted an amendment intended to be proposed by
him to the bill S. 1790, to authorize appropriations for fiscal year
2020 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the end of subtitle C of title XVI, add the following:
SEC. ___. ASSESSMENT OF VALUE OF SPEED IN CYBER THREAT
DETECTION, ANALYSIS, AND REMEDIATION.
(a) Assessment Required.--The Chief Information Officer of
the Department of Defense, in coordination with the Director
of the Defense Information Systems Agency, shall assess the
following:
(1) The range of times required by adversaries to gain
access through a cyber attack on a Department of Defense
network, conduct reconnaissance on the network, acquired
privileged credentials for operating on the network, move
laterally in the network, and accomplish the goal of the
intrusion.
(2) Trends over time in the speed with which adversaries
accomplish the steps listed in paragraph (1).
(3) The range of times required by network defenders to
detect indications of the intrusion, analyze and characterize
the intrusion, and to remediate the intrusion.
(4) The value of speed in detection, analysis, and
remediation of intrusions to effectively contain and defeat
adversaries from achieving their objectives.
(5) The advisability of adopting response times as a metric
for assessing the performance of the capabilities of network
defenses and cybersecurity programs and operators and
institutionalizing relevant data collection and forensic
processes across the Department.
(b) Briefing.--Not later than 180 days after the date of
the enactment of this Act, the Chief Information Officer
shall brief the congressional defense committees on the
results of the assessment conducted under subsection (a) and
any actions that the Chief Information Officer intends to
take with respect to the outcome of the assessment.
______