US Codex
Bill
Notes

H.R. 2952 — what changed

Cybersecurity Workforce Assessment Act

From Referred in Senate to Enrolled Bill. 4 sections amended between Referred in Senate and Enrolled Bill.

Section 1 Short title

changed This Act may be cited as the “Critical Infrastructure Research and Development Advancement Act of 2014” or the “CIRDA Act of 2014”.“Cybersecurity Workforce Assessment Act”.

Sec. 2 Definitions

changed Section 2 of the Homeland Security Act of 2002 (6 U.S.C. 101) is amended by redesignating paragraphs (15) through (18) as paragraphs (16) through (19), respectively, and by inserting after paragraph (14) the following:In this Act—

(1)
added the term Cybersecurity Category means a position’s or incumbent’s primary work function involving cybersecurity, which is further defined by Specialty Area;
(2)
added the term Department means the Department of Homeland Security;
(3)
added the term Secretary means the Secretary of Homeland Security; and
(4)
added the term Specialty Area means any of the common types of cybersecurity work as recognized by the National Initiative for Cybersecurity Education’s National Cybersecurity Workforce Framework report.

removed “(15) The term “Sector Coordinating Council” means a private sector coordinating council that is—

removed “(A) recognized by the Secretary as such a Council for purposes of this Act; and

removed “(B) comprised of representatives of owners and operators of critical infrastructure within a particular sector of critical infrastructure.”

Sec. 3 Cybersecurity workforce assessment and strategy

(a)
changed Strategic Plan; Public-Private Consortiums—Workforce assessment—
(1)
changed In general— Title III of Not later than 180 days after the Homeland Security Act date of 2002 (6 U.S.C. 181 et seq.) is amended by adding at enactment of this Act, and annually thereafter for 3 years, the end Secretary shall assess the following:cybersecurity workforce of the Department.

removed “318. Research and development strategy for critical infrastructure protection

removed “(a) In General—Not later than 180 days after the date of enactment of the Critical Infrastructure Research and Development Advancement Act of 2013, the Secretary, acting through the Under Secretary for Science and Technology, shall transmit to Congress a strategic plan to guide the overall direction of Federal physical security and cybersecurity technology research and development efforts for protecting critical infrastructure, including against all threats. Once every 2 years after the initial strategic plan is transmitted to Congress under this section, the Secretary shall transmit to Congress an update of the plan.

removed “(b) Contents of Plan—The strategic plan shall include the following:

removed “(1) An identification of critical infrastructure security risks and any associated security technology gaps, that are developed following—

removed “(A) consultation with stakeholders, including the Sector Coordinating Councils; and

removed “(B) performance by the Department of a risk/gap analysis that considers information received in such consultations.

removed “(2) A set of critical infrastructure security technology needs that—

removed “(A) is prioritized based on risk and gaps identified under paragraph (1);

removed “(B) emphasizes research and development of those technologies that need to be accelerated due to rapidly evolving threats or rapidly advancing infrastructure technology; and

removed “(C) includes research, development, and acquisition roadmaps with clearly defined objectives, goals, and measures.

removed “(3) An identification of laboratories, facilities, modeling, and simulation capabilities that will be required to support the research, development, demonstration, testing, evaluation, and acquisition of the security technologies described in paragraph (2).

removed “(4) An identification of current and planned programmatic initiatives for fostering the rapid advancement and deployment of security technologies for critical infrastructure protection. The initiatives shall consider opportunities for public-private partnerships, intragovernment collaboration, university centers of excellence, and national laboratory technology transfer.

removed “(5) A description of progress made with respect to each critical infrastructure security risk, associated security technology gap, and critical infrastructure technology need identified in the preceding strategic plan transmitted under this section.

removed “(c) Coordination—In carrying out this section, the Under Secretary for Science and Technology shall coordinate with the Under Secretary for the National Protection and Programs Directorate.

removed “(d) Consultation—In carrying out this section, the Under Secretary for Science and Technology shall consult with—

removed “(1) the critical infrastructure Sector Coordinating Councils;

removed “(2) to the extent practicable, subject matter experts on critical infrastructure protection from universities, colleges, including historically black colleges and universities, Hispanic- serving institutions, and tribal colleges and universities, national laboratories, and private industry;

removed “(3) the heads of other relevant Federal departments and agencies that conduct research and development for critical infrastructure protection; and

removed “(4) State, local, and tribal governments as appropriate.

removed “319. Report on public-private research and development consortiums

removed “(a) In general—Not later than 180 days after the enactment of the Critical Infrastructure Research and Development Advancement Act of 2014, the Secretary, acting through the Under Secretary for Science and Technology, shall transmit to Congress a report on the Department’s utilization of public-private research and development consortiums for accelerating technology development for critical infrastructure protection. Once every 2 years after the initial report is transmitted to Congress under this section, the Secretary shall transmit to Congress an update of the report. The report shall focus on those aspects of critical infrastructure protection that are predominately operated by the private sector and that would most benefit from rapid security technology advancement.

removed “(b) Contents of Report—The report shall include—

removed “(1) a summary of the progress and accomplishments of on-going consortiums for critical infrastructure security technologies;

removed “(2) in consultation with the Sector Coordinating Councils and, to the extent practicable, in consultation with subject-matter experts on critical infrastructure protection from universities, colleges, including historically black colleges and universities, Hispanic-serving institutions, and tribal colleges and universities, national laboratories, and private industry, a prioritized list of technology development focus areas that would most benefit from a public-private research and development consortium; and

removed “(3) based on the prioritized list developed under paragraph (2), a proposal for implementing an expanded research and development consortium program, including an assessment of feasibility and an estimate of cost, schedule, and milestones.”

(2)
changed Limitation on progress report requirement—Contents— Subsection (b)(5) of section 318 of the Homeland Security Act of 2002, as amended by The assessment required under paragraph (1) of this subsection, shall not apply with respect to the first strategic plan transmitted under that section.include, at a minimum—
(A)
added an assessment of the readiness and capacity of the workforce of the Department to meet its cybersecurity mission;
(B)
added information on where cybersecurity workforce positions are located within the Department;
(C)
added information on which cybersecurity workforce positions are—
(i)
added performed by—
(I)
added permanent full-time equivalent employees of the Department, including, to the greatest extent practicable, demographic information about such employees;
(II)
added independent contractors; and
(III)
added individuals employed by other Federal agencies, including the National Security Agency; or
(ii)
added vacant; and
(D)
added information on—
(i)
added the percentage of individuals within each Cybersecurity Category and Specialty Area who received essential training to perform their jobs; and
(ii)
added in cases in which such essential training was not received, what challenges, if any, were encountered with respect to the provision of such essential training.
(b)
added Workforce strategy—
(1)
added In general— The Secretary shall—
(A)
added not later than 1 year after the date of enactment of this Act, develop a comprehensive workforce strategy to enhance the readiness, capacity, training, recruitment, and retention of the cybersecurity workforce of the Department; and
(B)
added maintain and, as necessary, update the comprehensive workforce strategy developed under subparagraph (A).
(2)
added Contents— The comprehensive workforce strategy developed under paragraph (1) shall include a description of—
(A)
added a multi-phased recruitment plan, including with respect to experienced professionals, members of disadvantaged or underserved communities, the unemployed, and veterans;
(B)
added a 5-year implementation plan;
(C)
added a 10-year projection of the cybersecurity workforce needs of the Department;
(D)
added any obstacle impeding the hiring and development of a cybersecurity workforce in the Department; and
(E)
added any gap in the existing cybersecurity workforce of the Department and a plan to fill any such gap.
(b)
removed Clerical amendment— The table of contents in section 1(b) of such Act is amended by adding at the end of the items relating to such title the following:
(c)
changed Critical infrastructure protection technology clearinghouse—Updates— Section 313 of the Homeland Security Act of 2002 (6 U.S.C. 193) is amended by redesignating subsection (c) as subsection (d), and by inserting after subsection (b) The Secretary submit to the following:appropriate congressional committees annual updates on—
(1)
added the cybersecurity workforce assessment required under subsection (a); and
(2)
added the progress of the Secretary in carrying out the comprehensive workforce strategy required to be developed under subsection (b).

removed “(c) Critical infrastructure protection technology clearinghouse

removed “(1) Designation—Under the program required by this section, the Secretary, acting through the Under Secretary for Science and Technology, and in coordination with the Under Secretary for the National Protection and Programs Directorate, shall designate a technology clearinghouse for rapidly sharing proven technology solutions for protecting critical infrastructure.

removed “(2) Sharing of technology solutions—Technology solutions shared through the clearinghouse shall draw from Government-furnished, commercially furnished, and publically available trusted sources.

removed “(3) Technology metrics—All technologies shared through the clearinghouse shall include a set of performance and readiness metrics to assist end-users in deploying effective and timely solutions relevant for their critical infrastructures.

removed “(4) Review by privacy officer—The Privacy Officer of the Department appointed under section 222 shall annually review the clearinghouse process to evaluate its consistency with fair information practice principles issued by the Privacy Officer.”

(d)
removed Evaluation of Technology Clearinghouse by Government Accountability Office— Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall conduct an independent evaluation of, and submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on, the effectiveness of the clearinghouses established and designated, respectively, under section 313 of the Homeland Security Act of 2002, as amended by this section.

Sec. 4 Cybersecurity Fellowship Program

changed No additional funds are authorized to be appropriated to carry out this Act and Not later than 120 days after the amendments made by date of enactment of this Act, the Secretary shall submit to the appropriate congressional committees a report on the feasibility, cost, and this Act benefits of establishing a Cybersecurity Fellowship Program to offer a tuition payment plan for individuals pursuing undergraduate and such amendments shall be carried out using amounts otherwise available doctoral degrees who agree to work for such purpose.the Department for an agreed-upon period of time.