Department of Veterans Affairs Cyber Security Protection Act
A BILL
To amend title 38, United States Code, to make certain improvements in the information security of the Department of Veterans Affairs, and for other purposes.
Sec. 2 Department of Veterans Affairs information security improvements
“(17) Submitting to the Chairs and Ranking Members of the Committees on Veterans’ Affairs of the Senate and House of Representatives, by not later than 30 days after the last day of each fiscal quarter, a summary of any plans of action and milestones for any known information security vulnerability, as identified pursuant to a widely accepted industry or Government standard, that includes—
“(A) specific information about the industry or Government standard used to identify the known information security vulnerability;
“(B) a detailed timeline with specific deadlines for addressing the known information security vulnerability; and
“(C) an update of any previously specified timeline and the rationale for any deviations from such timeline.”
“(18) Submitting to the Committees on Veterans’ Affairs of the Senate and House of Representatives, by not later than January 1 of each year, a plan for identifying and replacing operating systems of the Department that are unsupported and that includes—
“(A) in the case of an operating system other than an operating system covered under subparagraph (C), requirements that the operating system be removed from the network of the Department no later than 15 days after the date on which the operating system is identified as being out-of-date or unsupported;
“(B) information concerning the number of systems so identified during the year preceding the year in which the report is submitted, when each such system was so identified, and when each system so identified was removed from the network of the Department; and
“(C) in the case of an operating system the Secretary determines is essential for the proper operation of any medical device or equipment, a description of the operating system and a detailed discussion of steps taken to ensure the security of the operating system.”
“(19) Ensuring that any software or Internet applications used on systems by the Department are as secure as practicable from any known vulnerabilities that could affect the confidentiality of sensitive personal information of veterans.”
Sec. 3 Information technology reporting requirements
“5727. Reporting requirements
“Not later than 30 days after the last day of each fiscal quarter, the Secretary shall submit to the Committees on Veterans’ Affairs of the Senate and House of Representatives a report that includes the following information for that fiscal quarter:
“(1) A detailed description of any incidents of failure to comply with established information security policies that occurred during that quarter.
“(2) Any actions taken in response to such an incident.
“(3) Any reports made under paragraphs (8) through (10) of subsection (b) of section 5723 of this title during that quarter.
“(4) Written certification that the requirements of section 5722(c) of this title were followed during that quarter.
“(5) A detailed discussion of whether each recommendation made by the National Institute of Standards and Technology, the Office of Management and Budget, or the Department of Homeland Security relating to information security have been implemented by the Department, and if not, an explanation of why such recommendation was not implemented.
“(6) Steps taken to ensure the security of the Veterans Health Information Systems and Technology Architecture of the Department that allows for an integrated inpatient and outpatient electronic health record for patients and provides administrative tools to employees of the Department taken during that quarter.
“5728. Information security strategic plan
“(a) Plan required—Not later than one year after the date of the enactment of this section, the Secretary shall submit to the Committees on Veterans’ Affairs of the Senate and House of Representatives a strategic plan for improving the information security and information technology infrastructure of the Department. Such plan shall address—
“(1) an information security plan for protecting the sensitive personal information of veterans while not unduly interfering with the ability of the Department to provide benefits and services to veterans and their dependents;
“(2) how the Department can improve its compliance with information security requirements;
“(3) training and recruitment of employees with the necessary expertise and abilities in information security; and
“(4) the institutional capability of the Department to address information security threats and to implement best practices related to information security.
“(b) Biannual updates—The Secretary shall submit to the Committees on Veterans’ Affairs of the Senate and House of Representatives biannual updates to the plan required by subsection (a).”
Sec. 4 Requirements for Department of Veterans Affairs contracts for data processing or maintenance
“(3) the contractor shall provide protective measures to safeguard from possible information security threats any information provided by the Department that will be resident on or transiting through information systems controlled by the contractor.”