Cybersecurity Responsibility and Accountability Act of 2016
A BILL
To enforce Federal cybersecurity responsibility and accountability.
Sec. 2 Definitions
“(6) The term “major cybersecurity incident” has the meaning given the term “major incident” in Office of Management and Budget Memorandum M–16–03, dated October 30, 2015, or any successor document.”
Sec. 3 Authority and functions of the Director of NIST
“(c) Director of the National Institute of Standards and Technology—The Director of the National Institute of Standards and Technology shall further develop and update as necessary the standards and guidelines under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) to fulfill the additional objectives and requirements of the Cybersecurity Responsibility and Accountability Act of 2016. Further, the Director of the National Institute of Standards and Technology shall—
“(1) provide to the Director of the Office of Management and Budget a framework and process for agency implementation of such standards and guidelines;
“(2) provide support to agency heads for the implementation of such standards and guidelines and their application to information security policies and principles, as well as with the development of information security training and certification for agency heads;
“(3) conduct cybersecurity research—
“(A) to identify and address prevalent information security challenges, concerns, and knowledge gaps identified by agencies, including those manifested in any of the reports, evaluations, assessments, and plans described in this subchapter that may undermine agencies’ information security policies and practices;
“(B) to assess the sufficiency of the current statutory requirements of the Federal Information Security Management Act of 2002 and the Federal Information Security Modernization Act of 2014, and their effectiveness in requiring agencies to implement standards and guidelines developed under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) and authorized by the Cybersecurity Responsibility and Accountability Act of 2016 regarding information security policies and practices; and
“(C) that shall require the Director of the Office of Management and Budget, the Secretary of Homeland Security, and the heads of other Federal agencies to provide the Director of the National Institute of Standards and Technology any resources, including reports, evaluations, assessments, and plans, that may be required for such research; and
“(4) develop, publish, and update as necessary information security standards and guidelines for national security systems based on established standards and guidelines for information systems.”
Sec. 4 Agency heads
Sec. 5 Federal agency head responsibilities
“(i) have the job description and responsibilities that shall be provided in guidance issued by the Director, developed in consultation with the Director of the National Institute of Standards and Technology and the Secretary, within 6 months after the date of enactment of the Cybersecurity Responsibility and Accountability Act of 2016;”
“(vi) be designated without increasing the number of full-time equivalent employee positions at the agency;”
“(5) mandatory annual information security training and certification designed specifically for the agency head, developed and updated as necessary by the National Institute of Standards and Technology, the purpose of which shall be to ensure that the agency head has an understanding of Federal cybersecurity policy, including an understanding of—
“(A) the information and information systems that support the operations and assets of the agency, using nontechnical terms as much as possible;
“(B) the potential impact of common types of cyber-attacks and data breaches on the agency’s operations and assets;
“(C) how cyber-attacks and data breaches occur;
“(D) steps the agency head and agency employees should take to protect their information and information systems, including not using private messaging system software or private e-mail servers for official communications; and
“(E) the annual reporting requirements required of the agency head under subsection (c), including the certifications required under subsection (c)(1)(A)(iv);”
“(iv) specific written certification by the agency head that—
“(I) certifies that information security standards developed under section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) are being met by the agency;
“(II) identifies the security controls in place at the agency and how they each meet the relevant information security standard;
“(III) may be based on or informed by the assessment described in section 3553(d)(4); and
“(IV) for any information security standard that the agency does not meet, provides the reasons therefor and includes documentation of the Director’s certification of the agency not meeting the standard; and”
“(e) Plans for implementation of recommendations
“(1) Comptroller General recommendations
“(A) In general—In addition to the requirements of subsections (c) and (d), each agency head shall, not later than 6 months after the date of enactment of the Cybersecurity Responsibility and Accountability Act of 2016, develop a plan, in consultation with the Comptroller General, to implement all of the Comptroller General’s recommendations regarding information security controls relevant to that agency.
“(B) Plan—The plan required under subparagraph (A)—
“(i) shall be submitted to the agencies and committees described in subsection (c)(1)(A);
“(ii) shall include a schedule for implementation of the Comptroller General’s recommendations, including a completion deadline;
“(iii) shall be updated annually, and such annual updates shall be included in the annual report described in subsection (c)(1)(A); and
“(iv) may, as appropriate, be based on or informed by recommendations included in the evaluation and report described in section 3555(h).
“(C) If no recommendations—If the Comptroller General does not have any relevant recommendations for an agency head to implement relative to information security controls, then the agency head shall accordingly notify the agencies and committees described in subsection (c)(1)(A).
“(D) Reasons for failure to implement—If there are any Comptroller General recommendations that an agency head does not implement, the agency head shall provide the reasons for that failure to the Director for the Director’s approval. For each unimplemented recommendation, the plan shall include either the Director’s approval or a certification by the Director of the agency head’s failure to implement such recommendation.
“(2) Inspector General recommendations
“(A) In general—In addition to the requirements of subsections (c) and (d), each agency head shall, not later than 6 months after the date of enactment of the Cybersecurity Responsibility and Accountability Act of 2016, develop a plan, in consultation with its Inspector General, to implement all of the Inspector General’s recommendations regarding the agency’s information security program.
“(B) Plan—The plan required under subparagraph (A)—
“(i) shall be submitted to the agencies and committees described in subsection (c)(1)(A);
“(ii) shall include a schedule for implementation of the Inspector General’s recommendations, including a completion deadline;
“(iii) shall be updated annually, and such annual updates shall be included in the annual report described in subsection (c)(1)(A); and
“(iv) may, as appropriate, be based on or informed by recommendations included in—
“(I) the evaluation described in section 3555(b)(1); or
“(II) if the agency does not have an Inspector General, the evaluation described in section 3555(b)(2).
“(C) If no recommendations—If the Inspector General does not have any relevant information security control recommendations for the agency head to implement, then the agency head shall accordingly notify the agencies and committees described in subsection (c)(1)(A).
“(D) Reasons for failure to implement—If there are any Inspector General recommendations that the agency head does not implement, the agency head shall provide the reasons for that failure to the Director for the Director’s approval. For each unimplemented recommendation, the plan shall include either the Director’s approval or a certification by the Director of the agency head’s failure to implement such recommendation.”
Sec. 6 Annual independent evaluation
Sec. 7 Major cybersecurity incident independent evaluations
“3555a. Major cybersecurity incident independent evaluations
“(a) Requirement—Each time an agency experiences a major cybersecurity incident, the agency head shall have performed an independent evaluation of such incident.
“(b) Inclusions—An evaluation of a major cybersecurity incident under this section shall be transmitted by the agency head to the agencies and committees described in section 3554(c)(1)(A), and shall include—
“(1) a description of each major cybersecurity incident including—
“(A) threats and threat actors, vulnerabilities, and impacts, including whether the incident involved information that is classified, controlled unclassified information proprietary, controlled unclassified information privacy, or controlled unclassified information other, as these terms are defined in Office of Management and Budget Memorandum M–16–03, dated October 30, 2015, or any successor document;
“(B) risk assessments conducted on the system before the incident;
“(C) the status of compliance of the affected information system with information security requirements at the time of the incident, including—
“(i) information security control recommendations made by the agency’s Inspector General that are part of the plan described in section 3554(e)(2);
“(ii) information security control recommendations made by the Comptroller General that are part of the plan described in section 3554(e)(1); and
“(iii) National Institute of Standards and Technology information security standards that are part of the agency head’s certification described in section 3554(c)(1)(A)(iv);
“(D) the detection, response, and remediation actions the agency has completed; and
“(E) recommendations for research, process, and policy actions the agency should consider taking in response to the incident and to help prevent future incidents of a similar nature; and
“(2) for each major cybersecurity incident involving a breach of personally identifiable information—
“(A) the number of individuals whose information was affected by the incident and a description of the information that was breached or exposed;
“(B) an assessment of the risk of harm to affected individuals; and
“(C) details of whether and when the agency provided notice to affected individuals about the data breach, including what protections were offered by the breached agency.
“(c) Enforcement
“(1) In general—If an evaluation of a major cybersecurity incident described in subsection (a) determines that the major cybersecurity incident occurred in part or in whole because the agency head had failed to comply sufficiently with the information security requirements, recommendations, or standards described in subsection (b)(1)(C), the Director shall, within 60 days of receiving the evaluation, take action under paragraph (2).
“(2) Enforcement actions—Enforcement actions the Director may take under this subsection are—
“(A) actions described in section 11303(b)(5) of title 40, United States Code; and
“(B) either—
“(i) recommending to the President the removal or demotion of the agency head; or
“(ii) action to ensure the agency head does not receive any cash or pay awards or bonuses for a period of 1 year after submission of the explanation required under paragraph (3).
“(3) Explanation—The Director shall provide a detailed explanation for enforcement actions taken under paragraph (2), or for a decision not to act, to the committees described in section 3554(c)(1)(A).”