Title II — Federal Cybersecurity Enhancement
II Federal Cybersecurity Enhancement
Sec. 202 Definitions
Sec. 203 Improved Federal network security
“228. Cybersecurity plans
“(a) Definitions—In this section—
“(1) the term agency information system means an information system used or operated by an agency or by another entity on behalf of an agency;
“(2) the terms cybersecurity risk and information system have the meanings given those terms in section 227;
“(3) the term intelligence community has the meaning given the term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)); and
“(4) the term national security system has the meaning given the term in section 11103 of title 40, United States Code.
“(b) Intrusion assessment plan
“(1) Requirement—The Secretary, in coordination with the Director of the Office of Management and Budget, shall develop and implement an intrusion assessment plan to identify and remove intruders in agency information systems.
“(2) Exception—The intrusion assessment plan required under paragraph (1) shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.”
“230. Federal intrusion detection and prevention system
“(a) Definitions—In this section—
“(1) the term agency has the meaning given that term in section 3502 of title 44, United States Code;
“(2) the term agency information means information collected or maintained by or on behalf of an agency;
“(3) the term agency information system has the meaning given the term in section 228; and
“(4) the terms cybersecurity risk and information system have the meanings given those terms in section 227.
“(b) Requirement
“(1) In general—Not later than 1 year after the date of enactment of this section, the Secretary shall deploy, operate, and maintain, to make available for use by any agency, with or without reimbursement—
“(A) a capability to detect cybersecurity risks in network traffic transiting or traveling to or from an agency information system; and
“(B) a capability to prevent network traffic associated with such cybersecurity risks from transiting or traveling to or from an agency information system or modify such network traffic to remove the cybersecurity risk.
“(2) Regular improvement—The Secretary shall regularly deploy new technologies and modify existing technologies to the intrusion detection and prevention capabilities described in paragraph (1) as appropriate to improve the intrusion detection and prevention capabilities.
“(c) Activities—In carrying out subsection (b), the Secretary—
“(1) may access, and the head of an agency may disclose to the Secretary or a private entity providing assistance to the Secretary under paragraph (2), information transiting or traveling to or from an agency information system, regardless of the location from which the Secretary or a private entity providing assistance to the Secretary under paragraph (2) accesses such information, notwithstanding any other provision of law that would otherwise restrict or prevent the head of an agency from disclosing such information to the Secretary or a private entity providing assistance to the Secretary under paragraph (2);
“(2) may enter into contracts or other agreements with, or otherwise request and obtain the assistance of, private entities to deploy and operate technologies in accordance with subsection (b);
“(3) may retain, use, and disclose information obtained through the conduct of activities authorized under this section only to protect information and information systems from cybersecurity risks;
“(4) shall regularly assess through operational test and evaluation in real world or simulated environments available advanced protective technologies to improve detection and prevention capabilities, including commercial and non-commercial technologies and detection technologies beyond signature-based detection, and utilize such technologies when appropriate;
“(5) shall establish a pilot to acquire, test, and deploy, as rapidly as possible, technologies described in paragraph (4);
“(6) shall periodically update the privacy impact assessment required under section 208(b) of the E-Government Act of 2002 (44 U.S.C. 3501 note); and
“(7) shall ensure that—
“(A) activities carried out under this section are reasonably necessary for the purpose of protecting agency information and agency information systems from a cybersecurity risk;
“(B) information accessed by the Secretary will be retained no longer than reasonably necessary for the purpose of protecting agency information and agency information systems from a cybersecurity risk;
“(C) notice has been provided to users of an agency information system concerning access to communications of users of the agency information system for the purpose of protecting agency information and the agency information system; and
“(D) the activities are implemented pursuant to policies and procedures governing the operation of the intrusion detection and prevention capabilities.
“(d) Private entities
“(1) Conditions—A private entity described in subsection (c)(2) may not—
“(A) disclose any network traffic transiting or traveling to or from an agency information system to any entity without the consent of the Department or the agency that disclosed the information under subsection (c)(1); or
“(B) use any network traffic transiting or traveling to or from an agency information system to which the private entity gains access in accordance with this section for any purpose other than to protect agency information and agency information systems against cybersecurity risks or to administer a contract or other agreement entered into pursuant to subsection (c)(2) or as part of another contract with the Secretary.
“(2) Limitation on liability—No cause of action shall lie in any court against a private entity for assistance provided to the Secretary in accordance with this section and any contract or agreement entered into pursuant to subsection (c)(2).
“(3) Rule of construction—Nothing in paragraph (2) shall be construed to authorize an Internet service provider to break a user agreement with a customer without the consent of the customer.
“(e) Attorney General review—Not later than 1 year after the date of enactment of this section, the Attorney General shall review the policies and guidelines for the program carried out under this section to ensure that the policies and guidelines are consistent with applicable law governing the acquisition, interception, retention, use, and disclosure of communications.”
Sec. 204 Advanced internal defenses
Sec. 205 Federal cybersecurity requirements
Sec. 206 Assessment; reports
Sec. 207 Termination
Sec. 208 Identification of information systems relating to national security
Sec. 209 Direction to agencies
“(h) Direction to agencies
“(1) Authority
“(A) In general—Subject to subparagraph (B), in response to a known or reasonably suspected information security threat, vulnerability, or incident that represents a substantial threat to the information security of an agency, the Secretary may issue an emergency directive to the head of an agency to take any lawful action with respect to the operation of the information system, including such systems used or operated by another entity on behalf of an agency, that collects, processes, stores, transmits, disseminates, or otherwise maintains agency information, for the purpose of protecting the information system from, or mitigating, an information security threat.
“(B) Exception—The authorities of the Secretary under this subsection shall not apply to a system described subsection (d) or to a system described in paragraph (2) or (3) of subsection (e).
“(2) Procedures for use of authority—The Secretary shall—
“(A) in coordination with the Director, establish procedures governing the circumstances under which a directive may be issued under this subsection, which shall include—
“(i) thresholds and other criteria;
“(ii) privacy and civil liberties protections; and
“(iii) providing notice to potentially affected third parties;
“(B) specify the reasons for the required action and the duration of the directive;
“(C) minimize the impact of a directive under this subsection by—
“(i) adopting the least intrusive means possible under the circumstances to secure the agency information systems; and
“(ii) limiting directives to the shortest period practicable;
“(D) notify the Director and the head of any affected agency immediately upon the issuance of a directive under this subsection;
“(E) consult with the Director of the National Institute of Standards and Technology regarding any directive under this subsection that implements standards and guidelines developed by the National Institute of Standards and Technology;
“(F) ensure that directives issued under this subsection do not conflict with the standards and guidelines issued under section 11331 of title 40;
“(G) consider any applicable standards or guidelines developed by the National Institute of Standards and issued by the Secretary of Commerce under section 11331 of title 40; and
“(H) not later than February 1 of each year, submit to the appropriate congressional committees a report regarding the specific actions the Secretary has taken pursuant to paragraph (1)(A).
“(3) Imminent threats
“(A) In general—Notwithstanding section 3554, the Secretary may authorize the intrusion detection and prevention capabilities under section 230(b)(1) of the Homeland Security Act of 2002 for the purpose of ensuring the security of agency information systems, if—
“(i) the Secretary determines there is an imminent threat to agency information systems;
“(ii) the Secretary determines a directive under subsection (b)(2)(C) or paragraph (1)(A) is not reasonably likely to result in a timely response to the threat;
“(iii) the Secretary determines the risk posed by the imminent threat outweighs any adverse consequences reasonably expected to result from the use of protective capabilities under the control of the Secretary;
“(iv) the Secretary provides prior notice to the Director, and the head and chief information officer (or equivalent official) of each agency to which specific actions will be taken pursuant to subparagraph (A), and notifies the appropriate congressional committees and authorizing committees of each such agencies within seven days of taking an action under this subsection of—
“(I) any action taken under this subsection; and
“(II) the reasons for and duration and nature of the action;
“(v) the action of the Secretary is consistent with applicable law; and
“(vi) the Secretary authorizes the use of protective capabilities in accordance with the advance procedures established under subparagraph (C).
“(B) Limitation on delegation—The authority under this subsection may not be delegated by the Secretary.
“(C) Advance procedures—The Secretary shall, in coordination with the Director, and in consultation with the heads of Federal agencies, establish procedures governing the circumstances under which the Secretary may authorize the use of protective capabilities subparagraph (A). The Secretary shall submit the procedures to Congress.
“(4) Limitation—The Secretary may direct or authorize lawful action or protective capability under this subsection only to—
“(A) protect agency information from unauthorized access, use, disclosure, disruption, modification, or destruction; or
“(B) require the remediation of or protect against identified information security risks with respect to—
“(i) information collected or maintained by or on behalf of an agency; or
“(ii) that portion of an information system used or operated by an agency or by a contractor of an agency or other organization on behalf of an agency.
“(i) Annual report to Congress—Not later than February 1 of each year, the Director shall submit to the appropriate congressional committees a report regarding the specific actions the Director has taken pursuant to subsection (a)(5), including any actions taken pursuant to section 11303(b)(5) of title 40.
“(j) Appropriate congressional committees defined—In this section, the term appropriate congressional committees means—
“(1) the Committee on Appropriations and the Committee on Homeland Security and Governmental Affairs of the Senate; and
“(2) the Committee on Appropriations, the Committee on Homeland Security, the Committee on Oversight and Government Reform, and the Committee on Science, Space, and Technology of the House of Representatives.”
“(v) emergency directives issued by the Secretary under section 3553(h); and”