US Codex
Bill
Notes

H.R. 1224 — what changed

NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017

From Introduced in House to Reported in House. 1 section amended between Introduced in House and Reported in House.

Sec. 3 Implementation of Cybersecurity Framework

The National Institute of Standards and Technology Act (15 U.S.C. 271 et seq.) is amended by inserting after section 20 the following:

“20A. Framework for Improving Critical Infrastructure Cybersecurity

changed “(a) Implementation by Federal agenciesagencies—The Institute shall promote the implementation by Federal agencies of the Framework for Improving Critical Infrastructure Cybersecurity (in this section and section 20B referred to as the “Framework”) by providing to the Office of Management and Budget, the Office of Science and Technology Policy, and all other Federal agencies, not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, guidance that Federal agencies may use to incorporate the Framework into their information security risk management efforts, including practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law.

changed “(1) In general—The Institute shall promote the implementation by Federal agencies of the Framework for Improving Critical Infrastructure Cybersecurity (in this section and section 20B referred to as the “Framework”) by providing to the Office of Management and Budget, the Office of Science and Technology Policy, and all other Federal agencies, not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, “(b) Guidance—The guidance that Federal agencies may use to incorporate the Framework into their information security risk management efforts, including practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law.required under subsection (a) shall—

changed “(2) Guidance—The guidance required under paragraph (1) shall—“(1) describe how the Framework aligns with or augments existing agency practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law;

changed “(A) describe how “(2) identify any areas of conflict or overlap between the Framework aligns with or augments and existing agency practices related cybersecurity requirements, including gap areas where additional policies, standards, guidelines, or programs may be needed to compliance with chapter 35 of title 44, United States Code, encourage Federal agencies to use the Framework and any other applicable improve the ability of Federal law;agencies to manage cybersecurity risk;

changed “(B) identify any areas of conflict or overlap between the Framework and existing cybersecurity requirements, including gap areas where additional policies, standards, guidelines, or programs may be needed to encourage “(3) include a template for Federal agencies on how to use the Framework Framework, and improve recommend procedures for streamlining and harmonizing existing and future cybersecurity-related requirements, in support of the ability goal of Federal agencies using the Framework to manage cybersecurity risk;supplant Federal agency practices in compliance with chapter 35 of title 44, United States Code;

changed “(C) include a template for Federal agencies on how to use the Framework, and “(4) recommend other procedures for streamlining and harmonizing existing and future cybersecurity-related requirements, in support of the goal of using the Framework to supplant Federal agency practices in compliance with cybersecurity reporting, oversight, and policy review and creation requirements under such chapter 35 of title 44, United States Code;and any other applicable Federal law; and

changed “(D) recommend other procedures for compliance with cybersecurity reporting, oversight, and policy review and creation requirements under such chapter 35 and any other applicable “(5) be updated, as the Institute considers necessary, to reflect what the Institute learns from ongoing research, the audits conducted pursuant to section 20B(c), the information compiled by the Federal law; andworking group established pursuant to subsection (c), and the annual reports published pursuant to subsection (d).

changed “(E) be updated, as the Institute considers necessary, to reflect what the Institute learns from ongoing research, “(c) Federal working group—Not later than 3 months after the audits conducted pursuant to section 20B(b), date of enactment of the information compiled by NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Federal Institute shall establish and chair a working group established pursuant (in this section referred to paragraph (3), the information compiled by as the public-private “Federal working group established pursuant to subsection (b)(1), group”), including representatives of the annual reports published pursuant to paragraph (4), Office of Management and Budget, the annual reports published pursuant to subsection (b)(2).Office of Science and Technology Policy, and other appropriate Federal agencies, which shall—

changed “(3) Federal working group—Not “(1) not later than 3 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall establish develop outcome-based and chair a working group (in this section referred quantifiable metrics to as the “Federal working group”), including representatives help Federal agencies in their analysis and assessment of the Office effectiveness of Science and Technology Policy the Framework in protecting their information and other appropriate Federal agencies, which shall—information systems;

changed “(A) not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop outcome-based and quantifiable metrics, in coordination with “(2) update such metrics as the public-private Federal working group established pursuant to subsection (b), to help Federal agencies in their analysis and assessment of the effectiveness of the Framework in protecting their information and information systems;considers necessary;

changed “(B) update such metrics as the “(3) compile information from Federal working group considers necessary;agencies on their use of the Framework and the results of the analysis and assessment described in paragraph (1); and

changed “(C) compile information from Federal agencies on their use of “(4) assist the Framework Office of Management and Budget and the results Office of the analysis Science and assessment described Technology Policy in subparagraph (A); andpublishing the annual report required under subsection (d).

changed “(D) assist “(d) Report—The Office of Management and Budget and the Office of Science and Technology Policy in publishing the shall develop and make publicly available an annual report required under paragraph (4).on agency adoption rates and the effectiveness of the Framework. In preparing such report, the Offices shall use the information compiled by the Federal working group pursuant to subsection (c)(3).

removed “(4) Report—The Office of Science and Technology Policy shall develop and make publicly available an annual report on agency adoption rates and the effectiveness of the Framework. In preparing such report, the Office shall use the information compiled by the Federal working group pursuant to paragraph (3)(C).

removed “(b) Implementation by private entities

removed “(1) Public-private working group—Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall, in coordination with industry stakeholders, establish a working group (in this section referred to as the “public-private working group”) which shall—

removed “(A) not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop specific Framework implementation models and measurement tools that private entities can use to adopt the Framework;

removed “(B) not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop, in coordination with the Federal working group, industry-led, consensus and outcome-based metrics that quantify the effectiveness and benefits of the Framework to enable private entities to voluntarily analyze and assess their individual corporate cybersecurity risks;

removed “(C) update the models and tools developed pursuant to subparagraph (A) and the metrics developed pursuant to subparagraph (B), as the public-private working group considers necessary;

removed “(D) compile information, derived from the metrics developed pursuant to subparagraph (B), voluntarily submitted by private entities on their use of the Framework and on the effectiveness and benefits of such use;

removed “(E) analyze the information compiled pursuant to subparagraph (D) and provide such information and analysis to—

removed “(i) the Institute, for the purpose of enabling the Institute to make improvements to the Framework; and

removed “(ii) private entities, for the purpose of providing such entities with a greater understanding of the benefits of the Framework to enable them to use the Framework more effectively to improve their cybersecurity; and

removed “(F) assist the Office of Science and Technology Policy in publishing the annual report required under paragraph (2).

removed “(2) Report—The Office of Science and Technology Policy shall develop and make publicly available an annual report on industry adoption rates and the effectiveness of the Framework. In preparing such report, the Office shall use information compiled by the public-private working group pursuant to paragraph (1)(D).

“20B. Cybersecurity audits

“(a) Initial assessment

“(1) Requirement—Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall complete an initial assessment of the cybersecurity preparedness of the agencies described in paragraph (2). Such assessment shall be based on information security standards developed under section 20, and may also be informed by work done or reports published by other Federal agencies or officials.

added “(2) Agencies—The agencies referred to in paragraph (1) are the agencies referred to in section 901(b) of title 31, United States Code, and any other agency that has reported a major incident (as defined in the Office of Management and Budget Memorandum—16—03, published on October 30, 2015, or any successor document).

removed “(2) Agencies—The agencies referred to in paragraph (1) are the agencies referred to in section 901(b) of title 31, United States Code, and any other agency that has reported a major incident (as defined in the Office of Management and Budget Memorandum—16–03, published on October 30, 2015, or any successor document).

“(3) National security systems—The requirement under paragraph (1) shall not apply to national security systems (as defined in section 3552(b) of title 44, United States Code).

added “(b) Audit plan—Not later than 6 months after the date of enactment of this Act, the Institute shall prepare a needs-based plan for carrying out the audits of agencies as required under subsection (c). Such plan shall include a description of staffing plans, workforce capabilities, methods for conducting such audits, coordination with agencies to support such audits, expected timeframes for the completion of audits, and other information the Institute considers relevant. The plan shall be transmitted by the Institute to the congressional entities described in subsection (c)(4)(F).

added “(c) Audits

removed “(b) Audits

“(1) Requirement—Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall initiate an individual cybersecurity audit of each agency described in subsection (a)(2), to assess the extent to which the agency is meeting the information security standards developed under section 20.

“(2) Relation to Framework—Audits conducted under this subsection shall—

added “(A) to the extent applicable and available, be informed by the report on agency adoption rates and the effectiveness of the Framework described in section 20A(d); and

added “(B) if the agency is required by law or executive order to adopt the Framework, be based on the guidance described in section 20A(b) and metrics developed under section 20A(c)(1).

removed “(A) to the extent applicable and available, be informed by the report on agency adoption rates and the effectiveness of the Framework described in section 20A(a)(4); and

removed “(B) if the agency is required by law or Executive order to adopt the Framework, be based on the guidance described in section 20A(a)(2) and metrics developed under section 20A(a)(3)(A).

“(3) Schedule—The Institute shall establish a schedule for completion of audits under this subsection to ensure that—

“(A) audits of agencies whose information security risk is high, based on the assessment conducted under subsection (a), are completed not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, and are audited annually thereafter; and

“(B) audits of all other agencies described in subsection (a)(2) are completed not later than 2 years after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, and are audited biennially thereafter.

“(4) Report—A report of each audit conducted under this subsection shall be transmitted by the Institute to—

“(A) the Office of Management and Budget;

“(B) the Office of Science and Technology Policy;

“(C) the Government Accountability Office;

“(D) the agency being audited;

“(E) the Inspector General of such agency, if there is one; and

“(F) Congress, including the Committee on Science, Space, and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate.”