US Codex
Bill
Notes

Title II — Post-Secondary Computer and Information Security Education

H.R. 1981 · 115th Congress · Apr 6, 2017 · Lineage

II Post-Secondary Computer and Information Security Education

Sec. 201 Computing and Information Research Working Group

(a)
Establishment— There is hereby established in the Department of Homeland Security the Computing and Information Security Post-Secondary Education Working Group, hereafter in this section referred to as the “Working Group”.
(b)
Responsibilities— The Working Group shall conduct research and—
(1)
assist the Secretary in developing voluntary guidelines that could serve as guidance to Federal civil agency training programs, computer and information security certification authorities, and accreditation bodies seeking guidance on developing, enhancing, or sustaining competitive information security; and
(2)
make recommendations to the Secretary regarding—
(A)
the state of the computing and information security workforce development;
(B)
evaluations and reports on the advantages, disadvantages, and approaches to professionalizing the Nation’s computing and information security workforce;
(C)
criteria that can be used to identify which, if any, specialty areas may require professionalization;
(D)
criteria for evaluating different approaches and tools for professionalization;
(E)
techniques that enhance the efficiency and effectiveness of computing and information security workers;
(F)
better tools and approaches for risk identification and assessment;
(G)
improved system design and development;
(H)
creation of better incentives for deployment of better computing and information security technologies;
(I)
improvements in end user behaviors through training and better coordination among network managers;
(J)
core curriculum requirements for computing and information security training;
(K)
efficacy and efficiencies of taxonomy and definitions for computer and information security;
(L)
guidelines for accreditations and certification of computing and information security college and university programs;
(M)
identifying the role of mentors in the retention of students enrolled in computing and technology programs at institutions of higher education who complete degree programs;
(N)
remote access to computing and information security education and training through the Internet; and
(O)
institution of higher education funding and research needs.
(c)
Deadline for submittal of research funding and recommendations—
(1)
Initial research— The Working Group shall submit to the Secretary an initial research plan that will guide the work of the Working Group.
(2)
Other research recommendations— The Working Group shall provide the Secretary a list of other areas that require research to accomplish the purpose of the agency’s goal of providing cyber security protection for the agency. The Working Group shall provide a description of the proposed research and the purpose of the research as it relates to the goals of cybersecurity of the agency.
(3)
Initial recommendations— The Working Group shall submit to the Secretary initial recommendations under this section by not later than nine months after the date on which all of the members of the Working Group are appointed.
(4)
Other recommendations— Not later than six months after all members of the Working Group are appointed, the Working Group shall submit to the Secretary research and recommendations on the effectiveness of Federal civil agency computer and information security training programs, including an evaluation of certification authorities and their role in providing work ready staff to fill positions with the agency.
(5)
Subsequent research and recommendations— Not later than one year after the date of the submittal of the initial research and recommendations under paragraph (1), and annually thereafter, the Working Group shall submit to the Secretary subsequent research and recommendations under this section and an update on the progress made toward a well trained and sustainable Department computer and information workforce.
(d)
Membership—
(1)
Chair— The Chair of the Working Group shall be the Director of the National Institute of Standards and Technology or the Director’s designee.
(2)
Other members— The Working Group shall be composed of 21 members, who are appointed by the Secretary of Homeland Security in consultation with the Director of NIST and the head of the entity represented by the member.
(3)
Appointment— All appointments are for a term of 2 years with one reappointment for an additional 2 years.
(4)
Quorum— A majority of the members of the Working Group shall constitute a quorum.
(e)
No compensation for service— While away from their homes or regular places of business in the performance of services for the Commission, members of the Commission shall be allowed travel expenses, including per diem in lieu of subsistence, in the same manner as persons employed intermittently in the Government service are allowed expenses under section 5703(b) of title 5, United States Code.
(f)
Technical support from the Department of Homeland Security— At the request of the Working Group, the Secretary of Homeland Security shall provide the Working Group with technical support necessary for the Working Group to carry out its duties under this section.
(g)
Intellectual property rights— No private-sector individual or entity shall obtain any intellectual property rights to any guidelines or recommendations nor the contents of any guideline (or any modification to any guideline) adopted by the Secretary under this section.
(h)
Report— Not later than one year after the date of the enactment of this Act, the Working Group shall submit to the Secretary a report containing researching findings, an outline for other areas requiring research and why as well as recommendations of the Working Group.
(i)
Submittal of recommendations to Congress— Not later than 18 months after the date of the enactment of this Act, the Secretary shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the research findings, an outline of other areas requiring research and why and recommendations for furthering the cybersecurity of the agency.
(j)
Treatment of recommendations— The Secretary has the benefit of the Working Group’s work which the Secretary may accept, reject, or modify. The Secretary shall not be bound by the recommendations of the Working Group.
(k)
Publication of recommendations in Federal Register— The Secretary shall approve the publication of grant application guidelines in the Federal Register by not later than 90 days after receiving the report submitted under subsection (h).
(l)
Applicability of FACA— Nothing in the Federal Advisory Committee Act (5 U.S.C. App.; relating to the termination of advisory committees) shall apply to the Working Group.

Sec. 202 Process for adoption research and a best practices voluntary guidelines for laboratory facilities

(a)
Establishment of the Post-Secondary Laboratory Development Task Force— The Secretary of Homeland Security shall establish a “Post-Secondary Laboratory Research Development Task Force” (hereinafter in this section referred to as the “Development Task Force”).
(b)
Responsibilities— The Development Task Force shall conduct research for and make recommendations to the Secretary regarding best practices voluntary guidelines for college and university laboratory facilities for education and research purposes related to information assurance, cybersecurity and computing security. Such research on what baseline equipment, capacity, skilled instruction, and certification may be needed for a set of best practices voluntary guidelines for colleague or university laboratories and make recommendations on the best methods of assuring that the greatest number of institutions have access to facilities that meet the baseline best practices regarding—
(1)
qualifications for laboratories for the purpose of providing education or instruction in computing security, computer networks, enterprises, informatics, and other systems designated by the Secretary;
(2)
types of software;
(3)
types of hardware;
(4)
types of firmware;
(5)
security applications, including firewalls, whole hat hackers, red teams, and blue teams;
(6)
security protocols needed to protect the physical and computer resources of the laboratory;
(7)
accreditation and certification of college and university computer and information security laboratories;
(8)
best practices for—
(A)
public-private collaborations to support secondary and post-secondary laboratory facilities for computer or information security;
(B)
visiting guest lecture programs for business and Government information technology security experts; and
(C)
developing real world laboratory exercise and proficiency measures; and
(9)
how best to recruit and retain instructors with requisite degrees to teach computer and information security courses to undergraduate and graduate students.
(c)
Membership—
(1)
Members— The Development Task Force shall be composed of 19 members, including the Chair. The Secretary of Homeland Security, in consultation with the head of the entity represented by the member agencies, shall appoint members. The Secretary shall appoint a chair from among the members of the Development Task Force. Such members shall consist of one representative of each of the following agencies:
(A)
The White House Office of Science and Technology Policy.
(B)
The Office of the Director of National Intelligence.
(C)
The Department of Energy.
(D)
The Defense Advanced Research Projects Agency.
(E)
The Department of Commerce.
(F)
The National Institutes of Health.
(G)
The National Institute of Science and Technology.
(H)
The National Science Foundation.
(I)
The Director of the Office of Personnel Management.
(2)
Other members— The Secretary shall consider for the other members of the Development Task Force representatives from organizations that advocate and promote professional development of professional and academic under represented areas and organizations with the mission of promoting professional development and academic excellence in information assurance, cybersecurity and computing security:
(A)
Organizations with the mission of advancing computing as a science and profession.
(B)
Organizations that promote information system security education.
(C)
Professional associations that are well established and broadly recognized for the advancement of technology.
(D)
Professional associations that represent professionals and academics referred to in section 230A of the Homeland Security Act of 2002, as added by section 101.
(E)
K–12 science and technology programs that conduct successful after school and summer programs for under represented populations, rural communities and serve communities where unemployment is at least two percent higher than the national average.
(F)
Organizations that promote education of Native Americans or other indigenous peoples of the United States or its territories.
(G)
Regional diversity of public and private school districts that excel at science and technology education.
(3)
Quorum— A majority of the members of the Development Task Force shall constitute a quorum.
(4)
Voting— Proxy voting shall be allowed on behalf of a member of the Development Task Force.
(5)
Rules of procedure— The Development Task Force may establish rules for the conduct of the Development Task Force’s business, if such rules are not inconsistent with this section or other applicable law.
(d)
Powers—
(1)
Hearings and evidence— The Development Task Force or, on the authority of the Development Task Force, or any subcommittee or member thereof, may, for the purpose of carrying out this section hold such hearings and sit and act at such times and places, take such testimony, receive such evidence, and administer such oaths.
(2)
Contract authority— After giving notice to the Secretary who may substitute agency staff with the requisite skills to fill a position needed by the Board at no additional cost to the Board. After 10 working days following notice to the Secretary the Development Task Force may enter into contracts to such extent and in such amounts as necessary for the Development Task Force to discharge its duties under this section.
(3)
Information from federal agencies—
(A)
In general— The Development Task Force is authorized to secure directly from any executive department, bureau, agency, board, office, independent establishment, or instrumentality of the Government information, suggestions, estimates, and statistics for the purposes of this section. Each department, bureau, agency, board, office, independent establishment, or instrumentality shall, to the extent authorized by law, furnish such information, suggestions, estimates, and statistics directly to the Board, upon request made by the chairman, the chairman of any subcommittee created by a majority of the Board, or any member designated by a majority of the Board.
(B)
Receipt, handling, storage, and dissemination— Information shall only be received, handled, stored, and disseminated by members of the Board and its staff consistent with all applicable statutes, regulations, and Executive orders.
(4)
Assistance from federal agencies—
(A)
General services administration— The Administrator of General Services shall provide to the Development Task Force on a reimbursable basis administrative support and other services for the performance of the Board’s functions.
(B)
Other departments and agencies— In addition to the assistance prescribed in subparagraph (A), departments and agencies of the United States may provide to the Board such services, funds, facilities, staff, and other support services as they may determine advisable and as may be authorized by law.
(C)
Postal services— The Development Task Force may use the United States mails in the same manner and under the same conditions as departments and agencies of the United States.
(e)
Staff—
(1)
In general— While away from their homes or regular places of business in the performance of services for the Commission, members of the Commission shall be allowed travel expenses, including per diem in lieu of subsistence, in the same manner as persons employed intermittently in the Government service are allowed expenses under section 5703(b) of title 5, United States Code.
(2)
Personnel as federal employees—
(A)
In general— The executive director and any personnel of the Development Task Force who are employees shall be employees under section 2105 of title 5, United States Code, for purposes of chapters 63, 81, 83, 84, 85, 87, 89, and 90 of that title.
(B)
Members of the development task force— Subparagraph (A) shall not be construed to apply to members of the Development Task Force.
(3)
Detailees— Any Federal Government employee may be detailed to the Board without reimbursement from the Development Task Force, and such detailee shall retain the rights, status, and privileges of his or her regular employment without interruption.
(f)
No compensation for service— Members of the Development Task Force shall not receive any compensation for their service, but shall be paid travel expenses, including per diem in lieu of subsistence, at rates authorized for employees of agencies under subchapter I of chapter 57 of title 5, United States Code, while away from their homes or regular places of business in the performance of services for the Development Task Force.
(g)
Prohibition of consultant or contracting work— No member of the Development Task Force while serving in this capacity or for 1 year following departure from the Development Task Force may work as a consultant or contract worker for the Department of Homeland Security in a position related to the work of the Development Task Force or member agency that participates as a member of the Development Task Force.
(h)
Report— The Development Task Force shall submit a report to the Secretary of Homeland Security; a report on research findings, best practices voluntary guidelines and recommendations to the Secretary. The report shall be in unclassified form but may include a classified annex.
(i)
Secretary of Homeland Security report— The Secretary shall submit to Congress a report on the work of the Development Task Force’s research into best practices voluntary guidelines, areas that require additional study and a set of recommendations. The Secretary shall indicate to the Congress which Development Task Force recommendations have been implemented, which will be implemented, or which will be rejected and why.
(j)
Technical support from the Department— At the request of Development Task Force the Secretary of Homeland Security shall provide the Development Task Force with technical support necessary for the Development Task Force to carry out its duties under this section.
(k)
Intellectual property— No private-sector individual or entity serving on the Development Task Force shall obtain any intellectual property rights to any guidelines or recommendations that derive from the work of the Development Task Force or any guidelines (or any modification to any guidelines) based on the work of the Development Task Force.
(l)
Prohibition of consultant or contracting work— No member of the Development Task Force while serving in this capacity or for 1 year following departure from the Development Task Force may work as a consultant or contract worker in a position related to the direct work of the Development Task Force to the Department of Homeland Security or member agency that participates as a member of the Development Task Force.

Sec. 203 Computing and information security mentoring programs for college students

(a)
Office of Cybersecurity and Information Security Professional’s Mentoring Program—
(1)
In general— Subtitle C of title II of the Homeland Security Act of 2002 (6 U.S.C. 141 et seq.) is further amended by adding at the end the following new section:

“230B. Office of Computing and Information Security Professional’s Mentoring Program

“(a) Establishment—There is in the Department an Office of Computing and Information Security Professional’s Mentoring Program. The head of the office is the Mentoring Coordinator, who shall be appointed by the Secretary.

“(b) Responsibilities—The Mentoring Coordinator shall be responsible for working with outreach to institution of higher education, critical infrastructure owners, and the heads of Federal departments and agencies to develop and promote the participation of professionals as volunteer mentors to—

“(1) undergraduate students at institutions of higher education who are enrolled in the third or fourth year of a program of education leading to a degree in computing or information security;

“(2) students enrolled in a program of education leading to a doctoral degree in computing or information security; and

“(3) new employees of Federal departments and agencies whose primary responsibilities relate to computing or information security.”

(2)
Clerical amendment— The table of contents in section 1(b) of such Act is further amended by inserting after the item relating to section 230A the following new item:
(b)
Grant program—
(1)
In general— The Secretary of Homeland Security shall determine existing authority to make grants to covered institutions of higher learning for the establishment of mentoring programs for undergraduates enrolled in programs or courses of education in information assurance, cybersecurity or computing security programs.
(2)
Covered institutions of higher learning— For purposes of this subsection, the term “covered institution of higher learning” means those institutions as defined in section 371 of the Higher Education Act of 1965 and listed in section 101 of this bill.

Sec. 204 Grants for computer equipment

(a)
Grants— The Secretary of Homeland Security may make grants to post-secondary institutions that offer courses or degrees in computing or information security to be used to establish or equip a computer laboratory to be made available to students and faculty for both teaching and research purposes.
(b)
Technical support— The Secretary shall ensure that each recipient of a grant under this section also receives technical support on the use and proper function of equipment and software.
(c)
Publication in Federal Register— The Secretary shall publish the name of each institution of higher education that receives a grant under this section and the amount of such grant.
(d)
Qualification— In making grants under this section, the Secretary—
(1)
shall take into consideration whether more than 50 percent of the students at an institution are taking online or distance learning computer science and information security courses; and
(2)
may establish guidance to institutions for entering into laboratory facilities sharing agreements to allow institutions to qualify for grants under this section.

Sec. 205 Centers of Academic Computing and Information Assurance

(a)
Program established— The Secretary of Homeland Security shall establish a program for Centers of Academic Computer and Information Assurance Distinction.
(b)
Designation of Centers—
(1)
In general— The Secretary may designate five colleges or universities as Centers of Distinction for Academic Computing and Information Security Assurance each year with no limit to the total number of such Centers that may be established. The Secretary may make public the Centers for Distinction in Academic Computing and Information Security Assurance.
(2)
Revocation of designations— The Secretary may revoke the designation of a Center of Distinction for Academic Computing and Information Security Assurance.
(3)
Criteria— The Secretary shall make available information regarding the criteria for designating an institution as a Center of Distinction for Academic Computing and Information Security Assurance under this section.
(4)
Distance learning— In designating Centers under this section, the Secretary shall consider the number of students who are enrolled in distance learning computer or information security courses and whether collaborations for in laboratory instruction through shared arrangements with established information assurance, cybersecurity computing security programs at secondary education programs that laboratory facilities that meet best practices as outlined by the Secretary would be sufficient to meet the requirements established under this section.
(c)
Outreach— The Secretary shall identify and report on the success of efforts to reach under represented populations in the field of computing and information security through work with institutions as defined under section 371 of the Higher Education Act of 1965 listed in section 101 of this bill.
(d)
Report— Not later than 220 days after the date of the enactment of this Act, the Secretary shall submit to Congress recommendations regarding distance learning computer and information security programs for meeting the cybersecurity professional requirements of the agency.
(e)
Consideration of programs— The Secretary may consider the following when making grants to postsecondary education institutions and private sector entities who are contracted, provided grants or funds to conduct research on information assurance, cybersecurity and computing security to advance the agency’s cybersecurity capacity:
(1)
Institutions designated as a Center of Distinction for Academic Computing and Information Security Assurance.
(2)
Institutions who have established academic mentoring and program development partnerships related to information assurance, cybersecurity, and computing security academic programs with institutions defined under section 371 of the Higher Education Act of 1965 listed in section 101 of this bill.