Advancing Cybersecurity Diagnostics and Mitigation Act
AN ACT
To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program at the Department of Homeland Security, and for other purposes.
Sec. 2 Establishment of continuous diagnostics and mitigation program in Department of Homeland Security
“(g) Continuous Diagnostics and Mitigation
“(1) Program
“(A) In general—The Secretary shall deploy, operate, and maintain a continuous diagnostics and mitigation program. Under such program, the Secretary shall—
“(i) develop and provide the capability to collect, analyze, and visualize information relating to security data and cybersecurity risks;
“(ii) make program capabilities available for use, with or without reimbursement;
“(iii) employ shared services, collective purchasing, blanket purchase agreements, and any other economic or procurement models the Secretary determines appropriate to maximize the costs savings associated with implementing an information system;
“(iv) assist entities in setting information security priorities and managing cybersecurity risks; and
“(v) develop policies and procedures for reporting systemic cybersecurity risks and potential incidents based upon data collected under such program.
“(B) Regular Improvement—The Secretary shall regularly deploy new technologies and modify existing technologies to the continuous diagnostics and mitigation program required under subparagraph (A), as appropriate, to improve the program.
“(2) Activities—In carrying out the continuous diagnostics and mitigation program under paragraph (1), the Secretary shall ensure, to the extent practicable, that—
“(A) timely, actionable, and relevant cybersecurity risk information, assessments, and analysis are provided in real time;
“(B) share the analysis and products developed under such program;
“(C) all information, assessments, analyses, and raw data under such program is made available to the national cybersecurity and communications integration center of the Department; and
“(D) provide regular reports on cybersecurity risks.”