Federal CIO Authorization Act of 2019
AN ACT
To amend chapter 36 of title 44, United States Code, to make certain changes relating to electronic Government services, and for other purposes.
Sec. 2 Changes relating to electronic Government services
“(18) Oversee the Federal Chief Information Security Officer.”
“3607. Federal Chief Information Security Officer
“(a) Establishment—There is established in the Office of Management and Budget a Federal Chief Information Security Officer, who shall—
“(1) be appointed by the President;
“(2) be within the Office of the Federal Chief Information Officer; and
“(3) report directly to the Federal Chief Information Officer.
“(b) Duties—The Federal Chief Information Security Officer shall—
“(1) direct the cybersecurity efforts of the Office of Management and Budget;
“(2) carry out the duties of the Director related to the security of information and information systems for agencies, including the duties and responsibilities assigned to the Director under subchapter II of chapter 35; and
“(3) carry out such other duties and powers assigned by the President, the Director, or the Federal Chief Information Officer.
“3608. Technology investment planning and oversight process
“(a) Report on information technology expenditures—The head of each agency shall submit to the Federal Chief Information Officer a report on any expenditure on information technology by that agency.
“(b) Implementation—The Director shall establish a process to implement subsection (a), and may update such process, as necessary, that shall—
“(1) use a widely accepted industry standard taxonomy with common data elements and definitions; and
“(2) display, on a website accessible to the public, timely, searchable, computer-readable data on the information technology expenditures, projects, and programs of agencies, if such information would otherwise be subject to public disclosure under section 552 of title 5, commonly known as the Freedom of Information Act.”