Advancing Cybersecurity Diagnostics and Mitigation Act
A BILL
To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes.
2. Establishment of continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency
“(g) Continuous diagnostics and mitigation
“(1) Program
“(A) In general—The Secretary, acting through the Director of Cybersecurity and Infrastructure Security, shall deploy, operate, and maintain a continuous diagnostics and mitigation program for agencies. Under such program, the Secretary shall—
“(i) assist agencies to continuously diagnose and mitigate cyber threats and vulnerabilities;
“(ii) develop and provide the capability to collect, analyze, and visualize information relating to security data and cybersecurity risks at agencies;
“(iii) make program capabilities available for use, with or without reimbursement, to civilian agencies and State, local, Tribal, and territorial governments;
“(iv) employ shared services, collective purchasing, blanket purchase agreements, and any other economic or procurement models the Secretary determines appropriate to maximize the costs savings associated with implementing an information system;
“(v) assist entities in setting information security priorities and assessing and managing cybersecurity risks; and
“(vi) develop policies and procedures for reporting systemic cybersecurity risks and potential incidents based upon data collected under such program.
“(B) Regular improvement—The Secretary shall regularly deploy new technologies and modify existing technologies to the continuous diagnostics and mitigation program required under subparagraph (A), as appropriate, to improve the program.
“(2) Agency responsibilities—Notwithstanding any other provision of law, each agency that uses the continuous diagnostics and mitigation program under paragraph (1) shall, continuously and in real time, provide to the Secretary all information, assessments, analyses, and raw data collected by the program, in a manner specified by the Secretary.
“(3) Responsibilities of the Secretary—In carrying out the continuous diagnostics and mitigation program under paragraph (1), the Secretary shall, as appropriate—
“(A) share with agencies relevant analysis and products developed under such program;
“(B) provide regular reports on cybersecurity risks to agencies; and
“(C) provide comparative assessments of cybersecurity risks for agencies.”