Risk-Informed Spending for Cybersecurity Act
A BILL
To require the Director of the Office of Management and Budget to develop a model for risk-based budgeting, and for other purposes.
2. Definitions
3. Establishment of risk-based budget model
“(7) developing a standard risk-based budget model to inform Federal agency cybersecurity budget development.”
“(V) a validation that the budgets submitted were developed using a risk-based methodology;”
“(D) an assessment of how the agency implemented the risk-based budget model required under section 3553(a)(7) and an evaluation of whether the model mitigates agency cyber vulnerabilities.”
“(6) an assessment of—
“(A) Federal agency implementation of the model required under subsection (a)(7);
“(B) how cyber vulnerabilities of Federal agencies changed from the previous year; and
“(C) whether the model mitigates the cyber vulnerabilities of the Federal Government.”