US Codex
Bill
Notes

Federal Information Security Modernization Act of 2022

H.R. 6497 · 117th Congress · Jan 25, 2022 · Lineage

A BILL

To modernize Federal information security management and improve Federal cybersecurity to combat persisting and emerging threats, and for other purposes.

Section 1 Short title

This Act may be cited as the “Federal Information Security Modernization Act of 2022”.

Sec. 2 Table of contents

The table of contents for this Act is as follows:

Sec. 3 Definitions

In this Act, unless otherwise specified:
(1)
Additional cybersecurity procedure— The term additional cybersecurity procedure has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act.
(2)
Agency— The term agency has the meaning given the term in section 3502 of title 44, United States Code.
(3)
Appropriate congressional committees— The term appropriate congressional committees means—
(A)
the Committee on Homeland Security and Governmental Affairs of the Senate;
(B)
the Committee on Oversight and Reform of the House of Representatives; and
(C)
the Committee on Homeland Security of the House of Representatives.
(4)
Director— The term Director means the Director of the Office of Management and Budget.
(5)
Incident— The term incident has the meaning given the term in section 3552(b) of title 44, United States Code.
(6)
National security system— The term national security system has the meaning given the term in section 3552(b) of title 44, United States Code.
(7)
Penetration test— The term penetration test has the meaning given the term in section 3552(b) of title 44, United States Code, as amended by this Act.
(8)
Threat hunting— The term threat hunting means iteratively searching systems for threats that evade detection by automated threat detection systems.
(9)
Zero trust architecture— The term zero trust architecture means a security model, a set of system design principles, and a coordinated cybersecurity and system management strategy that employs continuous monitoring, risk-based access controls, or system security automation techniques to address the cybersecurity principle that threats exist both inside and outside traditional network boundaries with an assumption that a breach is inevitable or has likely already occurred, and therefore employs least-privileged access for network or system users while monitoring for anomalous or malicious activity.