H.R. 7299 — what changed
Strengthening VA Cybersecurity Act of 2022
From Introduced in House to Engrossed in House. 1 section amended between Introduced in House and Engrossed in House.
Sec. 2 Independent cybersecurity assessment of information systems of Department of Veterans Affairs
Independent assessment required—
changed
In general— Not later than 60 days after the date of the enactment of this Act, the Secretary of Veterans Affairs shall seek to enter into an agreement with a federally funded research and development center to provide to the Secretary with an independent cybersecurity assessment of—
changed
not more than 10 and not fewer than three five high-impact information systems of the Department of Veterans Affairs; and
the effectiveness of the information security program and information security management system of the Department.
Detailed analysis— The independent cybersecurity assessment provided under paragraph (1) shall include a detailed analysis of the ability of the Department—
to ensure the confidentiality, integrity, and availability of the information, information systems, and devices of the Department; and
to protect against—
advanced persistent cybersecurity threats;
ransomware;
denial of service attacks;
insider threats;
changed
threats from foreign actors, including state-sponsored state sponsored criminals and other foreign based criminals;
phishing;
credential theft;
cybersecurity attacks that target the supply chain of the Department;
threats due to remote access and telework activity; and
other cyber threats.
Types of systems— The independent cybersecurity assessment provided under paragraph (1) shall cover on-premises, remote, cloud-based, and mobile information systems and devices used by, or in support of, Department activities.
changed
Shadow information technology— The independent cybersecurity assessment provided under paragraph (1) shall include an evaluation of the use of information technology systems, devices, and services by employees and contractors of the Department who do so without the heads of the elements of the Department that are responsible for information technology at the Department knowing or approving of such use.
changed
Methodology— In conducting the cybersecurity assessment to be provided under paragraph (1), the federally funded research and development center shall take into account industry best practices and the current state-of-the-art in cybersecurity evaluation and review.
Plan—
changed
In general— Not later than 120 days after the date on which an independent assessment is provided to the Secretary by a federally funded research and development center pursuant to an agreement entered into under subsection (a) with a federally funded research and development center, (a), the Secretary shall submit to Congress the Committees on Veterans’ Affairs of the House of Representatives and the Senate a plan to address the findings of the federally funded research and development center set forth in such assessment.
Elements— The plan submitted under paragraph (1) shall include the following:
added
Improvements to the security controls of the information systems of the Department assessed under subsection (a) to—
added
achieve the goals specified in subparagraph (A) of paragraph (2) of such subsection; and
added
protect against the threats specified in subparagraph (B) of such paragraph.
added
Improvements to the information security program and information security management system of the Department to achieve such goals and protect against such threats.
renumbered
was (3)(3)(3)
A cost estimate for implementing the plan.
renumbered
was (3)(3)(4)
A timeline for implementing the plan.
renumbered
was (3)(3)(5)
Such other elements as the Secretary considers appropriate.
changed
Comptroller General of the United States evaluation and review— Not later than 180 days after the date of the submission of the plan under subsection (b)(1), the Comptroller General of the United States shall—
changed
commence a an evaluation and review of—
the independent cybersecurity assessment provided under subsection (a); and
the response of the Department to such assessment; and
changed
submit provide to Congress a report the Committees on Veterans’ Affairs of the House of Representatives and the Senate a briefing on the results of that review commenced under paragraph (1), the evaluation and review, including any recommendations made to the Secretary regarding the matters covered by the report.briefing.