US Codex
Bill
Notes

S. 3600 — what changed

Strengthening American Cybersecurity Act of 2022

From Placed on Calendar Senate to Engrossed in Senate. 3 sections amended and 1 added between Placed on Calendar Senate and Engrossed in Senate.

Sec. 103 Title 44 amendments

(a)
Subchapter I amendments— Subchapter I of chapter 35 of title 44, United States Code, is amended—
(1)
in section 3504—
(A)
in subsection (a)(1)(B)—
(i)
by striking clause (v) and inserting the following:

“(v) confidentiality, privacy, disclosure, and sharing of information;”

(ii)
by redesignating clause (vi) as clause (vii); and
(iii)
by inserting after clause (v) the following:

“(vi) in consultation with the National Cyber Director, security of information; and”

(B)
in subsection (g), by striking paragraph (1) and inserting the following:

“(1) develop and oversee the implementation of policies, principles, standards, and guidelines on privacy, confidentiality, disclosure, and sharing, and in consultation with the National Cyber Director, oversee the implementation of policies, principles, standards, and guidelines on security, of information collected or maintained by or for agencies; and”

(2)
in section 3505—
(A)
by striking the first subsection designated as subsection (c);
(B)
in paragraph (2) of the second subsection designated as subsection (c), by inserting “an identification of internet accessible information systems and” after “an inventory under this subsection shall include”;
(C)
in paragraph (3) of the second subsection designated as subsection (c)—
(i)
in subparagraph (B)—
(I)
by inserting “the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, and” before “the Comptroller General”; and
(II)
by striking “and” at the end;
(ii)
in subparagraph (C)(v), by striking the period at the end and inserting “; and”; and
(iii)
by adding at the end the following:

“(D) maintained on a continual basis through the use of automation, machine-readable data, and scanning, wherever practicable.”

(3)
in section 3506—
(A)
in subsection (a)(3), by inserting “In carrying out these duties, the Chief Information Officer shall coordinate, as appropriate, with the Chief Data Officer in accordance with the designated functions under section 3520(c).” after “reduction of information collection burdens on the public.”;
(B)
in subsection (b)(1)(C), by inserting “, availability” after “integrity”; and
(C)
in subsection (h)(3), by inserting “security,” after “efficiency,”; and
(4)
in section 3513—
(A)
by redesignating subsection (c) as subsection (d); and
(B)
by inserting after subsection (b) the following:

“(c) Each agency providing a written plan under subsection (b) shall provide any portion of the written plan addressing information security to the Secretary of the Department of Homeland Security and the National Cyber Director.”

(b)
Subchapter II definitions—
(1)
In general— Section 3552(b) of title 44, United States Code, is amended—
(A)
by redesignating paragraphs (1), (2), (3), (4), (5), (6), and (7) as paragraphs (2), (4), (5), (6), (7), (9), and (11), respectively;
(B)
by inserting before paragraph (2), as so redesignated, the following:

“(1) The term additional cybersecurity procedure means a process, procedure, or other activity that is established in excess of the information security standards promulgated under section 11331(b) of title 40 to increase the security and reduce the cybersecurity risk of agency systems.”

(C)
by inserting after paragraph (2), as so redesignated, the following:

“(3) The term high value asset means information or an information system that the head of an agency, using policies, principles, standards, or guidelines issued by the Director under section 3553(a), determines to be so critical to the agency that the loss or corruption of the information or the loss of access to the information system would have a serious impact on the ability of the agency to perform the mission of the agency or conduct business.”

(D)
by inserting after paragraph (7), as so redesignated, the following:

“(8) The term major incident has the meaning given the term in guidance issued by the Director under section 3598(a).”

(E)
by inserting after paragraph (9), as so redesignated, the following:

“(10) The term penetration test—

“(A) means an authorized assessment that emulates attempts to gain unauthorized access to, or disrupt the operations of, an information system or component of an information system; and

“(B) includes any additional meaning given the term in policies, principles, standards, or guidelines issued by the Director under section 3553(a).”

(F)
by inserting after paragraph (11), as so redesignated, the following:

“(12) The term shared service means a centralized business or mission capability that is provided to multiple organizations within an agency or to multiple agencies.”

(2)
Conforming amendments—
(A)
Homeland Security Act of 2002— Section 1001(c)(1)(A) of the Homeland Security Act of 2002 (6 U.S.C. 511(1)(A)) is amended by striking “section 3552(b)(5)” and inserting “section 3552(b)”.
(B)
Title 10—
(i)
Section 2222— Section 2222(i)(8) of title 10, United States Code, is amended by striking “section 3552(b)(6)(A)” and inserting “section 3552(b)(9)(A)”.
(ii)
Section 2223— Section 2223(c)(3) of title 10, United States Code, is amended by striking “section 3552(b)(6)” and inserting “section 3552(b)”.
(iii)
Section 2315— Section 2315 of title 10, United States Code, is amended by striking “section 3552(b)(6)” and inserting “section 3552(b)”.
(iv)
Section 2339a— Section 2339a(e)(5) of title 10, United States Code, is amended by striking “section 3552(b)(6)” and inserting “section 3552(b)”.
(C)
High-Performance Computing Act of 1991— Section 207(a) of the High-Performance Computing Act of 1991 (15 U.S.C. 5527(a)) is amended by striking “section 3552(b)(6)(A)(i)” and inserting “section 3552(b)(9)(A)(i)”.
(D)
Internet of Things Cybersecurity Improvement Act of 2020— Section 3(5) of the Internet of Things Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g–3a) is amended by striking “section 3552(b)(6)” and inserting “section 3552(b)”.
(E)
National Defense Authorization Act for Fiscal Year 2013— Section 933(e)(1)(B) of the National Defense Authorization Act for Fiscal Year 2013 (10 U.S.C. 2224 note) is amended by striking “section 3542(b)(2)” and inserting “section 3552(b)”.
(F)
Ike Skelton National Defense Authorization Act for Fiscal Year 2011— The Ike Skelton National Defense Authorization Act for Fiscal Year 2011 (Public Law 111–383) is amended—
(i)
in section 806(e)(5) (10 U.S.C. 2304 note), by striking “section 3542(b)” and inserting “section 3552(b)”;
(ii)
in section 931(b)(3) (10 U.S.C. 2223 note), by striking “section 3542(b)(2)” and inserting “section 3552(b)”; and
(iii)
in section 932(b)(2) (10 U.S.C. 2224 note), by striking “section 3542(b)(2)” and inserting “section 3552(b)”.
(G)
E-Government Act of 2002— Section 301(c)(1)(A) of the E-Government Act of 2002 (44 U.S.C. 3501 note) is amended by striking “section 3542(b)(2)” and inserting “section 3552(b)”.
(H)
National Institute of Standards and Technology Act— Section 20 of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3) is amended—
(i)
in subsection (a)(2), by striking “section 3552(b)(5)” and inserting “section 3552(b)”; and
(ii)
in subsection (f)—
(I)
in paragraph (3), by striking “section 3532(1)” and inserting “section 3552(b)”; and
(II)
in paragraph (5), by striking “section 3532(b)(2)” and inserting “section 3552(b)”.
(c)
Subchapter II amendments— Subchapter II of chapter 35 of title 44, United States Code, is amended—
(1)
in section 3551—
(A)
in paragraph (4), by striking “diagnose and improve” and inserting “integrate, deliver, diagnose, and improve”;
(B)
in paragraph (5), by striking “and” at the end;
(C)
in paragraph (6), by striking the period at the end and inserting a semi colon; and
(D)
by adding at the end the following:

“(7) recognize that each agency has specific mission requirements and, at times, unique cybersecurity requirements to meet the mission of the agency;

“(8) recognize that each agency does not have the same resources to secure agency systems, and an agency should not be expected to have the capability to secure the systems of the agency from advanced adversaries alone; and

“(9) recognize that a holistic Federal cybersecurity model is necessary to account for differences between the missions and capabilities of agencies.”

(2)
in section 3553—
(A)
in subsection (a)—
(i)
in paragraph (1), by inserting “, in consultation with the Secretary and the National Cyber Director,” before “overseeing”;
(ii)
in paragraph (5), by striking “and” at the end; and
(iii)
by adding at the end the following:

“(8) promoting, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, and the Director of the National Institute of Standards and Technology—

“(A) the use of automation to improve Federal cybersecurity and visibility with respect to the implementation of Federal cybersecurity; and

“(B) the use of presumption of compromise and least privilege principles to improve resiliency and timely response actions to incidents on Federal systems.”

(B)
in subsection (b)—
(i)
in the matter preceding paragraph (1), by inserting “and the National Cyber Director” after “Director”; and
(ii)
in paragraph (2)(A), by inserting “and reporting requirements under subchapter IV of this chapter” after “section 3556”; and
(C)
in subsection (c)—
(i)
in the matter preceding paragraph (1)—
(I)
by striking “each year” and inserting “each year during which agencies are required to submit reports under section 3554(c)”; and
(II)
by striking “preceding year” and inserting “preceding 2 years”;
(ii)
by striking paragraph (1);
(iii)
by redesignating paragraphs (2), (3), and (4) as paragraphs (1), (2), and (3), respectively;
(iv)
in paragraph (3), as so redesignated, by striking “and” at the end;
(v)
by inserting after paragraph (3), as so redesignated the following:

“(4) a summary of each assessment of Federal risk posture performed under subsection (i);”

(vi)
in paragraph (5), by striking the period at the end and inserting “; and”;
(D)
by redesignating subsections (i), (j), (k), and (l) as subsections (j), (k), (l), and (m) respectively;
(E)
by inserting after subsection (h) the following:

“(i) Federal risk assessments—On an ongoing and continuous basis, the Director of the Cybersecurity and Infrastructure Security Agency shall perform assessments of Federal risk posture using any available information on the cybersecurity posture of agencies, and brief the Director and National Cyber Director on the findings of those assessments including—

“(1) the status of agency cybersecurity remedial actions described in section 3554(b)(7);

“(2) any vulnerability information relating to the systems of an agency that is known by the agency;

“(3) analysis of incident information under section 3597;

“(4) evaluation of penetration testing performed under section 3559A;

“(5) evaluation of vulnerability disclosure program information under section 3559B;

“(6) evaluation of agency threat hunting results;

“(7) evaluation of Federal and non-Federal cyber threat intelligence;

“(8) data on agency compliance with standards issued under section 11331 of title 40;

“(9) agency system risk assessments performed under section 3554(a)(1)(A); and

“(10) any other information the Director of the Cybersecurity and Infrastructure Security Agency determines relevant.”

(F)
in subsection (j), as so redesignated—
(i)
by striking “regarding the specific” and inserting “that includes a summary of—

“(1) the specific”

(ii)
in paragraph (1), as so designated, by striking the period at the end and inserting “; and” and
(iii)
by adding at the end the following:

“(2) the trends identified in the Federal risk assessment performed under subsection (i).”

(G)
by adding at the end the following:

changed “(n) Binding operational directives—If the Director of the Cybersecurity and Infrastructure Security Agency issues a binding operational directive or an emergency directive under this section, not later than 4 days after the date on which the binding operational directive requires an agency to take an action, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the Director, National Cyber Director, the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives the status of the implementation of the binding operational directive at the agency.”agency.

added “(o) Review of Office of Management and Budget guidance and policy

added “(1) Review

added “(A) In general—Not less frequently than once every 3 years, the Director, in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency, shall—

added “(i) review the efficacy of the guidance and policy developed by the Director under subsection (a)(1) in reducing cybersecurity risks, including an assessment of the requirements for agencies to report information to the Director; and

added “(ii) determine whether any changes to the guidance or policy developed under subsection (a)(1) is appropriate.

added “(B) Considerations—In conducting the review required under subparagraph (A), the Director shall consider—

added “(i) the Federal risk assessments performed under subsection (i);

added “(ii) the cumulative reporting and compliance burden to agencies; and

added “(iii) the clarity of the requirements and deadlines contained in guidance and policy documents.

added “(2) Updated guidance—Not later than 90 days after the date on which a review is completed under paragraph (1), the Director shall issue updated guidance or policy to agencies determined appropriate by the Director, based on the results of the review.

added “(3) Public report—Not later than 30 days after the date on which the Director completes a review under paragraph (1), the Director shall make publicly available a report that includes—

added “(A) an overview of the guidance and policy developed under subsection (a)(1) that is in effect;

added “(B) the cybersecurity risk mitigation, or other cybersecurity benefit, offered by each guidance or policy described in subparagraph (A);

added “(C) a summary of the guidance or policy developed under subsection (a)(1) to which changes were determined appropriate during the review; and

added “(D) the changes that are anticipated to be included in the updated guidance or policy issued under paragraph (2).

added “(4) Congressional briefing—Not later than 60 days after the date on which a review is completed under paragraph (1), the Director shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a briefing on the review.

added “(p) Automated standard implementation verification—When the Director of the National Institute of Standards and Technology issues a proposed standard pursuant to paragraphs (2) or (3) of section 20(a) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(a)), the Director of the National Institute of Standards and Technology shall consider developing and, if appropriate and practical, develop, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, specifications to enable the automated verification of the implementation of the controls within the standard.”

(3)
in section 3554—
(A)
in subsection (a)—
(i)
in paragraph (1)—
(I)
by redesignating subparagraphs (A), (B), and (C) as subparagraphs (B), (C), and (D), respectively;
(II)
by inserting before subparagraph (B), as so redesignated, the following:

“(A) on an ongoing and continuous basis, performing agency system risk assessments that—

“(i) identify and document the high value assets of the agency using guidance from the Director;

“(ii) evaluate the data assets inventoried under section 3511 for sensitivity to compromises in confidentiality, integrity, and availability;

“(iii) identify agency systems that have access to or hold the data assets inventoried under section 3511;

“(iv) evaluate the threats facing agency systems and data, including high value assets, based on Federal and non-Federal cyber threat intelligence products, where available;

“(v) evaluate the vulnerability of agency systems and data, including high value assets, including by analyzing—

“(I) the results of penetration testing performed by the Department of Homeland Security under section 3553(b)(9);

“(II) the results of penetration testing performed under section 3559A;

“(III) information provided to the agency through the vulnerability disclosure program of the agency under section 3559B;

“(IV) incidents; and

“(V) any other vulnerability information relating to agency systems that is known to the agency;

“(vi) assess the impacts of potential agency incidents to agency systems, data, and operations based on the evaluations described in clauses (ii) and (iv) and the agency systems identified under clause (iii); and

“(vii) assess the consequences of potential incidents occurring on agency systems that would impact systems at other agencies, including due to interconnectivity between different agency systems or operational reliance on the operations of the system or data in the system;”

(III)
in subparagraph (B), as so redesignated, in the matter preceding clause (i), by striking “providing information” and inserting “using information from the assessment conducted under subparagraph (A), providing information”;
(IV)
in subparagraph (C), as so redesignated—
(aa)
in clause (ii) by inserting “binding” before “operational”; and
(bb)
in clause (vi), by striking “and” at the end; and
(V)
by adding at the end the following:

“(E) providing an update on the ongoing and continuous assessment performed under subparagraph (A)—

“(i) upon request, to the inspector general of the agency or the Comptroller General of the United States; and

“(ii) on a periodic basis, as determined by guidance issued by the Director but not less frequently than annually, to—

“(I) the Director;

“(II) the Director of the Cybersecurity and Infrastructure Security Agency; and

“(III) the National Cyber Director;

“(F) in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and not less frequently than once every 3 years, performing an evaluation of whether additional cybersecurity procedures are appropriate for securing a system of, or under the supervision of, the agency, which shall—

“(i) be completed considering the agency system risk assessment performed under subparagraph (A); and

“(ii) include a specific evaluation for high value assets;

“(G) not later than 30 days after completing the evaluation performed under subparagraph (F), providing the evaluation and an implementation plan, if applicable, for using additional cybersecurity procedures determined to be appropriate to—

“(i) the Director of the Cybersecurity and Infrastructure Security Agency;

“(ii) the Director; and

“(iii) the National Cyber Director; and

“(H) if the head of the agency determines there is need for additional cybersecurity procedures, ensuring that those additional cybersecurity procedures are reflected in the budget request of the agency;”

(ii)
in paragraph (2)—
(I)
in subparagraph (A), by inserting “in accordance with the agency system risk assessment performed under paragraph (1)(A)” after “information systems”;
(II)
in subparagraph (B)—
(aa)
by striking “in accordance with standards” and inserting “in accordance with—

“(i) standards”

(bb)
by adding at the end the following:

“(ii) the evaluation performed under paragraph (1)(F); and

“(iii) the implementation plan described in paragraph (1)(G);”

(III)
in subparagraph (D), by inserting “, through the use of penetration testing, the vulnerability disclosure program established under section 3559B, and other means,” after “periodically”;
(iii)
in paragraph (3)—
(I)
in subparagraph (A)—
(aa)
in clause (iii), by striking “and” at the end;
(bb)
in clause (iv), by adding “and” at the end; and
(cc)
by adding at the end the following:

“(v) ensure that—

“(I) senior agency information security officers of component agencies carry out responsibilities under this subchapter, as directed by the senior agency information security officer of the agency or an equivalent official; and

“(II) senior agency information security officers of component agencies report to—

“(aa) the senior information security officer of the agency or an equivalent official; and

“(bb) the Chief Information Officer of the component agency or an equivalent official;”

(iv)
in paragraph (5), by inserting “and the Director of the Cybersecurity and Infrastructure Security Agency” before “on the effectiveness”;
(B)
in subsection (b)—
(i)
by striking paragraph (1) and inserting the following:

“(1) pursuant to subsection (a)(1)(A), performing ongoing and continuous agency system risk assessments, which may include using guidelines and automated tools consistent with standards and guidelines promulgated under section 11331 of title 40, as applicable;”

(ii)
in paragraph (2)—
(I)
by striking subparagraph (B) and inserting the following:

“(B) comply with the risk-based cyber budget model developed pursuant to section 3553(a)(7);”

(II)
in subparagraph (D)—
(aa)
by redesignating clauses (iii) and (iv) as clauses (iv) and (v), respectively;
(bb)
by inserting after clause (ii) the following:

“(iii) binding operational directives and emergency directives promulgated by the Director of the Cybersecurity and Infrastructure Security Agency under section 3553;”

(cc)
changed in clause (iv), as so redesignated, by striking “as determined by the agency; and” and inserting “as determined by the agency, considering—considering the agency risk assessment performed under subsection (a)(1)(A); and

removed “(I) the agency risk assessment performed under subsection (a)(1)(A); and

removed “(II) the determinations of applying more stringent standards and additional cybersecurity procedures pursuant to section 11331(c)(1) of title 40; and”

(iii)
in paragraph (5)(A), by inserting “, including penetration testing, as appropriate,” after “shall include testing”;
(iv)
in paragraph (6), by striking “planning, implementing, evaluating, and documenting” and inserting “planning and implementing and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, evaluating and documenting”;
(v)
by redesignating paragraphs (7) and (8) as paragraphs (8) and (9), respectively;
(vi)
by inserting after paragraph (6) the following:

“(7) a process for providing the status of every remedial action and unremediated identified system vulnerability to the Director and the Director of the Cybersecurity and Infrastructure Security Agency, using automation and machine-readable data to the greatest extent practicable;”

(vii)
in paragraph (8)(C), as so redesignated—
(I)
by striking clause (ii) and inserting the following:

“(ii) notifying and consulting with the Federal information security incident center established under section 3556 pursuant to the requirements of section 3594;”

(II)
by redesignating clause (iii) as clause (iv);
(III)
by inserting after clause (ii) the following:

“(iii) performing the notifications and other activities required under subchapter IV of this chapter; and”

(IV)
in clause (iv), as so redesignated—
(aa)
in subclause (I), by striking “and relevant offices of inspectors general”;
(bb)
in subclause (II), by adding “and” at the end;
(cc)
by striking subclause (III); and
(dd)
by redesignating subclause (IV) as subclause (III);
(C)
in subsection (c)—
(i)
by redesignating paragraph (2) as paragraph (5);
(ii)
by striking paragraph (1) and inserting the following:

“(1) Biannual report—Not later than 2 years after the date of enactment of the Federal Information Security Modernization Act of 2022 and not less frequently than once every 2 years thereafter, using the continuous and ongoing agency system risk assessment under subsection (a)(1)(A), the head of each agency shall submit to the Director, the Director of the Cybersecurity and Infrastructure Security Agency, the majority and minority leaders of the Senate, the Speaker and minority leader of the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, the Committee on Commerce, Science, and Transportation of the Senate, the Committee on Science, Space, and Technology of the House of Representatives, the appropriate authorization and appropriations committees of Congress, the National Cyber Director, and the Comptroller General of the United States a report that—

“(A) summarizes the agency system risk assessment performed under subsection (a)(1)(A);

“(B) evaluates the adequacy and effectiveness of information security policies, procedures, and practices of the agency to address the risks identified in the agency system risk assessment performed under subsection (a)(1)(A), including an analysis of the agency’s cybersecurity and incident response capabilities using the metrics established under section 224(c) of the Cybersecurity Act of 2015 (6 U.S.C. 1522(c));

“(C) summarizes the evaluation and implementation plans described in subparagraphs (F) and (G) of subsection (a)(1) and whether those evaluation and implementation plans call for the use of additional cybersecurity procedures determined to be appropriate by the agency; and

“(D) summarizes the status of remedial actions identified by inspector general of the agency, the Comptroller General of the United States, and any other source determined appropriate by the head of the agency.

“(2) Unclassified reports—Each report submitted under paragraph (1)—

“(A) shall be, to the greatest extent practicable, in an unclassified and otherwise uncontrolled form; and

“(B) may include a classified annex.

“(3) Access to information—The head of an agency shall ensure that, to the greatest extent practicable, information is included in the unclassified form of the report submitted by the agency under paragraph (2)(A).

“(4) Briefings—During each year during which a report is not required to be submitted under paragraph (1), the Director shall provide to the congressional committees described in paragraph (1) a briefing summarizing current agency and Federal risk postures.”

(iii)
in paragraph (5), as so redesignated, by striking the period at the end and inserting “, including the reporting procedures established under section 11315(d) of title 40 and subsection (a)(3)(A)(v) of this section”; and
(D)
in subsection (d)(1), in the matter preceding subparagraph (A), by inserting “and the National Cyber Director” after “the Director”; and
(E)
by adding at the end the following:

“(f) Reporting structure exemption

“(1) In general—On an annual basis, the Director may exempt an agency from the reporting structure requirement under subsection (a)(3)(A)(v)(II).

“(2) Report—On an annual basis, the Director shall submit a report to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives that includes a list of each exemption granted under paragraph (1) and the associated rationale for each exemption.

“(3) Component of other report—The report required under paragraph (2) may be incorporated into any other annual report required under this chapter.”

(4)
in section 3555—
(A)
in the section heading, by striking “Annual independent” and inserting “Independent”;
(B)
in subsection (a)—
(i)
in paragraph (1), by inserting “during which a report is required to be submitted under section 3553(c),” after “Each year”;
(ii)
in paragraph (2)(A), by inserting “, including by penetration testing and analyzing the vulnerability disclosure program of the agency” after “information systems”; and
(iii)
by adding at the end the following:

“(3) An evaluation under this section may include recommendations for improving the cybersecurity posture of the agency.”

(C)
in subsection (b)(1), by striking “annual”;
(D)
in subsection (e)(1), by inserting “during which a report is required to be submitted under section 3553(c)” after “Each year”;
(E)
by striking subsection (f) and inserting the following:

“(f) Protection of information

“(1) Agencies, evaluators, and other recipients of information that, if disclosed, may cause grave harm to the efforts of Federal information security officers, shall take appropriate steps to ensure the protection of that information, including safeguarding the information from public disclosure.

“(2) The protections required under paragraph (1) shall be commensurate with the risk and comply with all applicable laws and regulations.

“(3) With respect to information that is not related to national security systems, agencies and evaluators shall make a summary of the information unclassified and publicly available, including information that does not identify—

“(A) specific information system incidents; or

“(B) specific information system vulnerabilities.”

(F)
in subsection (g)(2)—
(i)
by striking “this subsection shall” and inserting “this subsection—

“(A) shall”

(ii)
in subparagraph (A), as so designated, by striking the period at the end and inserting “; and”; and
(iii)
by adding at the end the following:

“(B) identify any entity that performs an independent evaluation under subsection (b).”

(G)
by striking subsection (j) and inserting the following:

“(j) Guidance

“(1) In general—The Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, the Chief Information Officers Council, the Council of the Inspectors General on Integrity and Efficiency, and other interested parties as appropriate, shall ensure the development of risk-based guidance for evaluating the effectiveness of an information security program and practices

“(2) Priorities—The risk-based guidance developed under paragraph (1) shall include—

“(A) the identification of the most common successful threat patterns experienced by each agency;

“(B) the identification of security controls that address the threat patterns described in subparagraph (A);

“(C) any other security risks unique to the networks of each agency; and

“(D) any other element the Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the Council of the Inspectors General on Integrity and Efficiency, determines appropriate.”

(5)
in section 3556(a)—
(A)
in the matter preceding paragraph (1), by inserting “within the Cybersecurity and Infrastructure Security Agency” after “incident center”; and
(B)
in paragraph (4), by striking “3554(b)” and inserting “3554(a)(1)(A)”.
(d)
Conforming amendments—
(1)
Table of sections— The table of sections for chapter 35 of title 44, United States Code, is amended by striking the item relating to section 3555 and inserting the following:
(2)
OMB reports— Section 226(c) of the Cybersecurity Act of 2015 (6 U.S.C. 1524(c)) is amended—
(A)
in paragraph (1)(B), in the matter preceding clause (i), by striking “annually thereafter” and inserting “thereafter during the years during which a report is required to be submitted under section 3553(c) of title 44, United States Code”; and
(B)
in paragraph (2)(B), in the matter preceding clause (i)—
(i)
by striking “annually thereafter” and inserting “thereafter during the years during which a report is required to be submitted under section 3553(c) of title 44, United States Code”; and
(ii)
by striking “the report required under section 3553(c) of title 44, United States Code” and inserting “that report”.
(3)
NIST responsibilities— Section 20(d)(3)(B) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(d)(3)(B)) is amended by striking “annual”.
(e)
Federal system incident response—
(1)
In general— Chapter 35 of title 44, United States Code, is amended by adding at the end the following:

“IV Federal System Incident Response

“3591. Definitions

“(a) In general—Except as provided in subsection (b), the definitions under sections 3502 and 3552 shall apply to this subchapter.

“(b) Additional definitions—As used in this subchapter:

“(1) Appropriate reporting entities—The term appropriate reporting entities means—

“(A) the majority and minority leaders of the Senate;

“(B) the Speaker and minority leader of the House of Representatives;

“(C) the Committee on Homeland Security and Governmental Affairs of the Senate;

“(D) the Committee on Oversight and Reform of the House of Representatives;

“(E) the Committee on Homeland Security of the House of Representatives;

“(F) the appropriate authorization and appropriations committees of Congress;

“(G) the Director;

“(H) the Director of the Cybersecurity and Infrastructure Security Agency;

“(I) the National Cyber Director;

“(J) the Comptroller General of the United States; and

“(K) the inspector general of any impacted agency.

“(2) Awardee—The term awardee—

“(A) means a person, business, or other entity that receives a grant from, or is a party to a cooperative agreement or an other transaction agreement with, an agency; and

“(B) includes any subgrantee of a person, business, or other entity described in subparagraph (A).

“(3) Breach—The term breach—

“(A) means the loss, control, compromise, unauthorized disclosure, or unauthorized acquisition of personally identifiable information or any similar occurrence; and

“(B) includes any additional meaning given the term in policies, principles, standards, or guidelines issued by the Director under section 3553(a).

“(4) Contractor—The term contractor means a prime contractor of an agency or a subcontractor of a prime contractor of an agency.

“(5) Federal information—The term Federal information means information created, collected, processed, maintained, disseminated, disclosed, or disposed of by or for the Federal Government in any medium or form.

“(6) Federal information system—The term Federal information system means an information system used or operated by an agency, a contractor, an awardee, or another organization on behalf of an agency.

“(7) Intelligence community—The term intelligence community has the meaning given the term in section 3 of the National Security Act of 1947 (50 U.S.C. 3003).

“(8) Nationwide consumer reporting agency—The term nationwide consumer reporting agency means a consumer reporting agency described in section 603(p) of the Fair Credit Reporting Act (15 U.S.C. 1681a(p)).

“(9) Vulnerability disclosure—The term vulnerability disclosure means a vulnerability identified under section 3559B.

“3592. Notification of breach

“(a) Notification—As expeditiously as practicable and without unreasonable delay, and in any case not later than 45 days after an agency has a reasonable basis to conclude that a breach has occurred, the head of the agency, in consultation with a senior privacy officer of the agency, shall—

“(1) determine whether notice to any individual potentially affected by the breach is appropriate based on an assessment of the risk of harm to the individual that considers—

“(A) the nature and sensitivity of the personally identifiable information affected by the breach;

“(B) the likelihood of access to and use of the personally identifiable information affected by the breach;

“(C) the type of breach; and

“(D) any other factors determined by the Director; and

“(2) as appropriate, provide written notice in accordance with subsection (b) to each individual potentially affected by the breach—

“(A) to the last known mailing address of the individual; or

“(B) through an appropriate alternative method of notification that the head of the agency or a designated senior-level individual of the agency selects based on factors determined by the Director.

“(b) Contents of notice—Each notice of a breach provided to an individual under subsection (a)(2) shall include—

“(1) a brief description of the breach;

“(2) if possible, a description of the types of personally identifiable information affected by the breach;

“(3) contact information of the agency that may be used to ask questions of the agency, which—

“(A) shall include an e-mail address or another digital contact mechanism; and

“(B) may include a telephone number, mailing address, or a website;

“(4) information on any remedy being offered by the agency;

“(5) any applicable educational materials relating to what individuals can do in response to a breach that potentially affects their personally identifiable information, including relevant contact information for Federal law enforcement agencies and each nationwide consumer reporting agency; and

“(6) any other appropriate information, as determined by the head of the agency or established in guidance by the Director.

“(c) Delay of notification

“(1) In general—The Attorney General, the Director of National Intelligence, or the Secretary of Homeland Security may delay a notification required under subsection (a) or (d) if the notification would—

“(A) impede a criminal investigation or a national security activity;

“(B) reveal sensitive sources and methods;

“(C) cause damage to national security; or

“(D) hamper security remediation actions.

“(2) Documentation

“(A) In general—Any delay under paragraph (1) shall be reported in writing to the Director, the Attorney General, the Director of National Intelligence, the Secretary of Homeland Security, the National Cyber Director, the Director of the Cybersecurity and Infrastructure Security Agency, and the head of the agency and the inspector general of the agency that experienced the breach.

“(B) Contents—A report required under subparagraph (A) shall include a written statement from the entity that delayed the notification explaining the need for the delay.

“(C) Form—The report required under subparagraph (A) shall be unclassified but may include a classified annex.

“(3) Renewal—A delay under paragraph (1) shall be for a period of 60 days and may be renewed.

“(d) Update notification—If an agency determines there is a significant change in the reasonable basis to conclude that a breach occurred, a significant change to the determination made under subsection (a)(1), or that it is necessary to update the details of the information provided to potentially affected individuals as described in subsection (b), the agency shall as expeditiously as practicable and without unreasonable delay, and in any case not later than 30 days after such a determination, notify each individual who received a notification pursuant to subsection (a) of those changes.

“(e) Rule of construction—Nothing in this section shall be construed to limit—

“(1) the Director from issuing guidance relating to notifications or the head of an agency from notifying individuals potentially affected by breaches that are not determined to be major incidents; or

“(2) the Director from issuing guidance relating to notifications of major incidents or the head of an agency from providing more information than described in subsection (b) when notifying individuals potentially affected by breaches.

“3593. Congressional and Executive Branch reports

“(a) Initial report

“(1) In general—Not later than 72 hours after an agency has a reasonable basis to conclude that a major incident occurred, the head of the agency impacted by the major incident shall submit to the appropriate reporting entities a written report and, to the extent practicable, provide a briefing to the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Oversight and Reform of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the appropriate authorization and appropriations committees of Congress, taking into account—

“(A) the information known at the time of the report;

“(B) the sensitivity of the details associated with the major incident; and

“(C) the classification level of the information contained in the report.

“(2) Contents—A report required under paragraph (1) shall include, in a manner that excludes or otherwise reasonably protects personally identifiable information and to the extent permitted by applicable law, including privacy and statistical laws—

“(A) a summary of the information available about the major incident, including how the major incident occurred, information indicating that the major incident may be a breach, and information relating to the major incident as a breach, based on information available to agency officials as of the date on which the agency submits the report;

“(B) if applicable, a description and any associated documentation of any circumstances necessitating a delay in a notification to individuals potentially affected by the major incident under section 3592(c);

“(C) if applicable, an assessment of the impacts to the agency, the Federal Government, or the security of the United States, based on information available to agency officials on the date on which the agency submits the report; and

“(D) if applicable, whether any ransom has been demanded or paid, or plans to be paid, by any entity operating a Federal information system or with access to a Federal information system, unless disclosure of such information may disrupt an active Federal law enforcement or national security operation.

“(b) Supplemental report—Within a reasonable amount of time, but not later than 30 days after the date on which an agency submits a written report under subsection (a), the head of the agency shall provide to the appropriate reporting entities written updates, which may include classified annexes, on the major incident and, to the extent practicable, provide a briefing, which may include a classified component, to the congressional committees described in subsection (a)(1), including summaries of—

“(1) vulnerabilities, means by which the major incident occurred, and impacts to the agency relating to the major incident;

“(2) any risk assessment and subsequent risk-based security implementation of the affected information system before the date on which the major incident occurred;

“(3) the status of compliance of the affected information system with applicable security requirements that are directly related to the cause of the incident, at the time of the major incident;

“(4) an estimate of the number of individuals potentially affected by the major incident based on information available to agency officials as of the date on which the agency provides the update;

“(5) an assessment of the risk of harm to individuals potentially affected by the major incident based on information available to agency officials as of the date on which the agency provides the update;

“(6) an update to the assessment of the risk to agency operations, or to impacts on other agency or non-Federal entity operations, affected by the major incident based on information available to agency officials as of the date on which the agency provides the update;

“(7) the detection, response, and remediation actions of the agency, including any support provided by the Cybersecurity and Infrastructure Security Agency under section 3594(d) and status updates on the notification process described in section 3592(a), including any delay described in section 3592(c), if applicable; and

“(8) if applicable, a description of any circumstances or data leading the head of the agency to determine, pursuant to section 3592(a)(1), not to notify individuals potentially impacted by a breach.

“(c) Update report—If the agency determines that there is any significant change in the understanding of the agency of the scope, scale, or consequence of a major incident for which an agency submitted a written report under subsection (a), the agency shall provide an updated report to the appropriate reporting entities that includes information relating to the change in understanding.

“(d) Biannual report—Each agency shall submit as part of the biannual report required under section 3554(c)(1) of this title a description of each major incident that occurred during the 2-year period preceding the date on which the biannual report is submitted.

“(e) Delay and lack of notification report

“(1) In general—The Director shall submit to the appropriate reporting entities an annual report on all notification delays granted pursuant to section 3592(c).

“(2) Lack of breach notification—The Director shall submit to the appropriate reporting entities an annual report on each breach with respect to which the head of an agency determined, pursuant to section 3592(a)(1), not to notify individuals potentially impacted by the breach.

“(3) Component of other report—The Director may submit the report required under paragraph (1) as a component of the annual report submitted under section 3597(b).

“(f) Report delivery—Any written report required to be submitted under this section may be submitted in a paper or electronic format.

“(g) Threat briefing

“(1) In general—Not later than 7 days after the date on which an agency has a reasonable basis to conclude that a major incident occurred, the head of the agency, jointly with the Director, the National Cyber Director and any other Federal entity determined appropriate by the National Cyber Director, shall provide a briefing to the congressional committees described in subsection (a)(1) on the threat causing the major incident.

“(2) Components—The briefing required under paragraph (1)—

“(A) shall, to the greatest extent practicable, include an unclassified component; and

“(B) may include a classified component.

“(h) Rule of construction—Nothing in this section shall be construed to limit—

“(1) the ability of an agency to provide additional reports or briefings to Congress; or

“(2) Congress from requesting additional information from agencies through reports, briefings, or other means.

“3594. Government information sharing and incident response

“(a) In general

“(1) Incident reporting—Subject to the limitations described in subsection (b), the head of each agency shall provide any information relating to any incident affecting the agency, whether the information is obtained by the Federal Government directly or indirectly, to the Cybersecurity and Infrastructure Security Agency.

“(2) Contents—A provision of information relating to an incident made by the head of an agency under paragraph (1) shall—

“(A) include detailed information about the safeguards that were in place when the incident occurred;

“(B) whether the agency implemented the safeguards described in subparagraph (A) correctly;

“(C) in order to protect against a similar incident, identify—

“(i) how the safeguards described in subparagraph (A) should be implemented differently; and

“(ii) additional necessary safeguards; and

“(D) include information to aid in incident response, such as—

“(i) a description of the affected systems or networks;

“(ii) the estimated dates of when the incident occurred; and

“(iii) information that could reasonably help identify the party that conducted the incident or the cause of the incident, subject to appropriate privacy protections.

“(3) Information sharing—The Director of the Cybersecurity and Infrastructure Security Agency shall—

“(A) make incident information provided under paragraph (1) available to the Director and the National Cyber Director;

“(B) to the greatest extent practicable, share information relating to an incident with the head of any agency that may be—

“(i) impacted by the incident;

“(ii) similarly susceptible to the incident; or

“(iii) similarly targeted by the incident; and

“(C) coordinate any necessary information sharing efforts relating to a major incident with the private sector.

“(4) National security systems—Each agency operating or exercising control of a national security system shall share information about incidents that occur on national security systems with the Director of the Cybersecurity and Infrastructure Security Agency to the extent consistent with standards and guidelines for national security systems issued in accordance with law and as directed by the President.

“(b) Compliance—In providing information and selecting a method to provide information under subsection (a), the head of each agency shall take into account the level of classification of the information and any information sharing limitations and protections, such as limitations and protections relating to law enforcement, national security, privacy, statistical confidentiality, or other factors determined by the Director in order to implement subsection (a)(1) in a manner that enables automated and consistent reporting to the greatest extent practicable.

“(c) Incident response—Each agency that has a reasonable basis to conclude that a major incident occurred involving Federal information in electronic medium or form that does not exclusively involve a national security system, regardless of delays from notification granted for a major incident that is also a breach, shall coordinate with the Cybersecurity and Infrastructure Security Agency to facilitate asset response activities and provide recommendations for mitigating future incidents.

“3595. Responsibilities of contractors and awardees

“(a) Reporting

“(1) In general—Unless otherwise specified in a contract, grant, cooperative agreement, or an other transaction agreement, any contractor or awardee of an agency shall report to the agency within the same amount of time such agency is required to report an incident to the Cybersecurity and Infrastructure Security Agency, if the contractor or awardee has a reasonable basis to suspect or conclude that—

“(A) an incident or breach has occurred with respect to Federal information collected, used, or maintained by the contractor or awardee in connection with the contract, grant, cooperative agreement, or other transaction agreement of the contractor or awardee;

“(B) an incident or breach has occurred with respect to a Federal information system used or operated by the contractor or awardee in connection with the contract, grant, cooperative agreement, or other transaction agreement of the contractor or awardee; or

“(C) the contractor or awardee has received information from the agency that the contractor or awardee is not authorized to receive in connection with the contract, grant, cooperative agreement, or other transaction agreement of the contractor or awardee.

“(2) Procedures

“(A) Major incident—Following a report of a breach or major incident by a contractor or awardee under paragraph (1), the agency, in consultation with the contractor or awardee, shall carry out the requirements under sections 3592, 3593, and 3594 with respect to the major incident.

“(B) Incident—Following a report of an incident by a contractor or awardee under paragraph (1), an agency, in consultation with the contractor or awardee, shall carry out the requirements under section 3594 with respect to the incident.

“(b) Effective date—This section shall apply—

“(1) on and after the date that is 1 year after the date of enactment of the Federal Information Security Modernization Act of 2022; and

“(2) with respect to any contract entered into on or after the date described in paragraph (1).

“3596. Training

“(a) Covered individual defined—In this section, the term “covered individual” means an individual who obtains access to Federal information or Federal information systems because of the status of the individual as an employee, contractor, awardee, volunteer, or intern of an agency.

“(b) Requirement—The head of each agency shall develop training for covered individuals on how to identify and respond to an incident, including—

“(1) the internal process of the agency for reporting an incident; and

“(2) the obligation of a covered individual to report to the agency a confirmed major incident and any suspected incident involving information in any medium or form, including paper, oral, and electronic.

“(c) Inclusion in annual training—The training developed under subsection (b) may be included as part of an annual privacy or security awareness training of an agency.

“3597. Analysis and report on Federal incidents

“(a) Analysis of federal incidents

“(1) Quantitative and qualitative analyses—The Director of the Cybersecurity and Infrastructure Security Agency shall develop, in consultation with the Director and the National Cyber Director, and perform continuous monitoring and quantitative and qualitative analyses of incidents at agencies, including major incidents, including—

“(A) the causes of incidents, including—

“(i) attacker tactics, techniques, and procedures; and

“(ii) system vulnerabilities, including zero days, unpatched systems, and information system misconfigurations;

“(B) the scope and scale of incidents at agencies;

“(C) common root causes of incidents across multiple Federal agencies;

“(D) agency incident response, recovery, and remediation actions and the effectiveness of those actions, as applicable;

“(E) lessons learned and recommendations in responding to, recovering from, remediating, and mitigating future incidents; and

“(F) trends across multiple Federal agencies to address intrusion detection and incident response capabilities using the metrics established under section 224(c) of the Cybersecurity Act of 2015 (6 U.S.C. 1522(c)).

“(2) Automated analysis—The analyses developed under paragraph (1) shall, to the greatest extent practicable, use machine readable data, automation, and machine learning processes.

“(3) Sharing of data and analysis

“(A) In general—The Director shall share on an ongoing basis the analyses required under this subsection with agencies and the National Cyber Director to—

“(i) improve the understanding of cybersecurity risk of agencies; and

“(ii) support the cybersecurity improvement efforts of agencies.

“(B) Format—In carrying out subparagraph (A), the Director shall share the analyses—

“(i) in human-readable written products; and

“(ii) to the greatest extent practicable, in machine-readable formats in order to enable automated intake and use by agencies.

“(b) Annual report on Federal incidents—Not later than 2 years after the date of enactment of this section, and not less frequently than annually thereafter, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, the National Cyber Director and the heads of other Federal agencies, as appropriate, shall submit to the appropriate reporting entities a report that includes—

“(1) a summary of causes of incidents from across the Federal Government that categorizes those incidents as incidents or major incidents;

“(2) the quantitative and qualitative analyses of incidents developed under subsection (a)(1) on an agency-by-agency basis and comprehensively across the Federal Government, including—

“(A) a specific analysis of breaches; and

“(B) an analysis of the Federal Government’s performance against the metrics established under section 224(c) of the Cybersecurity Act of 2015 (6 U.S.C. 1522(c)); and

“(3) an annex for each agency that includes—

“(A) a description of each major incident;

“(B) the total number of incidents of the agency; and

“(C) an analysis of the agency’s performance against the metrics established under section 224(c) of the Cybersecurity Act of 2015 (6 U.S.C. 1522(c)).

“(c) Publication

“(1) In general—A version of each report submitted under subsection (b) shall be made publicly available on the website of the Cybersecurity and Infrastructure Security Agency during the year in which the report is submitted.

“(2) Exemption—The Director of the Cybersecurity and Infrastructure Security Agency may exempt all or a portion of a report described in paragraph (1) from public publication if the Director of the Cybersecurity and Infrastructure Security Agency determines the exemption is in the interest of national security.

“(3) Limitation on exemption—An exemption granted under paragraph (2) shall not apply to any version of a report submitted to the appropriate reporting entities under subsection (b).

“(d) Information provided by agencies

“(1) In general—The analysis required under subsection (a) and each report submitted under subsection (b) shall use information provided by agencies under section 3594(a).

“(2) Noncompliance reports

“(A) In general—Subject to subparagraph (B), during any year during which the head of an agency does not provide data for an incident to the Cybersecurity and Infrastructure Security Agency in accordance with section 3594(a), the head of the agency, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the Director, shall submit to the appropriate reporting entities a report that includes the information described in subsection (b) with respect to the agency.

“(B) Exception for national security systems—The head of an agency that owns or exercises control of a national security system shall not include data for an incident that occurs on a national security system in any report submitted under subparagraph (A).

“(3) National security system reports

“(A) In general—Annually, the head of an agency that operates or exercises control of a national security system shall submit a report that includes the information described in subsection (b) with respect to the national security system to the extent that the submission is consistent with standards and guidelines for national security systems issued in accordance with law and as directed by the President to—

“(i) the majority and minority leaders of the Senate,

“(ii) the Speaker and minority leader of the House of Representatives;

“(iii) the Committee on Homeland Security and Governmental Affairs of the Senate;

“(iv) the Select Committee on Intelligence of the Senate;

“(v) the Committee on Armed Services of the Senate;

“(vi) the Committee on Appropriations of the Senate;

“(vii) the Committee on Oversight and Reform of the House of Representatives;

“(viii) the Committee on Homeland Security of the House of Representatives;

“(ix) the Permanent Select Committee on Intelligence of the House of Representatives;

“(x) the Committee on Armed Services of the House of Representatives; and

“(xi) the Committee on Appropriations of the House of Representatives.

“(B) Classified form—A report required under subparagraph (A) may be submitted in a classified form.

“(e) Requirement for compiling information—In publishing the public report required under subsection (c), the Director of the Cybersecurity and Infrastructure Security Agency shall sufficiently compile information such that no specific incident of an agency can be identified, except with the concurrence of the Director of the Office of Management and Budget and in consultation with the impacted agency.

“3598. Major incident definition

“(a) In general—Not later than 180 days after the date of enactment of the Federal Information Security Modernization Act of 2022, the Director, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director, shall develop and promulgate guidance on the definition of the term “major incident” for the purposes of subchapter II and this subchapter.

“(b) Requirements—With respect to the guidance issued under subsection (a), the definition of the term major incident shall—

“(1) include, with respect to any information collected or maintained by or on behalf of an agency or an information system used or operated by an agency or by a contractor of an agency or another organization on behalf of an agency—

“(A) any incident the head of the agency determines is likely to have an impact on—

“(i) the national security, homeland security, or economic security of the United States; or

“(ii) the civil liberties or public health and safety of the people of the United States;

“(B) any incident the head of the agency determines likely to result in an inability for the agency, a component of the agency, or the Federal Government, to provide 1 or more critical services;

“(C) any incident that the head of an agency, in consultation with a senior privacy officer of the agency, determines is likely to have a significant privacy impact on 1 or more individual;

“(D) any incident that the head of the agency, in consultation with a senior privacy official of the agency, determines is likely to have a substantial privacy impact on a significant number of individuals;

“(E) any incident the head of the agency determines substantially disrupts the operations of a high value asset owned or operated by the agency;

“(F) any incident involving the exposure of sensitive agency information to a foreign entity, such as the communications of the head of the agency, the head of a component of the agency, or the direct reports of the head of the agency or the head of a component of the agency; and

“(G) any other type of incident determined appropriate by the Director;

“(2) stipulate that the National Cyber Director, in consultation with the Director, shall declare a major incident at each agency impacted by an incident if it is determined that an incident—

“(A) occurs at not less than 2 agencies; and

“(B) is enabled by—

“(i) a common technical root cause, such as a supply chain compromise, a common software or hardware vulnerability; or

“(ii) the related activities of a common threat actor; and

“(3) stipulate that, in determining whether an incident constitutes a major incident because that incident is any incident described in paragraph (1), the head of the agency shall consult with the National Cyber Director and may consult with the Director of the Cybersecurity and Infrastructure Security Agency.

“(c) Significant number of individuals—In determining what constitutes a significant number of individuals under subsection (b)(1)(D), the Director—

“(1) may determine a threshold for a minimum number of individuals that constitutes a significant amount; and

“(2) may not determine a threshold described in paragraph (1) that exceeds 5,000 individuals.

“(d) Evaluation and updates—Not later than 2 years after the date of enactment of the Federal Information Security Modernization Act of 2022, and not less frequently than every 2 years thereafter, the Director shall provide a briefing to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives, which shall include—

“(1) an evaluation of any necessary updates to the guidance issued under subsection (a);

“(2) an evaluation of any necessary updates to the definition of the term major incident included in the guidance issued under subsection (a); and

“(3) an explanation of, and the analysis that led to, the definition described in paragraph (2).”

(2)
Clerical amendment— The table of sections for chapter 35 of title 44, United States Code, is amended by adding at the end the following:

Sec. 104 Amendments to subtitle III of title 40

(a)
Modernizing Government Technology— Subtitle G of title X of Division A of the National Defense Authorization Act for Fiscal Year 2018 (40 U.S.C. 11301 note) is amended in section 1078—
(1)
by striking subsection (a) and inserting the following:

“(a) Definitions—In this section:

“(1) Agency—The term agency has the meaning given the term in section 551 of title 5, United States Code.

“(2) High value asset—The term high value asset has the meaning given the term in section 3552 of title 44, United States Code.”

(2)
in subsection (b), by adding at the end the following:

“(8) Proposal evaluation—The Director shall—

“(A) give consideration for the use of amounts in the Fund to improve the security of high value assets; and

“(B) require that any proposal for the use of amounts in the Fund includes a cybersecurity plan, including a supply chain risk management plan, to be reviewed by the member of the Technology Modernization Board described in subsection (c)(5)(C).”

(3)
in subsection (c)—
(A)
in paragraph (2)(A)(i), by inserting “, including a consideration of the impact on high value assets” after “operational risks”;
(B)
in paragraph (5)—
(i)
in subparagraph (A), by striking “and” at the end;
(ii)
in subparagraph (B), by striking the period at the end and inserting “and”; and
(iii)
by adding at the end the following:

“(C) a senior official from the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, appointed by the Director.”

(C)
in paragraph (6)(A), by striking “shall be—” and all that follows through “4 employees” and inserting “shall be 4 employees”.
(b)
Subchapter I— Subchapter I of chapter 113 of subtitle III of title 40, United States Code, is amended—
(1)
in section 11302—
(A)
in subsection (b), by striking “use, security, and disposal of” and inserting “use, and disposal of, and, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency and the National Cyber Director, promote and improve the security of,”;
(B)
in subsection (c)—
(i)
in paragraph (3)—
(I)
in subparagraph (A)—
(aa)
by striking “including data” and inserting

“(i) include data”

(bb)
by adding at the end the following:

“(ii) specifically denote cybersecurity funding under the risk-based cyber budget model developed pursuant to section 3553(a)(7) of title 44.”

(II)
in subparagraph (B), by adding at the end the following:

“(iii) The Director shall provide to the National Cyber Director any cybersecurity funding information described in subparagraph (A)(ii) that is provided to the Director under clause (ii) of this subparagraph.”

(C)
in subsection (f)—
(i)
by striking “heads of executive agencies to develop” and inserting “heads of executive agencies to—

“(1) develop”

(ii)
in paragraph (1), as so designated, by striking the period at the end and inserting “; and”; and
(iii)
by adding at the end the following:

“(2) consult with the Director of the Cybersecurity and Infrastructure Security Agency for the development and use of supply chain security best practices.”

(D)
in subsection (h), by inserting “, including cybersecurity performances,” after “the performances”; and
(2)
in section 11303(b)—
(A)
in paragraph (2)(B)—
(i)
in clause (i), by striking “or” at the end;
(ii)
in clause (ii), by adding “or” at the end; and
(iii)
by adding at the end the following:

“(iii) whether the function should be performed by a shared service offered by another executive agency;”

(B)
in paragraph (5)(B)(i), by inserting “, while taking into account the risk-based cyber budget model developed pursuant to section 3553(a)(7) of title 44” after “title 31”.
(c)
Subchapter II— Subchapter II of chapter 113 of subtitle III of title 40, United States Code, is amended—
(1)
in section 11312(a), by inserting “, including security risks” after “managing the risks”;
(2)
in section 11313(1), by striking “efficiency and effectiveness” and inserting “efficiency, security, and effectiveness”;
(3)
in section 11315, by adding at the end the following:

“(d) Component agency chief information officers—The Chief Information Officer or an equivalent official of a component agency shall report to—

“(1) the Chief Information Officer designated under section 3506(a)(2) of title 44 or an equivalent official of the agency of which the component agency is a component; and

“(2) the head of the component agency.

“(e) Reporting structure exemption

“(1) In general—On annual basis, the Director may exempt any agency from the reporting structure requirements under subsection (d).

“(2) Report—On an annual basis, the Director shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a report that includes a list of each exemption granted under paragraph (1) and the associated rationale for each exemption.

“(3) Component of other report—The report required under paragraph (2) may be incorporated into any other annual report required under chapter 35 of title 44, United States Code.”

(4)
in section 11317, by inserting “security,” before “or schedule”; and
(5)
in section 11319(b)(1), in the paragraph heading, by striking “CIOS” and inserting “Chief Information Officers”.
(d)
removed Subchapter III— Section 11331 of title 40, United States Code, is amended—
(1)
removed in subsection (a), by striking “section 3532(b)(1)” and inserting “section 3552(b)”;
(2)
removed in subsection (b)(1)(A), by striking “the Secretary of Homeland Security” and inserting “the Director of the Cybersecurity and Infrastructure Security Agency”;
(3)
removed by striking subsection (c) and inserting the following:

removed “(c) Application of more stringent standards

removed “(1) In general—The head of an agency shall—

removed “(A) evaluate, in consultation with the senior agency information security officers, the need to employ standards for cost-effective, risk-based information security for all systems, operations, and assets within or under the supervision of the agency that are more stringent than the standards promulgated by the Director under this section, if such standards contain, at a minimum, the provisions of those applicable standards made compulsory and binding by the Director; and

removed “(B) to the greatest extent practicable and if the head of the agency determines that the standards described in subparagraph (A) are necessary, employ those standards.

removed “(2) Evaluation of more stringent standards—In evaluating the need to employ more stringent standards under paragraph (1), the head of an agency shall consider available risk information, such as—

removed “(A) the status of cybersecurity remedial actions of the agency;

removed “(B) any vulnerability information relating to agency systems that is known to the agency;

removed “(C) incident information of the agency;

removed “(D) information from—

removed “(i) penetration testing performed under section 3559A of title 44; and

removed “(ii) information from the vulnerability disclosure program established under section 3559B of title 44;

removed “(E) agency threat hunting results under section 112 of the Federal Information Security Modernization Act of 2022;

removed “(F) Federal and non-Federal cyber threat intelligence;

removed “(G) data on compliance with standards issued under this section;

removed “(H) agency system risk assessments performed under section 3554(a)(1)(A) of title 44; and

removed “(I) any other information determined relevant by the head of the agency.”

(4)
removed in subsection (d)(2)—
(A)
removed in the paragraph heading, by striking “Notice and comment” and inserting “Consultation, notice, and comment”;
(B)
removed by inserting “promulgate,” before “significantly modify”; and
(C)
removed by striking “shall be made after the public is given an opportunity to comment on the Director’s proposed decision.” and inserting “shall be made—

removed “(A) for a decision to significantly modify or not promulgate such a proposed standard, after the public is given an opportunity to comment on the Director’s proposed decision;

removed “(B) in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency;

removed “(C) considering the Federal risk assessments performed under section 3553(i) of title 44; and

removed “(D) considering the extent to which the proposed standard reduces risk relative to the cost of implementation of the standard.”

(5)
removed by adding at the end the following:

removed “(e) Review of office of management and budget guidance and policy

removed “(1) Conduct of review

removed “(A) In general—Not less frequently than once every 3 years, the Director of the Office of Management and Budget, in consultation with the Chief Information Officers Council, the Director of the Cybersecurity and Infrastructure Security Agency, the National Cyber Director, the Comptroller General of the United States, and the Council of the Inspectors General on Integrity and Efficiency, shall review the efficacy of the guidance and policy promulgated by the Director in reducing cybersecurity risks, including an assessment of the requirements for agencies to report information to the Director, and determine whether any changes to that guidance or policy is appropriate.

removed “(B) Federal risk assessments—In conducting the review described in subparagraph (A), the Director shall consider the Federal risk assessments performed under section 3553(i) of title 44.

removed “(C) Requirements burden reduction and clarity—In conducting the review described in subparagraph (A), the Director shall consider—

removed “(i) the cumulative reporting and compliance burden to agencies; and

removed “(ii) the clarity of the requirements and deadlines contained in guidance and policy documents.

removed “(2) Updated guidance—Not later than 90 days after the date on which a review is completed under paragraph (1), the Director of the Office of Management and Budget shall issue updated guidance or policy to agencies determined appropriate by the Director, based on the results of the review.

removed “(3) Public report—Not later than 30 days after the date on which a review is completed under paragraph (1), the Director of the Office of Management and Budget shall make publicly available a report that includes—

removed “(A) an overview of the guidance and policy promulgated under this section that is currently in effect;

removed “(B) the cybersecurity risk mitigation, or other cybersecurity benefit, offered by each guidance or policy document described in subparagraph (A); and

removed “(C) a summary of the guidance or policy to which changes were determined appropriate during the review and what the changes are anticipated to include.

removed “(4) Congressional briefing—Not later than 60 days after the date on which a review is completed under paragraph (1), the Director shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Oversight and Reform of the House of Representatives a briefing on the review.

removed “(f) Automated standard implementation verification—When the Director of the National Institute of Standards and Technology issues a proposed standard pursuant to paragraphs (2) and (3) of section 20(a) of the National Institute of Standards and Technology Act (15 U.S.C. 278g–3(a)), the Director of the National Institute of Standards and Technology shall consider developing and, if appropriate and practical, develop, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, specifications to enable the automated verification of the implementation of the controls within the standard.”

Sec. 112 Ongoing threat hunting program

(a)
Threat hunting program—
(1)
In general— Not later than 540 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.
(2)
Plan— Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish the program required under paragraph (1) that describes how the Director of the Cybersecurity and Infrastructure Security Agency plans to—
(A)
determine the method for collecting, storing, accessing, analyzing, and safeguarding appropriate agency data;
(B)
provide on-premises support to agencies;
(C)
staff threat hunting services;
(D)
allocate available human and financial resources to implement the plan; and
(E)
changed provide input to the heads of agencies on the use of—of additional cybersecurity procedures under section 3554 of title 44, United States Code.
(i)
removed more stringent standards under section 11331(c)(1) of title 40, United States Code; and
(ii)
removed additional cybersecurity procedures under section 3554 of title 44, United States Code.
(b)
Reports— The Director of the Cybersecurity and Infrastructure Security Agency shall submit to the appropriate congressional committees—
(1)
not later than 30 days after the date on which the Director of the Cybersecurity and Infrastructure Security Agency completes the plan required under subsection (a)(2), a report on the plan to provide threat hunting services to agencies;
(2)
not less than 30 days before the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services under the program under subsection (a)(1), a report providing any updates to the plan developed under subsection (a)(2); and
(3)
not later than 1 year after the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services to agencies other than the Cybersecurity and Infrastructure Security Agency, a report describing lessons learned from providing those services.

Sec. 123 Federal cybersecurity requirements

added
(a)
added Exemption from Federal requirements— Section 225(b)(2) of the Federal Cybersecurity Enhancement Act of 2015 (6 U.S.C. 1523(b)(2)) is amended to read as follows:

added “(2) Exception

added “(A) In general—A particular requirement under paragraph (1) shall not apply to an agency information system of an agency if—

added “(i) with respect to the agency information system, the head of the agency submits to the Director an application for an exemption from the particular requirement, in which the head of the agency personally certifies to the Director with particularity that—

added “(I) operational requirements articulated in the certification and related to the agency information system would make it excessively burdensome to implement the particular requirement;

added “(II) the particular requirement is not necessary to secure the agency information system or agency information stored on or transiting the agency information system; and

added “(III) the agency has taken all necessary steps to secure the agency information system and agency information stored on or transiting the agency information system;

added “(ii) the head of the agency or the designee of the head of the agency has submitted the certification described in clause (i) to the appropriate congressional committees and any other congressional committee with jurisdiction over the agency; and

added “(iii) the Director grants the exemption from the particular requirement.

added “(B) Duration of exemption

added “(i) In general—An exemption granted under subparagraph (A) shall expire on the date that is 1 year after the date on which the Director granted the exemption.

added “(ii) Renewal—Upon the expiration of an exemption granted to an agency under subparagraph (A), the head of the agency may apply for an additional exemption.”

(b)
added Report on exemptions— Section 3554(c)(1) of title 44, United States Code, as amended by section 103(c) of this title, is amended—
(1)
added in subparagraph (C), by striking “and” at the end;
(2)
added in subparagraph (D), by striking the period at the end and inserting “; and”; and
(3)
added by adding at the end the following:

added “(E) with respect to any exemption the Director of the Office of Management and Budget has granted the agency under section 225(b)(2) of the Federal Cybersecurity Enhancement Act of 2015 (6 U.S.C. 1523(b)(2)) that is effective on the date of submission of the report—

added “(i) an identification of each particular requirement from which any agency information system (as defined in section 2210 of the Homeland Security Act of 2002 (6 U.S.C. 660)) is exempted; and

added “(ii) for each requirement identified under clause (i)—

added “(I) an identification of the agency information system described in clause (i) exempted from the requirement; and

added “(II) an estimate of the date on which the agency will to be able to comply with the requirement.”

(c)
added Effective date— The amendments made by this section shall take effect on the date that is 1 year after the date of enactment of this Act.