Advancing Cybersecurity Through Continuous Diagnostics and Mitigation Act
A BILL
To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes.
Sec. 2 Establishment of Federal intrusion detection and prevention system and continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency
“(g) Continuous diagnostics and mitigation
“(1) Program
“(A) In general—The Secretary, acting through the Director, shall, with or without reimbursement, deploy, operate, and maintain a continuous diagnostics and mitigation program for agencies under which the Secretary shall—
“(i) assist agencies to continuously diagnose and mitigate cyber threats and vulnerabilities;
“(ii) develop and provide the capability to collect, analyze, and visualize information relating to security data and cybersecurity risks at agencies;
“(iii) employ shared services, collective purchasing, blanket purchase agreements, and any other economic or procurement models the Secretary determines appropriate to maximize the costs savings associated with implementing the program;
“(iv) assist agencies in setting information security priorities and assessing and managing cybersecurity risks;
“(v) develop policies and procedures for reporting systemic cybersecurity risks and potential incidents based upon data collected under the program; and
“(vi) promote the adoption of a zero trust security model in improving agency cybersecurity readiness.
“(B) Regular improvement—The Secretary shall regularly—
“(i) deploy new technologies and modify existing technologies to the continuous diagnostics and mitigation program required under subparagraph (A), as appropriate, to improve the program; and
“(ii) update the technical requirements documentation of the continuous diagnostics and mitigation program required under subparagraph (A) to account for emerging technology capabilities such as cloud computing and comprehensive cloud security controls.
“(2) Agency responsibilities—Notwithstanding any other provision of law, each agency that uses the continuous diagnostics and mitigation program under paragraph (1) shall, continuously and in real time, provide to and allow access for the Secretary to collect all information, assessments, analyses, and raw data collected by the program, in a manner specified by the Secretary.
“(3) Responsibilities of the Secretary—In carrying out the continuous diagnostics and mitigation program under paragraph (1), the Secretary, acting through the Director, shall—
“(A) share with agencies relevant analysis and products developed under the program;
“(B) provide regular reports on cybersecurity risks to agencies;
“(C) provide comparative assessments of cybersecurity risks for agencies;
“(D) oversee the integration of continuous diagnostics and mitigation products and services into agency systems;
“(E) establish performance requirements for product integrators;
“(F) at the request of an agency, provide technical assistance in selecting, procuring, and integrating continuous diagnostics and mitigation products and services;
“(G) not less than once each fiscal year, submit to the appropriate committees of Congress a report that includes—
“(i) the progress made by each agency to meet continuous diagnostics and mitigation benchmarks from the beginning of the implementation through the date of the report; and
“(ii) a summary of the efforts of each agency to account for emerging technology capabilities; and
“(H) take steps to ensure that the security data collected through the program is aggregated with other Government-wide cybersecurity programs to better automate defensive capabilities.”