H. R. 2029—727
(1) IN GENERAL.—Consistent with policies, standards,
guidelines, and directives on information security under subchapter II of chapter 35 of title 44, United States Code, and
the standards and guidelines promulgated under section 11331
of title 40, United States Code, and except as provided in
paragraph (2), not later than 1 year after the date of the
enactment of this Act, the head of each agency shall—
(A) identify sensitive and mission critical data stored
by the agency consistent with the inventory required under
the first subsection (c) (relating to the inventory of major
information systems) and the second subsection (c) (relating
to the inventory of information systems) of section 3505
of title 44, United States Code;
(B) assess access controls to the data described in
subparagraph (A), the need for readily accessible storage
of the data, and individuals’ need to access the data;
(C) encrypt or otherwise render indecipherable to
unauthorized users the data described in subparagraph
(A) that is stored on or transiting agency information systems;
(D) implement a single sign-on trusted identity platform for individuals accessing each public website of the
agency that requires user authentication, as developed by
the Administrator of General Services in collaboration with
the Secretary; and
(E) implement identity management consistent with
section 504 of the Cybersecurity Enhancement Act of 2014
(Public Law 113–274; 15 U.S.C. 7464), including multifactor authentication, for—
(i) remote access to an agency information system;
and
(ii) each user account with elevated privileges on
an agency information system.
(2) EXCEPTION.—The requirements under paragraph (1)
shall not apply to an agency information system for which—
(A) the head of the agency has personally certified
to the Director with particularity that—
(i) operational requirements articulated in the certification and related to the agency information system
would make it excessively burdensome to implement
the cybersecurity requirement;
(ii) the cybersecurity requirement is not necessary
to secure the agency information system or agency
information stored on or transiting it; and
(iii) the agency has taken all necessary steps to
secure the agency information system and agency
information stored on or transiting it; and
(B) the head of the agency or the designee of the
head of the agency has submitted the certification described
in subparagraph (A) to the appropriate congressional
committees and the agency’s authorizing committees.
(3) CONSTRUCTION.—Nothing in this section shall be construed to alter the authority of the Secretary, the Director,
or the Director of the National Institute of Standards and
Technology in implementing subchapter II of chapter 35 of
title 44, United States Code. Nothing in this section shall
be construed to affect the National Institute of Standards and