H. R. 2029—728
Technology standards process or the requirement under section
3553(a)(4) of such title or to discourage continued improvements
and advancements in the technology, standards, policies, and
guidelines used to promote Federal information security.
(c) EXCEPTION.—The requirements under this section shall not
apply to the Department of Defense, a national security system,
or an element of the intelligence community.
SEC. 226. ASSESSMENT; REPORTS.
(a) DEFINITIONS.—In this section:
(1) AGENCY INFORMATION.—The term ‘‘agency information’’
has the meaning given the term in section 230 of the Homeland
Security Act of 2002, as added by section 223(a)(6) of this
division.
(2) CYBER THREAT INDICATOR; DEFENSIVE MEASURE.—The
terms ‘‘cyber threat indicator’’ and ‘‘defensive measure’’ have
the meanings given those terms in section 102.
(3) INTRUSION ASSESSMENTS.—The term ‘‘intrusion assessments’’ means actions taken under the intrusion assessment
plan to identify and remove intruders in agency information
systems.
(4) INTRUSION ASSESSMENT PLAN.—The term ‘‘intrusion
assessment plan’’ means the plan required under section
228(b)(1) of the Homeland Security Act of 2002, as added by
section 223(a)(4) of this division.
(5) INTRUSION DETECTION AND PREVENTION CAPABILITIES.—
The term ‘‘intrusion detection and prevention capabilities’’
means the capabilities required under section 230(b) of the
Homeland Security Act of 2002, as added by section 223(a)(6)
of this division.
(b) THIRD-PARTY ASSESSMENT.—Not later than 3 years after
the date of enactment of this Act, the Comptroller General of
the United States shall conduct a study and publish a report on
the effectiveness of the approach and strategy of the Federal
Government to securing agency information systems, including the
intrusion detection and prevention capabilities and the intrusion
assessment plan.
(c) REPORTS TO CONGRESS.—
(1) INTRUSION DETECTION AND PREVENTION CAPABILITIES.—
(A) SECRETARY OF HOMELAND SECURITY REPORT.—Not
later than 6 months after the date of enactment of this
Act, and annually thereafter, the Secretary shall submit
to the appropriate congressional committees a report on
the status of implementation of the intrusion detection
and prevention capabilities, including—
(i) a description of privacy controls;
(ii) a description of the technologies and capabilities utilized to detect cybersecurity risks in network
traffic, including the extent to which those technologies
and capabilities include existing commercial and noncommercial technologies;
(iii) a description of the technologies and capabilities utilized to prevent network traffic associated with
cybersecurity risks from transiting or traveling to or
from agency information systems, including the extent
to which those technologies and capabilities include
existing commercial and noncommercial technologies;