H. R. 2029—729
(iv) a list of the types of indicators or other identifiers or techniques used to detect cybersecurity risks
in network traffic transiting or traveling to or from
agency information systems on each iteration of the
intrusion detection and prevention capabilities and the
number of each such type of indicator, identifier, and
technique;
(v) the number of instances in which the intrusion
detection and prevention capabilities detected a cybersecurity risk in network traffic transiting or traveling
to or from agency information systems and the number
of times the intrusion detection and prevention
capabilities blocked network traffic associated with
cybersecurity risk; and
(vi) a description of the pilot established under
section 230(c)(5) of the Homeland Security Act of 2002,
as added by section 223(a)(6) of this division, including
the number of new technologies tested and the number
of participating agencies.
(B) OMB REPORT.—Not later than 18 months after
the date of enactment of this Act, and annually thereafter,
the Director shall submit to Congress, as part of the report
required under section 3553(c) of title 44, United States
Code, an analysis of agency application of the intrusion
detection and prevention capabilities, including—
(i) a list of each agency and the degree to which
each agency has applied the intrusion detection and
prevention capabilities to an agency information
system; and
(ii) a list by agency of—
(I) the number of instances in which the intrusion detection and prevention capabilities detected
a cybersecurity risk in network traffic transiting
or traveling to or from an agency information
system and the types of indicators, identifiers, and
techniques used to detect such cybersecurity risks;
and
(II) the number of instances in which the
intrusion detection and prevention capabilities prevented network traffic associated with a cybersecurity risk from transiting or traveling to or from
an agency information system and the types of
indicators, identifiers, and techniques used to
detect such agency information systems.
(C) CHIEF INFORMATION OFFICER.—Not earlier than 18
months after the date of enactment of this Act and not
later than 2 years after the date of enactment of this
Act, the Federal Chief Information Officer shall review
and submit to the appropriate congressional committees
a report assessing the intrusion detection and intrusion
prevention capabilities, including—
(i) the effectiveness of the system in detecting,
disrupting, and preventing cyber-threat actors,
including advanced persistent threats, from accessing
agency information and agency information systems;
(ii) whether the intrusion detection and prevention
capabilities, continuous diagnostics and mitigation, and