H. R. 2029—731
SEC. 228. IDENTIFICATION OF INFORMATION SYSTEMS RELATING TO
NATIONAL SECURITY.
(a) IN GENERAL.—Except as provided in subsection (c), not
later than 180 days after the date of enactment of this Act—
(1) the Director of National Intelligence and the Director
of the Office of Management and Budget, in coordination with
the heads of other agencies, shall—
(A) identify all unclassified information systems that
provide access to information that may provide an
adversary with the ability to derive information that would
otherwise be considered classified;
(B) assess the risks that would result from the breach
of each unclassified information system identified in
subparagraph (A); and
(C) assess the cost and impact on the mission carried
out by each agency that owns an unclassified information
system identified in subparagraph (A) if the system were
to be subsequently designated as a national security
system; and
(2) the Director of National Intelligence and the Director
of the Office of Management and Budget shall submit to the
appropriate congressional committees, the Select Committee
on Intelligence of the Senate, and the Permanent Select Committee on Intelligence of the House of Representatives a report
that includes the findings under paragraph (1).
(b) FORM.—The report submitted under subsection (a)(2) shall
be in unclassified form, and shall include a classified annex.
(c) EXCEPTION.—The requirements under subsection (a)(1) shall
not apply to the Department of Defense, a national security system,
or an element of the intelligence community.
(d) RULE OF CONSTRUCTION.—Nothing in this section shall be
construed to designate an information system as a national security
system.
SEC. 229. DIRECTION TO AGENCIES.
(a) IN GENERAL.—Section 3553 of title 44, United States Code,
is amended by adding at the end the following:
‘‘(h) DIRECTION TO AGENCIES.—
‘‘(1) AUTHORITY.—
‘‘(A) IN GENERAL.—Subject to subparagraph (B), in
response to a known or reasonably suspected information
security threat, vulnerability, or incident that represents
a substantial threat to the information security of an
agency, the Secretary may issue an emergency directive
to the head of an agency to take any lawful action with
respect to the operation of the information system,
including such systems used or operated by another entity
on behalf of an agency, that collects, processes, stores,
transmits, disseminates, or otherwise maintains agency
information, for the purpose of protecting the information
system from, or mitigating, an information security threat.
‘‘(B) EXCEPTION.—The authorities of the Secretary
under this subsection shall not apply to a system described
subsection (d) or to a system described in paragraph (2)
or (3) of subsection (e).
‘‘(2) PROCEDURES FOR USE OF AUTHORITY.—The Secretary
shall—