H. R. 2029—744
(B) A description and list of the logical access controls
and multi-factor authentication used by the covered agency
to govern access to covered systems by privileged users.
(C) If the covered agency does not use logical access
controls or multi-factor authentication to access a covered
system, a description of the reasons for not using such
logical access controls or multi-factor authentication.
(D) A description of the following information security
management practices used by the covered agency
regarding covered systems:
(i) The policies and procedures followed to conduct
inventories of the software present on the covered systems of the covered agency and the licenses associated
with such software.
(ii) What capabilities the covered agency utilizes
to monitor and detect exfiltration and other threats,
including—
(I) data loss prevention capabilities;
(II) forensics and visibility capabilities; or
(III) digital rights management capabilities.
(iii) A description of how the covered agency is
using the capabilities described in clause (ii).
(iv) If the covered agency is not utilizing capabilities described in clause (ii), a description of the reasons
for not utilizing such capabilities.
(E) A description of the policies and procedures of
the covered agency with respect to ensuring that entities,
including contractors, that provide services to the covered
agency are implementing the information security management practices described in subparagraph (D).
(3) EXISTING REVIEW.—The reports required under this subsection may be based in whole or in part on an audit, evaluation, or report relating to programs or practices of the covered
agency, and may be submitted as part of another report,
including the report required under section 3555 of title 44,
United States Code.
(4) CLASSIFIED INFORMATION.—Reports submitted under
this subsection shall be in unclassified form, but may include
a classified annex.
SEC. 407. STOPPING THE FRAUDULENT SALE OF FINANCIAL INFORMATION OF PEOPLE OF THE UNITED STATES.
Section 1029(h) of title 18, United States Code, is amended
by striking ‘‘title if—’’ and all that follows through ‘‘therefrom.’’
and inserting ‘‘title if the offense involves an access device issued,
owned, managed, or controlled by a financial institution, account
issuer, credit card system member, or other entity organized under
the laws of the United States, or any State, the District of Columbia,
or other territory of the United States.’’.