H. R. 2029—723 ‘‘(2) the terms ‘cybersecurity risk’ and ‘information system’ have the meanings given those terms in section 227; ‘‘(3) the term ‘intelligence community’ has the meaning given the term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)); and ‘‘(4) the term ‘national security system’ has the meaning given the term in section 11103 of title 40, United States Code. ‘‘(b) INTRUSION ASSESSMENT PLAN.— ‘‘(1) REQUIREMENT.—The Secretary, in coordination with the Director of the Office of Management and Budget, shall— ‘‘(A) develop and implement an intrusion assessment plan to proactively detect, identify, and remove intruders in agency information systems on a routine basis; and ‘‘(B) update such plan as necessary. ‘‘(2) EXCEPTION.—The intrusion assessment plan required under paragraph (1) shall not apply to the Department of Defense, a national security system, or an element of the intelligence community.’’; (5) in section 228(c), as so redesignated, by striking ‘‘section 226’’ and inserting ‘‘section 227’’; and (6) by inserting after section 229, as so redesignated, the following: ‘‘SEC. 230. FEDERAL SYSTEM. INTRUSION DETECTION AND PREVENTION ‘‘(a) DEFINITIONS.—In this section— ‘‘(1) the term ‘agency’ has the meaning given the term in section 3502 of title 44, United States Code; ‘‘(2) the term ‘agency information’ means information collected or maintained by or on behalf of an agency; ‘‘(3) the term ‘agency information system’ has the meaning given the term in section 228; and ‘‘(4) the terms ‘cybersecurity risk’ and ‘information system’ have the meanings given those terms in section 227. ‘‘(b) REQUIREMENT.— ‘‘(1) IN GENERAL.—Not later than 1 year after the date of enactment of this section, the Secretary shall deploy, operate, and maintain, to make available for use by any agency, with or without reimbursement— ‘‘(A) a capability to detect cybersecurity risks in network traffic transiting or traveling to or from an agency information system; and ‘‘(B) a capability to prevent network traffic associated with such cybersecurity risks from transiting or traveling to or from an agency information system or modify such network traffic to remove the cybersecurity risk. ‘‘(2) REGULAR IMPROVEMENT.—The Secretary shall regularly deploy new technologies and modify existing technologies to the intrusion detection and prevention capabilities described in paragraph (1) as appropriate to improve the intrusion detection and prevention capabilities. ‘‘(c) ACTIVITIES.—In carrying out subsection (b), the Secretary— ‘‘(1) may access, and the head of an agency may disclose to the Secretary or a private entity providing assistance to the Secretary under paragraph (2), information transiting or traveling to or from an agency information system, regardless

Select target paragraph3