H. R. 2029—723
‘‘(2) the terms ‘cybersecurity risk’ and ‘information system’
have the meanings given those terms in section 227;
‘‘(3) the term ‘intelligence community’ has the meaning
given the term in section 3(4) of the National Security Act
of 1947 (50 U.S.C. 3003(4)); and
‘‘(4) the term ‘national security system’ has the meaning
given the term in section 11103 of title 40, United States
Code.
‘‘(b) INTRUSION ASSESSMENT PLAN.—
‘‘(1) REQUIREMENT.—The Secretary, in coordination with
the Director of the Office of Management and Budget, shall—
‘‘(A) develop and implement an intrusion assessment
plan to proactively detect, identify, and remove intruders
in agency information systems on a routine basis; and
‘‘(B) update such plan as necessary.
‘‘(2) EXCEPTION.—The intrusion assessment plan required
under paragraph (1) shall not apply to the Department of
Defense, a national security system, or an element of the intelligence community.’’;
(5) in section 228(c), as so redesignated, by striking ‘‘section
226’’ and inserting ‘‘section 227’’; and
(6) by inserting after section 229, as so redesignated, the
following:
‘‘SEC.
230.
FEDERAL
SYSTEM.
INTRUSION
DETECTION
AND
PREVENTION
‘‘(a) DEFINITIONS.—In this section—
‘‘(1) the term ‘agency’ has the meaning given the term
in section 3502 of title 44, United States Code;
‘‘(2) the term ‘agency information’ means information collected or maintained by or on behalf of an agency;
‘‘(3) the term ‘agency information system’ has the meaning
given the term in section 228; and
‘‘(4) the terms ‘cybersecurity risk’ and ‘information system’
have the meanings given those terms in section 227.
‘‘(b) REQUIREMENT.—
‘‘(1) IN GENERAL.—Not later than 1 year after the date
of enactment of this section, the Secretary shall deploy, operate,
and maintain, to make available for use by any agency, with
or without reimbursement—
‘‘(A) a capability to detect cybersecurity risks in network traffic transiting or traveling to or from an agency
information system; and
‘‘(B) a capability to prevent network traffic associated
with such cybersecurity risks from transiting or traveling
to or from an agency information system or modify such
network traffic to remove the cybersecurity risk.
‘‘(2) REGULAR IMPROVEMENT.—The Secretary shall regularly
deploy new technologies and modify existing technologies to
the intrusion detection and prevention capabilities described
in paragraph (1) as appropriate to improve the intrusion detection and prevention capabilities.
‘‘(c) ACTIVITIES.—In carrying out subsection (b), the Secretary—
‘‘(1) may access, and the head of an agency may disclose
to the Secretary or a private entity providing assistance to
the Secretary under paragraph (2), information transiting or
traveling to or from an agency information system, regardless