H. R. 2029—726
as section 226 (relating to the national cybersecurity and communications integration center), section 227, and section 228 and
inserting the following:
‘‘Sec.
‘‘Sec.
‘‘Sec.
‘‘Sec.
‘‘Sec.
226.
227.
228.
229.
230.
Cybersecurity recruitment and retention.
National cybersecurity and communications integration center.
Cybersecurity plans.
Clearances.
Federal intrusion detection and prevention system.’’.
SEC. 224. ADVANCED INTERNAL DEFENSES.
(a) ADVANCED NETWORK SECURITY TOOLS.—
(1) IN GENERAL.—The Secretary shall include, in the efforts
of the Department to continuously diagnose and mitigate cybersecurity risks, advanced network security tools to improve visibility of network activity, including through the use of commercial and free or open source tools, and to detect and mitigate
intrusions and anomalous activity.
(2) DEVELOPMENT OF PLAN.—The Director shall develop
and the Secretary shall implement a plan to ensure that each
agency utilizes advanced network security tools, including those
described in paragraph (1), to detect and mitigate intrusions
and anomalous activity.
(b) PRIORITIZING ADVANCED SECURITY TOOLS.—The Director
and the Secretary, in consultation with appropriate agencies, shall—
(1) review and update Government-wide policies and programs to ensure appropriate prioritization and use of network
security monitoring tools within agency networks; and
(2) brief appropriate congressional committees on such
prioritization and use.
(c) IMPROVED METRICS.—The Secretary, in collaboration with
the Director, shall review and update the metrics used to measure
security under section 3554 of title 44, United States Code, to
include measures of intrusion and incident detection and response
times.
(d) TRANSPARENCY AND ACCOUNTABILITY.—The Director, in consultation with the Secretary, shall increase transparency to the
public on agency cybersecurity posture, including by increasing
the number of metrics available on Federal Government performance websites and, to the greatest extent practicable, displaying
metrics for department components, small agencies, and microagencies.
(e) MAINTENANCE OF TECHNOLOGIES.—Section 3553(b)(6)(B) of
title 44, United States Code, is amended by inserting ‘‘, operating,
and maintaining’’ after ‘‘deploying’’.
(f) EXCEPTION.—The requirements under this section shall not
apply to the Department of Defense, a national security system,
or an element of the intelligence community.
SEC. 225. FEDERAL CYBERSECURITY REQUIREMENTS.
(a) IMPLEMENTATION OF
ARDS.—Consistent with section
FEDERAL CYBERSECURITY STAND3553 of title 44, United States Code,
the Secretary, in consultation with the Director, shall exercise the
authority to issue binding operational directives to assist the
Director in ensuring timely agency adoption of and compliance
with policies and standards promulgated under section 11331 of
title 40, United States Code, for securing agency information systems.
(b) CYBERSECURITY REQUIREMENTS AT AGENCIES.—