H. R. 2029—731 SEC. 228. IDENTIFICATION OF INFORMATION SYSTEMS RELATING TO NATIONAL SECURITY. (a) IN GENERAL.—Except as provided in subsection (c), not later than 180 days after the date of enactment of this Act— (1) the Director of National Intelligence and the Director of the Office of Management and Budget, in coordination with the heads of other agencies, shall— (A) identify all unclassified information systems that provide access to information that may provide an adversary with the ability to derive information that would otherwise be considered classified; (B) assess the risks that would result from the breach of each unclassified information system identified in subparagraph (A); and (C) assess the cost and impact on the mission carried out by each agency that owns an unclassified information system identified in subparagraph (A) if the system were to be subsequently designated as a national security system; and (2) the Director of National Intelligence and the Director of the Office of Management and Budget shall submit to the appropriate congressional committees, the Select Committee on Intelligence of the Senate, and the Permanent Select Committee on Intelligence of the House of Representatives a report that includes the findings under paragraph (1). (b) FORM.—The report submitted under subsection (a)(2) shall be in unclassified form, and shall include a classified annex. (c) EXCEPTION.—The requirements under subsection (a)(1) shall not apply to the Department of Defense, a national security system, or an element of the intelligence community. (d) RULE OF CONSTRUCTION.—Nothing in this section shall be construed to designate an information system as a national security system. SEC. 229. DIRECTION TO AGENCIES. (a) IN GENERAL.—Section 3553 of title 44, United States Code, is amended by adding at the end the following: ‘‘(h) DIRECTION TO AGENCIES.— ‘‘(1) AUTHORITY.— ‘‘(A) IN GENERAL.—Subject to subparagraph (B), in response to a known or reasonably suspected information security threat, vulnerability, or incident that represents a substantial threat to the information security of an agency, the Secretary may issue an emergency directive to the head of an agency to take any lawful action with respect to the operation of the information system, including such systems used or operated by another entity on behalf of an agency, that collects, processes, stores, transmits, disseminates, or otherwise maintains agency information, for the purpose of protecting the information system from, or mitigating, an information security threat. ‘‘(B) EXCEPTION.—The authorities of the Secretary under this subsection shall not apply to a system described subsection (d) or to a system described in paragraph (2) or (3) of subsection (e). ‘‘(2) PROCEDURES FOR USE OF AUTHORITY.—The Secretary shall—

Select target paragraph3