<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HC5E152C6BC5C4A4C9F2D545C536FB7C5" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 6443 IH: Advancing Cybersecurity Diagnostics and Mitigation Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2018-07-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 6443</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20180719">July 19, 2018</action-date><action-desc><sponsor name-id="R000601">Mr. Ratcliffe</sponsor> (for himself, <cosponsor name-id="R000588">Mr. Richmond</cosponsor>, <cosponsor name-id="M001157">Mr. McCaul</cosponsor>, <cosponsor name-id="K000386">Mr. Katko</cosponsor>, and <cosponsor name-id="F000466">Mr. Fitzpatrick</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to
			 establish a continuous diagnostics and mitigation program at the
			 Department of Homeland Security, and for other purposes.</official-title></form>
	<legis-body id="H0C7EFAA690F044D7AA2976D42D24A423" style="OLC">
 <section id="H5A1B6A60DB4A4457A7B5867780D4FBED" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Advancing Cybersecurity Diagnostics and Mitigation Act</short-title></quote>.</text> </section><section id="H11381F549F894C6BBAB8BAEC27C25976"><enum>2.</enum><header>Establishment of continuous diagnostics and mitigation program in Department of Homeland Security</header> <subsection id="HBE527121C0444C3682F9890476AEB958"><enum>(a)</enum><header>In general</header><text>Section 230 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/151">6 U.S.C. 151</external-xref>) is amended by adding at the end the following new subsection:</text>
				<quoted-block display-inline="no-display-inline" id="H5FEBDC01D3E540458532453DCD3AF212" style="OLC">
					<subsection id="H08B23F938ED54B3A817DDD7365FF39EF"><enum>(g)</enum><header>Continuous Diagnostics and Mitigation</header>
						<paragraph id="H7D96F4F455D040BFAD1B39630FE98374"><enum>(1)</enum><header>Program</header>
 <subparagraph id="H03072C9DA07C463A99EC27EF6A12F763"><enum>(A)</enum><header>In general</header><text>The Secretary shall deploy, operate, and maintain a continuous diagnostics and mitigation program. Under such program, the Secretary shall—</text>
 <clause id="H2A020EBF773442DF89DB2ECDB746934B"><enum>(i)</enum><text>develop and provide the capability to collect, analyze, and visualize information relating to security data and cybersecurity risks;</text>
 </clause><clause id="H2F2FC6BCDC784C3FBBCB17FCC3AF5687"><enum>(ii)</enum><text>make program capabilities available for use, with or without reimbursement;</text> </clause><clause id="HA93BEE6CB07941F0825154057B88E3BA"><enum>(iii)</enum><text display-inline="yes-display-inline">employ shared services, collective purchasing, blanket purchase agreements, and any other economic or procurement models the Secretary determines appropriate to maximize the costs savings associated with implementing an information system;</text>
 </clause><clause id="H66DFB1913C664F878E327ED00F625F09"><enum>(iv)</enum><text>assist entities in setting information security priorities and managing cybersecurity risks; and</text> </clause><clause id="H8DD6D5B6D5D043C4879E5FC987D74F88"><enum>(v)</enum><text>develop policies and procedures for reporting systemic cybersecurity risks and potential incidents based upon data collected under such program.</text>
 </clause></subparagraph><subparagraph id="HB00C1DFD5A7C4D238266B5749FF298A8"><enum>(B)</enum><header>Regular Improvement</header><text>The Secretary shall regularly deploy new technologies and modify existing technologies to the continuous diagnostics and mitigation program required under subparagraph (A), as appropriate, to improve the program.</text>
 </subparagraph></paragraph><paragraph id="HBBB21620CDFC43FF961B2D491E89707F"><enum>(2)</enum><header>Activities</header><text>In carrying out the continuous diagnostics and mitigation program under paragraph (1), the Secretary shall ensure, to the extent practicable, that—</text>
 <subparagraph id="HC7771F78835C42CDAE2DECC5BD9A8820"><enum>(A)</enum><text>timely, actionable, and relevant cybersecurity risk information, assessments, and analysis are provided in real time;</text>
 </subparagraph><subparagraph id="HFECF1F6506274798B8EC17DCC02D184A"><enum>(B)</enum><text>share the analysis and products developed under such program;</text> </subparagraph><subparagraph id="H2175BA0C8CAA4FC5B9118A32293AE526"><enum>(C)</enum><text>all information, assessments, analyses, and raw data under such program is made available to the national cybersecurity and communications integration center of the Department; and</text>
 </subparagraph><subparagraph id="HD3BB03FDAF774D668067B3677A50FBC5"><enum>(D)</enum><text>provide regular reports on cybersecurity risks.</text> </subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block> </subsection><subsection id="H9D36A8208D784E95B6E3F9618C544600"><enum>(b)</enum><header>Continuous Diagnostics and Mitigation Strategy</header> <paragraph id="H410B1471879E42B19E6E4EBF989A2402"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security shall develop a comprehensive continuous diagnostics and mitigation strategy to carry out the continuous diagnostics and mitigation program required under subsection (g) of section 230 of such Act, as added by subsection (a).</text>
 </paragraph><paragraph id="HE99DE013393C4B2695B992F69EFBB5D8"><enum>(2)</enum><header>Scope</header><text>The strategy required under paragraph (1) shall include the following:</text> <subparagraph id="H1E81AF5838864F09BEBA8B4C8B17E238"><enum>(A)</enum><text display-inline="yes-display-inline">A description of the continuous diagnostics and mitigation program, including efforts by the Secretary of Homeland Security to assist with the deployment of program tools, capabilities, and services, from the inception of the program referred to in paragraph (1) to the date of the enactment of this Act.</text>
 </subparagraph><subparagraph id="H269D07AD37B648ED97F6D53329128EEB"><enum>(B)</enum><text>A description of the coordination required to deploy, install, and maintain the tools, capabilities, and services that the Secretary of Homeland Security determines to be necessary to satisfy the requirements of such program.</text>
 </subparagraph><subparagraph id="HDCCEB84F32D1488DA7BEBD2B96220154"><enum>(C)</enum><text>A description of any obstacles facing the deployment, installation, and maintenance of tools, capabilities, and services under such program.</text>
 </subparagraph><subparagraph id="H60EF485594334B9A8D307147D0A685ED"><enum>(D)</enum><text>Recommendations and guidelines to help maintain and continuously upgrade tools, capabilities, and services provided under such program.</text>
 </subparagraph><subparagraph id="H4EF7F8E899464D68846697D7DE4C155C"><enum>(E)</enum><text display-inline="yes-display-inline">Recommendations for using the data collected by such program for creating a common framework for data analytics, visualization of enterprise-wide risks, and real-time reporting.</text>
 </subparagraph><subparagraph id="H767FAA6AF88F4AE087776CEA2553C82D"><enum>(F)</enum><text>Recommendations for future efforts and activities related to securing networks, devices, data, and information technology assets through the use of such program.</text>
 </subparagraph></paragraph><paragraph id="H700A447DBAA44FAFAB3AF0A6E9EF7078"><enum>(3)</enum><header>Form</header><text>The strategy required under subparagraph (A) shall be submitted in an unclassified form, but may contain a classified annex.</text>
 </paragraph></subsection><subsection id="H42E7EBA3508941B3B2A1885D2B157A8E"><enum>(c)</enum><header>Report</header><text>Not later than 90 days after the development of the strategy required under subsection (b), the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representative a report on cybersecurity risk posture based on the data collected through the continuous diagnostics and mitigation program under subsection (g) of section 230 of the Homeland Security Act of 2002, as added by subsection (a).</text>
			</subsection></section></legis-body></bill>


