summary
Introduced
In Committee
Crossed Over
Passed
Dead
Introduced Session
113th Congress
Bill Summary
Federal Information Security Amendments Act of 2013 - Amends the Federal Information Security Management Act of 2002 (FISMA) to reestablish the oversight authority of the Director of the Office of Management and Budget (OMB) with respect to agency information and security policies and practices. Extends the security requirements of federal agencies to include responsibilities for: (1) complying with computer standards developed by the National Institute of Standards and Technology (NIST); (2) ensuring complementary and uniform standards for information systems and national security systems; (3) ensuring that information security management processes are integrated with budget processes; (4) securing facilities for classified information; (5) maintaining sufficient personnel with security clearances; and (6) ensuring that information security performance indicators are included in the annual performance evaluations of all managers, senior managers, senior executive service personnel, and political appointees. Directs senior agency officials, with a frequency sufficient to support risk-based security decisions, to: (1) test and evaluate information security controls and techniques, and (2) conduct threat assessments by monitoring information systems and identifying potential system vulnerabilities. (Current law requires only periodic testing and evaluation.) Directs agencies to collaborate with OMB and appropriate public and private sector security operations centers on security incidents that extend beyond the control of an agency. Requires that security incidents be reported, through an automated and continuous monitoring capability, when possible, to the federal information security incident center, appropriate security operations centers, and agency Inspector General. Directs agencies to conduct vulnerability assessments and penetration tests commensurate with the risk posed to agency information systems. Requires each agency to delegate to its Chief Information Officer the authority and primary responsibility for developing, implementing, and overseeing an agencywide information security (AIS) program. Directs agencies to implement an OMB-approved AIS program that is consistent with components across and within agencies. Requires that such program include automated and continuous monitoring, when possible, to: (1) mitigate risks associated with security incidents before substantial damage is done; and (2) notify and consult with the incident center, appropriate security operations response centers, law enforcement agencies, Inspectors General, and other entities or as directed by the President.
AI Summary
This bill, the Federal Information Security Amendments Act of 2013, amends the Federal Information Security Management Act of 2002 (FISMA) to strengthen federal agencies' information security by reestablishing the Office of Management and Budget (OMB) Director's oversight authority. It mandates that agencies comply with standards from the National Institute of Standards and Technology (NIST), ensure uniform security standards for both general and national security systems, integrate information security into budget processes, secure facilities for classified information, maintain adequate personnel with security clearances, and include information security performance in manager evaluations. Senior agency officials are required to regularly test security controls and conduct threat assessments through system monitoring, moving beyond the previous requirement of only periodic checks. The bill also directs agencies to collaborate with OMB and security operations centers on incidents affecting multiple entities, report security incidents through continuous monitoring when possible, and conduct vulnerability assessments and penetration tests based on risk. Crucially, each agency must delegate primary responsibility for its information security program to its Chief Information Officer (CIO), who must implement an OMB-approved program that includes continuous monitoring to mitigate risks and notify relevant parties of security incidents.
Committee Categories
Government Affairs, Military Affairs and Security
Sponsors (6)
Darrell Issa (R)*,
Jason Chaffetz (R),
Gerry Connolly (D),
Elijah Cummings (D),
John Mica (R),
John Tierney (D),
Last Action
Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs. (on 04/17/2013)
Official Document
bill text
bill summary
Loading...
bill summary
Loading...
bill summary
| Document Type | Source Location | Created |
|---|---|---|
| State Bill Page | https://www.congress.gov/bill/113th-congress/house-bill/1163/all-info | 04/25/2013 |
| Vote | clerk.house.gov/evs/2013/roll106.xml | 05/02/2013 |
| Bill | http://gpo.gov/fdsys/pkg/BILLS-113hr1163eh/pdf/BILLS-113hr1163eh.pdf.pdf | 04/18/2013 |
| Bill | http://gpo.gov/fdsys/pkg/BILLS-113hr1163rh/pdf/BILLS-113hr1163rh.pdf.pdf | 04/17/2013 |
| Bill | http://gpo.gov/fdsys/pkg/BILLS-113hr1163ih/pdf/BILLS-113hr1163ih.pdf.pdf | 03/23/2013 |
Loading...