Bill

Bill > HR4237


US HR4237

US HR4237
Advancing Cybersecurity Diagnostics and Mitigation Act


summary

Introduced
09/06/2019
In Committee
10/23/2019
Crossed Over
Passed
Dead
12/31/2020

Introduced Session

116th Congress

Bill Summary

To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program in the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, and for other purposes. This bill requires the Department of Homeland Security (DHS) to establish a program to assist agencies with continuously diagnosing and mitigating cyber threats and vulnerabilities. Pursuant to this program, DHS shall (1) develop the capability to collect, analyze, and visualize information relating to security data and cybersecurity risks at agencies; (2) make program capabilities available for use by civilian agencies, states, and local governments; (3) assist such entities in setting information security priorities and assessing and managing cybersecurity risks; and (4) develop policies and procedures for reporting systemic risks and potential incidents. DHS must also regularly deploy new technologies to improve the program. In addition, the Government Accountability Office must report on the potential impacts and benefits of replacing existing reporting requirements under the federal information policy with periodical real-time data provided by the program.

AI Summary

This bill requires the Department of Homeland Security (DHS) to establish a continuous diagnostics and mitigation program to assist federal agencies, state and local governments, and tribal entities in continuously monitoring and addressing cybersecurity threats and vulnerabilities. The program will provide capabilities to collect, analyze, and visualize security data, help entities prioritize and manage cybersecurity risks, and develop policies and procedures for reporting systemic risks. DHS must regularly update the program's technologies and provide agencies with relevant analysis and reports on cybersecurity risks. The bill also requires the development of a comprehensive strategy for the program and a report on the government's cybersecurity risk posture based on the program's data. Additionally, the Government Accountability Office must assess the potential benefits of replacing existing cybersecurity reporting requirements with the program's real-time data.

Committee Categories

Government Affairs, Transportation and Infrastructure

Sponsors (6)

Last Action

Ordered to be Reported (Amended). (on 10/23/2019)

bill text


bill summary

Loading...

bill summary

Loading...
Loading...