II
Calendar No. 1105
110th CONGRESS
2d Session
S. 3474
IN THE SENATE OF THE UNITED STATES
September 11, 2008
Mr. Carper (for himself, Mr. Lieberman, Ms. Collins, and Mr. Coleman) introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs
October 1 (legislative day, September 17), 2008
Reported by Mr. Lieberman, without amendment
A BILL
To amend title 44, United States Code, to enhance information security of the Federal Government, and for other purposes.
Short title
This Act may be cited as
the Federal Information Security
Management Act of 2008
or the FISMA Act of 2008
.
Definitions
Section 3542(b) of title 44, United States Code, is amended by adding at the end the following:
The term adequate security means security commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.
The term incident means an occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
The term information infrastructure means the underlying framework that information systems and assets rely on in processing, transmitting, receiving, or storing information electronically.
.
Annual independent audit
Requirement for audit instead of evaluation
Section 3545 of title 44, United States Code, is amended—
in the section
heading, by striking evaluation
and inserting
audit
; and
in paragraphs (1)
and (2) of subsection (a), by striking evaluation
and inserting
audit
both places that term appears.
Additional specific requirements for audits
Section 3545(a) of such title is amended—
in paragraph (2)—
in subparagraph
(A), by striking subset of the agency’s information systems;
and
inserting the following:
subset of—
the information systems used or operated by the agency; and
the information systems used, operated, or supported on behalf of the agency by a contractor of the agency, any subcontractor (at any tier) of such a contractor, or any other entity;
;
in subparagraph
(B), by striking and
at the end;
in subparagraph
(C), by striking the period and inserting ; and
; and
by adding at the end the following new subparagraph:
a conclusion as to whether the agency’s information security controls are effective, including an identification of any significant deficiencies identified in such controls.
; and
by adding at the end the following:
Each audit under this section shall conform to generally accepted government auditing standards.
.
Technical and conforming amendments
Each of the
following provisions of
section
3545 of title 44, United States Code, is amended by striking
evaluation
and inserting audit
each place it
appears:
Subsection (b)(1).
Subsection (b)(2).
Subsection (c).
Subsection (e)(1).
Subsection (e)(2).
Section 3545(d) of such title is amended to read as follows:
Existing information
The audit required by this section may include consideration of relevant audits, evaluations, reports, or other information relating to programs or practices of the applicable agency.
.
Section 3545(f) of
such title is amended by striking evaluators
and inserting
auditors
.
Section 3545(g)(1)
of such title is amended by striking evaluations
and inserting
audits
.
Section 3545(g)(3)
of such title is amended by striking Evaluations
and inserting
Audits
.
Section
3543(a)(8)(A) of such title is amended by striking evaluations
and inserting audits
.
Section
3544(b)(5)(B) of such title is amended by striking a evaluation
and inserting an audit, evaluation, report, or other information
relating to programs or practices of the applicable agency
.
Chief Information Security Officer and Chief Information Security Officer Council
Delegations to Chief Information Security Officer
Section 3544(a) of title 44, United States Code, is amended—
in paragraph (3)—
in the matter preceding subparagraph (A)—
by
striking Chief Information Officer established under section
3506
and inserting Chief Information Security Officer designated
under section 3548
; and
by striking ensure
compliance
and inserting enforce compliance
;
by striking subparagraph (A); and
by redesignating subparagraphs (B) through (E) as subparagraphs (A) through (D), respectively;
in paragraph (4),
by inserting and cleared
after trained
;
and
in paragraph (5),
by striking Chief Information Officer
and inserting Chief
Information Security Officer
.
Chief Information Security Officer and Chief Information Security Officer Council
Chapter 35 of title 44, United States Code, is amended—
by redesignating sections 3548 and 3549 as sections 3553 and 3554, respectively; and
by inserting after section 3547 the following:
Chief Information Security Officers
Designations
Except as provided under paragraph (2), the head of each agency shall designate a Chief Information Security Officer who with such agency head shall carry out the responsibilities of the agency under this subchapter. An individual may not serve as the Chief Information Officer and the Chief Information Security Officer for an agency at the same time. The Chief Information Security Officer shall report directly to the Chief Information Officer to carry out such responsibilities.
The Secretary of Defense and the Secretary of each military department may each designate Chief Information Security Officers who with the Secretary making the designation shall carry out the responsibilities of the applicable department under this subchapter. An individual may not serve as the Chief Information Officer and the Chief Information Security Officer for a department at the same time. The Secretary shall provide for the Chief Information Security Officer to report to the applicable Chief Information Officer to carry out such responsibilities. If more than 1 Chief Information Security Officer is designated, the respective duties of the Chief Information Security Officers shall be clearly delineated.
Qualifications and general duties
A Chief Information Security Officer shall—
possess necessary qualifications, including education, professional certifications, training, experience, and the security clearance required to administer the functions described under this subchapter; and
have information security duties as the primary duty of that official.
Responsibilities
A Chief Information Security Officer for an agency shall have the mission, budget, resources, and authority necessary to—
oversee the establishment and maintenance of an incident response capability that on a continuous basis can—
detect, report, respond to, contain, investigate, attribute, and mitigate any network, computer, or data security incident that impairs adequate security, in accordance with policy provided by the Office of Management and Budget, in consultation with the Chief Information Security Officer Council, and guidance from the National Institute of Standards and Technology;
collaborate with other public and private sector incident response resources to address incidents that extend beyond the agency; and
not later than 24 hours after discovery of any incident described under subparagraph (A) unless otherwise directed by policy of the Office of Management and Budget, provide notice to the appropriate supporting information security operating center, inspector general, and the United States Computer Emergency Readiness Team;
collaborate with the Chief Information Officer to establish, maintain, and update an enterprise network, system, storage, and security architecture framework documentation to be submitted quarterly to the United States Computer Emergency Readiness Team, that includes—
documentation of how technical, managerial, and operational security controls are implemented throughout the agency's information infrastructure; and
documentation of how the controls described under subparagraph (A) maintain the appropriate level of confidentiality, integrity, and availability of electronic information and information systems based on National Institute of Standards and Technology guidance and Chief Information Security Officers Council recommended approaches;
ensure that—
risk assessments are conducted on a periodic basis;
penetration tests are conducted commensurate with risk (as defined by the National Institute of Standards and Technology) for an agency's information infrastructure; and
information security vulnerabilities are mitigated in a timely fashion;
ensure that annual information technology security awareness and role-based training for agency employees and contractors is conducted;
create, maintain, and manage an information security performance measurement system that aligns with agency goals and budget process; and
direct and manage information technology security programs and functions within all subordinate agency organizations (including components, bureaus, offices, and other organizations within the agency).
Continuous Technical Monitoring for malicious activity of Agency Network and Information System
Each agency shall establish a mechanism that allows the Chief Information Security Officer of the agency to detect, monitor, correlate, and analyze, the security of any information system that is connected to the agency's information infrastructure on a continuous basis through automated monitoring.
The Chief Information Security Officer of an agency shall be responsible for and have the authority to assure that any information system connected to the network (directly or indirectly) that does not comply with security policies and standards, or has been compromised, is denied access and use of the agency network until the information system meets or exceeds accepted security policies and standards established by—
the National Institute of Standards and Technology;
the Office of Management and Budget; and
the applicable agency.
After notification to the applicable agency’s Chief Information Officer, the Chief Information Security Officer of an agency may prevent access to any information system or individual that is using or attempts to use the agency information infrastructure if information security policies and procedures have not been followed or implemented.
If the Chief Information Security Officer recognizes a network, computer, or data security incident that impairs adequate security of an interagency information system, the Chief Information Security Officer shall notify the managing agency, agency inspector general, and the United States Computer Emergency Readiness Team within 24 hours after discovery of an incident as defined by policy of the Office of Management and Budget.
Operational Evaluation
The Chief Information Security Officer of an agency in consultation with the agency Chief Information Officer, with recommendations from the Chief Information Security Officers Council and in consultation with the Secretary of Homeland Security and the heads of other appropriate Federal agencies, shall—
establish security control testing protocols that ensure that the information infrastructure of the agency, including contractor information systems operating on behalf of the agency are effectively protected against known vulnerabilities, attacks, and exploitations;
oversee the deployment of such protocols throughout the information infrastructure of the agency; and
update and test such protocols on a recurring basis.
After consideration of best practices and recommendations for operational evaluations established by the Chief Information Security Officer Council and in consultation with the heads of appropriate agencies, the Department of Homeland Security shall no less than annually—
conduct an operational evaluation of the information infrastructure of each agency for known vulnerabilities, attacks, and exploitations of Federal networks on a frequent and recurring basis;
evaluate the ability of each agency to monitor, detect, correlate, analyze, report, and respond to breaches in information security policies and practices;
report to the agency head, the Chief Information Officer, and the Chief Information Security Officer of the applicable agency the findings of the operational evaluation; and
in consultation with the Chief Information Officer and the Chief Information Security Officer of the applicable agency, assist with mitigating exploited vulnerabilities, attacks, and exploitations.
Not later than 30 days after receiving an operational evaluation under paragraph (2), the Chief Information Security Officer of an agency shall provide the Chief Information Officer and the agency head a plan for addressing recommendations and mitigating vulnerabilities contained in the security reports identified under paragraph (2), including a timeline and budget for implementing such plan.
National security systems
Subsections (c), (d), and (e) shall not apply to any national security system as defined under section 3542(b)(2) so long as that system is evaluated in a manner consistent with processes described under subsection (e)(2) (A) through (D) of this section.
Chief Information Security Officer Council
Establishment
There
is established in the executive branch a Chief Information Security Officers
Council (in this section referred to as the Council
).
Membership
The members of the Council shall be full-time senior government employees. The members shall be as follows:
The Administrator of the Office of Electronic Government of the Office of Management and Budget.
The Chief Information Security Officer of each agency described under section 901(b) of title 31.
The Chief Information Security Officer of the Department of the Army, the Department of the Navy, and the Department of the Air Force, if chief information officers have been designated for such departments under section 3506(a)(2)(B).
A representative from the Office of the Director of National Intelligence.
A representative from the United States Strategic Command.
A representative from the United States Computer Emergency Readiness Team.
A representative from the Intelligence Community Incident Response Center.
A representative from the Committee on National Security Systems.
Any other officer or employee of the United States designated by the chairperson.
Co-Chairpersons and Vice Chairpersons
The Director of the National Cyber Security Center shall act as chairperson of the Council. The Administrator of the Office of Electronic Government of the Office of Management and Budget shall act as co-chairperson of the Council.
The vice chairperson of the Council shall be selected by the Council from among its members. The vice chairperson shall serve a 1-year term and may serve multiple terms. The vice chairperson shall serve as a liaison to the Chief Information Officer, Council Committee on National Security Systems, and other councils or committees as appointed by the chairperson.
Functions
The Council shall be the principal interagency forum for establishing best practices and recommendations for operational evaluations that use attack-based testing protocols established under section 3548(e).
The Council shall—
share experiences and innovative approaches relating to information sharing and information security best practices, penetration testing regimes, and incident response mitigation;
promote the development and use of standard performance measures for agency information security that—
are outcome-based;
focus on risk management;
align with the business and program goals of the agency;
measure improvements in the agency security posture over time; and
reduce burdensome compliance measures;
develop and recommend to the Office of Management and Budget the necessary qualifications to be established for Chief Information Security Officers to be capable of administering the functions described under this subchapter including education, training, and experience;
enhance information system certification and accreditation processes by establishing a prioritized baseline of information security measures and controls that can be continuously monitored through automated mechanisms; and
submit proposed enhancements to the Office of Management and Budget.
Requirements for contracts relating to agency information and information systems
In general
Not later than 180 days after the date of enactment of the Federal Information Security Management Act of 2008, the Director of the Office of Management and Budget, in consultation with the Director of the National Institutes of Standards and Technology, shall promulgate information security regulations governing contracts (including task or delivery orders issued pursuant to contracts) between the Federal Government and any individual, corporation, partnership, organization, or other entity that interfaces with an information system of an agency or collects, stores, operates, or maintains information on behalf of the agency.
Regulations promulgated under this subsection shall specify requirements concerning—
adequacy and effectiveness of the security of information systems;
the collection and transmission of information, including personally identifiable information; and
procedures in the event of a security incident.
Compliance
Notwithstanding any other provision of law, effective 180 days after the issuance of regulations under subsection (a), no agency may enter into a contract (or issue a task or delivery orders under a contract), or otherwise enter into an agreement, with an individual, corporation, partnership, organization, or other entity that interfaces with an information system of an agency or collects, stores, operates, or maintains information on behalf of the agency, unless the requirements of the contract or agreement are in compliance with such regulations.
Security requirements
Notwithstanding any other provision of law, effective 3 years after the issuance of regulations under subsection (a), no agency may enter into a contract (or issue a task or delivery order under contract), or otherwise enter into an agreement, with an individual, corporation, partnership, organization, or other entity for commercial off the shelf items, including hardware and software that does not conform to the security requirements in such regulations.
Reports to Congress
Annual reports
On March 1 of each year, the Department of Homeland Security shall submit a report on operational evaluations and testing protocols to—
the Committee on Homeland Security and Governmental Affairs of the Senate;
the Committee on Oversight and Government Reform and the Committee on Homeland Security of the House of Representatives;
the Select Committee on Intelligence of the Senate;
the Permanent Select Committee on Intelligence of the House of Representatives;
the Government Accountability Office; and
the President’s Council on Integrity and Efficiency and the Executive Council on Integrity and Efficiency.
Each report submitted under this subsection shall—
provide detailed information on the operational evaluations of each agency performed during the preceding fiscal year, the results of such evaluations, and any actions that remain to be taken under plans included in corrective action reports under section 3548(e)(3);
describe the effectiveness of the testing protocols developed under section 3548(e)(1) in mitigating the risks associated with known vulnerabilities, attacks, and exploitations of the information infrastructure of each agency;
describe the information security posture of the Federal Government, including—
the risks to the confidentiality, integrity, and availability of information governmentwide; and
a plan of action and milestones to mitigate the risks governmentwide;
include any recommendations for relevant executive branch action and congressional oversight; and
include an unclassified and classified report of the operational evaluation.
Security reports and corrective action reports
The agency head and inspector general of each agency shall make all information security reports and information security corrective action reports available upon request to—
the Secretary of Homeland Security for purposes of completing the requirements under subsection (a); and
the Comptroller General of the United States.
.
Technical and conforming amendments
The table of sections for chapter 35 of title 44, United States Code, is amended by striking the items relating to sections 3548 and 3549 and inserting the following:
Sec.
3548. Chief Information Security Officers.
3549. Chief Information Security Officer Council.
3550. Requirements for contracts relating to agency information and information systems.
3551. Reports to Congress.
3552. Authorization of appropriations.
3553. Effect on existing law.
.
October 1 (legislative day, September 17), 2008
Reported without amendment