S. 3464Senate115th Congress (2017-2019)In Committee

Advancing Cybersecurity Diagnostics and Mitigation Act

Introduced September 18, 2018

AI-Generated Summary

Updated April 15, 2026 at 11:43 PM UTC

The Advancing Cybersecurity Diagnostics and Mitigation Act would require the Department of Homeland Security (DHS) to set up a continuous diagnostics and mitigation (CDM) program. The program is meant to collect, analyze, and share real‑time cybersecurity risk data across the federal government and to help agencies prioritize and manage cyber threats. It also directs DHS to create a strategy for the program and to report on the nation’s cyber risk posture.

Key Provisions

  • Amends the Homeland Security Act to add a new subsection authorizing the DHS secretary to deploy, operate, and maintain a continuous diagnostics and mitigation program that gathers, visualizes, and shares cybersecurity risk information.
  • Requires the program to provide tools and services to federal entities, using shared services and procurement models to reduce costs, and to develop policies for reporting systemic risks and incidents.
  • Mandates that DHS develop a comprehensive CDM strategy within 180 days of the law’s enactment, outlining program description, coordination, obstacles, upgrade recommendations, data‑analytics framework, and future rollout plans.
  • Orders DHS to submit a report to the relevant Senate and House committees within 90 days after the strategy is completed, detailing the nation’s cybersecurity risk posture based on data collected by the CDM program.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

1 earlier action
SenateIntro Referral Latest Action

Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

September 18, 2018

View full timeline
SenateIntro Referral

Introduced in Senate

September 18, 2018

SenateIntro Referral

Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

September 18, 2018

Floor Debate

2 members

What members said about S. 3464 on the floor

1 Republican1 Democrat
Doug  Jones
Sen. Doug JonesD-AL · Sep 18, 2018

Mr. President, I rise today to talk about an issue that, quite frankly, I do not think gets enough attention on the floor of the Senate or on the floor of the House of Representatives, and that is…

John Cornyn
Sen. John CornynR-TX · Sep 18, 2018

Mr. President, I ask unanimous consent that the text of the bill be printed in the Record.

John Cornyn
Sen. John CornynR-TX · Sep 18, 2018

Mr. President, I ask unanimous consent that the text of the bill be printed in the Record.

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in SenateIssued September 18, 2018

II

115th CONGRESS

2d Session

S. 3464

IN THE SENATE OF THE UNITED STATES

September 18, 2018

Mr. Cornyn (for himself and Ms. Hassan) introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs

A BILL

To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to establish a continuous diagnostics and mitigation program at the Department of Homeland Security, and for other purposes.

1.

Short title

This Act may be cited as the Advancing Cybersecurity Diagnostics and Mitigation Act.

2.

Establishment of continuous diagnostics and mitigation program in Department of Homeland Security

(a)

In general

Section 230 of the Homeland Security Act of 2002 (6 U.S.C. 151) is amended by adding at the end the following new subsection:

(g)

Continuous Diagnostics and Mitigation

(1)

Program

(A)

In general

The Secretary shall deploy, operate, and maintain a continuous diagnostics and mitigation program. Under such program, the Secretary shall—

(i)

develop and provide the capability to collect, analyze, and visualize information relating to security data and cybersecurity risks;

(ii)

make program capabilities available for use, with or without reimbursement;

(iii)

employ shared services, collective purchasing, blanket purchase agreements, and any other economic or procurement models the Secretary determines appropriate to maximize the costs savings associated with implementing an information system;

(iv)

assist entities in setting information security priorities and managing cybersecurity risks; and

(v)

develop policies and procedures for reporting systemic cybersecurity risks and potential incidents based upon data collected under such program.

(B)

Regular Improvement

The Secretary shall regularly deploy new technologies and modify existing technologies to the continuous diagnostics and mitigation program required under subparagraph (A), as appropriate, to improve the program.

(2)

Activities

In carrying out the continuous diagnostics and mitigation program under paragraph (1), the Secretary shall ensure, to the extent practicable, that—

(A)

timely, actionable, and relevant cybersecurity risk information, assessments, and analysis are provided in real time;

(B)

share the analysis and products developed under such program;

(C)

all information, assessments, analyses, and raw data under such program is made available to the national cybersecurity and communications integration center of the Department; and

(D)

provide regular reports on cybersecurity risks.

.

(b)

Continuous Diagnostics and Mitigation Strategy

(1)

In general

Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security shall develop a comprehensive continuous diagnostics and mitigation strategy to carry out the continuous diagnostics and mitigation program required under subsection (g) of section 230 of the Homeland Security Act of 2002 (6 U.S.C. 151), as added by subsection (a).

(2)

Scope

The strategy required under paragraph (1) shall include the following:

(A)

A description of the continuous diagnostics and mitigation program, including efforts by the Secretary of Homeland Security to assist with the deployment of program tools, capabilities, and services, from the inception of the program referred to in paragraph (1) to the date of the enactment of this Act.

(B)

A description of the coordination required to deploy, install, and maintain the tools, capabilities, and services that the Secretary of Homeland Security determines to be necessary to satisfy the requirements of such program.

(C)

A description of any obstacles facing the deployment, installation, and maintenance of tools, capabilities, and services under such program.

(D)

Recommendations and guidelines to help maintain and continuously upgrade tools, capabilities, and services provided under such program.

(E)

Recommendations for using the data collected by such program for creating a common framework for data analytics, visualization of enterprise-wide risks, and real-time reporting.

(F)

Recommendations for future efforts and activities, including for the rollout of new tools, capabilities and services, proposed timelines for delivery, and whether to continue the use of phased rollout plans, related to securing networks, devices, data, and information technology assets through the use of such program.

(3)

Form

The strategy required under subparagraph (A) shall be submitted in an unclassified form, but may contain a classified annex.

(c)

Report

Not later than 90 days after the development of the strategy required under subsection (b), the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representative a report on cybersecurity risk posture based on the data collected through the continuous diagnostics and mitigation program under subsection (g) of section 230 of the Homeland Security Act of 2002 (6 U.S.C. 151), as added by subsection (a).