S. 3863Senate117th Congress (2021-2023)In Committee

Strengthening VA Cybersecurity Act of 2022

Introduced March 17, 2022

AI-Generated Summary

Updated February 8, 2026 at 10:07 AM UTC

The bill directs the Secretary of Veterans Affairs to obtain an independent cybersecurity assessment of the VA’s high‑impact information systems and to develop a plan to address any weaknesses. It also requires a review by the Comptroller General and reporting to Congress. The measures affect the VA’s information systems, its employees, contractors, and the veterans who rely on those services.

Key Provisions

  • Within 60 days, the VA must contract with a federally funded research and development center to assess 3‑10 high‑impact VA information systems, covering on‑premises, cloud, mobile, and remote systems.
  • The assessment must analyze confidentiality, integrity, and availability, and evaluate protection against threats such as ransomware, insider threats, foreign actors, supply‑chain attacks, phishing, credential theft, and shadow IT use.
  • Within 120 days of receiving the assessment, the Secretary must submit to Congress a remediation plan that includes cost estimates and a timeline for implementation.
  • The Comptroller General must review the assessment and the VA’s response within 180 days of the plan’s submission and report findings and recommendations to Congress.

Legislative Activity

Stay on top of the latest movement without scrolling through every action

1 earlier action
SenateIntro Referral Latest Action

Read twice and referred to the Committee on Veterans' Affairs.

March 17, 2022

View full timeline
SenateIntro Referral

Introduced in Senate

March 17, 2022

SenateIntro Referral

Read twice and referred to the Committee on Veterans' Affairs.

March 17, 2022

Floor Debate

1 member

What members said about S. 3863 on the floor

1 Democrat
Amy Klobuchar
Sen. Amy KlobucharD-MN · Apr 14, 2021

Mr. President, I ask unanimous consent for the legislative activities report of the Committee on Rules and Administration during the 116th Congress be printed in the Congressional Record.

Bill Text

Latest available legislative text

Reading Mode
Latest
Introduced in SenateIssued March 17, 2022

II

117th CONGRESS

2d Session

S. 3863

IN THE SENATE OF THE UNITED STATES

March 17, 2022

Ms. Rosen (for herself and Mrs. Blackburn) introduced the following bill; which was read twice and referred to the Committee on Veterans' Affairs

A BILL

To require the Secretary of Veterans Affairs to obtain an independent cybersecurity assessment of information systems of the Department of Veterans Affairs, and for other purposes.

1.

Short title

This Act may be cited as the Strengthening VA Cybersecurity Act of 2022.

2.

Independent cybersecurity assessment of information systems of Department of Veterans Affairs

(a)

Independent assessment required

(1)

In general

Not later than 60 days after the date of the enactment of this Act, the Secretary of Veterans Affairs shall enter into an agreement with a federally funded research and development center to provide the Secretary with an independent cybersecurity assessment of—

(A)

not more than 10 and not fewer than three high-impact information systems of the Department of Veterans Affairs; and

(B)

the effectiveness of the information security program and information security management system of the Department.

(2)

Detailed analysis

The independent cybersecurity assessment provided under paragraph (1) shall include a detailed analysis of the ability of the Department—

(A)

to ensure the confidentiality, integrity, and availability of the information, information systems, and devices of the Department; and

(B)

to protect against—

(i)

advanced persistent cybersecurity threats;

(ii)

ransomware;

(iii)

denial of service attacks;

(iv)

insider threats;

(v)

threats from foreign actors, including State sponsored criminals and other foreign based criminals;

(vi)

phishing;

(vii)

credential theft;

(viii)

cybersecurity attacks that target the supply chain of the Department;

(ix)

threats due to remote access and telework activity; and

(x)

other cyber threats.

(3)

Types of systems

The independent cybersecurity assessment provided under paragraph (1) shall cover on-premises, remote, cloud-based, and mobile information systems and devices used by, or in support of, Department activities.

(4)

Shadow information technology

The independent cybersecurity assessment provided under paragraph (1) shall include an evaluation of the use of information technology systems, devices, and services by employees and contractors of the Department who do so without the elements of the Department that are responsible for information technology at the Department knowing or approving of such use.

(5)

Methodology

In conducting the cybersecurity assessment provided under paragraph (1), the federally funded research and development center shall take into account industry best practices and the current state-of-the-art in cybersecurity evaluation and review.

(b)

Plan

(1)

In general

Not later than 120 days after the date on which an independent assessment is provided to the Secretary pursuant to an agreement entered into under subsection (a) with a federally funded research and development center, the Secretary shall submit to Congress a plan to address the findings of the federally funded research and development center set forth in such assessment.

(2)

Elements

The plan submitted under paragraph (1) shall include the following:

(A)

A cost estimate for implementing the plan.

(B)

A timeline for implementing the plan.

(C)

Such other elements as the Secretary considers appropriate.

(c)

Comptroller General of the United States review

Not later than 180 days after the date of the submission of the plan under (b)(1), the Comptroller General of the United States shall—

(1)

commence a review of—

(A)

the independent cybersecurity assessment provided under subsection (a); and

(B)

the response of the Department to such assessment; and

(2)

submit to Congress a report of the results of that review commenced under paragraph (1), including any recommendations made to the Secretary regarding the matters covered by the report.