Us Congress 2023-2024 Regular Session

Us Congress House Bill HB5786 Compare Versions

Only one version of the bill is available at this time.
OldNewDifferences
11 I
22 118THCONGRESS
33 1
44 STSESSION H. R. 5786
55 To establish in the National Nuclear Security Administration a Cybersecurity
66 Risk Inventory, Assessment, and Mitigation Working Group.
77 IN THE HOUSE OF REPRESENTATIVES
88 SEPTEMBER28, 2023
99 Mr. C
1010 ARBAJAL(for himself, Mr. BACON, and Mr. GALLAGHER) introduced the
1111 following bill; which was referred to the Committee on Armed Services
1212 A BILL
1313 To establish in the National Nuclear Security Administration
1414 a Cybersecurity Risk Inventory, Assessment, and Mitiga-
1515 tion Working Group.
1616 Be it enacted by the Senate and House of Representa-1
1717 tives of the United States of America in Congress assembled, 2
1818 SECTION 1. CYBERSECURITY RISK INVENTORY, ASSESS-3
1919 MENT, AND MITIGATION WORKING GROUP. 4
2020 Subtitle A of title XXXII of the National Defense Au-5
2121 thorization Act for Fiscal Year 2000 (Public Law 106– 6
2222 65) is amended by adding at the end the following new 7
2323 section: 8
2424 VerDate Sep 11 2014 04:16 Oct 01, 2023 Jkt 039200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\H5786.IH H5786
2525 kjohnson on DSK7ZCZBW3PROD with $$_JOB 2
2626 •HR 5786 IH
2727 ‘‘SEC. 3222. CYBERSECURITY RISK INVENTORY, ASSESS-1
2828 MENT, AND MITIGATION WORKING GROUP. 2
2929 ‘‘(a) E
3030 STABLISHMENT.—There is in the Administra-3
3131 tion a working group, to be known as the ‘Cybersecurity 4
3232 Risk Inventory, Assessment, and Mitigation Working 5
3333 Group’. 6
3434 ‘‘(b) M
3535 EMBERSHIP.—Members of the working group 7
3636 shall include the Deputy Administrator for Defense Pro-8
3737 grams, the Associate Administrator for Information Man-9
3838 agement and Chief Information Officer, and staff from 10
3939 other offices as determined appropriate by the Deputy Ad-11
4040 ministrator and Associate Administrator. 12
4141 ‘‘(c) C
4242 OMPREHENSIVE STRATEGY.—The working 13
4343 group shall prepare a comprehensive strategy for 14
4444 inventorying the range of National Nuclear Security Ad-15
4545 ministration systems that are potentially at risk in the 16
4646 operational technology and nuclear weapons information 17
4747 technology environments, assessing the systems at risk, 18
4848 and implementing risk mitigation actions. Such strategy 19
4949 shall incorporate key elements of effective cybersecurity 20
5050 risk management strategies, as identified by the Govern-21
5151 ment Accountability Office, including the specification 22
5252 of— 23
5353 ‘‘(1) goals, objectives, activities, and perform-24
5454 ance measures; 25
5555 VerDate Sep 11 2014 04:16 Oct 01, 2023 Jkt 039200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\H5786.IH H5786
5656 kjohnson on DSK7ZCZBW3PROD with $$_JOB 3
5757 •HR 5786 IH
5858 ‘‘(2) organizational roles, responsibilities, and 1
5959 coordination; 2
6060 ‘‘(3) necessary resources needed to implement 3
6161 the strategy over the next ten years; and 4
6262 ‘‘(4) detailed milestones and schedules for com-5
6363 pletion of tasks. 6
6464 ‘‘(d) S
6565 UBMISSION TOCONGRESS.— 7
6666 ‘‘(1) B
6767 RIEFING.—Not later than 120 days after 8
6868 the date of the enactment of this Act, the members 9
6969 of the working group shall provide to the congres-10
7070 sional defense committees a briefing on the plan of 11
7171 the working group plan to develop the strategy re-12
7272 quired under subsection (c). 13
7373 ‘‘(2) S
7474 UBMISSION OF STRATEGY .—Not later 14
7575 than April 1, 2025, the working group shall submit 15
7676 the congressional defense committees a copy of the 16
7777 completed strategy. 17
7878 ‘‘(e) T
7979 ERMINATION.—The working group shall termi-18
8080 nate on the date that is five years after the date of the 19
8181 enactment of this section.’’. 20
8282 Æ
8383 VerDate Sep 11 2014 04:16 Oct 01, 2023 Jkt 039200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6301 E:\BILLS\H5786.IH H5786
8484 kjohnson on DSK7ZCZBW3PROD with $$_JOB