Bill Sponsor
Senate Bill 2902
117th Congress(2021-2022)
Federal Information Security Modernization Act of 2021
Introduced
Introduced
Introduced in Senate on Sep 29, 2021
Overview
Text
Introduced
Sep 29, 2021
Latest Action
Dec 19, 2022
Origin Chamber
Senate
Type
Bill
Bill
The primary form of legislative measure used to propose law. Depending on the chamber of origin, bills begin with a designation of either H.R. or S. Joint resolution is another form of legislative measure used to propose law.
Bill Number
2902
Congress
117
Policy Area
Government Operations and Politics
Government Operations and Politics
Primary focus of measure is government administration, including agency organization, contracting, facilities and property, information management and services; rulemaking and administrative law; elections and political activities; government employees and officials; Presidents; ethics and public participation; postal service. Measures concerning agency appropriations and the budget process may fall under Economics and Public Finance policy area.
Sponsorship by Party
Democrat
Michigan
Democrat
Delaware
Senate Votes (0)
House Votes (0)
No Senate votes have been held for this bill.
Summary

Federal Information Security Modernization Act of 2021

This bill addresses federal information security management, notification and remediation of cybersecurity incidents, and the role of the Office of Management and Budget (OMB) and the Cybersecurity and Infrastructure Security Agency (CISA).

The OMB and CISA must perform, on an ongoing and continuous basis, assessments of federal risk posture. The bill requires annual evaluation by each agency of whether additional cybersecurity procedures are appropriate.

An agency, within 30 days of concluding that a major incident has occurred due to a high risk exposure of personal identifiable information, must provide notification to the last known home mailing address of each individual whom the incident may have impacted. Notification may be delayed under specified circumstances.

Each agency must provide any information relating to an incident to CISA, the OMB, the Office of the National Cyber Director, the Government Accountability Office, and Congress. An agency's contractors and grant recipients must immediately notify the agency of an incident involving federal information.

Each agency shall develop training for individuals at the agency with access to federal information or information systems on how to identify and respond to an incident.

The OMB and CISA must (1) develop and promulgate guidance on the definition of major incident, and (2) develop a framework for prioritizing federal penetration testing resources among agencies. CISA must establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.

The bill establishes specified pilot programs to enhance federal cybersecurity.

Text (2)
December 19, 2022
September 29, 2021
Actions (5)
12/19/2022
Placed on Senate Legislative Calendar under General Orders. Calendar No. 673.
12/19/2022
Committee on Homeland Security and Governmental Affairs. Reported by Senator Peters with an amendment in the nature of a substitute. With written report No. 117-274.
10/06/2021
Committee on Homeland Security and Governmental Affairs. Ordered to be reported with an amendment in the nature of a substitute favorably.
09/29/2021
Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
09/29/2021
Introduced in Senate
Public Record
Record Updated
Aug 3, 2023 7:45:17 PM