Bill Sponsor
House Bill 6497
117th Congress(2021-2022)
Federal Information Security Modernization Act of 2022
Introduced
Introduced
Introduced in House on Jan 25, 2022
Overview
Text
Introduced
Jan 25, 2022
Latest Action
Feb 2, 2022
Origin Chamber
House
Type
Bill
Bill
The primary form of legislative measure used to propose law. Depending on the chamber of origin, bills begin with a designation of either H.R. or S. Joint resolution is another form of legislative measure used to propose law.
Bill Number
6497
Congress
117
Policy Area
Government Operations and Politics
Government Operations and Politics
Primary focus of measure is government administration, including agency organization, contracting, facilities and property, information management and services; rulemaking and administrative law; elections and political activities; government employees and officials; Presidents; ethics and public participation; postal service. Measures concerning agency appropriations and the budget process may fall under Economics and Public Finance policy area.
Sponsorship by Party
Democrat
New York
Democrat
District of Columbia
Republican
Georgia
Republican
Kentucky
Democrat
Maryland
Democrat
Maryland
Democrat
Massachusetts
Republican
Pennsylvania
Republican
South Carolina
Democrat
Tennessee
House Votes (0)
Senate Votes (0)
No House votes have been held for this bill.
Summary

Federal Information Security Modernization Act of 2022

This bill addresses federal information security management, notification and remediation of cybersecurity incidents, and the roles of the Office of Management and Budget (OMB) and the Cybersecurity and Infrastructure Security Agency (CISA).

CISA must perform, on an ongoing and continuous basis, assessments of federal risk posture. The bill requires evaluation by each agency of whether additional cybersecurity procedures are appropriate at least once every three years.

An agency, as expeditiously as practicable and without unreasonable delay, and within 45 days after it has a reasonable basis to conclude that a breach has occurred, must (1) determine whether notice to any individual potentially affected by the breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected. Notification may be delayed under specified circumstances.

Each agency must provide any information relating to a major incident to CISA, the OMB, the Office of the National Cyber Director, the agency's office of inspector general, the Government Accountability Office, and Congress.

An agency's contractors and grant recipients must notify the agency of an incident involving federal information within a specified time frame.

Each agency shall develop training for individuals at the agency with access to federal information or information systems on how to identify and respond to an incident.

CISA must establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.

The bill establishes specified pilot programs to enhance federal cybersecurity.

Text (1)
January 25, 2022
Actions (4)
02/02/2022
Ordered to be Reported (Amended) by Voice Vote.
02/02/2022
Committee Consideration and Mark-up Session Held.
01/25/2022
Referred to the Committee on Oversight and Reform, and in addition to the Committee on Science, Space, and Technology, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
01/25/2022
Introduced in House
Public Record
Record Updated
May 11, 2023 3:46:24 PM