Calendar No. 348
117th CONGRESS 2d Session |
[Report No. 117–97]
To establish a Civilian Cyber Security Reserve as a pilot project to address the cyber security needs of the United States with respect to national security, and for other purposes.
April 22, 2021
Ms. Rosen (for herself and Mrs. Blackburn) introduced the following bill; which was read twice and referred to the Committee on Homeland Security and Governmental Affairs
April 27, 2022
Reported by Mr. Peters, with an amendment
[Strike out all after the enacting clause and insert the part printed in italic]
To establish a Civilian Cyber Security Reserve as a pilot project to address the cyber security needs of the United States with respect to national security, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SEC. 2. Civilian Cyber Security Reserve pilot project.
(a) Definitions.—In this section:
(1) APPROPRIATE AGENCY HEAD.—The term “appropriate agency head” means—
(A) in the case of the Department of Homeland Security, the Secretary of Homeland Security; and
(B) in the case of the Department of Defense, the Secretary of Defense.
(2) COMPETITIVE SERVICE.—The term “competitive service” has the meaning given the term in section 2102 of title 5, United States Code.
(3) COVERED AGENCY.—The term “covered agency” means the Department of Homeland Security or the Department of Defense.
(4) EXCEPTED SERVICE.—The term “excepted service” has the meaning given the term in section 2103 of title 5, United States Code.
(5) TEMPORARY.—The term “temporary” means a period of not more than 6 months.
(6) UNIFORMED SERVICES.—The term “uniformed services” has the meaning given the term in section 2101 of title 5, United States Code.
(1) IN GENERAL.—Each appropriate agency head may carry out a pilot project to establish a Civilian Cyber Security Reserve at the covered agency to address the cyber security needs of the United States with respect to national security.
(2) APPOINTMENTS.—Under a pilot project authorized under paragraph (1), the appropriate agency head may noncompetitively appoint members of the Civilian Cyber Security Reserve to temporary positions in the competitive or excepted service.
(3) STATUS AS EMPLOYEES.—An individual appointed under paragraph (2) shall be considered a Federal civil service employee under section 2105 of title 5, United States Code.
(4) ADDITIONAL EMPLOYEES.—Individuals appointed under paragraph (2) shall be in addition to any employees of the covered agency who provide cyber security services.
(5) EMPLOYMENT PROTECTIONS.—The Secretary of Labor shall prescribe such regulations as necessary to ensure the reemployment, continuation of benefits, and non-discrimination in reemployment of individuals appointed under paragraph (2), provided that such regulations shall include, at a minimum, those rights and obligations set forth under chapter 43 of title 38, United States Code.
(c) Eligibility; application and selection.—
(1) IN GENERAL.—Under a pilot project authorized under subsection (b), the appropriate agency head shall establish criteria for—
(A) individuals to be eligible for the Civilian Cyber Security Reserve in the covered agency; and
(B) the application and selection processes for the Reserve.
(2) REQUIREMENTS FOR INDIVIDUALS.—The criteria established under paragraph (1)(A) with respect to an individual shall include—
(A) previous employment by the Federal Government or within the uniformed services; and
(B) cyber security expertise.
(3) AGREEMENT REQUIRED.—An individual may become a member of the Civilian Cyber Security Reserve only if the individual enters into an agreement with the appropriate agency head to become such a member, which shall set forth the rights and obligations of the individual and the covered agency.
(4) EXCEPTION FOR CONTINUING MILITARY SERVICE COMMITMENTS.—A member of the Selected Reserve under section 10143 of title 10, United States Code, may not be a member of the Civilian Cyber Security Reserve.
(d) Components of the Civilian Cyber Security Reserve.—The appropriate agency head may consider, in carrying out a pilot project authorized under subsection (b), developing different components of the Civilian Cyber Security Reserve in the covered agency, one with an obligation to respond when called into activation at the direction of the appropriate agency head and one that is not compelled to so respond, with appropriate corresponding differing benefits for each such component.
(1) IN GENERAL.—The appropriate agency head shall ensure that all members of the Civilian Cyber Security Reserve in the covered agency undergo the appropriate personnel vetting and adjudication commensurate with the duties of the position, including a determination of eligibility for access to classified information where a security clearance is necessary, in accordance with Executive Order 12968 (50 U.S.C. 3161 note; relating to access to classified information) and Executive Order 13467 (50 U.S.C. 3161 note; relating to reforming processes related to suitability for Government employment, fitness for contractor employees, and eligibility for access to classified national security information).
(2) COST OF MAINTAINING CLEARANCES.—The original sponsor of a security clearance of a member of a Civilian Cyber Security Reserve at a covered agency shall be responsible for the cost of maintaining that security clearance.
(1) IN GENERAL.—Not later than 180 days after the date of enactment of this Act, each appropriate agency head may issue guidance establishing and implementing a pilot project authorized under subsection (b) at the covered agency.
(A) IN GENERAL.—In developing guidance under paragraph (1), an appropriate agency head may provide for penalties for individuals who do not respond to activation when called, such as recoupment of pay or benefits earned as a member of the Civilian Cyber Security Reserve or recoupment of civilian service creditable under section 8411 of title 5, United States Code.
(B) PROCEDURES.—In the case of a proposed penalty or action under this paragraph, the individual shall be entitled to the applicable procedures set forth in title 5, Code of Federal Regulations, or as otherwise specified in applicable guidance.
(g) Evaluation.—Not later than 5 years after the pilot project authorized under subsection (b) is established in each covered agency, the Comptroller General of the United States shall—
(1) conduct a study evaluating the pilot project at the covered agency; and
(A) a report on the results of the study; and
(B) a recommendation with respect to whether the pilot project should be modified, extended in duration, or established as a permanent program.
(h) Report.—Not later than 5 years after the pilot project authorized under subsection (b) is established in a covered agency, the appropriate agency head shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services of the Senate and the Committee on Homeland Security and the Committee on Armed Services of the House of Representatives a report—
(1) on the activities carried out under the pilot project; and
(2) that includes a recommendation with respect to whether the pilot project should be modified, extended in duration, or established as a permanent program.
This Act may be cited as the “Civilian Cybersecurity Reserve Act”.
SEC. 2. Civilian Cybersecurity Reserve pilot project.
(a) Definitions.—In this section:
(3) COMPETITIVE SERVICE.—The term “competitive service” has the meaning given the term in section 2102 of title 5, United States Code.
(5) EXCEPTED SERVICE.—The term “excepted service” has the meaning given the term in section 2103 of title 5, United States Code.
(6) SIGNIFICANT INCIDENT.—The term “significant incident”—
(A) means an incident or a group of related incidents that results, or is likely to result, in demonstrable harm to—
(b) Pilot project.—
(1) IN GENERAL.—The Director may carry out a pilot project to establish a Civilian Cybersecurity Reserve at the Agency.
(2) PURPOSE.—The purpose of a Civilian Cybersecurity Reserve is to enable the Agency to effectively respond to significant incidents.
(3) ALTERNATIVE METHODS.—Consistent with section 4703 of title 5, United States Code, in carrying out a pilot project authorized under paragraph (1), the Director may, without further authorization from the Office of Personnel Management, provide for alternative methods of—
(4) APPOINTMENTS.—Under the pilot project authorized under paragraph (1), upon occurrence of a significant incident, the Director—
(5) STATUS AS EMPLOYEES.—An individual appointed under subsection (b)(4) shall be considered a Federal civil service employee under section 2105 of title 5, United States Code.
(6) ADDITIONAL EMPLOYEES.—Individuals appointed under subsection (b)(4) shall be in addition to any employees of the Agency who provide cybersecurity services.
(7) EMPLOYMENT PROTECTIONS.—The Secretary of Labor shall prescribe such regulations as necessary to ensure the reemployment, continuation of benefits, and non-discrimination in reemployment of individuals appointed under subsection (b)(4), provided that such regulations shall include, at a minimum, those rights and obligations set forth under chapter 43 of title 38, United States Code.
(8) STATUS IN RESERVE.—During the period beginning on the date on which an individual is recruited by the Agency to serve in the Civilian Cybersecurity Reserve and ending on the date on which the individual is appointed under subsection (b)(4), and during any period in between any such appointments, the individual shall not be considered a Federal employee.
(c) Eligibility; application and selection.—
(1) IN GENERAL.—Under the pilot project authorized under subsection (b), the Director shall establish criteria for—
(2) REQUIREMENTS FOR INDIVIDUALS.—The criteria established under paragraph (1)(A) with respect to an individual shall include—
(3) PRESCREENING.—The Agency shall—
(4) AGREEMENT REQUIRED.—An individual may become a member of the Civilian Cybersecurity Reserve only if the individual enters into an agreement with the Director to become such a member, which shall set forth the rights and obligations of the individual and the Agency.
(5) EXCEPTION FOR CONTINUING MILITARY SERVICE COMMITMENTS.—A member of the Selected Reserve under section 10143 of title 10, United States Code, may not be a member of the Civilian Cybersecurity Reserve.
(d) Security clearances.—
(1) IN GENERAL.—The Director shall ensure that all members of the Civilian Cybersecurity Reserve undergo the appropriate personnel vetting and adjudication commensurate with the duties of the position, including a determination of eligibility for access to classified information where a security clearance is necessary, according to applicable policy and authorities.
(e) Study and implementation plan.—
(1) STUDY.—Not later than 60 days after the date of enactment of this Act, the Agency shall begin a study on the design and implementation of the pilot project authorized under subsection (b)(1) at the Agency, including—
(C) methods for identifying and recruiting members, including alternatives to traditional qualifications requirements;
(D) methods for preventing conflicts of interest or other ethical concerns as a result of participation in the pilot project and details of mitigation efforts to address any conflict of interest concerns;
(f) Project guidance.—Not later than 2 years after the date of enactment of this Act, the Director shall, in consultation with the Office of Personnel Management and the Office of Government Ethics, issue guidance establishing and implementing the pilot project authorized under subsection (b)(1) at the Agency.
(g) Briefings and report.—
(1) BRIEFINGS.—Not later than 1 year after the date of enactment of this Act, and every year thereafter, the Agency shall provide to the appropriate congressional committees a briefing on activities carried out under the pilot project of the Agency, including—
(A) participation in the Civilian Cybersecurity Reserve, including the number of participants, the diversity of participants, and any barriers to recruitment or retention of members;
(2) REPORT.—Not earlier than 6 months and not later than 3 months before the date on which the pilot project of the Agency terminates under subsection (i), the Agency shall submit to the appropriate congressional committees a report and provide a briefing on recommendations relating to the pilot project, including recommendations for—
(A) whether the pilot project should be modified, extended in duration, or established as a permanent program, and if so, an appropriate scope for the program;
(B) how to attract participants, ensure a diversity of participants, and address any barriers to recruitment or retention of members of the Civilian Cybersecurity Reserve;
(h) Evaluation.—Not later than 3 years after the pilot project authorized under subsection (b) is established in the Agency, the Comptroller General of the United States shall—
(i) Sunset.—The pilot project authorized under this section shall terminate on the date that is 4 years after the date on which the pilot project is established.
Calendar No. 348 | |||||
| |||||
[Report No. 117–97] | |||||
A BILL | |||||
To establish a Civilian Cyber Security Reserve as a pilot project to address the cyber security needs of the United States with respect to national security, and for other purposes. | |||||
April 27, 2022 | |||||
Reported with an amendment |