US HB4257 | 2011-2012 | 112th Congress

Status

Spectrum: Slight Partisan Bill (Democrat 2-1)
Status: Engrossed on May 7 2012 - 50% progression, died in committee
Action: 2012-05-07 - Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
Pending: Senate Homeland Security And Governmental Affairs Committee
Text: Latest bill text (Engrossed) [PDF]

Summary

Federal Information Security Amendments Act of 2012 - (Sec. 2) Amends the Federal Information Security Management Act of 2002 (FISMA) to reestablish the oversight authority of the Director of the Office of Management and Budget (OMB) with respect to agency information and security policies and practices. Extends the security requirements of federal agencies to include responsibilities for: (1) complying with computer standards developed by the National Institute of Standards and Technology (NIST), (2) ensuring complementary and uniform standards for information systems and national security systems, (3) ensuring that information security management processes are integrated with budget processes, (4) securing facilities for classified information, (5) maintaining sufficient personnel with security clearances, and (6) ensuring that information security performance indicators are included in the annual performance evaluations of all managers, senior managers, senior executive service personnel, and political appointees. Directs senior agency officials, with a frequency sufficient to support risk-based security decisions, to: (1) test and evaluate information security controls and techniques, and (2) conduct threat assessments by monitoring information systems and identifying potential system vulnerabilities. (Current law requires only periodic testing and evaluation.) Defines "information system" as a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. Includes in such definition: (1) computers and computer networks; (2) ancillary equipment; (3) software, firmware, and related procedures; (4) support services; and (5) related resources and services. Directs agencies to determine information security levels in accordance with information security classifications and standards promulgated under the National Institute of Standards and Technology Act. Directs agencies to collaborate with OMB and appropriate public and private sector security operations centers on security incidents that extend beyond the control of an agency. Requires that security incidents be reported, through an automated and continuous monitoring capability, when possible, to the federal information security incident center (the incident center), appropriate security operations centers, and agency Inspector General. Directs agencies to conduct vulnerability assessments and penetration tests commensurate with the risk posed to agency information systems. Requires each agency to delegate to its Chief Information Officer the authority and primary responsibility for developing, implementing, and overseeing an agencywide information security (AIS) program. Directs agencies to implement an OMB-approved AIS program that is consistent with components across and within agencies. Requires that such program include automated and continuous monitoring, when possible, to: (1) mitigate risks associated with security incidents before substantial damage is done; and (2) notify and consult with the incident center, appropriate security operations response centers, law enforcement agencies, Inspectors General, and other entities or as directed by the President. Directs the OMB Director to review and approve information security policies and procedures to ensure that the incident center has the capability to detect, correlate, and respond to incidents that impair the security of multiple agencies' information systems. Requires the capability, where practicable, to be continuous and technically automated. (Sec. 4) Specifies that no additional funds are authorized for agencies to carry out their responsibilities under this Act. Requires agencies to carry out such responsibilities using amounts otherwise authorized or appropriated.

Tracking Information

Register now for our free OneVote public service or GAITS Pro trial account and you can begin tracking this and other legislation, all driven by the real-time data of the LegiScan API. Providing tools allowing you to research pending legislation, stay informed with email alerts, content feeds, and share dynamic reports. Use our new PolitiCorps to join with friends and collegaues to monitor & discuss bills through the process.

Monitor Legislation or view this same bill number from multiple sessions or take advantage of our national legislative search.

Title

Federal Information Security Amendments Act of 2012

Sponsors


History

DateChamberAction
2012-05-07SenateReceived in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.
2012-04-26HouseMotion to reconsider laid on the table Agreed to without objection.
2012-04-26HouseOn motion to suspend the rules and pass the bill, as amended Agreed to by voice vote. (text: CR H2187-2189)
2012-04-26HouseDEBATE - The House proceeded with forty minutes of debate on H.R. 4257.
2012-04-26HouseConsidered under suspension of the rules. (consideration: CR H2187-2189)
2012-04-26HouseMr. Issa moved to suspend the rules and pass the bill, as amended.
2012-04-26HousePlaced on the Union Calendar, Calendar No. 318.
2012-04-26HouseReported (Amended) by the Committee on Oversight and Government Reform. H. Rept. 112-455.
2012-04-18HouseOrdered to be Reported (Amended).
2012-04-18HouseCommittee Consideration and Mark-up Session Held.
2012-03-26HouseReferred to the House Committee on Oversight and Government Reform.

Same As/Similar To

HB1136 (Related) 2011-04-01 - Referred to the Subcommittee on Government Organization, Efficiency, and Financial Management.
SB413 (Related) 2011-05-23 - Committee on Homeland Security and Governmental Affairs. Hearings held. Hearings printed: S.Hrg. 112-221.

Subjects


US Congress State Sources


Bill Comments

feedback