US HB4370 | 2013-2014 | 113th Congress

Status

Spectrum: Partisan Bill (Republican 30-0)
Status: Introduced on April 2 2014 - 25% progression, died in committee
Action: 2014-04-04 - Referred to the Subcommittee on Oversight and Investigations.
Pending: House Subcommittee on Oversight and Investigations Committee
Text: Latest bill text (Introduced) [PDF]

Summary

Veterans Information Security Improvement Act - Directs the Secretary of Veterans Affairs to: (1) carry out certain information security activities, (2) ensure that officials and staff of the Department of Veterans Affairs (VA) possess specified qualifications in such areas, and (3) coordinate the staffing of related information technology and security offices. Requires the Secretary to ensure that: (1) the Assistant Secretary for Information and Technology, the head of the Office of Information Security (OIS), and relevant field staff possess certain levels of information technology education, certifications, and experience; (2) Office of Information and Technology (OIT) staff are assigned to the OIS; and (3) subordinate OIT offices maintain appropriate information security functions. Directs the Secretary to ensure that subordinate OIT offices maintain functions to: (1) integrate the VA's security architecture into the VA's overall enterprise architecture strategy, (2) restrict the development of new data warehouses and data marts holding sensitive personal information of veterans, and (3) reduce the number of data marts holding such personal information. Defines: (1) "data mart" as a subset of a data warehouse that contains information for a specific entity of an organization rather than the entire organization, and (2) "data warehouse" as a collection of data designed to support management decision making that contains a wide variety of data presenting a coherent picture of business conditions for an entire organization at a single point in time and whose development includes systems to extract data from operating systems plus installation of a warehouse database system that provides managers flexible access to the data. Requires the Secretary to safeguard VA network infrastructure, computers, and servers. Directs the Secretary to protect the confidentiality of sensitive personal information of veterans by: (1) providing upgrades or phaseouts of outdated or unsupported operating systems to protect against harmful viruses and malicious software, and (2) securing VA web applications and the Veterans Health Information Systems and Technology Architecture (commonly referred to as the "Vista system," which allows for an integrated inpatient and outpatient electronic health record for patients and provides administrative tools to VA employees). Directs the Secretary to submit certifications to Congress regarding the VA's compliance with information security requirements, including actions required by the National Institute of Standards and Technology (NIST) and the Office of Management and Budget (OMB). Requires the Secretary to submit monthly reports to Congress regarding security vulnerabilities discovered after performing regular scans of VA computers and servers.

Tracking Information

Register now for our free OneVote public service or GAITS Pro trial account and you can begin tracking this and other legislation, all driven by the real-time data of the LegiScan API. Providing tools allowing you to research pending legislation, stay informed with email alerts, content feeds, and share dynamic reports. Use our new PolitiCorps to join with friends and collegaues to monitor & discuss bills through the process.

Monitor Legislation or view this same bill number from multiple sessions or take advantage of our national legislative search.

Title

Veterans Information Security Improvement Act

Sponsors


History

DateChamberAction
2014-04-04HouseReferred to the Subcommittee on Oversight and Investigations.
2014-04-02HouseReferred to the House Committee on Veterans' Affairs.

Subjects


US Congress State Sources


Bill Comments

feedback