S-1869 : Still Just a Bill

Federal Cybersecurity Enhancement Act of 2015

Amends the Homeland Security Act of 2002 to require the Department of Homeland Security (DHS), in coordination with the Office of Management and Budget (OMB), to implement an intrusion assessment plan to identify and remove intruders in federal agency information systems.

Directs DHS to deploy and operate, for use by other agencies, capabilities to detect and prevent or remove cybersecurity risks in network traffic transiting or traveling to or from agency information systems. Authorizes the DHS Secretary to access, and agency heads to disclose to the Secretary, information transiting agency systems, regardless of the location from which the information is accessed, notwithstanding any laws that would otherwise restrict or prevent such disclosures. Requires agencies to utilize such capabilities and adopt subsequent improvements.

Provides liability protections to private entities authorized to assist the Secretary with such capabilities.

Terminates authority for such capabilities seven years after enactment of this Act.

Requires DHS to include in the Continuous Diagnostics and Mitigation Program advanced network security tools to improve visibility of network activity to detect and mitigate intrusions and anomalous activity. Directs the OMB to implement a plan to ensure that agencies utilize such advanced tools.

Directs DHS to collaborate with the OMB to update government information security metrics to include measures of intrusion and incident detection and response times. Requires the OMB to display additional agency metrics on federal government performance websites.

Authorizes DHS, upon an agency's request, to operate and maintain technology that is deployed to agencies to diagnose and mitigate against cyber threats and vulnerabilities.

Requires agencies to: (1) encrypt sensitive and mission critical data, (2) implement single sign-on trusted identity platforms for public websites, and (3) implement multifactor authentication standards for remote access to agency systems.

Excludes the Department of Defense and the intelligence community from procedures of this Act.

Action Timeline

Action DateTypeTextSource
2016-11-17CalendarsPlaced on Senate Legislative Calendar under General Orders. Calendar No. 673.Senate
2016-11-17CommitteeCommittee on Homeland Security and Governmental Affairs. Reported by Senator Johnson with amendments. With written report No. 114-378.Senate
2015-07-29CommitteeCommittee on Homeland Security and Governmental Affairs. Ordered to be reported with amendments favorably.Senate
2015-07-27IntroReferralRead twice and referred to the Committee on Homeland Security and Governmental Affairs.Senate
2015-07-27IntroReferralIntroduced in SenateLibrary of Congress

Policy Area :

Government Operations and Politics
See Subjects
  • Civil actions and liability
  • Computer security and identity theft
  • Congressional oversight
  • Government information and archives
  • Government studies and investigations
  • Performance measurement
  • Technology assessment

Related Bills

See Related Bills