HR-6497 : Still Just a Bill


Federal Information Security Modernization Act of 2022

This bill addresses federal information security management, notification and remediation of cybersecurity incidents, and the roles of the Office of Management and Budget (OMB) and the Cybersecurity and Infrastructure Security Agency (CISA).

CISA must perform, on an ongoing and continuous basis, assessments of federal risk posture. The bill requires evaluation by each agency of whether additional cybersecurity procedures are appropriate at least once every three years.

An agency, as expeditiously as practicable and without unreasonable delay, and within 45 days after it has a reasonable basis to conclude that a breach has occurred, must (1) determine whether notice to any individual potentially affected by the breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected. Notification may be delayed under specified circumstances.

Each agency must provide any information relating to a major incident to CISA, the OMB, the Office of the National Cyber Director, the agency's office of inspector general, the Government Accountability Office, and Congress.

An agency's contractors and grant recipients must notify the agency of an incident involving federal information within a specified time frame.

Each agency shall develop training for individuals at the agency with access to federal information or information systems on how to identify and respond to an incident.

CISA must establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.

The bill establishes specified pilot programs to enhance federal cybersecurity.

Action Timeline

Action DateTypeTextSource
2022-02-02CommitteeOrdered to be Reported (Amended) by Voice Vote.House committee actions
2022-02-02CommitteeCommittee Consideration and Mark-up Session Held.House committee actions
2022-01-25IntroReferralReferred to the Committee on Oversight and Reform, and in addition to the Committee on Science, Space, and Technology, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.House floor actions
2022-01-25IntroReferralReferred to the Committee on Oversight and Reform, and in addition to the Committee on Science, Space, and Technology, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.House floor actions
2022-01-25IntroReferralIntroduced in HouseLibrary of Congress

Policy Area :

Government Operations and Politics
Related Subjects
  • Administrative law and regulatory procedures
  • Advisory bodies
  • Computers and information technology
  • Computer security and identity theft
  • Congressional oversight
  • Criminal investigation, prosecution, interrogation
  • Employment and training programs
  • Executive agency funding and structure
  • Federal officials
  • Government employee pay, benefits, personnel management
  • Government information and archives
  • Government studies and investigations
  • Infrastructure development
  • Internet, web applications, social media
  • Performance measurement
  • Public contracts and procurement
  • Right of privacy
  • Technology assessment
  • Telephone and wireless communication
Related Geographic Entities
Related Organizations
  • Department of Homeland Security
  • Office of Management and Budget (OMB)

Related Bills

See Related Bills