S. 2902 · 117th Congress · Senate

Federal Information Security Modernization Act of 2021

Active· Placed on Senate Legislative Calendar under General Orders. Calendar No. 673.
Introduced
Sep 29, 21
Passed Senate
Pending
Passed House
Pending
Sent to President
Pending
Signed into Law
Pending

Executive Summary

Federal Information Security Modernization Act of 2021

This bill addresses federal information security management, notification and remediation of cybersecurity incidents.

For example, the bill requires (1) the Cybersecurity and Infrastructure Security Agency to perform ongoing and continuous assessments of federal information security risk posture; and (2) federal agencies to take certain actions in response to information security breaches, such as notifying affected individuals.

Previous Versions

00Sep 29, 2021

Federal Information Security Modernization Act of 2021

This bill addresses federal information security management, notification and remediation of cybersecurity incidents, and the role of the Office of Management and Budget (OMB) and the Cybersecurity and Infrastructure Security Agency (CISA).

The OMB and CISA must perform, on an ongoing and continuous basis, assessments of federal risk posture. The bill requires annual evaluation by each agency of whether additional cybersecurity procedures are appropriate.

An agency, within 30 days of concluding that a major incident has occurred due to a high risk exposure of personal identifiable information, must provide notification to the last known home mailing address of each individual whom the incident may have impacted. Notification may be delayed under specified circumstances.

Each agency must provide any information relating to an incident to CISA, the OMB, the Office of the National Cyber Director, the Government Accountability Office, and Congress. An agency's contractors and grant recipients must immediately notify the agency of an incident involving federal information.

Each agency shall develop training for individuals at the agency with access to federal information or information systems on how to identify and respond to an incident.

The OMB and CISA must (1) develop and promulgate guidance on the definition of major incident, and (2) develop a framework for prioritizing federal penetration testing resources among agencies. CISA must establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency.

The bill establishes specified pilot programs to enhance federal cybersecurity.

Action Timeline

6
  1. DEC 19, 2022Committee

    Committee on Homeland Security and Governmental Affairs

    Reported by Senator Peters with an amendment in the nature of a substitute. With written report No. 117-274.

    117Yea
    274Nay
    0NV
  2. DEC 19, 2022Committee

    Committee on Homeland Security and Governmental Affairs

    Reported by Senator Peters with an amendment in the nature of a substitute. With written report No. 117-274.

    117Yea
    274Nay
    0NV
  3. DEC 19, 2022Calendars

    Placed on Senate Legislative Calendar under General Orders. Calendar No. 673.

  4. OCT 06, 2021Committee

    Committee on Homeland Security and Governmental Affairs

    Ordered to be reported with an amendment in the nature of a substitute favorably.

  5. SEP 29, 2021IntroReferral

    Introduced in Senate

  6. SEP 29, 2021IntroReferral

    Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Committees

3

Homeland Security and Governmental Affairs Committee

ssga00

Referred: Dec 19, 2022

Active

Homeland Security and Governmental Affairs Committee

ssga00

Referred: Oct 6, 2021

Active

Homeland Security and Governmental Affairs Committee

ssga00

Referred: Sep 29, 2021

Active