HR 1224 — NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017
Last action — Placed on the Union Calendar, Calendar No. 276.
-
✓Introduced
-
2In Committee
-
3Passed House
-
4Passed Senate
-
5To Executive
-
6Enacted
This bill died with 115th Congress. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.
Bill Text
What changed in the latest version
98 added · 136 removedPlain-language change summary
The amendment to HR 1224 streamlines the implementation section by removing the introductory phrase and reformatting the guidance requirements. It now focuses solely on the need for guidance to align with the Framework for Improving Critical Infrastructure Cybersecurity, instead of detailing how this guidance should identify conflicts or overlaps with existing requirements. This change simplifies the expectations for the guidance provided to Federal agencies and clarifies the immediate focus on the alignment of practices.
1224 IntroducedReported in House (IH)](RH)] <DOC> 115thUnion CONGRESSCalendar 1stNo. Session H.
276 115th CONGRESS 1st Session H.
1224 To[Report amendNo. the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
115-376] To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
which was referred to the Committee on Science, Space, and Technology _______________________________________________________________________October A31, BILL2017 ToAdditional amendsponsor: the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
Mr.
Sessions October 31, 2017 Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed [Strike out all after the enacting clause and insert the part printed in italic] [For text of introduced bill, see copy of bill as introduced on February 27, 2017] _______________________________________________________________________ A BILL To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
``(a) Implementation by Federal Agencies.--Agencies.--The ``(1) In general.--The Institute shall promote the implementation by Federal agencies of the Framework for Improving Critical Infrastructure Cybersecurity (in this section and section 20B referred to as the `Framework') by providing to the Office of Management and Budget, the Office of Science and Technology Policy, and all other Federal agencies, not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, guidance that Federal agencies may use to incorporate the Framework into their information security risk management efforts, including practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law.
``(2)``(b) Guidance.--The guidance required under paragraphsubsection (1)(a) shall-- ``(A)``(1) describe how the Framework aligns with or augments existing agency practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law;
``(B)``(2) identify any areas of conflict or overlap between the Framework and existing cybersecurity requirements, including gap areas where additional policies, standards, guidelines, or programs may be needed to encourage Federal agencies to use the Framework and improve the ability of Federal agencies to manage cybersecurity risk;
``(C)``(3) include a template for Federal agencies on how to use the Framework, and recommend procedures for streamlining and harmonizing existing and future cybersecurity-related requirements, in support of the goal of using the Framework to supplant Federal agency practices in compliance with chapter 35 of title 44, United States Code;
``(D)``(4) recommend other procedures for compliance with cybersecurity reporting, oversight, and policy review and creation requirements under such chapter 35 and any other applicable Federal law;
and ``(E)``(5) be updated, as the Institute considers necessary, to reflect what the Institute learns from ongoing research, the audits conducted pursuant to section 20B(b),20B(c), the information compiled by the Federal working group established pursuant to paragraph (3), the information compiled by the public-private working group established pursuant to subsection (b)(1),(c), the annual reports published pursuant to paragraph (4), and the annual reports published pursuant to subsection (b)(2).(d).
``(3)``(c) Federal workingWorking group.--NotGroup.--Not later than 3 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall establish and chair a working group (in this section referred to as the `Federal working group'), including representatives of the Office of Management and Budget, the Office of Science and Technology PolicyPolicy, and other appropriate Federal agencies, which shall-- ``(A)``(1) not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop outcome-outcome-based based and quantifiable metrics,metrics in coordination with the public-private working group established pursuant to subsection (b), to help Federal agencies in their analysis and assessment of the effectiveness of the Framework in protecting their information and information systems;
``(B)``(2) update such metrics as the Federal working group considers necessary;
``(C)``(3) compile information from Federal agencies on their use of the Framework and the results of the analysis and assessment described in subparagraphparagraph (A);(1);
and ``(D)``(4) assist the Office of Management and Budget and the Office of Science and Technology Policy in publishing the annual report required under paragraphsubsection (4).(d).
``(4)``(d) Report.--The Office of Management and Budget and the Office of Science and Technology Policy shall develop and make publicly available an annual report on agency adoption rates and the effectiveness of the Framework.
In preparing such report, the OfficeOffices shall use the information compiled by the Federal working group pursuant to paragraphsubsection (3)(C).(c)(3).
``(b) Implementation by Private Entities.-- ``(1) Public-private working group.--Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall, in coordination with industry stakeholders, establish a working group (in this section referred to as the `public- private working group') which shall-- ``(A) not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop specific Framework implementation models and measurement tools that private entities can use to adopt the Framework;
``(B) not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop, in coordination with the Federal working group, industry- led, consensus and outcome-based metrics that quantify the effectiveness and benefits of the Framework to enable private entities to voluntarily analyze and assess their individual corporate cybersecurity risks;
``(C) update the models and tools developed pursuant to subparagraph (A) and the metrics developed pursuant to subparagraph (B), as the public-private working group considers necessary;
``(D) compile information, derived from the metrics developed pursuant to subparagraph (B), voluntarily submitted by private entities on their use of the Framework and on the effectiveness and benefits of such use;
``(E) analyze the information compiled pursuant to subparagraph (D) and provide such information and analysis to-- ``(i) the Institute, for the purpose of enabling the Institute to make improvements to the Framework;
and ``(ii) private entities, for the purpose of providing such entities with a greater understanding of the benefits of the Framework to enable them to use the Framework more effectively to improve their cybersecurity;
and ``(F) assist the Office of Science and Technology Policy in publishing the annual report required under paragraph (2).
``(2) Report.--The Office of Science and Technology Policy shall develop and make publicly available an annual report on industry adoption rates and the effectiveness of the Framework.
In preparing such report, the Office shall use information compiled by the public-private working group pursuant to paragraph (1)(D).
``(2) Agencies.--The agencies referred to in paragraph (1) are the agencies referred to in section 901(b) of title 31, United States Code, and any other agency that has reported a major incident (as defined in the Office of Management and Budget Memorandum--16-03,Memorandum--16--03, published on October 30, 2015, or any successor document).
``(b) Audits.--Audit ``(1)Plan.--Not Requirement.--Not later than 6 months after the date of enactment of thethis NISTAct, Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall initiateprepare ana individualneeds-based cybersecurityplan auditfor ofcarrying eachout agency described in subsection (a)(2), to assess the extentaudits toof whichagencies theas agencyrequired is meeting the information security standards developed under sectionsubsection 20.(c).
``(2)Such Relationplan toshall framework.--Auditsinclude conducteda underdescription thisof subsectionstaffing shall--plans, ``(A)workforce tocapabilities, themethods extentfor applicableconducting andsuch available,audits, becoordination informedwith byagencies theto reportsupport onsuch agencyaudits, adoptionexpected ratestimeframes andfor the effectivenesscompletion of theaudits, Frameworkand describedother ininformation sectionthe 20A(a)(4);Institute considers relevant.
andThe ``(B)plan ifshall thebe agencytransmitted is required by lawthe orInstitute Executive order to adopt the Framework,congressional beentities based on the guidance described in sectionsubsection 20A(a)(2)(c)(4)(F). and metrics developed under section 20A(a)(3)(A).
``(c) Audits.-- ``(1) Requirement.--Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall initiate an individual cybersecurity audit of each agency described in subsection (a)(2), to assess the extent to which the agency is meeting the information security standards developed under section 20.
``(2) Relation to framework.--Audits conducted under this subsection shall-- ``(A) to the extent applicable and available, be informed by the report on agency adoption rates and the effectiveness of the Framework described in section 20A(d);
and ``(B) if the agency is required by law or executive order to adopt the Framework, be based on the guidance described in section 20A(b) and metrics developed under section 20A(c)(1).
<all>Union Calendar No.
276 115th CONGRESS 1st Session H.
R.
1224 [Report No.
115-376] _______________________________________________________________________ A BILL To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
Show all 41 changed lines (1 more)
_______________________________________________________________________ October 31, 2017 Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed
Show all 41 changed rows (1 more)
View plain text versions (2)
- Reported Reported in House Current html October 31, 2017
- Introduced Introduced in House html February 27, 2017
Action History
-
Introduced in House
-
Introduced in House
-
Referred to the House Committee on Science, Space, and Technology.
-
Committee Consideration and Mark-up Session Held.
-
Ordered to be Reported (Amended) by the Yeas and Nays: 19 - 14.
-
Reported (Amended) by the Committee on Science, Space, and Technology. H. Rept. 115-376.
-
Reported (Amended) by the Committee on Science, Space, and Technology. H. Rept. 115-376.
-
Placed on the Union Calendar, Calendar No. 276.
Sponsors
- Ralph Lee Abraham · Primary
Sponsorship breakdown
Export CSV (upgrade) →1 sponsors · 0 co-sponsors · 546 not signed on
Sponsors (1)
- Abraham, Ralph Lee Republican
Co-sponsors (0)
None.
Not signed on (546)
546 members have not signed on to this bill.
Show all 546 →"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.
Subjects
Frequently asked questions
- Who sponsors HR 1224?
- HR 1224 is sponsored by Abraham, Ralph Lee (Republican).
- What is the current status of HR 1224?
- This bill died with 115th Congress. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
- Where can I track HR 1224?
- Track HR 1224 free on One Click Politics — get push/email alerts when it moves.
Make your voice heard on HR 1224
Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.
Stay ahead of HR 1224
Last checked for changes 3 months ago · updated continuously
One Click Politics tracks every bill in Congress and all 50 states.
Track this bill →