United States 115th Congress Status: In Committee 1 R cosponsors

HR 1224 — NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017

Last action — Placed on the Union Calendar, Calendar No. 276.

  1. ✓
    Introduced
  2. 2
    In Committee
  3. 3
    Passed House
  4. 4
    Passed Senate
  5. 5
    To Executive
  6. 6
    Enacted

This bill died with 115th Congress. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.

This bill is no longer active — its legislative session has ended, so there are no live odds of enactment. It would have to be reintroduced in the current session to move again.

Bill Text

What changed in the latest version

98 added · 136 removed

Plain-language change summary

The amendment to HR 1224 streamlines the implementation section by removing the introductory phrase and reformatting the guidance requirements. It now focuses solely on the need for guidance to align with the Framework for Improving Critical Infrastructure Cybersecurity, instead of detailing how this guidance should identify conflicts or overlaps with existing requirements. This change simplifies the expectations for the guidance provided to Federal agencies and clarifies the immediate focus on the alignment of practices.

→
Previous
Latest
1224 Introduced in House (IH)] <DOC> 115th CONGRESS 1st Session H.
1224 Reported in House (RH)] <DOC> Union Calendar No.
276 115th CONGRESS 1st Session H.
1224 To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
1224 [Report No.
115-376] To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
which was referred to the Committee on Science, Space, and Technology _______________________________________________________________________ A BILL To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
which was referred to the Committee on Science, Space, and Technology October 31, 2017 Additional sponsor:
Mr.
Sessions October 31, 2017 Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed [Strike out all after the enacting clause and insert the part printed in italic] [For text of introduced bill, see copy of bill as introduced on February 27, 2017] _______________________________________________________________________ A BILL To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
``(a) Implementation by Federal Agencies.-- ``(1) In general.--The Institute shall promote the implementation by Federal agencies of the Framework for Improving Critical Infrastructure Cybersecurity (in this section and section 20B referred to as the `Framework') by providing to the Office of Management and Budget, the Office of Science and Technology Policy, and all other Federal agencies, not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, guidance that Federal agencies may use to incorporate the Framework into their information security risk management efforts, including practices related to compliance with chapter of title 44, United States Code, and any other applicable Federal law.
``(a) Implementation by Federal Agencies.--The Institute shall promote the implementation by Federal agencies of the Framework for Improving Critical Infrastructure Cybersecurity (in this section and section 20B referred to as the `Framework') by providing to the Office of Management and Budget, the Office of Science and Technology Policy, and all other Federal agencies, not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, guidance that Federal agencies may use to incorporate the Framework into their information security risk management efforts, including practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law.
``(2) Guidance.--The guidance required under paragraph (1) shall-- ``(A) describe how the Framework aligns with or augments existing agency practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law;
``(b) Guidance.--The guidance required under subsection (a) shall-- ``(1) describe how the Framework aligns with or augments existing agency practices related to compliance with chapter 35 of title 44, United States Code, and any other applicable Federal law;
``(B) identify any areas of conflict or overlap between the Framework and existing cybersecurity requirements, including gap areas where additional policies, standards, guidelines, or programs may be needed to encourage Federal agencies to use the Framework and improve the ability of Federal agencies to manage cybersecurity risk;
``(2) identify any areas of conflict or overlap between the Framework and existing cybersecurity requirements, including gap areas where additional policies, standards, guidelines, or programs may be needed to encourage Federal agencies to use the Framework and improve the ability of Federal agencies to manage cybersecurity risk;
``(C) include a template for Federal agencies on how to use the Framework, and recommend procedures for streamlining and harmonizing existing and future cybersecurity-related requirements, in support of the goal of using the Framework to supplant Federal agency practices in compliance with chapter 35 of title 44, United States Code;
``(3) include a template for Federal agencies on how to use the Framework, and recommend procedures for streamlining and harmonizing existing and future cybersecurity-related requirements, in support of the goal of using the Framework to supplant Federal agency practices in compliance with chapter 35 of title 44, United States Code;
``(D) recommend other procedures for compliance with cybersecurity reporting, oversight, and policy review and creation requirements under such chapter 35 and any other applicable Federal law;
``(4) recommend other procedures for compliance with cybersecurity reporting, oversight, and policy review and creation requirements under such chapter 35 and any other applicable Federal law;
and ``(E) be updated, as the Institute considers necessary, to reflect what the Institute learns from ongoing research, the audits conducted pursuant to section 20B(b), the information compiled by the Federal working group established pursuant to paragraph (3), the information compiled by the public-private working group established pursuant to subsection (b)(1), the annual reports published pursuant to paragraph (4), and the annual reports published pursuant to subsection (b)(2).
and ``(5) be updated, as the Institute considers necessary, to reflect what the Institute learns from ongoing research, the audits conducted pursuant to section 20B(c), the information compiled by the Federal working group established pursuant to subsection (c), and the annual reports published pursuant to subsection (d).
``(3) Federal working group.--Not later than 3 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall establish and chair a working group (in this section referred to as the `Federal working group'), including representatives of the Office of Science and Technology Policy and other appropriate Federal agencies, which shall-- ``(A) not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop outcome- based and quantifiable metrics, in coordination with the public-private working group established pursuant to subsection (b), to help Federal agencies in their analysis and assessment of the effectiveness of the Framework in protecting their information and information systems;
``(c) Federal Working Group.--Not later than 3 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall establish and chair a working group (in this section referred to as the `Federal working group'), including representatives of the Office of Management and Budget, the Office of Science and Technology Policy, and other appropriate Federal agencies, which shall-- ``(1) not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop outcome-based and quantifiable metrics to help Federal agencies in their analysis and assessment of the effectiveness of the Framework in protecting their information and information systems;
``(B) update such metrics as the Federal working group considers necessary;
``(2) update such metrics as the Federal working group considers necessary;
``(C) compile information from Federal agencies on their use of the Framework and the results of the analysis and assessment described in subparagraph (A);
``(3) compile information from Federal agencies on their use of the Framework and the results of the analysis and assessment described in paragraph (1);
and ``(D) assist the Office of Science and Technology Policy in publishing the annual report required under paragraph (4).
and ``(4) assist the Office of Management and Budget and the Office of Science and Technology Policy in publishing the annual report required under subsection (d).
``(4) Report.--The Office of Science and Technology Policy shall develop and make publicly available an annual report on agency adoption rates and the effectiveness of the Framework.
``(d) Report.--The Office of Management and Budget and the Office of Science and Technology Policy shall develop and make publicly available an annual report on agency adoption rates and the effectiveness of the Framework.
In preparing such report, the Office shall use the information compiled by the Federal working group pursuant to paragraph (3)(C).
In preparing such report, the Offices shall use the information compiled by the Federal working group pursuant to subsection (c)(3).
``(b) Implementation by Private Entities.-- ``(1) Public-private working group.--Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall, in coordination with industry stakeholders, establish a working group (in this section referred to as the `public- private working group') which shall-- ``(A) not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop specific Framework implementation models and measurement tools that private entities can use to adopt the Framework;
``(B) not later than 1 year after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, develop, in coordination with the Federal working group, industry- led, consensus and outcome-based metrics that quantify the effectiveness and benefits of the Framework to enable private entities to voluntarily analyze and assess their individual corporate cybersecurity risks;
``(C) update the models and tools developed pursuant to subparagraph (A) and the metrics developed pursuant to subparagraph (B), as the public-private working group considers necessary;
``(D) compile information, derived from the metrics developed pursuant to subparagraph (B), voluntarily submitted by private entities on their use of the Framework and on the effectiveness and benefits of such use;
``(E) analyze the information compiled pursuant to subparagraph (D) and provide such information and analysis to-- ``(i) the Institute, for the purpose of enabling the Institute to make improvements to the Framework;
and ``(ii) private entities, for the purpose of providing such entities with a greater understanding of the benefits of the Framework to enable them to use the Framework more effectively to improve their cybersecurity;
and ``(F) assist the Office of Science and Technology Policy in publishing the annual report required under paragraph (2).
``(2) Report.--The Office of Science and Technology Policy shall develop and make publicly available an annual report on industry adoption rates and the effectiveness of the Framework.
In preparing such report, the Office shall use information compiled by the public-private working group pursuant to paragraph (1)(D).
``(2) Agencies.--The agencies referred to in paragraph (1) are the agencies referred to in section 901(b) of title 31, United States Code, and any other agency that has reported a major incident (as defined in the Office of Management and Budget Memorandum--16-03, published on October 30, 2015, or any successor document).
``(2) Agencies.--The agencies referred to in paragraph (1) are the agencies referred to in section 901(b) of title 31, United States Code, and any other agency that has reported a major incident (as defined in the Office of Management and Budget Memorandum--16--03, published on October 30, 2015, or any successor document).
``(b) Audits.-- ``(1) Requirement.--Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall initiate an individual cybersecurity audit of each agency described in subsection (a)(2), to assess the extent to which the agency is meeting the information security standards developed under section 20.
``(b) Audit Plan.--Not later than 6 months after the date of enactment of this Act, the Institute shall prepare a needs-based plan for carrying out the audits of agencies as required under subsection (c).
``(2) Relation to framework.--Audits conducted under this subsection shall-- ``(A) to the extent applicable and available, be informed by the report on agency adoption rates and the effectiveness of the Framework described in section 20A(a)(4);
Such plan shall include a description of staffing plans, workforce capabilities, methods for conducting such audits, coordination with agencies to support such audits, expected timeframes for the completion of audits, and other information the Institute considers relevant.
and ``(B) if the agency is required by law or Executive order to adopt the Framework, be based on the guidance described in section 20A(a)(2) and metrics developed under section 20A(a)(3)(A).
The plan shall be transmitted by the Institute to the congressional entities described in subsection (c)(4)(F).
``(c) Audits.-- ``(1) Requirement.--Not later than 6 months after the date of enactment of the NIST Cybersecurity Framework, Assessment, and Auditing Act of 2017, the Institute shall initiate an individual cybersecurity audit of each agency described in subsection (a)(2), to assess the extent to which the agency is meeting the information security standards developed under section 20.
``(2) Relation to framework.--Audits conducted under this subsection shall-- ``(A) to the extent applicable and available, be informed by the report on agency adoption rates and the effectiveness of the Framework described in section 20A(d);
and ``(B) if the agency is required by law or executive order to adopt the Framework, be based on the guidance described in section 20A(b) and metrics developed under section 20A(c)(1).
<all>
Union Calendar No.
276 115th CONGRESS 1st Session H.
R.
1224 [Report No.
115-376] _______________________________________________________________________ A BILL To amend the National Institute of Standards and Technology Act to implement a framework, assessment, and audits for improving United States cybersecurity.
Show all 41 changed rows (1 more)
Previous
Latest
_______________________________________________________________________ October 31, 2017 Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed
View plain text versions (2)

Action History

  1. Introduced in House

  2. Introduced in House

  3. Referred to the House Committee on Science, Space, and Technology.

  4. Committee Consideration and Mark-up Session Held.

  5. Ordered to be Reported (Amended) by the Yeas and Nays: 19 - 14.

  6. Reported (Amended) by the Committee on Science, Space, and Technology. H. Rept. 115-376.

  7. Reported (Amended) by the Committee on Science, Space, and Technology. H. Rept. 115-376.

  8. Placed on the Union Calendar, Calendar No. 276.

Sponsors

Sponsorship breakdown

Export CSV (upgrade) →

1 sponsors · 0 co-sponsors · 546 not signed on

Sponsors (1)

Co-sponsors (0)

None.

Not signed on (546)

546 members have not signed on to this bill.

Show all 546 →

"Not signed on" means a member has not sponsored or co-sponsored this bill — it does not imply opposition. Members flagged Voted No have a recorded No vote on this bill.

Whip count is in markup. Polling the chamber and every recorded vote this session. Only the first open is slow. It’s instant for you after this. Calling the roll · Tallying · Engrossing

Subjects

Cross-referencing the record. Reading this bill against every other bill in the corpus by meaning, not keywords. Only the first open is slow. It’s instant for you after this. Matching · Ranking · Engrossing

Frequently asked questions

Who sponsors HR 1224?
HR 1224 is sponsored by Abraham, Ralph Lee (Republican).
What is the current status of HR 1224?
This bill died with 115th Congress. It reached “In Committee” and never advanced before the session ended, so it can no longer move — a new version would have to be reintroduced in the current session.
Where can I track HR 1224?
Track HR 1224 free on One Click Politics — get push/email alerts when it moves.

Make your voice heard on HR 1224

Find the representatives who decide this bill and tell them where you stand — for yourself, or mobilize your whole list in one click with One Click Politics advocacy software.

Stay ahead of HR 1224

Last checked for changes 3 months ago · updated continuously

One Click Politics tracks every bill in Congress and all 50 states.

Track this bill →