Home > 106th Congressional Bills > S. 1994 (is) To amend the Internal Revenue Code of 1986 to provide assistance to first-time homebuyers. [Introduced in Senate] ...

S. 1994 (is) To amend the Internal Revenue Code of 1986 to provide assistance to first-time homebuyers. [Introduced in Senate] ...


Google
 
Web GovRecords.org






                                                       Calendar No. 489

106th CONGRESS

  2d Session

                                S. 1993

                          [Report No. 106-259]

_______________________________________________________________________

                                 A BILL

To reform Government information security by strengthening information 
         security practices throughout the Federal Government.

_______________________________________________________________________

                             April 10, 2000

                       Reported with an amendment





                                                       Calendar No. 489
106th CONGRESS
  2d Session
                                S. 1993

                          [Report No. 106-259]

To reform Government information security by strengthening information 
         security practices throughout the Federal Government.


_______________________________________________________________________


                   IN THE SENATE OF THE UNITED STATES

                           November 19, 1999

 Mr. Thompson (for himself, Mr. Lieberman, Mr. Abraham, Mr. Voinovich, 
   Mr. Akaka, Mr. Cleland, Ms. Collins, Mr. Stevens, and Mr. Helms) 
introduced the following bill; which was read twice and referred to the 
                   Committee on Governmental Affairs

                             April 10, 2000

              Reported by Mr. Thompson, with an amendment
 [Strike out all after the enacting clause and insert the part printed 
                               in italic]

_______________________________________________________________________

                                 A BILL


 
To reform Government information security by strengthening information 
         security practices throughout the Federal Government.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

<DELETED>SECTION 1. SHORT TITLE.</DELETED>

<DELETED>    This Act may be cited as the ``Government Information 
Security Act of 1999''.</DELETED>

<DELETED>SEC. 2. COORDINATION OF FEDERAL INFORMATION POLICY.</DELETED>

<DELETED>    Chapter 35 of title 44, United States Code, is amended by 
inserting at the end the following:</DELETED>

        <DELETED>``SUBCHAPTER II--INFORMATION SECURITY</DELETED>

<DELETED>``Sec. 3531. Purposes</DELETED>
<DELETED>    ``The purposes of this subchapter are to--</DELETED>
        <DELETED>    ``(1) provide a comprehensive framework for 
        establishing and ensuring the effectiveness of controls over 
        information resources that support Federal operations and 
        assets;</DELETED>
        <DELETED>    ``(2)(A) recognize the highly networked nature of 
        the Federal computing environment including the need for 
        Federal Government interoperability and, in the implementation 
        of improved security management measures, assure that 
        opportunities for interoperability are not adversely affected; 
        and</DELETED>
        <DELETED>    ``(B) provide effective governmentwide management 
        and oversight of the related information security risks, 
        including coordination of information security efforts 
        throughout the civilian, national security, and law enforcement 
        communities;</DELETED>
        <DELETED>    ``(3) provide for development and maintenance of 
        minimum controls required to protect Federal information and 
        information systems; and</DELETED>
        <DELETED>    ``(4) provide a mechanism for improved oversight 
        of Federal agency information security programs.</DELETED>
<DELETED>``Sec. 3532. Definitions</DELETED>
<DELETED>    ``(a) Except as provided under subsection (b), the 
definitions under section 3502 shall apply to this 
subchapter.</DELETED>
<DELETED>    ``(b) As used in this subchapter the term `information 
technology' has the meaning given that term in section 5002 of the 
Clinger-Cohen Act of 1996 (40 U.S.C. 1401).</DELETED>
<DELETED>``Sec. 3533. Authority and functions of the Director</DELETED>
<DELETED>    ``(a)(1) Consistent with subchapter I, the Director shall 
establish governmentwide policies for the management of programs that 
support the cost-effective security of Federal information systems by 
promoting security as an integral component of each agency's business 
operations.</DELETED>
<DELETED>    ``(2) Policies under this subsection shall--</DELETED>
        <DELETED>    ``(A) be founded on a continuing risk management 
        cycle that recognizes the need to--</DELETED>
                <DELETED>    ``(i) identify, assess, and understand 
                risk; and</DELETED>
                <DELETED>    ``(ii) determine security needs 
                commensurate with the level of risk;</DELETED>
        <DELETED>    ``(B) implement controls that adequately address 
        the risk;</DELETED>
        <DELETED>    ``(C) promote continuing awareness of information 
        security risk;</DELETED>
        <DELETED>    ``(D) continually monitor and evaluate policy; 
        and</DELETED>
        <DELETED>    ``(E) control effectiveness of information 
        security practices.</DELETED>
<DELETED>    ``(b) The authority under subsection (a) includes the 
authority to--</DELETED>
        <DELETED>    ``(1) oversee and develop policies, principles, 
        standards, and guidelines for the handling of Federal 
        information and information resources to improve the efficiency 
        and effectiveness of governmental operations, including 
        principles, policies, and guidelines for the implementation of 
        agency responsibilities under applicable law for ensuring the 
        privacy, confidentiality, and security of Federal 
        information;</DELETED>
        <DELETED>    ``(2) consistent with the standards and guidelines 
        promulgated under section 5131 of the Clinger-Cohen Act of 1996 
        (40 U.S.C. 1441) and sections 5 and 6 of the Computer Security 
        Act of 1987 (40 U.S.C. 759 note; Public Law 100-235; 101 Stat. 
        1729), require Federal agencies to identify and afford security 
        protections commensurate with the risk and magnitude of the 
        harm resulting from the loss, misuse, or unauthorized access to 
        or modification of information collected or maintained by or on 
        behalf of an agency;</DELETED>
        <DELETED>    ``(3) direct the heads of agencies to coordinate 
        such agencies and coordinate with industry to--</DELETED>
                <DELETED>    ``(A) identify, use, and share best 
                security practices; and</DELETED>
                <DELETED>    ``(B) develop voluntary consensus-based 
                standards for security controls, in a manner consistent 
                with section 2(b)(13) of the National Institute of 
                Standards and Technology Act (15 U.S.C. 
                272(b)(13));</DELETED>
        <DELETED>    ``(4) oversee the development and implementation 
        of standards and guidelines relating to security controls for 
        Federal computer systems by the Secretary of Commerce through 
        the National Institute of Standards and Technology under 
        section 5131 of the Clinger-Cohen Act of 1996 (40 U.S.C. 1441) 
        and section 20 of the National Institute of Standards and 
        Technology Act (15 U.S.C. 278g-3);</DELETED>
        <DELETED>    ``(5) oversee and coordinate compliance with this 
        section in a manner consistent with--</DELETED>
                <DELETED>    ``(A) sections 552 and 552a of title 
                5;</DELETED>
                <DELETED>    ``(B) sections 20 and 21 of the National 
                Institute of Standards and Technology Act (15 U.S.C. 
                278g-3 and 278g-4);</DELETED>
                <DELETED>    ``(C) section 5131 of the Clinger-Cohen 
                Act of 1996 (40 U.S.C. 1441);</DELETED>
                <DELETED>    ``(D) sections 5 and 6 of the Computer 
                Security Act of 1987 (40 U.S.C. 759 note; Public Law 
                100-235; 101 Stat. 1729); and</DELETED>
                <DELETED>    ``(E) related information management laws; 
                and</DELETED>
        <DELETED>    ``(6) take any authorized action that the Director 
        considers appropriate, including any action involving the 
        budgetary process or appropriations management process, to 
        enforce accountability of the head of an agency for information 
        resources management and for the investments made by the agency 
        in information technology, including--</DELETED>
                <DELETED>    ``(A) recommending a reduction or an 
                increase in any amount for information resources that 
                the head of the agency proposes for the budget 
                submitted to Congress under section 1105(a) of title 
                31;</DELETED>
                <DELETED>    ``(B) reducing or otherwise adjusting 
                apportionments and reapportionments of appropriations 
                for information resources; and</DELETED>
                <DELETED>    ``(C) using other authorized 
                administrative controls over appropriations to restrict 
                the availability of funds for information 
                resources.</DELETED>
<DELETED>    ``(c) The authority under this section may be delegated 
only to the Deputy Director for Management of the Office of Management 
and Budget.</DELETED>
<DELETED>``Sec. 3534. Federal agency responsibilities</DELETED>
<DELETED>    ``(a) The head of each agency shall--</DELETED>
        <DELETED>    ``(1) be responsible for--</DELETED>
                <DELETED>    ``(A) adequately protecting the integrity, 
                confidentiality, and availability of information and 
                information systems supporting agency operations and 
                assets; and</DELETED>
                <DELETED>    ``(B) developing and implementing 
                information security policies, procedures, and control 
                techniques sufficient to afford security protections 
                commensurate with the risk and magnitude of the harm 
                resulting from unauthorized disclosure, disruption, 
                modification, or destruction of information collected 
                or maintained by or for the agency;</DELETED>
        <DELETED>    ``(2) ensure that each senior program manager is 
        responsible for--</DELETED>
                <DELETED>    ``(A) assessing the information security 
                risk associated with the operations and assets of such 
                manager;</DELETED>
                <DELETED>    ``(B) determining the levels of 
                information security appropriate to protect the 
                operations and assets of such manager; and</DELETED>
                <DELETED>    ``(C) periodically testing and evaluating 
                information security controls and techniques;</DELETED>
        <DELETED>    ``(3) delegate to the agency Chief Information 
        Officer established under section 3506, or a comparable 
        official in an agency not covered by such section, the 
        authority to administer all functions under this subchapter 
        including--</DELETED>
                <DELETED>    ``(A) designating a senior agency 
                information security officer;</DELETED>
                <DELETED>    ``(B) developing and maintaining an 
                agencywide information security program as required 
                under subsection (b);</DELETED>
                <DELETED>    ``(C) ensuring that the agency effectively 
                implements and maintains information security policies, 
                procedures, and control techniques;</DELETED>
                <DELETED>    ``(D) training and overseeing personnel 
                with significant responsibilities for information 
                security with respect to such responsibilities; 
                and</DELETED>
                <DELETED>    ``(E) assisting senior program managers 
                concerning responsibilities under paragraph 
                (2);</DELETED>
        <DELETED>    ``(4) ensure that the agency has trained personnel 
        sufficient to assist the agency in complying with the 
        requirements of this subchapter and related policies, 
        procedures, standards, and guidelines; and</DELETED>
        <DELETED>    ``(5) ensure that the agency Chief Information 
        Officer, in coordination with senior program managers, 
        periodically--</DELETED>
                <DELETED>    ``(A)(i) evaluates the effectiveness of 
                the agency information security program, including 
                testing control techniques; and</DELETED>
                <DELETED>    ``(ii) implements appropriate remedial 
                actions based on that evaluation; and</DELETED>
                <DELETED>    ``(B) reports to the agency head on--
                </DELETED>
                        <DELETED>    ``(i) the results of such tests 
                        and evaluations; and</DELETED>
                        <DELETED>    ``(ii) the progress of remedial 
                        actions.</DELETED>
<DELETED>    ``(b)(1) Each agency shall develop and implement an 
agencywide information security program to provide information security 
for the operations and assets of the agency, including information 
security provided or managed by another agency.</DELETED>
<DELETED>    ``(2) Each program under this subsection shall include--
</DELETED>
        <DELETED>    ``(A) periodic assessments of information security 
        risks that consider internal and external threats to--
        </DELETED>
                <DELETED>    ``(i) the integrity, confidentiality, and 
                availability of systems; and</DELETED>
                <DELETED>    ``(ii) data supporting critical operations 
                and assets;</DELETED>
        <DELETED>    ``(B) policies and procedures that--</DELETED>
                <DELETED>    ``(i) are based on the risk assessments 
                required under paragraph (1) that cost-effectively 
                reduce information security risks to an acceptable 
                level; and</DELETED>
                <DELETED>    ``(ii) ensure compliance with--</DELETED>
                        <DELETED>    ``(I) the requirements of this 
                        subchapter;</DELETED>
                        <DELETED>    ``(II) policies and procedures as 
                        may be prescribed by the Director; 
                        and</DELETED>
                        <DELETED>    ``(III) any other applicable 
                        requirements;</DELETED>
        <DELETED>    ``(C) security awareness training to inform 
        personnel of--</DELETED>
                <DELETED>    ``(i) information security risks 
                associated with personnel activities; and</DELETED>
                <DELETED>    ``(ii) responsibilities of personnel in 
                complying with agency policies and procedures designed 
                to reduce such risks;</DELETED>

Pages: 1 2 3 4 Next >>

Other Popular 106th Congressional Bills Documents:

1 S. 3137 (es) To establish a commission to commemorate the 250th anniversary of the birth of James Madison. [Engrossed in Senate] ...
2 S. 2352 (is) To designate portions of the Wekiva River and associated tributaries as a component of the National Wild and Scenic Rivers System. [Introduced in Senate] ...
3 S. 1896 (is) To amend the Public Buildings Act of 1959 to give first priority to the location of Federal facilities in central business areas, and for other purposes. [Introduced in Senate] ...
4 S. 748 (is) To improve Native hiring and contracting by the Federal Government within the State of Alaska, and for other purposes. [Introduced in Senate] ...
5 S.Res. 251 (ats) Designating March 25, 2000, as ``Greek Independence Day: A National Day of Celebration of Greek and American Democracy''. [Agreed to Senate] ...
6 S.Res. 97 (ats) Designating the week of May 2 through 8, 1999, as the 14th Annual Teacher Appreciation Week, and designating Tuesday, May 4, 1999, as National Teacher Day. [Agreed to Senate] ...
7 H.R. 1025 (ih) To authorize the Secretary of Transportation to issue a certificate of documentation with appropriate endorsement for employment in the fisheries for each of 3 vessels. [Introduced in House] ...
8 S. 968 (is) To authorize the Administrator of the Environmental Protection Agency [Introduced in Senate] ...
9 S. 2164 (is) To suspend temporarily the duty on certain compound optical microscopes. [Introduced in Senate] ...
10 H.R. 5215 (ih) To amend the Internal Revenue Code of 1986 to exclude national service educational awards from the recipient's gross income. [Introduced in House] ...
11 H.R. 2798 (rh) To authorize the Secretary of Commerce to provide financial assistance to the States of Alaska, Washington, Oregon, and California for salmon habitat restoration projects in coastal waters and upland drainages. [Reported in House] %%Filenam...
12 H.R. 5327 (ih) To amend the Public Health Service Act with respect to the Vaccine Injury Compensation Program. [Introduced in House] ...
13 H.R. 457 (rh) To amend title 5, United States Code, to increase the amount of leave time available to a Federal employee in any year in connection with serving as an organ donor, and for other purposes. [Reported in House] ...
14 H.R. 4924 (rfs) To establish a 3-year pilot project for the General Accounting Office to report to Congress on economically significant rules of Federal agencies, and for other purposes. [Referred in Senate] ...
15 S. 2002 (is) For the relief of Tony Lara. [Introduced in Senate] ...
16 H.R. 269 (ih) To amend the Public Health Service Act with respect to employment opportunities in the Department of Health and Human Services for women who are scientists, and for other purposes. [Introduced in House] ...
17 H.R. 1664 (rs) Making emergency supplemental appropriations for military operations, refugee relief, and humanitarian assistance relating to the conflict in Kosovo, and for military operations in Southwest Asia for the fiscal year ending September 30, 199...
18 H.R. 5200 (ih) To amend title XVIII of the Social Security Act to ensure that the [Introduced in House] ...
19 S. 174 (is) To provide funding for States to correct Y2K problems in computers that are used to administer State and local government programs. [Introduced in Senate] ...
20 H.R. 2685 (ih) To guarantee the right of all active duty military personnel, merchant mariners, and their dependents to vote in Federal, State, and local elections. [Introduced in House] ...
21 H.R. 1653 (rh) To approve a governing international fishery agreement between the United States and the Russian Federation. [Reported in House] ...
22 S. 246 (is) To protect private property rights guaranteed by the fifth amendment to the Constitution by requiring Federal agencies to prepare private property taking impact analyses and by allowing expanded access to Federal courts. [Introduced in Senate]...
23 S.Con.Res. 158 (ats) Expressing the sense of Congress regarding appropriate actions of the [Agreed to Senate] ...
24 H.Res. 651 (eh) [Engrossed in House] ...
25 S. 2873 (is) To provide for all right, title, and interest in and to certain property in Washington County, Utah, to be vested in the United States. [Introduced in Senate] ...
26 S.Con.Res. 102 (is) To commend the bravery and honor of the citizens of Remy, France, for their actions with respect to Lieutenant Houston Braly and to recognize the efforts of the 364th Fighter Group to raise funds to restore the stained glass windows of...
27 H.R. 5496 (ih) To amend the National Wildlife Refuge System Administration Act of 1966 [Introduced in House] ...
28 H.R. 3113 (ih) To protect individuals, families, and Internet service providers from unsolicited and unwanted electronic mail. [Introduced in House] ...
29 S.Con.Res. 127 (is) Expressing the sense of the Congress that the Parthenon Marbles should be returned to Greece. [Introduced in Senate] ...
30 H.R. 4733 (enr) Making appropriations for energy and water development for the fiscal year ending September 30, 2001, and for other purposes. [Enrolled bill] ...


Other Documents:

106th Congressional Bills Records and Documents

GovRecords.org presents information on various agencies of the United States Government. Even though all information is believed to be credible and accurate, no guarantees are made on the complete accuracy of our government records archive. Care should be taken to verify the information presented by responsible parties. Please see our reference page for congressional, presidential, and judicial branch contact information. GovRecords.org values visitor privacy. Please see the privacy page for more information.
House Rules:

104th House Rules
105th House Rules
106th House Rules

Congressional Bills:

104th Congressional Bills
105th Congressional Bills
106th Congressional Bills
107th Congressional Bills
108th Congressional Bills

Supreme Court Decisions

Supreme Court Decisions

Additional

1995 Privacy Act Documents
1997 Privacy Act Documents
1994 Unified Agenda
2004 Unified Agenda

Congressional Documents:

104th Congressional Documents
105th Congressional Documents
106th Congressional Documents
107th Congressional Documents
108th Congressional Documents

Congressional Directory:

105th Congressional Directory
106th Congressional Directory
107th Congressional Directory
108th Congressional Directory

Public Laws:

104th Congressional Public Laws
105th Congressional Public Laws
106th Congressional Public Laws
107th Congressional Public Laws
108th Congressional Public Laws

Presidential Records

1994 Presidential Documents
1995 Presidential Documents
1996 Presidential Documents
1997 Presidential Documents
1998 Presidential Documents
1999 Presidential Documents
2000 Presidential Documents
2001 Presidential Documents
2002 Presidential Documents
2003 Presidential Documents
2004 Presidential Documents

Home Executive Judicial Legislative Additional Reference About Privacy