<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!--<?xml version="1.0"?>-->
<!--<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "C:\Program Files\Blast Radius\rules\bill.dtd" []>-->
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill v2.8 20020720//EN" "http://thomas.loc.gov/dtd/bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H6E78028986D446728BEFCCFFC9D553E" public-private="public">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>110 HR 5983 IH: Homeland
</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2008-05-07</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>110th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 5983</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20080507">May 7, 2008</action-date>
			<action-desc><sponsor name-id="L000559">Mr. Langevin</sponsor> (for
			 himself and <cosponsor name-id="T000193">Mr. Thompson of
			 Mississippi</cosponsor>) introduced the following bill; which was referred to
			 the <committee-name committee-id="HHM00">Committee on Homeland
			 Security</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend the Homeland Security Act of 2002 to enhance the
		  information security of the Department of Homeland Security, and for other
		  purposes.</official-title>
	</form>
	<legis-body id="H6D132F57A23E46C99876BAC8AAB2E600" style="OLC">
		<section id="H19E9B7BE4B3B49DFA857E2878323AE2F" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Homeland Security Network Defense and
			 Accountability Act of 2008</short-title></quote>.</text>
		</section><section id="H164CCA74590243EE97AF66EFD5949697"><enum>2.</enum><header>Authority of
			 Chief Information Officer; qualifications for appointment</header><text display-inline="no-display-inline">Section 703(a) of the Homeland Security Act
			 of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343(a)</external-xref>) is amended—</text>
			<paragraph id="H75364D1607E24EE586C109256FCB363C"><enum>(1)</enum><text>by inserting
			 before the first sentence the following:</text>
				<quoted-block display-inline="no-display-inline" id="H46B5AC4360A04E7FB1A68935C4B7604" style="OLC">
					<paragraph id="H3BFB15E4E524483982F47D58347690CF"><enum>(1)</enum><header>Authorities and
				duties</header><text display-inline="yes-display-inline">The Secretary shall
				delegate to the Chief Information Officer such authority necessary for the
				development, approval, implementation, integration, and oversight of policies,
				procedures, processes, activities, funding, and systems of the Department
				relating to the management of information and information infrastructure for
				the Department, including the management of all related mission applications,
				information resources, and personnel.</text>
					</paragraph><paragraph id="HF12DCF9BAC8C4DD48351902345ECD08F"><enum>(2)</enum><header>Line
				authority</header>
					</paragraph><after-quoted-block>;
				and</after-quoted-block></quoted-block>
			</paragraph><paragraph id="H81ED462C3F3F49E6B03F78B3819D681D"><enum>(2)</enum><text>by adding at the
			 end the following new paragraphs:</text>
				<quoted-block id="H42AEFC174F3341C086DA762C9F3E52EC" style="OLC">
					<paragraph id="H7EE84E14FE8747B2BB8DC735BE14A484"><enum>(3)</enum><header>Qualifications
				for appointment</header><text>An individual may not be appointed as Chief
				Information Officer unless the individual has—</text>
						<subparagraph id="HE156E0A72CA8468CA1E7F50039E85349"><enum>(A)</enum><text>demonstrated
				ability in and knowledge of information technology and information security;
				and</text>
						</subparagraph><subparagraph id="H374790907B464256A8744D1D01BFD830"><enum>(B)</enum><text>not less than 5
				years of executive leadership and management experience in information
				technology and information security in the public or private sector.</text>
						</subparagraph></paragraph><paragraph id="HC26912A42F4B475096344721757C4E58"><enum>(4)</enum><header>Functions</header><text>The
				Chief Information Officer shall—</text>
						<subparagraph id="H2FF33EADE68C4A1EACBEB500D3B3BB4C"><enum>(A)</enum><text>establish and
				maintain an incident response team that provides a continuous, real-time
				capability within the Department of Homeland Security to—</text>
							<clause id="HB94512D815AF4A6EBFEFF829B8009DBB"><enum>(i)</enum><text>detect, respond
				to, contain, investigate, attribute, and mitigate any computer incident, as
				defined by the National Institute of Standards and Technology, that could
				violate or pose an imminent threat of violation of computer security policies,
				acceptable use policies, or standard security practices of the Department;
				and</text>
							</clause><clause id="H9DA7766559D84D04A185ADA3CC9B6105"><enum>(ii)</enum><text>deliver timely
				notice of any incident to individuals responsible for information
				infrastructure of the Department, and to the United States Computer Emergency
				Readiness Team;</text>
							</clause></subparagraph><subparagraph id="HD4320DFD12D9477EA8AAE317A91E9859"><enum>(B)</enum><text>establish,
				maintain, and update a network architecture, including a diagram detailing how
				security controls are positioned throughout the information infrastructure of
				the Department to maintain the confidentiality, integrity, availability,
				accountability, and assurance of electronic information; and</text>
						</subparagraph><subparagraph id="H1127DC050729477C9DB9F489D535EA6"><enum>(C)</enum><text>ensure that
				vulnerability assessments are conducted on a regular basis for any Department
				information infrastructure connected to the Internet or another external
				network, and that vulnerabilities are mitigated in a timely
				fashion.</text>
						</subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
			</paragraph></section><section id="HE2D570D5E4C0447C9E4DFAA73F3D62C8"><enum>3.</enum><header>Attack-based
			 testing protocols</header><text display-inline="no-display-inline">Section 703
			 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343</external-xref>) is amended by adding at the
			 end the following new subsection:</text>
			<quoted-block id="H782B1F512B3F40D88447B8787C08527F" style="OLC">
				<subsection id="HC574471031E94AC5A6B598B3FA6C7F61"><enum>(c)</enum><header>Attack-based
				testing protocols</header><text>The Chief Information Officer, in consultation
				with the Inspector General, the Assistant Secretary for Cybersecurity, and the
				heads of other appropriate Federal agencies, shall—</text>
					<paragraph id="H86F532C7275A475FBB40EBAB72D9453"><enum>(1)</enum><text>establish security
				control testing protocols that ensure that the Department’s information
				infrastructure is effectively protected against known attacks against and
				exploitations of Federal and contractor information infrastructure;</text>
					</paragraph><paragraph id="HEE962589CF15457BB6A3BBF199F2C7E8"><enum>(2)</enum><text>oversee the
				deployment of such protocols throughout the information infrastructure of the
				Department; and</text>
					</paragraph><paragraph id="H04B3C8FD597D4FBAABEC318287E28BED"><enum>(3)</enum><text>update such
				protocols on a regular
				basis.</text>
					</paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="H1E49F181BC7F40909413CC4BC20273D0"><enum>4.</enum><header>Inspector General
			 reviews of information infrastructure</header><text display-inline="no-display-inline">Section 703 of the Homeland Security Act of
			 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343</external-xref>) is further amended by adding at the end the following new
			 subsection:</text>
			<quoted-block display-inline="no-display-inline" id="HCC98FD5BF7394F4CBEB43D905200B646" style="OLC">
				<subsection id="H4DAC894E59ED454700300027944DB442"><enum>(d)</enum><header>Inspector
				General reviews</header>
					<paragraph id="HB510B0A88FD3451F8EBA5CCEFB3982A5"><enum>(1)</enum><header>In
				general</header><text>The Inspector General of the Department shall use
				authority under the Inspector General Act of 1978 (5 App. U.S.C.) to conduct
				announced and unannounced performance reviews and programmatic reviews of the
				information infrastructure of the Department to determine the effectiveness of
				security policies and controls of the Department.</text>
					</paragraph><paragraph id="HD453C05AEC1445A0B915C7BF7499AA92"><enum>(2)</enum><header>Performance
				reviews</header><text>Performance reviews under this subsection shall test and
				validate a system’s security controls using the protocols created under
				subsection (c), beginning not later than 270 days after the date of enactment
				of the <short-title>Homeland Security Network Defense and
				Accountability Act of 2008</short-title>.</text>
					</paragraph><paragraph id="HA9C9B87B403C41AF9C3300ED9B1F8935"><enum>(3)</enum><header>Programmatic
				reviews</header><text>Programmatic reviews under this subsection shall—</text>
						<subparagraph id="H5B905F855F4045738636D74BA4A783DB"><enum>(A)</enum><text>determine whether
				an agency of the Department is complying with policies, processes, and
				procedures established by the Chief Information Officer; and</text>
						</subparagraph><subparagraph id="H0437A7BDF0654B47A8A13FAFE8CD426"><enum>(B)</enum><text display-inline="yes-display-inline">focus primarily on authentication, access
				control, risk management, intrusion detection and prevention, incident
				response, risk assessment, remote access, and any other controls the Inspector
				General considers necessary.</text>
						</subparagraph></paragraph><paragraph id="H5B17A31E2DE6488BB32D4BE258BCB640"><enum>(4)</enum><header>Information
				security report</header><text>The Inspector General shall submit a security
				report containing the results of each review under this subsection and
				prioritized recommendations for improving security controls based on that
				review, including recommendations regarding funding changes and personnel
				management, to—</text>
						<subparagraph id="H2457A7D401B1419C998F68004B87CF"><enum>(A)</enum><text>the
				Secretary;</text>
						</subparagraph><subparagraph id="H353360F2355E45ABA49BD005ACA73085"><enum>(B)</enum><text>the Chief
				Information Officer; and</text>
						</subparagraph><subparagraph id="H1E91D77EDCE84FFB83B4F00D6356052"><enum>(C)</enum><text>the head of the
				Department component that was the subject of the review, and other appropriate
				individuals responsible for the information infrastructure of such
				agency.</text>
						</subparagraph></paragraph><paragraph id="H00BA02672AE6454DBE2F5C21C6001568"><enum>(5)</enum><header>Corrective
				action report</header>
						<subparagraph id="HCDD8F0999D50499C8B0488E62E5E43AC"><enum>(A)</enum><header>In
				general</header><text display-inline="yes-display-inline">Within 60 days after
				receiving a security report under paragraph (4), the head of the Department
				component that was the subject of the review and the Chief Information Officer
				shall jointly submit a corrective action report to the Secretary and the
				Inspector General.</text>
						</subparagraph><subparagraph id="H15F8FD87DF9D42649E177577425B85FC"><enum>(B)</enum><header>Contents</header><text>The
				corrective action report—</text>
							<clause id="H9E83297F4583478D9EDEBD709DBC69E0"><enum>(i)</enum><text>shall contain a
				plan for addressing recommendations and mitigating vulnerabilities contained in
				the security report, including a timeline and budget for implementing such
				plan; and</text>
							</clause><clause id="H2DC321B0246D4994A317963227A559CF"><enum>(ii)</enum><text display-inline="yes-display-inline">shall note any matters in disagreement
				between the head of the Department component and the Chief Information
				Officer.</text>
							</clause></subparagraph></paragraph><paragraph id="H2C9902140BFD4DB7BD3BCAE393F705F9"><enum>(6)</enum><header>Reports to
				Congress</header>
						<subparagraph id="HA84C6F4529544C0496A0D5F28E56F5BC"><enum>(A)</enum><header>Annual
				reports</header><text display-inline="yes-display-inline">In conjunction with
				the reporting requirements of <external-xref legal-doc="usc" parsable-cite="usc/44/3545">section 3545</external-xref> of title 44, United States Code, the
				Inspector General shall submit an annual report to the Committee on Homeland
				Security of the House of Representatives and the Committee on Homeland Security
				and Governmental Affairs of the Senate—</text>
							<clause id="HD5146BFAC56B45C2B2BFEFAC1E1298E4"><enum>(i)</enum><text>summarizing the
				performance and programmatic reviews performed during the preceding fiscal
				year, the results of those reviews, and any actions that remain to be taken
				under plans included in corrective action reports under paragraph (5);
				and</text>
							</clause><clause id="HF9638FD2BA384FA39B2BF46BAEBFB2F1"><enum>(ii)</enum><text>describing the
				effectiveness of the testing protocols developed under subsection (c) in
				reducing successful exploitations of the Department’s information
				infrastructure.</text>
							</clause></subparagraph><subparagraph id="H74BEFA9705FC42129878EFAB8280FCA"><enum>(B)</enum><header>Security reports
				and corrective action reports</header><text>The Inspector General shall make
				all security reports and corrective action reports available to any member of
				the Committee on Homeland Security of the House of Representatives, any member
				of the Committee on Homeland Security and Governmental Affairs of the Senate,
				and the Comptroller General of the United States, upon
				request.</text>
						</subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="H71F8E1AC4615485E82B580DD3805BABB"><enum>5.</enum><header>Information
			 infrastructure defined</header><text display-inline="no-display-inline">Section
			 703 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/343">6 U.S.C. 343</external-xref>) is further amended by
			 adding at the end the following:</text>
			<quoted-block display-inline="no-display-inline" id="H4EA59D7E1A4E43D7B3EB54BCB1A3C209" style="OLC">
				<subsection id="HAF35B7A349B849829D799E26A4935E73"><enum>(e)</enum><header>Information
				infrastructure defined</header><text display-inline="yes-display-inline">In
				this section, the term <term>information infrastructure</term> means systems
				and assets used in processing, transmitting, receiving, or storing information
				electronically.</text>
				</subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="HBC2FDA0808254036AB9529ABE4B29293"><enum>6.</enum><header>Network service
			 providers</header>
			<subsection id="HA0019C7F85144FE9A8BA4F6410A207E"><enum>(a)</enum><header>In
			 general</header><text>Subtitle D of title VIII of the Homeland Security Act of
			 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/391">6 U.S.C. 391 et seq.</external-xref>) is amended by adding at the end the following new
			 section:</text>
				<quoted-block display-inline="no-display-inline" id="H1E62A68A116C4AF987EAFC7ED9ECF8FE" style="OLC">
					<section id="H9C093A818722455698E3B0365D19A8C5"><enum>836.</enum><header>Requirements
				for network service providers</header>
						<subsection id="HFBE7A0D2319247CE9884ABB87D80DA62"><enum>(a)</enum><header>Compatibility
				determination</header>
							<paragraph id="HC29D232F6A6648E892F4348B1A4AD00"><enum>(1)</enum><header>In
				general</header><text display-inline="yes-display-inline">Before entering into
				or renewing a covered contract, the Secretary, acting through the Chief
				Information Officer, must determine that the contractor has an internal
				information systems security policy that complies with the Department’s
				information security requirements, including with regard to authentication,
				access control, risk management, intrusion detection and prevention, incident
				response, risk assessment, and remote access, and any other policies that the
				Secretary considers necessary to ensure the security of the Department’s
				information infrastructure.</text>
							</paragraph><paragraph id="HB3B65389404F419C9263C0BCA5412130"><enum>(2)</enum><header>Limitation on
				public disclosures</header><text display-inline="yes-display-inline">The Chief
				Information Officer shall not disclose to the public any information provided
				for purposes of such determination, notwithstanding any other provision of
				Federal, State, or local law, including <external-xref legal-doc="usc" parsable-cite="usc/5/552">section 552</external-xref> of title 5, United States
				Code.</text>
							</paragraph></subsection><subsection id="H2E7CF25B010A469EA5375F4D67CD8492"><enum>(b)</enum><header>Contract
				requirements regarding security</header><text>The Secretary shall include in
				each covered contract provisions requiring the contractor to—</text>
							<paragraph id="HA8FC8FB7C8C14FE7A2AB44D8CCD396D"><enum>(1)</enum><text>implement and
				regularly update the internal information systems security policy required
				under subsection (a);</text>
							</paragraph><paragraph id="H0ABD350B547F42FDB8D4F08F45769095"><enum>(2)</enum><text display-inline="yes-display-inline">maintain the capability to provide
				contracted services on a continuing and ongoing basis to the Department in the
				event of unplanned or disruptive event; and</text>
							</paragraph><paragraph id="H8CE2C46EBA604EB1B4F7BEF3A11EF2A7"><enum>(3)</enum><text>deliver timely
				notice of any internal computer incident, as defined by the National Institute
				of Standards and Technology, that could violate or pose an imminent threat of
				violation of computer security policies, acceptable use policies, or standard
				security practices at the Department, to the United States Computer Emergency
				Readiness Team and the incident response team established under section
				703(a)(4).</text>
							</paragraph></subsection><subsection id="H5154A157C53A4DD981D93013898D66D4"><enum>(c)</enum><header>Contract
				requirements regarding subcontracting</header><text>The Secretary shall include
				in each covered contract—</text>
							<paragraph id="HCA620F1AC5DE4CC39B4CCC4E308B3CFF"><enum>(1)</enum><text>a requirement that
				the contractor develop and implement a plan for the award of subcontracts, as
				appropriate, to small business concerns and disadvantaged business concerns in
				accordance with other applicable requirements, including the terms of such
				plan, as appropriate; and</text>
							</paragraph><paragraph id="HDD1C01FFCF4642C690EC8321031FDB9F"><enum>(2)</enum><text>a requirement that
				the contractor submit to the Secretary, during performance of the contract,
				periodic reports describing the extent to which the contractor has complied
				with such plan, including specification (by total dollar amount and by
				percentage of the total dollar value of the contract) of the value of
				subcontracts awarded at all tiers of subcontracting to small business concerns,
				including socially and economically disadvantaged small businesses concerns,
				small business concerns owned and controlled by service-disabled veterans,
				HUBZone small business concerns, small business concerns eligible to be awarded
				contracts pursuant to section 8(a) of the Small Business Act (15 U.S.C.
				637(a)), and historically Black colleges and universities and Hispanic-serving
				institutions, tribal colleges and universities, and other minority
				institutions.</text>
							</paragraph></subsection><subsection id="H72D0F364920A406F8000D73EEA43E5C7"><enum>(d)</enum><header>Existing
				contracts</header><text display-inline="yes-display-inline">The Secretary
				shall, to the extent practicable under the terms of existing contracts, require
				each contractor who provides covered information services under a contract in
				effect on the date of the enactment of the <short-title>Homeland Security Network Defense and Accountability Act
				of 2008</short-title> to comply with the requirements described in subsection
				(b).</text>
						</subsection><subsection id="HC78C5CFF68924752A5EF31A2C444F62"><enum>(e)</enum><header>Definitions</header><text>For
				purposes of this section:</text>
							<paragraph id="H43BB88DB5CA047B6BBF9F97F42D9B89"><enum>(1)</enum><header>Socially and
				economically disadvantaged small businesses concern, small business concern
				owned and controlled by service-disabled veterans, and HUBZone small business
				concern</header><text>The terms <term>socially and economically disadvantaged
				small businesses concern</term>, <term>small business concern owned and
				controlled by service-disabled veterans</term>, and <term>HUBZone small
				business concern</term> have the meanings given such terms under the Small
				Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/631">15 U.S.C. 631 et seq.</external-xref>).</text>
							</paragraph><paragraph id="HE6FBA6C6E6EC4091B43FE58EDD2E6E6F"><enum>(2)</enum><header>Contractor</header><text>The
				term <term>contractor</term> includes each subcontractor of a
				contractor.</text>
							</paragraph><paragraph id="H16F3C994351A4582B2A42C2CF9EFB9A7"><enum>(3)</enum><header>Covered
				contract</header><text display-inline="yes-display-inline">The term
				<term>covered contract</term> means a contract entered into or renewed after
				the date of the enactment of the <short-title>Homeland
				Security Network Defense and Accountability Act of 2008</short-title> for the
				provision of covered information services.</text>
							</paragraph><paragraph id="H77818FE6851345C99F00CD902C47D2B1"><enum>(4)</enum><header>Covered
				information services</header><text display-inline="yes-display-inline">The term
				<term>covered information services</term> means creation, management,
				maintenance, control, or operation of information networks or Internet Web
				sites for the Department.</text>
							</paragraph><paragraph id="HA5E1DF3705D9495682737839B346005F"><enum>(5)</enum><header>Historically
				Black colleges and universities</header><text>The term <term>historically Black
				colleges and universities</term> means part B institutions under title III of
				the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1061">20 U.S.C. 1061</external-xref>).</text>
							</paragraph><paragraph id="H44635F8E274A4398B2A26DA337055FF0"><enum>(6)</enum><header>Hispanic-serving
				institution</header><text>The term <term>Hispanic-serving institution</term>
				has the meaning given such term under title V of the Higher Education Act of
				1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1101a">20 U.S.C. 1101a(a)(5)</external-xref>).</text>
							</paragraph><paragraph id="H673F0839995048EBB5D4FF1227E71D84"><enum>(7)</enum><header>Information
				infrastructure</header><text>The term <term>information infrastructure</term>
				has the meaning that term has under section 703.</text>
							</paragraph><paragraph id="H07751C590E554D8590B7CE564737EF31"><enum>(8)</enum><header>Tribal colleges
				and universities</header><text>The term <term>tribal colleges and
				universities</term> has the meaning given such term under the Tribally
				Controlled College or University Assistance Act of 1978 (25 U.S.C. 1801 et
				seq.).</text>
							</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H457A44787DD44338BE3059C23CB6D9D9"><enum>(b)</enum><header>Clerical
			 amendment</header><text display-inline="yes-display-inline">The table of
			 contents in section 1(b) of such Act is amended by inserting after the item
			 relating to section 835 the following new item:</text>
				<quoted-block display-inline="no-display-inline" id="HDA43ECE4ECC84557B4F61EBDA3FE90AF" style="OLC">
					<toc container-level="quoted-block-container" idref="H1E62A68A116C4AF987EAFC7ED9ECF8FE" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration">
						<toc-entry idref="H9C093A818722455698E3B0365D19A8C5" level="section">Sec. 836. Requirements for network service
				providers.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="H1E5049B9412443EFA32D9CE262758C75"><enum>(c)</enum><header>Report</header><text display-inline="yes-display-inline">Within 90 days after the date of enactment
			 of this Act, the Secretary of Homeland Security shall transmit to the Committee
			 on Homeland Security of the House of Representatives and the Homeland Security
			 and Governmental Affairs Committee of the Senate a report describing—</text>
				<paragraph id="H293D9DED1BE84DCFA8DEAB06BF839FD0"><enum>(1)</enum><text>the progress in
			 implementing requirements issued by the Office of Management and Budget for
			 encryption, authentication, Internet Protocol version 6, and Trusted Internet
			 Connections, including a timeline for completion;</text>
				</paragraph><paragraph id="H36FE56E5A1484225861BE1000069FFF2"><enum>(2)</enum><text>a
			 plan, including an estimated budget and a timeline, to investigate breaches
			 against the Department of Homeland Security’s information infrastructure for
			 purposes of counterintelligence assessment, attribution, and response;</text>
				</paragraph><paragraph id="HD7AC10A6A6D4487CA6E7006521497E03"><enum>(3)</enum><text>a
			 proposal to increase threat information sharing with cleared and uncleared
			 contractors and provide specialized damage assessment training to private
			 sector information security professionals; and</text>
				</paragraph><paragraph id="HEA72C59B2A0B42B29FE165871BB4E600"><enum>(4)</enum><text>a
			 process to coordinate the Department of Homeland Security’s information
			 infrastructure protection activities.</text>
				</paragraph></subsection></section></legis-body>
</bill>


