Sec. 5. Federal cybersecurity best practices
256 words·~1 min read·
/bill/114/s/1869/is/section-5·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary, in consultation with the Director, shall regularly assess and require implementation of best practices for securing agency information systems against intrusion and preventing data exfiltration in the event of an intrusion. Except as provided in paragraph (2), not later than 1 year after the date of enactment of this Act, the head of each agency shall— identify sensitive and mission critical data stored by the agency consistent with the inventory required under the first subsection
(c)(relating to the inventory of major information systems) and the second subsection
(c)(relating to the inventory of information systems) of section 3505 of title 44, United States Code; assess access controls to the data described in subparagraph (A), the need for readily accessible storage of the data, and individuals' need to access the data; encrypt the data described in subparagraph
(A)that is stored on or transiting agency information systems consistent with standards and guidelines promulgated under section 11331 of title 40, United States Code; implement a single sign-on trusted identity platform for individuals accessing each public website of the agency that requires user authentication, as developed by the Administrator of General Services in collaboration with the Secretary; and implement multi-factor authentication consistent with standards and guidelines promulgated under section 11331 of title 40, United States Code, for— remote access to an agency information system; and each user account with elevated privileges on an agency information system. The requirements under paragraph
(1)shall not apply to the Department of Defense or an element of the intelligence community.