Sec. 9. OPM data breach damage assessment
169 words·~1 min read·
/bill/114/s/1869/rs/section-9·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The Secretary and the Director of National Intelligence shall jointly, and in coordination with the head of each appropriate agency, conduct an ongoing damage and risk assessment relating to the data breaches at the Office of Personnel Management (referred to in this section as the OPM data breach ). Not later than 180 days after the date of enactment of this Act, and once not later than 180 days thereafter, the Director of National Intelligence shall submit to Congress a report on the assessment conducted under subsection (a).
Each report submitted under this subsection shall include— updates on the extent to which Federal data was compromised, exfiltrated, or manipulated by the same entity that caused the OPM data breach; analysis of the impact of the OPM data breach on national security; and analysis of whether any information accessed through the OPM data breach has been released or deployed, whether publicly or privately. Each report submitted under this subsection shall be in unclassified form, but may include a classified annex.