Sec. 114. GAO review of Department-wide efforts to manage cybersecurity
352 words·~2 min read·
/bill/116/s/3930/is/section-114A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 3 years after the date of enactment of this title, the Secretary of Transportation shall implement the recommendation for the Department of Transportation made by the Comptroller General of the United States in the report entitled Cybersecurity: Agencies Need to Fully Establish Risk Management Programs and Address Challenges , numbered GAO–19–384, and dated July 2019, by— developing a cybersecurity risk management strategy for the systems and information of the Department of Transportation; updating policies to address an organization-wide risk assessment; and updating the processes for coordination between cybersecurity risk management functions and enterprise risk management functions.
Not later than 3 years after the date of enactment of this title, the Secretary of Transportation shall implement the recommendation of the Comptroller General of the United States in the report entitled Cybersecurity Workforce: Agencies Need to Accurately Categorize Positions to Effectively Identify Critical Staffing Needs , numbered GAO–19–144, and dated March 2019, by reviewing positions in the Department of Transportation and assigning appropriate work roles in accordance with the National Initiative for Cybersecurity Education Cybersecurity Workforce Framework.
Not later than 18 months after the date of enactment of this title, the Comptroller General of the United States shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Transportation and Infrastructure of the House of Representatives a report that examines the approach of the Department of Transportation to managing cybersecurity for the systems and information of the Department of Transportation. The report under paragraph
(1)shall include an evaluation of— the roles, responsibilities, and reporting relationships of the senior officials of the Department of Transportation with respect to cybersecurity at the components of the Department of Transportation; the extent to which officials of the Department of Transportation— establish requirements for, share information with, provide resources to, and monitor the performance of managers with respect to cybersecurity within the components of the Department of Transportation; and hold managers accountable for cybersecurity within the components of the Department of Transportation; and other aspects of cybersecurity, as the Comptroller General of the United States determines to be appropriate.