Sec. 25022. GAO cybersecurity recommendations
330 words·~2 min read·
/bill/117/hr/3684/eas/section-25022·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 3 years after the date of enactment of this Act, the Secretary shall implement the recommendation for the Department made by the Comptroller General of the United States in the report entitled Cybersecurity: Agencies Need to Fully Establish Risk Management Programs and Address Challenges , numbered GAO–19–384, and dated July 2019— by developing a cybersecurity risk management strategy for the systems and information of the Department; by updating policies to address an organization-wide risk assessment; and by updating the processes for coordination between cybersecurity risk management functions and enterprise risk management functions.
Not later than 3 years after the date of enactment of this Act, the Secretary shall implement the recommendation of the Comptroller General of the United States in the report entitled Cybersecurity Workforce: Agencies Need to Accurately Categorize Positions to Effectively Identify Critical Staffing Needs , numbered GAO–19–144, and dated March 2019, by— reviewing positions in the Department; and assigning appropriate work roles in accordance with the National Initiative for Cybersecurity Education Cybersecurity Workforce Framework.
Not later than 18 months after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Commerce, Science, and Transportation of the Senate and the Committee on Transportation and Infrastructure of the House of Representatives a report that examines the approach of the Department to managing cybersecurity for the systems and information of the Department. The report under paragraph
(1)shall include an evaluation of— the roles, responsibilities, and reporting relationships of the senior officials of the Department with respect to cybersecurity at the components of the Department; the extent to which officials of the Department— establish requirements for, share information with, provide resources to, and monitor the performance of managers with respect to cybersecurity within the components of the Department; and hold managers accountable for cybersecurity within the components of the Department; and other aspects of cybersecurity, as the Comptroller General of the United States determines to be appropriate.