Sec. 201. Evaluation of effectiveness of standards
287 words·~1 min read·
/bill/117/s/2902/is/section-201A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
As a component of the evaluation and report required under section 3555(h) of title 44, United States Code, and not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall perform a study that— assesses the standards promulgated under section 11331(b) of title 40, United States Code to determine the degree to which agencies use the authority under section 11331(c)(1) of title 40, United States Code to customize the standards relative to the risks facing each agency and agency system; assesses the effectiveness of the standards described in paragraph (1), including any standards customized by agencies under section 11331(c)(1) of title 40, United States Code, at improving agency cybersecurity; examines the quantification of cybersecurity risk in the private sector for any applicability for use by the Federal Government; examines cybersecurity metrics existing as of the date of enactment of this Act used by the Director, the Director of the Cybersecurity and Infrastructure Security Agency, and the heads of other agencies to evaluate the effectiveness of information security policies and practices; and with respect to the standards described in paragraph (1), provides recommendations for— the addition or removal of standards; or the customization of— the standards by agencies under section 11331(c)(1) of title 40, United States Code; or specific controls within the standards.
The Director shall incorporate the results of the study performed under subsection
(a)into the review of standards required under section 11331(e) of title 40, United States Code. Not later than 30 days after the date on which the study performed under subsection
(a)is completed, the Comptroller General of the United States shall provide to the appropriate congressional committees a briefing on the study.