Sec. 207. Ongoing threat hunting program
291 words·~1 min read·
/bill/117/s/2902/is/section-207·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 540 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall establish a program to provide ongoing, hypothesis-driven threat-hunting services on the network of each agency. Not later than 180 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish the program required under paragraph
(1)that describes how the Director of the Cybersecurity and Infrastructure Security Agency plans to— determine the method for collecting, storing, accessing, and analyzing appropriate agency data; provide on-premises support to agencies; staff threat hunting services; allocate available human and financial resources to implement the plan; and provide input to the heads of agencies on the use of— more stringent standards under section 11331(c)(1) of title 40, United States Code; and additional cybersecurity procedures under section 3554 of title 44, United States Code. The Director of the Cybersecurity and Infrastructure Security Agency shall submit to the appropriate congressional committees— not later than 30 days after the date on which the Director of the Cybersecurity and Infrastructure Security Agency completes the plan required under subsection (a)(2), a report on the plan to provide threat hunting services to agencies; not less than 30 days before the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services under the program, a report providing any updates to the plan developed under subsection (a)(2); and not later than 1 year after the date on which the Director of the Cybersecurity and Infrastructure Security Agency begins providing threat hunting services to agencies other than the Cybersecurity and Infrastructure Security Agency, a report describing lessons learned from providing those services.