Sec. 209. Implementing presumption of compromise and zero trust architectures
229 words·~1 min read·
/bill/117/s/2902/is/section-209·A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Not later than 60 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director of the National Institute of Standards and Technology, shall develop recommendations to increase the internal defenses of agency systems to— limit the ability of entities that cause incidents to move laterally through or between agency systems; identify incidents more quickly; isolate and remove unauthorized entities from agency systems more quickly; implement zero trust architecture; and otherwise increase the resource costs for entities that cause incidents; and Not later than 180 days after the date on which the recommendations under subsection
(a)are completed, the Director shall issue guidance to agencies that requires the implementation of the recommendations. Not later than 60 days after the date on which the Director issues guidance under subsection (b), the head of each agency shall submit to the Director a plan to implement zero trust architecture that includes— a description of any steps the agency has completed; an identification of activities that will have the most immediate security impact; and a schedule to implement the plan. Not later than 90 days after the date on which the Director issues guidance required under subsection (b), the Director shall provide a briefing to the appropriate congressional committees on the guidance and the agency implementation plans submitted under subsection (c).