Sec. 121. Security operations center as a service pilot
357 words·~2 min read·
/bill/117/s/3600/es/section-121A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
The purpose of this section is for the Cybersecurity and Infrastructure Security Agency to run a security operation center on behalf of another agency, alleviating the need to duplicate this function at every agency, and empowering a greater centralized cybersecurity capability. Not later than 1 year after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall develop a plan to establish a centralized Federal security operations center shared service offering within the Cybersecurity and Infrastructure Security Agency. The plan required under subsection
(b)shall include considerations for— collecting, organizing, and analyzing agency information system data in real time; staffing and resources; and appropriate interagency agreements, concepts of operations, and governance plans. Not later than 180 days after the date on which the plan required under subsection
(b)is developed, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, shall enter into a 1-year agreement with not less than 2 agencies to offer a security operations center as a shared service. After the date on which the briefing required under subsection (e)(1) is provided, the Director of the Cybersecurity and Infrastructure Security Agency, in consultation with the Director, may enter into additional 1-year agreements described in paragraph
(1)with agencies. Not later than 270 days after the date of enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Oversight and Reform of the House of Representatives a briefing on the parameters of any 1-year agreements entered into under subsection (d)(1). Not later than 90 days after the date on which the first 1-year agreement entered into under subsection
(d)expires, the Director of the Cybersecurity and Infrastructure Security Agency shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security and the Committee on Oversight and Reform of the House of Representatives a report on— the agreement; and any additional agreements entered into with agencies under subsection (d).