Sec. 11. Federal penetration testing policy
396 words·~2 min read·
/bill/118/hr/4552/ih/section-11A research copy — for the controlling text, always check the official state or federal source. Not legal advice.
Subchapter II of chapter 35 of title 44, United States Code, is amended by adding at the end the following: The Director, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall issue guidance to agencies that— requires agencies to perform penetration testing on information systems, as appropriate, including on high value assets; provides policies governing the development of— rules of engagement for using penetration testing; and procedures to use the results of penetration testing to improve the cybersecurity and risk management of the agency; ensures that operational support or a shared service is available; and in no manner restricts the authority of the Secretary of Homeland Security or the Director of the Cybersecurity and Infrastructure Agency to conduct threat hunting pursuant to section 3553 of title 44, United States Code, or penetration testing under this chapter.
The guidance issued under subsection
(a)shall not apply to national security systems. The authorities of the Director described in subsection
(a)shall be delegated to— the Secretary of Defense in the case of a system described in section 3553(e)(2); and the Director of National Intelligence in the case of a system described in section 3553(e)(3). . Compliance with guidance issued by the Director relating to penetration testing before the date of enactment of this Act shall be deemed to be compliant with section 3559A of title 44, United States Code, as added by this Act. Nothing in section 3559A of title 44, United States Code, as added by this Act, shall be construed to require the Director to issue new guidance to agencies relating to penetration testing before the date described in paragraph (3). Notwithstanding paragraphs
(1)and (2), not later than 2 years after the date of enactment of this Act, the Director shall review and, as appropriate, update existing guidance requiring penetration testing by agencies. The table of sections for chapter 35 of title 44, United States Code, is amended by adding after the item relating to section 3559 the following: 3559A. Federal penetration testing. . Section 3553(b) of title 44, United States Code, as amended by this Act, is further amended by inserting after paragraph
(8)the following: performing penetration testing that may leverage manual expert analysis to identify threats and vulnerabilities within information systems— without consent or authorization from agencies; and with prior notification to the head of the agency; .