To encourage and improve Federal proactive cybersecurity initiatives, and for other purposes.
About This Bill
Committee
Latest Action · July 15, 2022
Referred to the Committee on Oversight and Reform, and in addition to the Committee on Armed Services, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.
Proactive Cyber Initiatives Act of 2022
This bill addresses proactive cybersecurity initiatives.
Specifically, each department or agency must (1) conduct regular penetration testing on the information systems of such department or agency; and (2) provide to the Cybersecurity and Infrastructure Security Agency (CISA) and the Office of Management and Budget a report on the results of such testing, including identifying any risks discovered and describing how cybersecurity may be improved.
CISA must issue guidance to facilitate the implementation of such requirements.
Further, CISA must report to Congress, including an analysis of
whether increased engagement is needed from national laboratories and the private sector to assist with the protection of the information systems of agencies through the use of active defense techniques, deception technologies, and penetration testing; the feasibility and benefits of consolidating within CISA proactive cybersecurity initiatives; and whether CISA requires additional authorities or resources to carry out proactive cybersecurity initiatives for agencies. The bill directs the Office of the National Cyber Director to deconflict overlapping cybersecurity jurisdiction between agencies.
The Government Accountability Office must report to Congress on penetration testing and active defense techniques, and study innovative uses of proactive cybersecurity initiatives.
Take Action
Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.