Nonpartisan civic infrastructure
AllCiv·Legis1
·

H.R. 4552

BillFederalHouseFloor Consideration
Federal Information Security Modernization Act of 2024
About This Bill
Introduced
Latest Action · December 19, 2024
Placed on the Union Calendar, Calendar No. 790.
Congress
118th (2023–2025)
Introduced
July 11, 2023
Cosponsors (4)
3D 1R
View PDF ↗

Summary

Highlight any text to annotate
This bill updates and strengthens federal cybersecurity law by modernizing the Federal Information Security Modernization Act, primarily affecting federal agencies, their contractors, and grant recipients. It requires agencies to conduct ongoing risk assessments, adopt zero trust architecture, use automation and artificial intelligence to improve security, and establish penetration testing and vulnerability disclosure programs to identify weaknesses in government systems. The legislation sets clearer rules for reporting cybersecurity incidents and data breaches, including tighter timelines for notifying Congress, affected individuals, and the Cybersecurity and Infrastructure Security Agency, while extending some notification duties to contractors and grant recipients. It also creates a new Federal Chief Information Security Officer position, renames the Office of the Federal Chief Information Officer, and updates privacy and identity-management requirements, including single sign-on and multi-factor authentication standards. Most provisions take effect over the next one to four years, with agencies required to submit various reports, briefings, and biennial risk assessments to oversight committees during that period, and national security systems are largely exempted or subject to separate reporting channels.

Take Action

Your position
Add a comment
to comment on this bill.
Annotate the text
Highlight any passage on the Summary or Full Text tab to attach a note. Annotations appear on the Annotations tab.