Skip to main content

S. 3600

Introduced

Strengthening American Cybersecurity Act of 2022

Introduced 2/8/2022•117th Congress•Senate

Latest Action

Held at the desk.

3/2/2022 • House

Summary

Strengthening American Cybersecurity Act of 2022

This bill addresses cybersecurity threats against critical infrastructure and the federal government.

The Cybersecurity and Infrastructure Security Agency (CISA) must perform ongoing and continuous assessments of federal risk posture.

An agency, within a specified time frame, must (1) determine whether notice to any individual potentially affected by a breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected.

Each agency must (1) provide information relating to a major incident to specified parties, and (2) develop specified training for individuals with access to federal information or information systems.

The bill requires reporting and other actions to address cybersecurity incidents.

Entities that own or operate critical infrastructure must report cyber incidents and ransom payments within specified time frames.

The bill limits the use and disclosure of reported information.

The bill establishes (1) an interagency council to standardize federal reporting of cybersecurity threats, (2) a task force on ransomware attacks, and (3) a pilot program to identify information systems vulnerable to such attacks.

The bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA).

FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing products and services.

The bill establishes a FedRAMP Board to examine the operations of FedRAMP and the Federal Secure Cloud Advisory Committee.

Passed Senate • 3/1/2022

Enter your district to see how this bill affects your community
-

Topics & Subjects

Administrative law and regulatory proceduresAdvisory bodiesCivil actions and liabilityComputer security and identity theftComputers and information technologyCongressional oversightCriminal investigation, prosecution, interrogationDepartment of Homeland SecurityEmployment and training programsExecutive agency funding and structureFederal officialsGovernment employee pay, benefits, personnel managementGovernment information and archivesGovernment studies and investigationsInfrastructure developmentPerformance measurementPublic contracts and procurementRight of privacyTechnology assessment

Amendments (2)

This bill has 2 amendments proposed or adopted.

View all amendments on Congress.gov

Congressional Votes (0)

No recorded votes yet

Roll call votes will appear here as the bill moves through Congress

Related Federal Spending

Sponsor & Cosponsors (16)

Party Breakdown

8
Democrats
7
Republicans
1
Independents

Sponsor

S[
Sen. Peters, Gary C. [D-MI]

Democrat • MI

Sponsored 2/8/2022

Cosponsors (15)

S[
Sen. Portman, Rob [R-OH]

R-OH

Joined 2/8/2022

S[
Sen. Warner, Mark R. [D-VA]

D-VA

Joined 2/10/2022

S[
Sen. Collins, Susan M. [R-ME]

R-ME

Joined 2/10/2022

S[
S[
Sen. Burr, Richard [R-NC]

R-NC

Joined 2/10/2022

S[

Bill Journey

Originated in the Senate

Introduced

February 8, 2022

Introduced in the Senate. Read the first time. Placed on Senate Legislative Calendar under Read the First Time.

Committee Review

Floor Debate

March 1, 2022

Passed Chamber

Other Chamber

March 2, 2022

President

Enacted into Law

Text Versions (2)

Engrossed in Senate3/1/2022
Placed on Calendar Senate2/9/2022

Details

Bill TypeS
Current StatusIntroduced
Cosponsors15