PoliticalRepoPoliticalRepo

United States · Bill · HR

H.R. 2413 (106th)

Computer Security Enhancement Act of 2000

openUnited States· United States Congress· EN

Introduced

1 July 1999

Last action

Status

Received in the Senate.

Sponsors

Subjects

Discovery layer

Source updated

7 April 2025

Summary

Computer Security Enhancement Act of 1999 - Amends the National Institute of Standards and Technology Act to require the National Institute of Standards and Technology (NIST), in fulfilling its responsibilities under the computer standards program, to: (1) upon request from the private sector, assist in establishing voluntary interoperable standards, guidelines, and associated methods and techniques to facilitate and expedite the establishment of non-Federal public key management infrastructures that can be used to communicate with and conduct transactions with the Federal Government; and (2) provide assistance to Federal agencies in the protection of computer networks, and coordinate Federal response efforts related to unauthorized access to Federal computer systems. Requires the Institute to perform evaluation and tests of: (1) information technologies to assess security vulnerabilities; and (2) commercially available security products for their suitability for use by Federal agencies for protecting sensitive information in computer systems. (Sec. 5) Requires the Institute to carry out specified activities in the development of uniform standards and guidelines for the cost-effective security and privacy of sensitive information in certain Federal computer systems. (Sec. 6) Directs the Institute to solicit the recommendations of the Computer System Security and Privacy Advisory Board regarding standards and guidelines that are being considered for submittal to the Secretary of Commerce. Authorizes separate appropriations for FY 2000 and FY 2001 to enable the Board to identify emerging issues related to computer security, privacy, and cryptography and to convene public meetings on those subjects, receive presentations, and publish reports, digests, and summaries for public distribution on those subjects. (Sec. 7) Prohibits the Institute from promulgating, enforcing, or otherwise adopting standards, or carrying out activities or policies, for the Federal establishment of encryption standards required for use in computer systems other than Federal Government computer systems. (Sec. 8) Revises specified requirements, including authorizing (currently, requiring) the Institute, for the purposes of performing research and conducting studies, to draw upon computer system security guidelines developed by the National Security Agency. (Sec. 9) Amends the Computer Security Act of 1987 to revise requirements regarding Federal computer system security training to require such training to include emphasis on protecting sensitive information in Federal databases and Federal computer sites that are accessible through public networks. (Sec. 10) Authorizes appropriations for FY 2000 and 2001 for fellowships to support students at institutions of higher learning in computer security. (Sec. 11) Requires a study by the National Research Council of the National Academy of Sciences of public key infrastructures. Authorizes appropriations for carrying out the study. (Sec. 12) Directs the Under Secretary of Commerce for Technology (Under Secretary) to: (1) promote the more widespread use of cryptography applications and associated technologies to enhance the security of the Nation's information infrastructure; (2) establish a central clearinghouse for the collection by the Federal Government and dissemination to the public of information to promote awareness of information security threats; (3) promote the development of the national, standards-based infrastructure needed to support commercial and private uses of encryption technologies for confidentiality and authentication. (Sec. 13) Directs the NIST Director to: (1) develop electronic authentication infrastructure guidelines and standards to enable Federal agencies to utilize electronic authentication technologies in a manner that is sufficiently secure and interoperable; (2) maintain and make available to Federal agencies and the public a list of commercially available electronic authentication products, and other such products used by Federal agencies, evaluated as conforming with such guidelines and standards; (3) establish minimum technical criteria for the use of electronic certification and management systems by Federal agencies and a program for evaluating the conformance of such systems with such criteria; (4) maintain and make available to Federal agencies a list of such systems evaluated as conforming to such criteria; and (5) transmit annual reports to Congress on agency conformance with these matters. Establishes a National Policy Panel for Digital Signatures to serve as a forum for exploring all relevant factors associated with the development of a national digital signature infrastructure based on uniform guidelines and standards to enable the widespread availability and use of digital signature systems. Requires the Under Secretary to transmit to Congress a report containing the Panel's recommendations. (Sec. 14) Authorizes appropriations.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

9 official files

Engrossed in House (text)

View fileDownload file

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.