PoliticalRepoPoliticalRepo

United States · Bill · HR

H.R. 4257 (112th)

Federal Information Security Amendments Act of 2012

referredUnited States· United States Congress· EN

Introduced

26 March 2012

Last action

Status

Received in the Senate and Read twice and referred to the Committee on Homeland Security and Governmental Affairs.

Sponsors

Subjects

Discovery layer

Source updated

7 April 2025

Summary

Federal Information Security Amendments Act of 2012 - Amends the Federal Information Security Management Act of 2002 (FISMA) to reestablish the oversight authority of the Director of the Office of Management and Budget (OMB) with respect to agency information and security policies and practices. Expands the term "information security" to include authentication. Defines "authentication" as the use of digital credentials to assure users' identities and validate access. Extends the security requirements of federal agencies to include responsibilities for: (1) ensuring complementary and uniform standards for information systems and national security systems, (2) securing facilities for classified information, and (3) maintaining sufficient personnel with security clearances. Directs senior agency officials to continuously conduct risk-commensurate: (1) testing and evaluation of information of security controls and techniques, and (2) threat assessments by monitoring information infrastructure and identifying potential system vulnerabilities. (Current law requires only periodic testing and evaluation.) Directs agencies to determine information security levels in accordance with information security classifications and standards promulgated under the National Institute of Standards and Technology Act. Directs agencies to collaborate with OMB and appropriate public and private sector security operations centers on security incidents that extend beyond the control of an agency. Requires that security incidents be reported to the appropriate security operations center and agency Inspector General through an automated and continuous monitoring capability. Requires each agency to delegate to its Chief Information Officer the authority and primary responsibility for developing, implementing, and overseeing an agencywide information security (AIS) program. Directs agencies to implement an OMB-approved AIS program that is consistent with components across and within agencies. Requires that such program include automated and continuous monitoring to: (1) mitigate risks associated with security incidents before substantial damage is done; and (2) notify and consult with appropriate security operations response centers, law enforcement agencies, Inspectors General, and other entities or as directed by the President.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

10 official files

Referred in Senate (text)

View fileDownload file

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.