PoliticalRepoPoliticalRepo

United States · Law · S

S. 2521 (113th)

Federal Information Security Modernization Act of 2014

enactedUnited States· United States Congress· EN

Introduced

24 June 2014

Last action

Status

Became Public Law No: 113-283.

Sponsors

Subjects

Discovery layer

Source updated

7 April 2025

Summary

Federal Information Security Modernization Act of 2014 - Amends the Federal Information Security Management Act of 2002 (FISMA) to: (1) reestablish the oversight authority of the Director of the Office of Management and Budget (OMB) with respect to agency information security policies, and (2) set forth authority for the Secretary of Homeland Security (DHS) to carry out the operational aspects of such policies for information systems. Requires the Secretary to develop and oversee implementation of operational directives to agencies to implement the Director's standards and guidelines, as well as the requirements of this Act. Authorizes the Director to repeal operational directives that are not in accordance with the Director's policies. Requires the Secretary (currently, the Director) to ensure the operation of the federal information security incident center (FISIC). Provides for OMB's information security authorities to be delegated to the Director of National Intelligence (DNI) for certain systems operated by an element of the intelligence community. Directs agency heads to ensure that: (1) senior agency officials, including chief information officers, carry out their information security responsibilities; and (2) all personnel are held accountable for complying with the agency-wide information security program. Requires agencies to notify Congress of discovered security incidents within seven days. Directs agencies to submit an annual report regarding major incidents to OMB, DHS, Congress, and the Comptroller General (GAO). Authorizes GAO to provide technical assistance to agencies and inspectors general, including by testing information security controls and procedures. Directs FISIC to provide agencies with intelligence about cyber threats, vulnerabilities, and incidents for risk assessments. Requires OMB to revise OMB Circular A-130 to eliminate inefficient and wasteful reporting. Directs the Information Security and Privacy Advisory Board to advise and provide annual reports to DHS. Requires OMB to establish procedures for agencies to follow in the event of a breach involving disclosure of personally identifiable information, including requirements for notice to affected individuals, FISIC, and Congress.

This text is taken from the official record. PoliticalRepo does not editorialize.

Timeline

No timeline events have been ingested for this record yet.

Votes

No vote records are attached yet.

Versions

No version snapshots stored. Document URLs remain at the source.

Documents

15 official files

Enrolled Bill (text)

View fileDownload file

Sponsors

No sponsors or actors listed by the source.

Related records

No cross-record relationships stored yet.

Sources

PoliticalRepo is an index and interpretation layer, not the authoritative legal source.