Legis Daily

Strengthening American Cybersecurity Act of 2022

USA117th CongressS-3600| Senate 
| Updated: 3/2/2022
Gary C. Peters

Gary C. Peters

Democratic Senator

Michigan

Cosponsors (15)
Jon Ossoff (Democratic)James E. Risch (Republican)Alex Padilla (Democratic)Mark R. Warner (Democratic)Angus S. King (Independent)John W. Hickenlooper (Democratic)Roy Blunt (Republican)Robert P. Casey (Democratic)Jacky Rosen (Democratic)Michael F. Bennet (Democratic)John Cornyn (Republican)Susan M. Collins (Republican)Marco Rubio (Republican)Rob Portman (Republican)Richard Burr (Republican)
  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
Strengthening American Cybersecurity Act of 2022 This bill addresses cybersecurity threats against critical infrastructure and the federal government. The Cybersecurity and Infrastructure Security Agency (CISA) must perform ongoing and continuous assessments of federal risk posture. An agency, within a specified time frame, must (1) determine whether notice to any individual potentially affected by a breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected. Each agency must (1) provide information relating to a major incident to specified parties, and (2) develop specified training for individuals with access to federal information or information systems. The bill requires reporting and other actions to address cybersecurity incidents. Entities that own or operate critical infrastructure must report cyber incidents and ransom payments within specified time frames. The bill limits the use and disclosure of reported information. The bill establishes (1) an interagency council to standardize federal reporting of cybersecurity threats, (2) a task force on ransomware attacks, and (3) a pilot program to identify information systems vulnerable to such attacks. The bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA). FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing products and services. The bill establishes a FedRAMP Board to examine the operations of FedRAMP and the Federal Secure Cloud Advisory Committee.

Bill Text Versions

View Text
2 versions available

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
Feb 8, 2022
Introduced in Senate
Feb 8, 2022
Introduced in the Senate. Read the first time. Placed on Senate Legislative Calendar under Read the First Time.
Feb 9, 2022
Read the second time. Placed on Senate Legislative Calendar under General Orders. Calendar No. 265.
Mar 1, 2022
Passed Senate with amendments by Unanimous Consent. (text: CR S897-919)
Mar 1, 2022
Passed/agreed to in Senate: Passed Senate with amendments by Unanimous Consent.
Mar 1, 2022
Measure laid before Senate by unanimous consent. (consideration: CR S896-919)
Mar 2, 2022
Message on Senate action sent to the House.
Mar 2, 2022
Received in the House.
Mar 2, 2022
Held at the desk.
  • February 8, 2022
    Introduced in Senate


  • February 8, 2022
    Introduced in the Senate. Read the first time. Placed on Senate Legislative Calendar under Read the First Time.


  • February 9, 2022
    Read the second time. Placed on Senate Legislative Calendar under General Orders. Calendar No. 265.


  • March 1, 2022
    Passed Senate with amendments by Unanimous Consent. (text: CR S897-919)


  • March 1, 2022
    Passed/agreed to in Senate: Passed Senate with amendments by Unanimous Consent.


  • March 1, 2022
    Measure laid before Senate by unanimous consent. (consideration: CR S896-919)


  • March 2, 2022
    Message on Senate action sent to the House.


  • March 2, 2022
    Received in the House.


  • March 2, 2022
    Held at the desk.

Government Operations and Politics

Related Bills

  • HR 117-8956: FedRAMP Authorization Act
  • HR 117-6497: Federal Information Security Modernization Act of 2022
  • S 117-3099: Federal Secure Cloud Improvement and Jobs Act of 2021
Administrative law and regulatory proceduresAdvisory bodiesCivil actions and liabilityComputers and information technologyComputer security and identity theftCongressional oversightCriminal investigation, prosecution, interrogationDepartment of Homeland SecurityEmployment and training programsExecutive agency funding and structureFederal officialsGovernment employee pay, benefits, personnel managementGovernment information and archivesGovernment studies and investigationsInfrastructure developmentPerformance measurementPublic contracts and procurementRight of privacyTechnology assessmentTelephone and wireless communication

Strengthening American Cybersecurity Act of 2022

USA117th CongressS-3600| Senate 
| Updated: 3/2/2022
Strengthening American Cybersecurity Act of 2022 This bill addresses cybersecurity threats against critical infrastructure and the federal government. The Cybersecurity and Infrastructure Security Agency (CISA) must perform ongoing and continuous assessments of federal risk posture. An agency, within a specified time frame, must (1) determine whether notice to any individual potentially affected by a breach is appropriate based on a risk assessment; and (2) as appropriate, provide written notice to each individual potentially affected. Each agency must (1) provide information relating to a major incident to specified parties, and (2) develop specified training for individuals with access to federal information or information systems. The bill requires reporting and other actions to address cybersecurity incidents. Entities that own or operate critical infrastructure must report cyber incidents and ransom payments within specified time frames. The bill limits the use and disclosure of reported information. The bill establishes (1) an interagency council to standardize federal reporting of cybersecurity threats, (2) a task force on ransomware attacks, and (3) a pilot program to identify information systems vulnerable to such attacks. The bill provides statutory authority for the Federal Risk and Authorization Management Program (FedRAMP) within the General Services Administration (GSA). FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud computing products and services. The bill establishes a FedRAMP Board to examine the operations of FedRAMP and the Federal Secure Cloud Advisory Committee.

Bill Text Versions

View Text
2 versions available

Suggested Questions

Get AI-generated questions to help you understand this bill better

Timeline
Feb 8, 2022
Introduced in Senate
Feb 8, 2022
Introduced in the Senate. Read the first time. Placed on Senate Legislative Calendar under Read the First Time.
Feb 9, 2022
Read the second time. Placed on Senate Legislative Calendar under General Orders. Calendar No. 265.
Mar 1, 2022
Passed Senate with amendments by Unanimous Consent. (text: CR S897-919)
Mar 1, 2022
Passed/agreed to in Senate: Passed Senate with amendments by Unanimous Consent.
Mar 1, 2022
Measure laid before Senate by unanimous consent. (consideration: CR S896-919)
Mar 2, 2022
Message on Senate action sent to the House.
Mar 2, 2022
Received in the House.
Mar 2, 2022
Held at the desk.
  • February 8, 2022
    Introduced in Senate


  • February 8, 2022
    Introduced in the Senate. Read the first time. Placed on Senate Legislative Calendar under Read the First Time.


  • February 9, 2022
    Read the second time. Placed on Senate Legislative Calendar under General Orders. Calendar No. 265.


  • March 1, 2022
    Passed Senate with amendments by Unanimous Consent. (text: CR S897-919)


  • March 1, 2022
    Passed/agreed to in Senate: Passed Senate with amendments by Unanimous Consent.


  • March 1, 2022
    Measure laid before Senate by unanimous consent. (consideration: CR S896-919)


  • March 2, 2022
    Message on Senate action sent to the House.


  • March 2, 2022
    Received in the House.


  • March 2, 2022
    Held at the desk.
Gary C. Peters

Gary C. Peters

Democratic Senator

Michigan

Cosponsors (15)
Jon Ossoff (Democratic)James E. Risch (Republican)Alex Padilla (Democratic)Mark R. Warner (Democratic)Angus S. King (Independent)John W. Hickenlooper (Democratic)Roy Blunt (Republican)Robert P. Casey (Democratic)Jacky Rosen (Democratic)Michael F. Bennet (Democratic)John Cornyn (Republican)Susan M. Collins (Republican)Marco Rubio (Republican)Rob Portman (Republican)Richard Burr (Republican)

Government Operations and Politics

Related Bills

  • HR 117-8956: FedRAMP Authorization Act
  • HR 117-6497: Federal Information Security Modernization Act of 2022
  • S 117-3099: Federal Secure Cloud Improvement and Jobs Act of 2021
  • Introduced
  • In Committee
  • On Floor
  • Passed Chamber
  • Enacted
Administrative law and regulatory proceduresAdvisory bodiesCivil actions and liabilityComputers and information technologyComputer security and identity theftCongressional oversightCriminal investigation, prosecution, interrogationDepartment of Homeland SecurityEmployment and training programsExecutive agency funding and structureFederal officialsGovernment employee pay, benefits, personnel managementGovernment information and archivesGovernment studies and investigationsInfrastructure developmentPerformance measurementPublic contracts and procurementRight of privacyTechnology assessmentTelephone and wireless communication