Federal
Safe and Secure Federal Websites Act of 2019
Source: Congress.gov ·
1,841 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
I
116TH CONGRESS
1ST SESSION
H. R. 455
To ensure the functionality and security of new Federal websites that collect
personally identifiable information, and for other purposes.
IN THE HOUSE OF REPRESENTATIVES
JANUARY 10, 2019
Mr. FLEISCHMANN introduced the following bill; which was referred to the
Committee on Oversight and Reform
A BILL
To ensure the functionality and security of new Federal
websites that collect personally identifiable information,
and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Safe and Secure Fed-
4
eral Websites Act of 2019’’.
5
SEC. 2. ENSURING FUNCTIONALITY AND SECURITY OF NEW
6
FEDERAL WEBSITES THAT COLLECT PERSON-
7
ALLY IDENTIFIABLE INFORMATION.
8
(a) CERTIFICATION REQUIREMENT.—
9
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
2
•HR 455 IH
(1) IN
GENERAL.—Except as otherwise pro-
1
vided under this subsection, an agency may not de-
2
ploy or make available to the public a new Federal
3
PII website until the date on which the chief infor-
4
mation officer of the agency submits a certification
5
to Congress that the website is fully functional and
6
secure.
7
(2) TRANSITION.—In the case of a new Federal
8
PII website that is operational on the date of the en-
9
actment of this Act, paragraph (1) shall not apply
10
until the end of the 90-day period beginning on such
11
date of enactment. If the certification required under
12
paragraph (1) for such website has not been sub-
13
mitted to Congress before the end of such period,
14
the head of the responsible agency shall render the
15
website inaccessible to the public until such certifi-
16
cation is submitted to Congress.
17
(3) EXCEPTION FOR BETA WEBSITE WITH EX-
18
PLICIT PERMISSION.—Paragraph (1) shall not apply
19
to a website (or portion thereof) that is in a develop-
20
ment or testing phase, if the following conditions are
21
met:
22
(A) A member of the public may access
23
PII-related portions of the website only after
24
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
3
•HR 455 IH
executing an agreement that acknowledges the
1
risks involved.
2
(B) No agency compelled, enjoined, or oth-
3
erwise provided incentives for such a member to
4
access the website for such purposes.
5
(4) CONSTRUCTION.—Nothing in this section
6
shall be construed as applying to a website that is
7
operated entirely by an entity (such as a State or lo-
8
cality) that is independent of the Federal Govern-
9
ment, regardless of the receipt of funding in support
10
of such website from the Federal Government.
11
(b) DEFINITIONS.—In this section:
12
(1) AGENCY.—The term ‘‘agency’’ has the
13
meaning given that term under section 551 of title
14
5, United States Code.
15
(2) FULLY
FUNCTIONAL.—The term ‘‘fully
16
functional’’ means, with respect to a new Federal
17
PII website, that the website can fully support the
18
activities for which it is designed or intended with
19
regard to the eliciting, collection, storage, or mainte-
20
nance of personally identifiable information, includ-
21
ing handling a volume of queries relating to such in-
22
formation commensurate with the purpose for which
23
the website is designed.
24
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
4
•HR 455 IH
(3) NEW FEDERAL PERSONALLY IDENTIFIABLE
1
INFORMATION
WEBSITE
(NEW
FEDERAL
PII
2
WEBSITE).—The terms ‘‘new Federal personally
3
identifiable information website’’ and ‘‘new Federal
4
PII website’’ mean a website that—
5
(A) is operated by (or under a contract
6
with) an agency;
7
(B) elicits, collects, stores, or maintains
8
personally identifiable information of individuals
9
and is accessible to the public; and
10
(C) is first made accessible to the public
11
and collects or stores personally identifiable in-
12
formation of individuals, on or after October 1,
13
2012.
14
(4) OPERATIONAL.—The term ‘‘operational’’
15
means, with respect to a website, that such website
16
elicits, collects, stores, or maintains personally iden-
17
tifiable information of members of the public and is
18
accessible to the public.
19
(5) PERSONALLY IDENTIFIABLE INFORMATION
20
(PII).—The terms ‘‘personally identifiable informa-
21
tion’’ and ‘‘PII’’ mean any information about an in-
22
dividual elicited, collected, stored, or maintained by
23
an agency, including—
24
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
5
•HR 455 IH
(A) any information that can be used to
1
distinguish or trace the identity of an indi-
2
vidual, such as a name, a social security num-
3
ber, a date and place of birth, a mother’s maid-
4
en name, or biometric records; and
5
(B) any other information that is linked or
6
linkable to an individual, such as medical, edu-
7
cational, financial, and employment informa-
8
tion.
9
(6) RESPONSIBLE AGENCY.—The term ‘‘respon-
10
sible agency’’ means, with respect to a new Federal
11
PII website, the agency that is responsible for the
12
operation (whether directly or through contracts
13
with other entities) of the website.
14
(7) SECURE.—The term ‘‘secure’’ means, with
15
respect to a new Federal PII website, that the fol-
16
lowing requirements are met:
17
(A) The website is in compliance with sub-
18
chapter II of chapter 35 of title 44, United
19
States Code.
20
(B) The website ensures that personally
21
identifiable
information
elicited,
collected,
22
stored, or maintained in connection with the
23
website is captured at the latest possible step in
24
a user input sequence.
25
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
6
•HR 455 IH
(C) The responsible agency for the website
1
has encrypted, masked, or taken other similar
2
actions to protect personally identifiable infor-
3
mation elicited, collected, stored, or maintained
4
in connection with the website.
5
(D) The responsible agency for the website
6
has taken reasonable efforts to minimize do-
7
main name confusion, including through addi-
8
tional domain registrations.
9
(E) The responsible agency requires all
10
personnel who have access to personally identi-
11
fiable information in connection with the
12
website to have completed a Standard Form
13
85P and signed a nondisclosure agreement with
14
respect to personally identifiable information,
15
and the agency takes proper precautions to en-
16
sure that only the fewest reasonable number of
17
trustworthy persons may access such informa-
18
tion.
19
(F) The responsible agency maintains (ei-
20
ther directly or through contract) sufficient per-
21
sonnel to respond in a timely manner to issues
22
relating to the proper functioning and security
23
of the website, and to monitor on an ongoing
24
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
7
•HR 455 IH
basis existing and emerging security threats to
1
the website.
2
(8) STATE.—The term ‘‘State’’ means each
3
State of the United States, the District of Columbia,
4
each territory or possession of the United States,
5
and each federally recognized Indian tribe.
6
SEC. 3. PRIVACY BREACH REQUIREMENTS.
7
(a) INFORMATION SECURITY AMENDMENT.—Sub-
8
chapter II of chapter 35 of title 44, United States Code,
9
is amended by adding at the end the following:
10
‘‘§ 3559. Privacy breach requirements
11
‘‘(a) POLICIES AND PROCEDURES.—The Director of
12
the Office of Management and Budget shall establish and
13
oversee policies and procedures for agencies to follow in
14
the event of a breach of information security involving the
15
disclosure of personally identifiable information, including
16
requirements for—
17
‘‘(1) not later than 72 hours after the agency
18
discovers such a breach, or discovers evidence that
19
reasonably indicates such a breach has occurred, no-
20
tice to the individuals whose personally identifiable
21
information could be compromised as a result of
22
such breach;
23
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
8
•HR 455 IH
‘‘(2) timely reporting to a Federal cybersecurity
1
center, as designated by the Director of the Office
2
of Management and Budget; and
3
‘‘(3) any additional actions that the Director
4
finds necessary and appropriate, including data
5
breach analysis, fraud resolution services, identity
6
theft insurance, and credit protection or monitoring
7
services.
8
‘‘(b) REQUIRED AGENCY ACTION.—The head of each
9
agency shall ensure that actions taken in response to a
10
breach of information security involving the disclosure of
11
personally identifiable information under the authority or
12
control of the agency comply with policies and procedures
13
established by the Director of the Office of Management
14
and Budget under subsection (a).
15
‘‘(c) REPORT.—Not later than March 1 of each year,
16
the Director of the Office of Management and Budget
17
shall report to Congress on agency compliance with the
18
policies and procedures established under subsection (a).
19
‘‘(d)
FEDERAL
CYBERSECURITY
CENTER
DE-
20
FINED.—The term ‘Federal cybersecurity center’ means
21
any of the following:
22
‘‘(1) The Department of Defense Cyber Crime
23
Center.
24
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
9
•HR 455 IH
‘‘(2) The Intelligence Community Incident Re-
1
sponse Center.
2
‘‘(3) The United States Cyber Command Joint
3
Operations Center.
4
‘‘(4) The National Cyber Investigative Joint
5
Task Force.
6
‘‘(5) Central Security Service Threat Oper-
7
ations Center of the National Security Agency.
8
‘‘(6) The United States Computer Emergency
9
Readiness Team.
10
‘‘(7) Any successor to a center, team, or task
11
force described in paragraphs (1) through (6).
12
‘‘(8) Any center that the Director of the Office
13
of Management and Budget determines is appro-
14
priate to carry out the requirements of this sec-
15
tion.’’.
16
(b) TECHNICAL AND CONFORMING AMENDMENT.—
17
The table of sections for subchapter II of chapter 35 of
18
title 44, United States Code, is amended by adding at the
19
end the following:
20
‘‘3559. Privacy breach requirements.’’.
Æ
VerDate Sep 11 2014
22:32 Jan 24, 2019
Jkt 089200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6301
E:\BILLS\H455.IH
H455
pbinns on DSK79D2C42PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.