To improve the information security of the Department of Veterans Affairs by directing the Secretary of Veterans Affairs to carry out certain actions to improve the transparency and the governance of the information security program of the Department, and for other purposes.
Veterans Information Security Improvement Act
Directs the Secretary of Veterans Affairs to: (1) carry out certain information security activities, (2) ensure that officials and staff of the Department of Veterans Affairs (VA) possess specified qualifications in such areas, and (3) coordinate the staffing of related information technology and security offices.
Requires the Secretary to ensure that: (1) the Assistant Secretary for Information and Technology, the head of the Office of Information Security (OIS), and relevant field staff possess certain levels of information technology education, certifications, and experience; (2) Office of Information and Technology (OIT) staff are assigned to the OIS; and (3) subordinate OIT offices maintain appropriate information security functions.
Directs the Secretary to ensure that subordinate OIT offices maintain functions to: (1) integrate the VA's security architecture into the VA's overall enterprise architecture strategy, (2) restrict the development of new data warehouses and data marts holding sensitive personal information of veterans, (3) reduce the number of data marts holding such personal information, and (4) deploy an incident response capability.
Defines:
Requires the Secretary to safeguard VA network infrastructure, computers, and servers.
Directs the Secretary to protect the confidentiality of sensitive personal information of veterans by:
Directs the Secretary to submit certifications to Congress regarding the VA's compliance with information security requirements, including actions required by the National Institute of Standards and Technology and the Office of Management and Budget.
Requires the Secretary to submit monthly reports to Congress regarding security vulnerabilities discovered after performing regular scans of VA computers and servers.
Introduced in House
Introduced in House
Referred to the House Committee on Veterans' Affairs.
Referred to the Subcommittee on Oversight and Investigations.
Subcommittee Hearings Held.
Subcommittee Consideration and Mark-up Session Held.
Forwarded by Subcommittee to Full Committee in the Nature of a Substitute (Amended) by Voice Vote .
checking server…
Ask anything about this bill. The AI reads the full text to answer.
Enter to send · Shift+Enter for new line