Homeland Security Network Defense And Accountability Act Of 2008

Floor Speech

Date: July 28, 2008
Location: Washington, DC
Issues: Defense

BREAK IN TRANSCRIPT

Mr. THOMPSON of Mississippi. Mr. Speaker, I rise in support of this measure and yield myself as much time as I may consume.

Keeping our Federal and critical infrastructure network secure is an issue of national security. The United States and its allies face a significant and growing threat to our information technology systems. The acquisition of our government's information by outsiders undermines our strength as a Nation. Over time the theft of critical information from government computers could cost the United States our advantage over our adversaries.

This legislation is the result of extensive oversight work undertaken by the chairman of the Subcommittee on Emerging Threats, Science and Technology, Mr. Langevin.

An organization is only as strong as the integrity and reliability of the information that it keeps. H.R. 5983, a piece of the DHS authorization package, seeks to improve cybersecurity at DHS by ensuring that DHS's defenses of information systems are robust and by holding individuals at all levels accountable for mitigating vulnerabilities.

H.R. 5983, which was approved by voice vote in the committee, Mr. Speaker, is composed of five important provisions:

First, it establishes authorities and qualifications for the Chief Information Officer position at the Department. Through our oversight work, Mr. Speaker, we have observed how lack of an information security background can hamper the CIO's understanding and ultimately efforts to secure DHS' networks.

Second, the bill establishes specific operational security practices for the CIO, including a continuous real-time cyber incident response capability, network security architecture, and vulnerability assessments. These are fundamental elements for a comprehensive information security program.

Third, H.R. 5983 establishes testing protocols to reduce the number of vulnerability exploitations throughout the Department's networks. Time and again we have heard the current Federal information security requirements do not go far enough to actually ``operationalize'' security to reduce the number of successful attacks. Under H.R. 5983 security will be ``operationalized'' at DHS, a Federal agency that has a critical homeland security mission and is the receptacle of highly sensitive information.

Fourth, Mr. Speaker, the bill requires the Secretary of Homeland Security to determine if the internal security policy of a contractor who provides network services to DHS is consistent with the agency's requirements. This is a standard operating procedure for all private sector companies. It should be also for DHS as well.

Finally, Mr. Speaker, this bill seeks a formal report from the Secretary of Homeland Security on meeting the deadlines established by the Office of Management and Budget for Trusted Internet Connections, encryption and authentication mandates. These are critical for the Department's efforts to improve information security. It is unclear whether proper deadlines are being met.

BREAK IN TRANSCRIPT

Mr. THOMPSON of Mississippi. Mr. Speaker, I yield myself such time as I may consume.

Mr. Speaker, H.R. 5983 is the product of extensive oversight by Chairman Langevin and the other members of the Emerging Threats, Science and Technology Subcommittee.

After hearing from hundreds of experts on how best to improve information security, reviewing best practices in the public and private sectors, and investigating cyber incidents across the public and private sectors, Chairman Langevin authored the Homeland Security Network Defense and Accountability Act.

H.R. 5983 will ensure that a qualified leader serves as the Chief Information Officer and has direction on what specific operational security practices should be implemented to make DHS's information security defenses robust.

This legislation seeks to make DHS the gold standard when it comes to information security. After all, Mr. Speaker, how can DHS legitimately be the lead Federal agency for cybersecurity and infrastructure protection when it doesn't have its own house in order.

I am pleased to include H.R. 5983 in the package of DHS authorization bills that the Committee on Homeland Security has approved on a bipartisan basis. I urge my colleagues to support me in passing this critical piece of legislation.

BREAK IN TRANSCRIPT


Source
arrow_upward