Skip to main content
HR 1128 114th Congress House Armed Forces and National Security Computer security and identity theft Computers and information technology Congressional oversight Department of Veterans Affairs Executive agency funding and structure Government information and archives Health information and medical records Health technology, devices, supplies Internet and video services Internet, web applications, social media Public contracts and procurement Right of privacy Technology assessment Veterans' education, employment, rehabilitation Veterans' loans, housing, homeless programs Veterans' medical care Veterans' pensions and compensation

Department of Veterans Affairs Cyber Security Protection Act

Introduced: February 26, 2015 See on congress.gov
 Everywhere this bill has been 4 steps
Introduced
In committee
Reported out
Passed House
Passed Senate
To President
Became law
Mar 19, 2015
Subcommittee Hearings Held.
Mar 13, 2015
Referred to the Subcommittee on Oversight and Investigations.
Feb 26, 2015
Introduced in House
Feb 26, 2015
Referred to the House Committee on Veterans' Affairs.
 Plain-English summary Congressional Research Service

Department of Veterans Affairs Cyber Security Protection Act

Directs the Assistant Secretary of Veterans Affairs for Information and Technology to submit to the congressional veterans committees (under current law only to the Secretary of Veterans Affairs) quarterly reports on Department of Veterans Affairs (VA) compliance with federally-required information security improvements.

Directs the Assistant Secretary to submit to such committees: (1) quarterly, a plan of action to address critical known VA information security vulnerabilities; and (2) annually, a plan for identifying and replacing VA operating systems that are out-of-date or unsupported.

Directs the Assistant Secretary to ensure that any software or Internet applications used on VA operating systems are secure from vulnerabilities that could affect the confidentiality of sensitive personal information on veterans.

Directs the Secretary to:

  • report quarterly to such committees on any incidents of failure to comply with established information security policies, any actions taken in response to such incidents, and certain related information;
  • submit a strategic plan to such committees for improving VA information security and to update such plan at least every two years; and
  • report to such committees within five years on information security protection and accountability of the VA for information security breeches and incidents.

Requires VA contractors with access to sensitive personal information to provide protective measures to safeguard from possible information security threats any information provided by the VA that will be resident on, or transiting through, information systems controlled by that contractor.

What's happening now March 19, 2015

Subcommittee Hearings Held.

 Committees of jurisdiction 2