Davis aims to solidify GISRA

Government Information Security Reform Act

Rep. Tom Davis (R-Va.) is working on legislation to reauthorize the Government Information Security Reform Act to make the law permanent and include mandatory standards for information security.

Davis, chairman of the House Government Reform Committee's Technology and Procurement Policy Subcommittee, said Dec. 11 that his legislation would require agencies to implement security best practices for their information systems. GISRA is set to expire in October 2002, and Davis intends to introduce his bill early next year.

"Unfortunately, GISRA...lacked any type of mandatory authority that would force agencies to implement security best practices for their information systems, adopt minimum security standards for these same systems and engage in activities...which identifies the interconnectivity of an agency's critical assets in focusing on system vulnerabilities," Davis told a cybersecurity conference sponsored by the Information Technology Association of America.

The bill also would strengthen the National Institute of Standards and Technology's role in developing and maintaining standards for information security.

"It is important...to signal Congress' deep concerns that information security is not being taken seriously by every agency and department, and that in the e-gov, networked era, federal information security systems are only as strong as their weakest link," Davis said.

GISRA requires agencies to better manage their security and document their progress through a self-assessment and an independent review by inspectors general. Standards could be waived under current law, but Davis' draft bill, which he said he is circulating among lawmakers, would make standards compulsory and binding.

Featured

  • Defense
    DOD photo by Senior Airman Perry Aston  11th Wing Public Affairs

    How DOD's executive exodus could affect tech modernization

    Back-to-back resignations raise concerns about how things will be run without permanent leadership in key areas from policy to tech development.

  • Budget
    cybersecurity (vs148/Shutterstock.com)

    House's DHS funding bill would create public-private cyber center

    The legislation would give $2.25 billion to DHS' cyber wing and set up an integrated cybersecurity center with other agencies, state and local governments and private industry.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.