BAGIOOI SL
Mok. KR Menez
AMENDMENT NO.__ Calendar No.
Purpose: ‘To require an assessment of value of speed in
cyber threat detection, , and remediation,
IN THE SENATE OF THE UNITED STATES—116th Cong,, Ist Ses:
S.1790
To authorize appropriation
acti of the Denart
AMENDMENT N° 0670
By... Wat.O2C.
for fiseal year 2020 for military
font Dsfen for milital
the Depar
personnel
her purpose
and
To: .
$1790
a i inted
3
Pas) WARNER
1 At the end of subtitle C of title XVI, add the fol-
2 ie:
3 SEC. __. ASSESSMENT OF VALUE OF SPEED IN CYBER
4 THREAT DETECTION, ANALYSIS, AND REME-
5 DIATION.
(a) ASSESSMENT REQUIRED.—The Chief Informa-
¢, in coordination
tion Officer of the Department of Defi
with the Director of the Defense Information Sys
Cwm aA
the followin,BAGiOo1I
oe e
oo
SLE.
(1) The range of times required by adversaries
to gain access through a cyber attack on a Depart~
ment of Defense network, conduct reconnaissance on
the network, acquired privileged credentials for ope
ating on the network, move laterally in the network,
and accomplish the goal of the intrusion.
(2) Trends over time in the speed with which
adversaries accomplish the steps listed in paragraph
qd).
(3) The range of times required by network de-
fenders to detect indications of the intrusion, ana-
nediate
‘acterize the intrusion, and to re
lyze and cha
the intrusion,
(4) The value of speed in detection, analysis,
and remediation of intrusi contain
ons to effectivel
nd defeat adversaries from achieving their objec
tives
(5) The advisability of adopting response times
as a metric for assessing the performance of the ea-
of network defen
pabilitis y pro-
grams and operators and institutionalizing relevant
data collection and for
sic processes across the De-
partment.
(b) BRIEFING.—Not later than 180 days after the
25 date of the enactment of this Act, the Chief InformationBAGIOOII SLE.
wk ON
3
Officer shall brief the congressional defense committees on
the results of the assessment conducted under subsection
\s that the Chief Information Officer in-
(a) and any actio
tends to take with respect to the outcome of the assess-
ment