(A)
In general.—
Each agency shall submit to the Director, the Secretary, the Committee on Government Reform, the Committee on Homeland Security, and the Committee on Science of the House of Representatives, the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate, the appropriate authorization and appropriations committees of Congress, and the Comptroller General a report on the adequacy and effectiveness of information security policies, procedures, and practices, including—
(i)
a description of each major information security incident or related sets of incidents, including summaries of—
(I)
the threats and threat actors, vulnerabilities, and impacts relating to the incident;
(II)
the risk assessments conducted under section 3554(a)(2)(A) of the affected information systems before the date on which the incident occurred;
(III)
the status of compliance of the affected information systems with applicable security requirements at the time of the incident; and
(IV)
the detection, response, and remediation actions;
(ii)
the total number of information security incidents, including a description of incidents resulting in significant compromise of information security, system impact levels, types of incident, and locations of affected systems;
(iii)
a description of each major information security incident that involved a breach of personally identifiable information, as defined by the Director, including—
(I)
the number of individuals whose information was affected by the major information security incident; and
(II)
a description of the information that was breached or exposed; and
(iv)
any other information as the Director or the Secretary, in consultation with the Director, may require.
(B)
Unclassified report.—
(i)
In general.—
Each report submitted under subparagraph (A) shall be in unclassified form, but may include a classified annex.
(ii)
Access to information.—
The head of an agency shall ensure that, to the greatest extent practicable, information is included in the unclassified version of the reports submitted by the agency under subparagraph (A).