The Cybersecurity Act of 2012 would make significant changes on how the federal government governs IT security. The bill would update the decade-old Federal Information Security Management Act. It would require continuous monitoring of the operational status and security of agency IT systems. The legislation also would require penetration testing – so-called ethical hacking – exercises to evaluate whether agencies adequately protect against, detect and respond to cyber incidents. “This bill would replace our outdated, paper-based security practices with a real-time security system,” Sen. Tom Carper says.”]
Source: https://www.inforisktoday.com/beyond-hype-cybersecurity-act-a-4978

