<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>113 S2519 RS: National Cybersecurity and Communications Integration Center Act of 2014</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2014-06-24</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 526</calendar><congress>113th CONGRESS</congress><session>2d Session</session><legis-num>S. 2519</legis-num><associated-doc role="report">[Report No. 113–240]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20140624">June 24, 2014</action-date><action-desc><sponsor name-id="S277">Mr. Carper</sponsor> (for himself and <cosponsor name-id="S301">Mr. Coburn</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date>July 31, 2014</action-date><action-desc>Reported by <sponsor name-id="S277">Mr. Carper</sponsor>, with an amendment</action-desc><action-instruction>Insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To codify an existing operations center for cybersecurity.  </official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
		  <quote><short-title>National Cybersecurity and Communications Integration Center Act of 2014</short-title></quote>.</text></section><section id="id0CF6A07001154E209A51B420B28F0C2A"><enum>2.</enum><header>National Cybersecurity and Communications Integration Center</header><subsection id="id8FDF2848F60146A2AB49C770E2DA0C3A"><enum>(a)</enum><header>In general</header><text>Subtitle A of title II of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/121">6 U.S.C. 121 et seq.</external-xref>) is amended by
			 adding at the end the following:</text><quoted-block display-inline="no-display-inline" id="id3255D247D6B34B109E8D7C8ABB200B5F" style="OLC"><section commented="no" id="idE625D0ACD2B44794A73F23EC55CEF5BB"><enum>210G.</enum><header>Operations center</header><subsection commented="no" id="id95E28DC9EDF94920B452DDA11822F738"><enum>(a)</enum><header>Functions</header><text>There is in the Department an operations center, which may carry out the responsibilities of the
			 Under Secretary appointed under
			 section
			 103(a)(1)(H) with respect to security and
			 resilience,
			 including by—</text><paragraph commented="no" id="id51cfc5411ce2453c88b0e3ab3f886eff"><enum>(1)</enum><text>serving as a Federal civilian information sharing interface for cybersecurity;</text></paragraph><paragraph commented="no" id="idD55AED174F544F1E82E17921810BEF24"><enum>(2)</enum><text>providing shared situational awareness to enable real-time, integrated, and operational actions
			 across the Federal Government;</text></paragraph><paragraph commented="no" id="id165ea6e090e2458ba4ad5ba6edf51dd6"><enum>(3)</enum><text>sharing cybersecurity threat, vulnerability, impact, and incident information and analysis by and
			 among Federal,
			 State, and
			 local government entities and private sector entities;</text></paragraph><paragraph id="idd1ed62b1bcef407dac4c5a4cc69f0fc3"><enum>(4)</enum><text>coordinating cybersecurity information sharing throughout the Federal Government;</text></paragraph><paragraph id="id3d96386d08694a1e91001e0c7af2933a"><enum>(5)</enum><text>conducting analysis of cybersecurity risks and incidents;</text></paragraph><paragraph commented="no" id="idae4ef45629734d9e8f5523785029b480"><enum>(6)</enum><text>upon request, providing timely technical assistance to Federal and non-Federal entities with
			 respect  to cybersecurity threats and attribution, vulnerability
			 mitigation, and incident response and remediation; and</text></paragraph><paragraph commented="no" id="id0eed7f43c06d498babf662d9524ece7f"><enum>(7)</enum><text>providing recommendations on security and resilience measures to Federal and non-Federal entities.</text></paragraph></subsection><subsection commented="no" id="id1278ECB909874B058FE7C4CDA1D467A8"><enum>(b)</enum><header>Composition</header><text>The operations center shall be composed of—</text><paragraph commented="no" id="idDB948D25967A40E28FF1944B3A4A82B8"><enum>(1)</enum><text>personnel or other representatives of Federal agencies, including civilian and law enforcement
			 agencies and elements of the intelligence community, as such term is
			 defined under section 3(4) of the National Security Act of 1947 (50 U.S.C.
			 3003(4)); and</text></paragraph><paragraph commented="no" id="id4DA6359FA4C146DB88B0FBBE5CA57045"><enum>(2)</enum><text>representatives from
			 State and local governments and other non-Federal entities, including—</text><subparagraph commented="no" id="id4F5FCF7F663D40E6ACEA34B7C5141985"><enum>(A)</enum><text>representatives from information sharing and analysis organizations; and</text></subparagraph><subparagraph commented="no" id="idB58AF8D90D174D7992365C6D05C3B213"><enum>(B)</enum><text>private sector owners and operators of critical information systems.</text></subparagraph></paragraph></subsection><subsection commented="no" id="id68F2AD7420234312AE4FED9F1902B697"><enum>(c)</enum><header>Annual report</header><text>Not later than 1 year after the date of enactment of the <short-title>National Cybersecurity and Communications Integration Center Act of 2014</short-title>, and every year thereafter for 3 years, the Secretary shall submit to the Committee on Homeland
			 Security and Governmental Affairs of the
			 Senate and the Committee on Homeland Security of the House of
			 Representatives a report on the operations center, which shall
			 include—</text><paragraph commented="no" id="id36B22EA7DBFF476A9AF92255FDB38131"><enum>(1)</enum><text>an analysis of the performance of the operations center in carrying out the functions under
			 subsection (a);</text></paragraph><paragraph commented="no" id="id74460A6EE6F140748C8CA7959349E3D8"><enum>(2)</enum><text>information on the composition of the center, including—</text><subparagraph commented="no" id="idBDB666A00FF645A1A2DBA355F4D02D6F"><enum>(A)</enum><text>the number of representatives from non-Federal entities that are participating in the operations
			 center, including the number of representatives from States, nonprofit
			 organizations, and private sector entities, respectively; and</text></subparagraph><subparagraph commented="no" id="id86ADEF21599645EC87F5334226A97AE4"><enum>(B)</enum><text>the number of requests from non-Federal entities to participate in the operations center and the
			 response to such requests, including—</text><clause commented="no" id="idC47ADDF280B54F03A098852DB10DA20B"><enum>(i)</enum><text>the average length of time to fulfill such identified requests by the Federal agency   responsible
			 for fulfilling such requests; and</text></clause><clause commented="no" id="idB26541EF90984419939D98EFE8A3050F"><enum>(ii)</enum><text>a description of any obstacles or challenges to fulfilling such requests; and</text></clause></subparagraph></paragraph><paragraph commented="no" id="idDE363A140A9944DEBB3AE25422D77617"><enum>(3)</enum><text>the policies and procedures established by the operations center to safeguard privacy and civil
			 liberties.</text></paragraph></subsection><subsection commented="no" id="idA16F4DED67D6475A820790B19C2098FC"><enum>(d)</enum><header>GAO report</header><text>Not later than 1 year after the date of enactment of the <short-title>National Cybersecurity and Communications Integration Center Act of 2014</short-title>, the Comptroller General of the United States shall submit to the Committee on Homeland Security
			 and Governmental Affairs of the Senate and the Committee on Homeland
			 Security of the House of Representatives a report on the effectiveness of
			 the operations center.</text></subsection><subsection commented="no" id="idDFF92D8FD0A74E82B97DEFF94029E853"><enum>(e)</enum><header>No right or benefit</header><text>The provision of assistance or information to, and inclusion in the operations center of,
			 governmental or private entities under this section shall be at the
			 discretion of the Under Secretary appointed under section 103(a)(1)(H).
			 The provision of certain assistance or information to, or inclusion in the
			 operations center of, one governmental or private entity pursuant to this
			 section shall not create a right or benefit, substantive or procedural, to
			 similar assistance or information for any other governmental or private
			 entity.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idF4A6B48E782641A18DE594703D36C50E"><enum>(b)</enum><header>Technical and conforming amendment</header><text>The table of contents in section 1(b) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/101">6 U.S.C. 101</external-xref> note) is
			 amended by inserting after the item relating to section 210F the
			 following:</text><quoted-block display-inline="no-display-inline" id="idDCFF4C7B9CCD4CF3BFB5B88F4C925B17" style="OLC"><toc><toc-entry bold="off" level="section">Sec. 210G. Operations center.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section><section changed="added" id="idC9C0B4AAA65B454698794146C9138935" reported-display-style="italic"><enum>3.</enum><header>Rule of construction</header><subsection id="id32060AF72A6048DFB1E7D0D338EE62B0"><enum>(a)</enum><header>Definition</header><text>In this section, the term <term>critical infrastructure</term> has the meaning given that term under section 2 of the Homeland Security Act of 2002 (6 U.S.C.
			 101).</text></subsection><subsection id="id0192FBBFB24F4D859882E26D984FA48E"><enum>(b)</enum><header>Rule of construction</header><text>Nothing in this Act shall be construed to grant the Secretary of Homeland Security any authority to
			 promulgate regulations or set
			 standards relating to the cybersecurity of private sector critical
			 infrastructure that was not in effect on the day before the date of
			 enactment of this Act.</text></subsection></section></legis-body><endorsement><action-date>July 31, 2014</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill>


