<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 S2083 IS: Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2017-11-07</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>115th CONGRESS</congress><session>1st Session</session>
		<legis-num>S. 2083</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20171107">November 7, 2017</action-date>
			<action-desc><sponsor name-id="S387">Ms. Harris</sponsor> (for herself and <cosponsor name-id="S383">Mr. Sullivan</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To enhance cybersecurity information sharing and coordination at ports in the United States, and
			 for other purposes.</official-title>
	</form>
	<legis-body>
 <section id="H85F5072FF6634A8988E301454DDBF424" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Strengthening Cybersecurity Information Sharing and Coordination in Our Ports Act of 2017</short-title></quote>.</text> </section><section id="H1207BE2DB2FD4AA5A6D84A9DDC9D4480"><enum>2.</enum><header>Improving cybersecurity risk assessments, information sharing, and coordination</header><text display-inline="no-display-inline">The Secretary of Homeland Security shall—</text>
 <paragraph id="HF8D3967C7E8E4FBEB4FFF14D07EB31BC"><enum>(1)</enum><text>develop and implement a maritime cybersecurity risk assessment model within 120 days after the date of the enactment of this Act, consistent with the National Institute of Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity and any update to that document pursuant to <external-xref legal-doc="public-law" parsable-cite="pl/113/274">Public Law 113–274</external-xref>, to evaluate current and future cybersecurity risks (as such term is defined in section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>));</text>
 </paragraph><paragraph id="H632D565C12634D40A72980A494EF214B"><enum>(2)</enum><text display-inline="yes-display-inline">evaluate, on a periodic basis but not less often than once every 2 years, the effectiveness of the maritime cybersecurity risk assessment model under paragraph (1);</text>
 </paragraph><paragraph id="H0C7D47D9AC614B9798CA0C2A552460DC"><enum>(3)</enum><text>seek to ensure participation of at least one information sharing and analysis organization (as such term is defined in section 212 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/131">6 U.S.C. 131</external-xref>)) representing the maritime community in the National Cybersecurity and Communications Integration Center, pursuant to subsection (d)(1)(B) of section 227 of such Act;</text>
 </paragraph><paragraph id="HB1937D6A093E4D3A9DF9EF94623510C0"><enum>(4)</enum><text>establish guidelines for voluntary reporting of maritime-related cybersecurity risks and incidents (as such terms are defined in section 227 of such Act) to the Center (as such term is defined subsection (b) of such section 227), and other appropriate Federal agencies; and</text>
 </paragraph><paragraph id="H951ADF5DBC2C45859F95D2F9D3BCEBD0"><enum>(5)</enum><text>request the National Maritime Security Advisory Committee established under section 70112 of title 46, United States Code, to report and make recommendations to the Secretary on enhancing the sharing of information related to cybersecurity risks and incidents, consistent with the responsibilities of the Center, between relevant Federal agencies and—</text>
 <subparagraph id="HDF317123A17D45E28DFAF071839BC16C"><enum>(A)</enum><text>State, local, and tribal governments;</text> </subparagraph><subparagraph id="H59B6E5A4C1484830A06EBF32792F5125"><enum>(B)</enum><text>relevant public safety and emergency response agencies;</text>
 </subparagraph><subparagraph id="H166707ED2963451C8652D6F00C19FC57"><enum>(C)</enum><text>relevant law enforcement and security organizations;</text> </subparagraph><subparagraph id="HAE7FC0B315E3407E8A6266C4DEEC1B25"><enum>(D)</enum><text>maritime industry;</text>
 </subparagraph><subparagraph id="H8EC1EA932F3C44CB9FA98157C020C448"><enum>(E)</enum><text>port owners and operators; and</text> </subparagraph><subparagraph id="H5E2962CC9F164662A54F6D18B70BA88D"><enum>(F)</enum><text>terminal owners and operators.</text>
 </subparagraph></paragraph></section><section id="H1ED36CA727C14639857901E37249BD15"><enum>3.</enum><header>Cybersecurity enhancements to maritime security activities</header><text display-inline="no-display-inline">The Secretary of Homeland Security, acting through the Commandant of the Coast Guard, shall direct—</text> <paragraph id="H0A6693CEDA8742699E3A6D67FD56E5F6"><enum>(1)</enum><text>each Area Maritime Security Advisory Committee established under section 70112 of title 46, United States Code, to facilitate the sharing of cybersecurity risks and incidents to address port-specific cybersecurity risks, which may include the establishment of a working group of members of Area Maritime Security Advisory Committees to address port-specific cybersecurity vulnerabilities; and</text>
 </paragraph><paragraph id="H6A8716A5DF1A40F99E5C7FD86B1EE94E"><enum>(2)</enum><text display-inline="yes-display-inline">that any area maritime transportation security plan and any vessel or facility security plan required under section 70103 of title 46, United States Code, approved after the development of the cybersecurity risk assessment model required by paragraph (1) of section 2 include a mitigation plan to prevent, manage, and respond to cybersecurity risks (as such term is defined in section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>)).</text>
 </paragraph></section><section id="H212ABDE3A05E44BDA066A84D70287BA0"><enum>4.</enum><header>Vulnerability assessments and security plans</header><text display-inline="no-display-inline">Title 46, United States Code, is amended—</text> <paragraph id="H327EB6D57EFA42F881701D05AF124B18"><enum>(1)</enum><text>in section 70102(b)(1)(C), by inserting <quote>cybersecurity,</quote> after <quote>physical security,</quote>; and</text>
 </paragraph><paragraph id="H2C50145D98D74CE7B9F2878D0A00F03B"><enum>(2)</enum><text>in section 70103(c)(3)(C), by striking <quote>and</quote> after the semicolon at the end of clause (iv), by redesignating clause (v) as clause (vi), and by inserting after clause (iv) the following:</text>
				<quoted-block display-inline="no-display-inline" id="H8847070C833A49E9A382945D8950DB28" style="OLC">
 <clause commented="no" display-inline="no-display-inline" id="H943393A7A48D4A13ACC15699529C07CA" indent="up1"><enum>(v)</enum><text display-inline="yes-display-inline">prevention, management, and response to cybersecurity risks; and</text></clause><after-quoted-block>.</after-quoted-block></quoted-block> </paragraph></section></legis-body> </bill> 

