<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" bill-type="olc" dms-id="A1" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 S594 IS: National Cybersecurity Preparedness Consortium Act of 2017</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2017-03-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>115th CONGRESS</congress><session>1st Session</session><legis-num>S. 594</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20170309">March 9, 2017</action-date><action-desc><sponsor name-id="S287">Mr. Cornyn</sponsor> (for himself, <cosponsor name-id="S355">Mr. Cruz</cosponsor>, and <cosponsor name-id="S057">Mr. Leahy</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To authorize the Secretary of Homeland Security to work with cybersecurity consortia for training,
			 and for other purposes.</official-title></form>
	<legis-body display-enacting-clause="yes-display-enacting-clause" id="H7DC0DF4214C04DEE82650CF303E28277" style="OLC">
 <section id="HE4CED05437F74A398D411C27FD41ED3B" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>National Cybersecurity Preparedness Consortium Act of 2017</short-title></quote>.</text> </section><section id="id8D71A38CFD504369829171D75DD02E50"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act—</text>
 <paragraph id="id50A5EEF38EE341688E96AB709E3E9FEA"><enum>(1)</enum><text display-inline="yes-display-inline">the term <term>consortium</term> means a group primarily composed of nonprofit entities, including academic institutions, that develop, update, and deliver cybersecurity training in support of homeland security;</text>
 </paragraph><paragraph id="id6981FB4E5F2741C2894619A14364C2FC"><enum>(2)</enum><text display-inline="yes-display-inline">the terms <term>cybersecurity risk</term> and <term>incident</term> have the meanings given those terms in section 227(a) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148(a)</external-xref>);</text>
 </paragraph><paragraph id="id0D6527AC9EC44E0985FDB181DBFB3F9B"><enum>(3)</enum><text>the term <term>Department</term> means the Department of Homeland Security; and</text> </paragraph><paragraph id="idABC7EF6BF491444EBC0133910A141002"><enum>(4)</enum><text>the term <term>Secretary</term> means the Secretary of Homeland Security.</text>
			</paragraph></section><section id="HE488EEF2156D42188111D330C4F89168"><enum>3.</enum><header>National Cybersecurity Preparedness Consortium</header>
 <subsection id="HE6EF682D13A64AC995771979CBC116BC"><enum>(a)</enum><header>In general</header><text>The Secretary may work with a consortium, including the National Cybersecurity Preparedness Consortium, to support efforts to address cybersecurity risks and incidents, including threats of terrorism and acts of terrorism.</text>
 </subsection><subsection id="H3C89BB4211184EB3A1AE936A09ADFDAE"><enum>(b)</enum><header>Assistance to the NCCIC</header><text>The Secretary may work with a consortium to assist the national cybersecurity and communications integration center of the Department (established under section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>)) to—</text>
 <paragraph id="H9538AB0609F649988A74BA185F2ED1C4"><enum>(1)</enum><text display-inline="yes-display-inline">provide training to State and local first responders and officials specifically for preparing for and responding to cybersecurity risks and incidents, including threats of terrorism and acts of terrorism, in accordance with applicable law;</text>
 </paragraph><paragraph id="HF005C0F67B6E4A1988B2F41D6A8AF92E"><enum>(2)</enum><text>develop and update a curriculum utilizing existing programs and models in accordance with such section 227, for State and local first responders and officials, related to cybersecurity risks and incidents, including threats of terrorism and acts of terrorism;</text>
 </paragraph><paragraph id="H04F6357C12024E0AB5A4D71FF885C960"><enum>(3)</enum><text>provide technical assistance services to build and sustain capabilities in support of preparedness for and response to cybersecurity risks and incidents, including threats of terrorism and acts of terrorism, in accordance with such section 227;</text>
 </paragraph><paragraph id="H78C79AEB4E384D5890F37227E4E3586B"><enum>(4)</enum><text>conduct cross-sector cybersecurity training and simulation exercises for entities, including State and local governments, critical infrastructure owners and operators, and private industry, to encourage community-wide coordination in defending against and responding to cybersecurity risks and incidents, including threats of terrorism and acts of terrorism, in accordance with section 228(c) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/149">6 U.S.C. 149(c)</external-xref>);</text>
 </paragraph><paragraph id="H776A5905A3464781A69FACDAAC49CEB3"><enum>(5)</enum><text>help States and communities develop cybersecurity information sharing programs, in accordance with section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>), for the dissemination of homeland security information related to cybersecurity risks and incidents, including threats of terrorism and acts of terrorism; and</text>
 </paragraph><paragraph commented="no" id="HE5B25D3C9E5141378B17DBB3FE257E87"><enum>(6)</enum><text display-inline="yes-display-inline">help incorporate cybersecurity risk and incident prevention and response (including related to threats of terrorism and acts of terrorism) into existing State and local emergency plans, including continuity of operations plans.</text>
 </paragraph></subsection><subsection id="H095260FDFDB74A6090566CF0FA67AD6E"><enum>(c)</enum><header>Prohibition on duplication</header><text>In carrying out the functions under subsection (b), the Secretary shall, to the greatest extent practicable, seek to prevent unnecessary duplication of existing programs or efforts of the Department.</text>
 </subsection><subsection id="HAAC8D97C9ECD4A7CA89EDC2BB933F4B5"><enum>(d)</enum><header>Considerations regarding selection of a consortium</header><text display-inline="yes-display-inline">In selecting a consortium with which to work under this Act, the Secretary shall take into consideration the following:</text>
 <paragraph id="HD1D5FEBF27F84DBAA34BC87A86077CE3"><enum>(1)</enum><text>Any prior experience conducting cybersecurity training and exercises for State and local entities.</text> </paragraph><paragraph id="H19A442748C1740CEBD599B6144D31795"><enum>(2)</enum><text display-inline="yes-display-inline">Geographic diversity of the members of any such consortium so as to cover different regions throughout the United States.</text>
 </paragraph></subsection><subsection id="H3090EE611EAD4C78B804AD3BFC11F770"><enum>(e)</enum><header>Metrics</header><text display-inline="yes-display-inline">If the Secretary works with a consortium under subsection (a), the Secretary shall measure the effectiveness of the activities undertaken by the consortium under this Act.</text>
 </subsection><subsection id="HEAE179D249424F63B2584F2A42730A71"><enum>(f)</enum><header>Outreach</header><text display-inline="yes-display-inline">The Secretary shall conduct outreach to universities and colleges, including historically Black colleges and universities, Hispanic-serving institutions, Tribal Colleges and Universities, and other minority-serving institutions, regarding opportunities to support efforts to address cybersecurity risks and incidents, including threats of terrorism and acts of terrorism, by working with the Secretary under subsection (a).</text>
 </subsection><subsection id="HCE3667CB63C04B4FAAEC84262718D846"><enum>(g)</enum><header>Termination</header><text>The authority to carry out this Act shall terminate on the date that is 5 years after the date of enactment of this Act.</text></subsection></section></legis-body></bill>


