<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H9C7A9E0260E34BC493EF7197C12FDB5A" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 HR 5239 IH: Cyber Sense Act of 2018</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2018-03-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">115th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 5239</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20180309">March 9, 2018</action-date><action-desc><sponsor name-id="L000566">Mr. Latta</sponsor> (for himself and <cosponsor name-id="M001166">Mr. McNerney</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and Commerce</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To require the Secretary of Energy to establish a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system, and for other purposes.</official-title></form><legis-body id="HFD388FD3ADB049199505AA35C2E5DB35" style="OLC"> 
<section id="HD4D4D20B994C4E27BC993326AE1F00D5" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Sense Act of 2018</short-title></quote>.</text></section> <section id="HFEB51881B0374411864C9D2FC05C7ECD" section-type="subsequent-section"><enum>2.</enum><header>Cyber Sense</header> <subsection id="HF9BA472BBAFC479EB8D218C1924E3225"><enum>(a)</enum><header>In general</header><text>The Secretary of Energy shall establish a voluntary Cyber Sense program to identify and promote cyber-secure products intended for use in the bulk-power system, as defined in section 215(a) of the Federal Power Act (<external-xref legal-doc="usc" parsable-cite="usc/16/824o">16 U.S.C. 824o(a)</external-xref>).</text></subsection> 
<subsection id="H7524CC1BB21643629DA9FA5CEF6DC426"><enum>(b)</enum><header>Program requirements</header><text>In carrying out subsection (a), the Secretary of Energy shall—</text> <paragraph id="H38526712FE034AF3BFB70A187E65BFCA"><enum>(1)</enum><text>establish a Cyber Sense testing process to identify products and technologies intended for use in the bulk-power system that are cyber-secure, including products relating to industrial control systems, such as supervisory control and data acquisition systems; </text></paragraph> 
<paragraph id="H5898BC528A644635ADBAA9C2BF19C3FF"><enum>(2)</enum><text>for products tested and identified as cyber-secure under the Cyber Sense program, establish and maintain cybersecurity vulnerability reporting processes and a related database;</text> </paragraph> <paragraph id="H92D90F4894B14D48ABED49F435058D9C"><enum>(3)</enum><text display-inline="yes-display-inline">provide technical assistance to electric utilities, product manufacturers, and other electricity sector stakeholders to develop solutions to mitigate identified cybersecurity vulnerabilities in products tested and identified as cyber-secure under the Cyber Sense program;</text></paragraph> 
<paragraph id="H1AD7421094904E0786E3101366514BB5"><enum>(4)</enum><text display-inline="yes-display-inline">biennially review products tested and identified as cyber-secure under the Cyber Sense program for cybersecurity vulnerabilities and provide analysis with respect to how such products respond to and mitigate cyber threats;</text></paragraph> <paragraph id="HCE0701C850764E9385302692F4A16213"><enum>(5)</enum><text display-inline="yes-display-inline">develop procurement guidance for electric utilities for products tested and identified as cyber-secure under the Cyber Sense program;</text></paragraph> 
<paragraph id="H806C06ADCCD84F028FD89E2D82E2D696"><enum>(6)</enum><text>provide reasonable notice to the public, and solicit comments from the public, prior to establishing or revising the Cyber Sense testing process;</text></paragraph> <paragraph id="H92775141E52B4D699B0EBDEAC4D94ED8"><enum>(7)</enum><text>establish procedures for disqualifying products that were tested and identified as cyber-secure under the Cyber Sense program but that no longer meet the qualifications to be identified cyber-secure products under such program;</text></paragraph> 
<paragraph id="HE50BD84CF720412D8E90B25E97DA5253"><enum>(8)</enum><text>oversee Cyber Sense testing carried out by third parties; and</text></paragraph> <paragraph id="HE7652BCAA2494DD3AE5550A5A7FA4276"><enum>(9)</enum><text>consider incentives to encourage the use in the bulk-power system of products tested and identified as cyber-secure under the Cyber Sense program.</text></paragraph></subsection> 
<subsection id="HC31D8F382D1F429C9EEF290E344FD7C7"><enum>(c)</enum><header>Disclosure of information</header><text display-inline="yes-display-inline">Any cybersecurity vulnerability reported pursuant to the process established under subsection (b)(2), the disclosure of which the Secretary of Energy reasonably foresees would cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be deemed to be critical electric infrastructure information for purposes of section 215A(d) of the Federal Power Act.</text></subsection> <subsection id="H583908C39976422EBBE30095E65FD2D5"><enum>(d)</enum><header>Federal Government liability</header><text>Nothing in this section shall be construed to authorize the commencement of an action against the United States Government with respect to the testing and identification of a product under the Cyber Sense program.</text></subsection> </section> 
</legis-body></bill>

