<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" bill-type="olc" dms-id="A1" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>115 S3309 RS: DHS Cyber Incident Response Teams Act of 2018</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2018-07-31</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 716</calendar><congress>115th CONGRESS</congress><session>2d Session</session><legis-num>S. 3309</legis-num><associated-doc role="report">[Report No. 115–412]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20180731">July 31, 2018</action-date><action-desc><sponsor name-id="S388">Ms. Hassan</sponsor> (for herself and <cosponsor name-id="S349">Mr. Portman</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name added-display-style="italic" committee-id="SSGA00" deleted-display-style="strikethrough">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date>December 4, 2018</action-date><action-desc>Reported by <sponsor name-id="S345">Mr. Johnson</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To authorize cyber incident response teams at the Department of Homeland Security, and for other
			 purposes.</official-title></form>
	<legis-body display-enacting-clause="yes-display-enacting-clause" id="HFF282EDD8C8849229F4DAE17C83A5A4D" style="OLC">
 <section changed="deleted" committee-id="SSGA00" id="HAB3522D9542743999C3EDA317364BB35" reported-display-style="strikethrough" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>DHS Cyber Incident Response Teams Act of 2018</short-title></quote>.</text> </section><section changed="deleted" committee-id="SSGA00" id="H3B592926D12947E7B5C71794D18D6812" reported-display-style="strikethrough"><enum>2.</enum><header>Department of Homeland Security cyber incident response teams</header> <subsection id="H03CD2880BCA3458EB55AD9450BFE97F6"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>) is amended—</text>
 <paragraph id="H092745598A7E4B69A9C7CB5DAD2943AE"><enum>(1)</enum><text>in subsection (d)(1)(B)(iv), by inserting <quote>, including cybersecurity specialists</quote> after <quote>entities</quote>;</text> </paragraph><paragraph id="H9CE982B96A264A1BAB2C7A70186F8E0F"><enum>(2)</enum><text>by redesignating subsections (f) through (m) as subsections (g) through (n), respectively;</text>
 </paragraph><paragraph id="HAD01CDFFFA0F4088A714F4C6CA096E39"><enum>(3)</enum><text>by inserting after subsection (e) the following:</text> <quoted-block changed="deleted" committee-id="SSGA00" display-inline="no-display-inline" id="H8DF4517C88074B8CBE1F5952D2E3DE35" reported-display-style="strikethrough" style="OLC"> <subsection id="H4EA05A7952684C8A9F68F4ADCA6E39F4"><enum>(f)</enum><header>Cyber incident response teams</header> <paragraph id="H2706D65067584FEDB4F2D8B76AE0747A"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Center shall maintain cyber hunt and incident response teams for the purpose of providing, as appropriate and upon request, assistance, including—</text>
 <subparagraph id="H25405A2861034B108A3EE71546C26FC3"><enum>(A)</enum><text>assistance to asset owners and operators in restoring services following a cyber incident;</text> </subparagraph><subparagraph id="H6112BAB7EFB24C798618F6A531D6CE5C"><enum>(B)</enum><text>identification of cybersecurity risk and unauthorized cyber activity;</text>
 </subparagraph><subparagraph id="HE87B54C932C64EB096855FCAF628A3A9"><enum>(C)</enum><text>mitigation strategies to prevent, deter, and protect against cybersecurity risks;</text> </subparagraph><subparagraph id="H4D55BC920D6C468A954AAF63D20C49E4"><enum>(D)</enum><text>recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate; and</text>
 </subparagraph><subparagraph id="H1390071C25284B1FBD924EBD39F9F612"><enum>(E)</enum><text>such other capabilities as the Under Secretary appointed under section 103(a)(1)(H) determines appropriate.</text>
 </subparagraph></paragraph><paragraph id="H84FF62939D9C4E979A027A6711C12830"><enum>(2)</enum><header>Cybersecurity specialists</header><text display-inline="yes-display-inline">The Secretary may include cybersecurity specialists from the private sector on cyber hunt and incident response teams.</text>
 </paragraph><paragraph id="HDD61392183EB450ABC8ADE8A03A7937B"><enum>(3)</enum><header>Associated metrics</header><text display-inline="yes-display-inline">The Center shall continually assess and evaluate the cyber incident response teams and the operations of those cyber incident response teams using robust metrics.</text>
 </paragraph><paragraph id="H0C908091CB3443118A61A06C46A4EFC6"><enum>(4)</enum><header>Report</header><text display-inline="yes-display-inline">At the conclusion of each of the first 4 fiscal years after the date of the enactment of this subsection, the Center shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report that includes—</text>
 <subparagraph id="id7B7FCED4E5F2465692DB1C787508B050"><enum>(A)</enum><text display-inline="yes-display-inline">information relating to the metrics used for evaluation and assessment of the cyber incident response teams and operations under paragraph (3), including the resources and staffing of those cyber incident response teams; and</text>
 </subparagraph><subparagraph id="id36A859520B914FED9DABCAD043DDEDF7"><enum>(B)</enum><text display-inline="yes-display-inline">for the period covered by the report—</text> <clause id="H1252643E54EF4A42B8D7308839A45998"><enum>(i)</enum><text>the total number of incident response requests received;</text>
 </clause><clause id="HA05318810EBF43BEA3228E3D2AF05DF4"><enum>(ii)</enum><text>the number of incident response tickets opened; and</text> </clause><clause id="H1F99B812D8ED475CA9F5CA4682B05B15"><enum>(iii)</enum><text>a statement of—</text>
 <subclause id="idC01071A135274BDDA7DED016BD591631"><enum>(I)</enum><text>all interagency staffing of incident response teams; and</text> </subclause><subclause id="H996E965F821C49BBBE3F35BFA651E9C4"><enum>(II)</enum><text>the interagency collaborations established to support incident response teams.</text></subclause></clause></subparagraph></paragraph></subsection><after-quoted-block>; and</after-quoted-block></quoted-block>
 </paragraph><paragraph id="H39DBF6417ECC444BBA3ED1B6650C4C7F"><enum>(4)</enum><text>in subsection (g), as so redesignated—</text> <subparagraph id="HD93928C3ABA1499DBC635E425E0C6C7F"><enum>(A)</enum><text>in paragraph (1), by inserting <quote>, or any team or activity of the Center,</quote> after <quote>Center</quote>; and</text>
 </subparagraph><subparagraph id="HDF1C3369BE7A44DC84289F8C6B753CEF"><enum>(B)</enum><text>in paragraph (2), by inserting <quote>, or any team or activity of the Center,</quote> after <quote>Center</quote>.</text> </subparagraph></paragraph></subsection><subsection id="HA2D5F35FA00A4F4A87DF82D7BE79FB10"><enum>(b)</enum><header>No additional funds authorized</header><text display-inline="yes-display-inline">No additional funds are authorized to be appropriated to carry out the requirements of this Act and the amendments made by this Act. Such requirements shall be carried out using amounts otherwise authorized to be appropriated.</text></subsection></section></legis-body>
	<legis-body display-enacting-clause="no-display-enacting-clause" style="OLC">
 <section changed="added" committee-id="SSGA00" id="ida12234f2-378f-4e9a-b19e-e25d4fa5cc85" reported-display-style="italic" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>DHS Cyber Incident Response Teams Act of 2018</short-title></quote>.</text> </section><section changed="added" committee-id="SSGA00" id="id10d32b1c-295f-42c9-ab01-f98d5d8b81a3" reported-display-style="italic"><enum>2.</enum><header>Department of Homeland Security cyber hunt and incident response teams</header> <subsection id="id48ebcff3-df8f-4761-8868-e34540862ca0"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Section 227 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/148">6 U.S.C. 148</external-xref>) is amended—</text>
 <paragraph id="id7aea465a-d2aa-41b4-b96f-81354c7beab2"><enum>(1)</enum><text>in subsection (d)(1)(B)(iv), by inserting <quote>, including cybersecurity specialists</quote> after <quote>entities</quote>;</text> </paragraph><paragraph id="id91b198f0-1e51-44fb-be49-7fc5726ec76d"><enum>(2)</enum><text>by redesignating subsections (f) through (m) as subsections (g) through (n), respectively;</text>
 </paragraph><paragraph id="id8014880d-feb3-48c9-882e-f38803b0f7a6"><enum>(3)</enum><text>by inserting after subsection (e) the following:</text> <quoted-block changed="added" committee-id="SSGA00" display-inline="no-display-inline" id="idbaa4e705-c51e-429e-a194-700bdab3f533" reported-display-style="italic" style="OLC"> <subsection id="id3cfe3934-f907-491a-9417-feb3df57dc52"><enum>(f)</enum><header>Cyber hunt and incident response teams</header> <paragraph id="idb069af24-15d4-45a8-8ced-d64b1eb41e68"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Center shall maintain cyber hunt and incident response teams for the purpose of leading Federal asset response activities and providing timely technical assistance to Federal and non-Federal entities, including across all critical infrastructure sectors, regarding actual or potential security incidents, as appropriate and upon request, including—</text>
 <subparagraph id="id9d06994b-2619-43b5-b3ad-aebd05ba186e"><enum>(A)</enum><text>assistance to asset owners and operators in restoring services following a cyber incident;</text> </subparagraph><subparagraph id="id6dd5a13f-1ee8-497e-ac6c-85d13e8676e3"><enum>(B)</enum><text>identification and analysis of cybersecurity risk and unauthorized cyber activity;</text>
 </subparagraph><subparagraph id="id4498e088-d1da-48cf-bad0-2e47ae83a41d"><enum>(C)</enum><text>mitigation strategies to prevent, deter, and protect against cybersecurity risks;</text> </subparagraph><subparagraph id="id00202610-9989-4841-af6e-6c2b54aca2f0"><enum>(D)</enum><text>recommendations to asset owners and operators for improving overall network and control systems security to lower cybersecurity risks, and other recommendations, as appropriate; and</text>
 </subparagraph><subparagraph id="id4037577a-14c5-4826-b56f-6fe05eaa2dc7"><enum>(E)</enum><text>such other capabilities as the Secretary determines appropriate.</text>
 </subparagraph></paragraph><paragraph id="id5ce08258-f693-4468-bfb8-f91c2972555a"><enum>(2)</enum><header>Associated metrics</header><text display-inline="yes-display-inline">The Center shall continually assess and evaluate the cyber hunt and incident response teams and the operations of those cyber hunt and incident response teams using robust metrics.</text>
 </paragraph><paragraph id="id3ae116ef-0f02-43fb-acd2-d966b1bcf93c"><enum>(3)</enum><header>Report</header><text display-inline="yes-display-inline">At the conclusion of each of the first 4 fiscal years after the date of enactment of the <short-title>DHS Cyber Incident Response Teams Act of 2018</short-title>, the Center shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report that includes—</text>
 <subparagraph id="idec78920f-ad48-43c9-b5dd-b543a53ac369"><enum>(A)</enum><text display-inline="yes-display-inline">information relating to the metrics used for evaluation and assessment of the cyber hunt and incident response teams and operations under paragraph (2), including the resources and staffing of those cyber hunt and incident response teams; and</text>
 </subparagraph><subparagraph id="id57bd97e0-41ae-4c53-8101-a5da1a983486"><enum>(B)</enum><text display-inline="yes-display-inline">for the period covered by the report—</text> <clause id="id4b32a32b-2a30-4bc4-b7c5-16b84e5cf3f4"><enum>(i)</enum><text>the total number of incident response requests received;</text>
 </clause><clause id="id307ef1dd-539d-4026-b15b-87d7e791b507"><enum>(ii)</enum><text>the number of incident response tickets opened; and</text> </clause><clause id="idd2fa8da6-f05c-4a83-b831-d0f3c021040d"><enum>(iii)</enum><text>a statement of—</text>
 <subclause id="id9f97b887-14bf-4b00-ac78-8b9f4335ad7a"><enum>(I)</enum><text>all interagency staffing of cyber hunt and incident response teams; and</text> </subclause><subclause id="idc38b9613-6a89-4076-bebf-6e548e3bc5ec"><enum>(II)</enum><text>the interagency collaborations established to support cyber hunt and incident response teams.</text>
 </subclause></clause></subparagraph></paragraph><paragraph id="id9CDCDFAA5A8B4BFE9A7520F8B7735CA8"><enum>(4)</enum><header>Cybersecurity specialists</header><text>After notice to, and with the approval of, the entity requesting action by or technical assistance from the Center, the Secretary may include cybersecurity specialists from the private sector on a cyber hunt and incident response team.</text></paragraph></subsection><after-quoted-block>; and</after-quoted-block></quoted-block>
 </paragraph><paragraph id="id5aa34e09-83f7-4e14-a895-9063965d3216"><enum>(4)</enum><text>in subsection (g), as so redesignated—</text> <subparagraph id="id6632c4cc-9765-4902-8b59-1cc885054a9e"><enum>(A)</enum><text>in paragraph (1), by inserting <quote>, or any team or activity of the Center,</quote> after <quote>Center</quote>; and</text>
 </subparagraph><subparagraph id="idb88d9d53-a259-4747-b705-73f03282dd8c"><enum>(B)</enum><text>in paragraph (2), by inserting <quote>, or any team or activity of the Center,</quote> after <quote>Center</quote>.</text> </subparagraph></paragraph></subsection><subsection id="idc121dc2f-5518-4d0d-bcb0-c20bb561e419"><enum>(b)</enum><header>No additional funds authorized</header><text display-inline="yes-display-inline">No additional funds are authorized to be appropriated to carry out the requirements of this Act and the amendments made by this Act. Such requirements shall be carried out using amounts otherwise authorized to be appropriated.</text></subsection></section></legis-body><endorsement><action-date>December 4, 2018</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill>


