<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H6DBB3599CE034E8ABFD965EA3A3E9833" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 HR 5394 IH: Strengthening State and Local Cybersecurity Defenses Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2019-12-11</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">116th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 5394</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20191211">December 11, 2019</action-date><action-desc><sponsor name-id="T000479">Mr. Taylor</sponsor> (for himself, <cosponsor name-id="R000575">Mr. Rogers of Alabama</cosponsor>, <cosponsor name-id="H001073">Mr. Hurd of Texas</cosponsor>, <cosponsor name-id="P000613">Mr. Panetta</cosponsor>, <cosponsor name-id="G000553">Mr. Green of Texas</cosponsor>, <cosponsor name-id="G000591">Mr. Guest</cosponsor>, and <cosponsor name-id="S001208">Ms. Slotkin</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name>, and in addition to the Committee on <committee-name committee-id="HGO00">Oversight and Reform</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such
			 provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend the Homeland Security Act of 2002 to require certain coordination between the Department
			 of Homeland Security and Federal and non-Federal entities relating to
			 cybersecurity risks and incidents, and for other purposes.</official-title></form>
	<legis-body id="H87C6561B15AF40D5BB8F71DB3555D3D5" style="OLC">
 <section id="H4A99141E3E69460C9938F66A197CC138" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Strengthening State and Local Cybersecurity Defenses Act</short-title></quote>.</text> </section><section id="H2886FCFB122B4870A5D05F8E925F3792"><enum>2.</enum><header>Cooperation relating to cybersecurity risks and incidents</header><text display-inline="no-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/652">6 U.S.C. 652</external-xref> et seq.) is amended—</text>
 <paragraph id="H558B5FC1943E4AD285922606F6F89AFD"><enum>(1)</enum><text>in section 2201 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651</external-xref>)—</text> <subparagraph id="HDF7A54F832994D008F785231A5ABB82E"><enum>(A)</enum><text>by redesignating paragraphs (4), (5), and (6) as paragraphs (5), (6), and (7), respectively; and</text>
 </subparagraph><subparagraph id="HD0BCE791C9624A0DA40E6F4E9EC66F69"><enum>(B)</enum><text>by inserting after paragraph (3) the following new paragraph:</text> <quoted-block display-inline="no-display-inline" id="H476973AE5B82436EACD543DE15661478" style="OLC"> <paragraph id="H63C6375804C34A84832D9DDD77E66FEB"><enum>(4)</enum><header>Entity</header><text>The term <quote>entity</quote> includes—</text>
 <subparagraph id="H6348DB68DCA049558256AB9E991A5939"><enum>(A)</enum><text>an association, corporation, whether for-profit or nonprofit, partnership, proprietorship, organization, institution, establishment, or individual, whether domestic or foreign;</text>
 </subparagraph><subparagraph id="H4240D7D507D84D2D82C80B27AC31F97D"><enum>(B)</enum><text>a government agency or other governmental entity, whether domestic or foreign, including State, local, Tribal, and territorial government entities; and</text>
 </subparagraph><subparagraph id="H1D332EC8C9B34E6CAB52A17DF6547659"><enum>(C)</enum><text>the general public.</text></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block> </subparagraph></paragraph><paragraph id="H67ED224E8DDB497AAF9C3F25D95B9AF3"><enum>(2)</enum><text display-inline="yes-display-inline">in section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>), by adding at the end the following new subsection:</text>
				<quoted-block display-inline="no-display-inline" id="H18C5DD10189C42F2B71D2F275D407DA1" style="OLC">
 <subsection id="H3AACFD0AF6A84FE3AA45DAC0154AE6F4"><enum>(n)</enum><header>Coordination</header><text>The Director shall, to the extent practicable, and in coordination as appropriate with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center—</text>
 <paragraph id="HD453C351BC3643788A30B1CF0CBEFD70"><enum>(1)</enum><text>conduct exercises with Federal and non-Federal entities;</text> </paragraph><paragraph id="HA1FEDF62A5164060965317E249A51A2F"><enum>(2)</enum><text>provide operational and technical cybersecurity training related to cyber threat indicators, defensive measures, cybersecurity risks, and incidents to Federal and non-Federal entities to address cybersecurity risks or incidents, with or without reimbursement;</text>
 </paragraph><paragraph id="H675E0DE4B2324D2DAC56BBA15D2143C4"><enum>(3)</enum><text>assist Federal and non-Federal entities, upon request, in sharing cyber threat indicators, defensive measures, cybersecurity risks, and incidents from and to the Federal Government as well as among Federal and non-Federal entities, in order to increase situational awareness and help prevent incidents;</text>
 </paragraph><paragraph id="HE05B49BF49A44D2FA5A1F3201025DAF7"><enum>(4)</enum><text>provide Federal and non-Federal entities timely notifications containing specific incident and malware information that may affect such entities or individuals with respect to whom such entities have a relationship;</text>
 </paragraph><paragraph id="HC773E87C4C2F4BC5BA3117FCBD4C07AF"><enum>(5)</enum><text>provide and periodically update via a web portal and other means tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security;</text>
 </paragraph><paragraph id="H3347AAF8044042B2A400B00640079842"><enum>(6)</enum><text display-inline="yes-display-inline">work with senior Federal and non-Federal officials, including State and local Chief Information Officers, senior election officials, and through national associations, to coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security to secure and ensure the resiliency of Federal and non-Federal information systems, including election systems;</text>
 </paragraph><paragraph id="H5996A1716DE548A59F38B42DFBEF56A7"><enum>(7)</enum><text display-inline="yes-display-inline">provide, upon request, operational and technical assistance to Federal and non-Federal entities to implement tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security, including by, as appropriate, deploying and sustaining cybersecurity technologies, such as an intrusion detection capability, to assist such Federal and non-Federal entities in detecting cybersecurity risks and incidents;</text>
 </paragraph><paragraph id="H6DD0766BA0A9418196EC4175A5416431"><enum>(8)</enum><text>assist Federal and non-Federal entities in developing policies and procedures for coordinating vulnerability disclosures, to the extent practicable, consistent with international and national standards in the information technology industry;</text>
 </paragraph><paragraph id="H6FED1C2BCBAB478796E2D32143A087C8"><enum>(9)</enum><text display-inline="yes-display-inline">ensure that Federal and non-Federal entities, as appropriate, are made aware of the tools, products, resources, policies, guidelines, controls, procedures, and other cybersecurity standards and best practices and procedures related to information security developed by the Department and other appropriate Federal entities for ensuring the security and resiliency of civilian information systems; and</text>
 </paragraph><paragraph id="HF9B095B5B2994D26AA1BD5D8832350F1"><enum>(10)</enum><text>promote cybersecurity education and awareness through engagements with Federal and non-Federal entities.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
			</paragraph></section></legis-body></bill>


