<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 S429 IS: Cyber Security Exchange Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2019-02-07</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>116th CONGRESS</congress><session>1st Session</session>
		<legis-num>S. 429</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20190207">February 7, 2019</action-date>
			<action-desc><sponsor name-id="S311">Ms. Klobuchar</sponsor> (for herself and <cosponsor name-id="S303">Mr. Thune</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To require the establishment of exchange programs relating to cybersecurity positions between the
			 private sector and certain Federal agencies, and for other purposes.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header>
 <text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Security Exchange Act</short-title></quote>.</text>
		</section><section id="id260310F6353944BA9EB4F4524475A7A4"><enum>2.</enum><header>Cybersecurity professional exchange programs</header>
			<subsection id="idECBCFEF6E42E464983480B2256AA7F79"><enum>(a)</enum><header>Establishment of programs</header>
				<paragraph id="id6DD275818A194AC39C6FC135E4703E6C"><enum>(1)</enum><header>Reports to Congress</header>
 <subparagraph id="id69B8EB7AAA924676A1912C66EBD6ACAB"><enum>(A)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Director of National Intelligence, the Secretary of Defense, the Secretary of Homeland Security, the Secretary of Energy, and the Attorney General shall each submit to the appropriate committees of Congress with respect to that agency head a report that contains—</text>
 <clause id="id4A8DEEC6AC124A28B9E38EC3D11D3146"><enum>(i)</enum><text>a plan and timeline for implementing the program described in paragraph (2) at the agency (or, in the case of the Director of National Intelligence, at an element of the intelligence community); and</text>
 </clause><clause id="idC793BD20EBCC4BD295E2D34A3D806E5A"><enum>(ii)</enum><text>an evaluation of the benefits to the agency (or, in the case of the Director of National Intelligence, to an element of the intelligence community) from the establishment of the program described in paragraph (2).</text>
 </clause></subparagraph><subparagraph id="id9F1749F9107740D4B12289604B5C606E"><enum>(B)</enum><header>Inability to establish program</header><text>If an agency head described in subparagraph (A) determines that the agency head is unable to establish the program required under paragraph (2) at the agency (or, in the case of the Director of National Intelligence, at an element of the intelligence community), the agency head shall submit to Congress a notification that describes—</text>
 <clause id="id50C941014820445995835F36EAF377D8"><enum>(i)</enum><text>the legal basis for that inability; and</text> </clause><clause commented="no" display-inline="no-display-inline" id="id4C4C3044CD1646F7957517B3620245F9"><enum>(ii)</enum><text>any other specific factor that prevents the establishment of the program.</text>
 </clause></subparagraph></paragraph><paragraph id="idD8599350611747C9ACE0DC82227EDF3C"><enum>(2)</enum><header>Establishment</header><text>Except in the case of a determination made under paragraph (1)(B), not later than 180 days after the date on which each agency head described in paragraph (1)(A) submits the report required under that paragraph, the agency head shall, after consultation with the Director of the Office of Personnel Management, establish a voluntary exchange program between the applicable agency (or, with respect to the Director of National Intelligence, an element of the intelligence community) and private sector institutions, under which—</text>
 <subparagraph id="idE9C80B245EFF452AB31266194D90FB1C"><enum>(A)</enum><text>a covered individual who is an employee of the agency, or of an element of the intelligence community, as applicable—</text>
 <clause id="id47AC293DE5254EF388171035D761D4D0"><enum>(i)</enum><text>may elect to be temporarily detailed to a private sector institution that has elected to receive the covered individual; and</text>
 </clause><clause id="idB53F3A31A13C41CCBAF88807C660BB0E"><enum>(ii)</enum><text>during the period of detail described in clause (i), shall be considered to be on detail to a regular work assignment in that agency or element for all purposes; and</text>
 </clause></subparagraph><subparagraph id="idC90EEA6EB8AB45BF881D485056F332E8"><enum>(B)</enum><text>a covered individual who is an employee of a private sector institution—</text> <clause id="id5D9D7E317D194E879776A3E7B1FE964C"><enum>(i)</enum><text>may elect to be temporarily detailed to the agency or element—</text>
 <subclause id="idE1859D7C3BB84F90B5378D2DDAED8B85"><enum>(I)</enum><text>if the agency or element has elected to receive the covered individual; and</text>
 </subclause><subclause id="idD3AB66FAEB934C3B8B2F12139A3A419E"><enum>(II)</enum><text>for a period of not shorter than 90 days and not longer than 2 years; and</text> </subclause></clause><clause id="idC38D3F0717774D1ABAA27159AD89FB4A"><enum>(ii)</enum><text>during the period of detail described in clause (i)(II), shall—</text>
 <subclause id="id13D8D90B535A4FDDA3736AC4AE745DB0"><enum>(I)</enum><text>receive from the private sector institution financial compensation, benefits, and any other type of compensation or support otherwise provided by or through the private sector institution during the course of the employment of the covered individual with the private sector institution; and</text>
 </subclause><subclause id="id5C1D2C72A26A43CF893E2A22DB4FA4A3"><enum>(II)</enum><text>be considered to be an employee of the private sector institution, and not of the agency or element, for all purposes.</text>
 </subclause></clause></subparagraph></paragraph></subsection><subsection id="id1FFD3E9316F946A0942E1024646A834A"><enum>(b)</enum><header>Rules of construction</header><text>Nothing in this Act may be construed to—</text> <paragraph id="idB7476CD2F96D49B0870C8A6CAFA4AEAC"><enum>(1)</enum><text>modify or otherwise affect any program that is in effect on the day before the date of enactment of this Act; or</text>
 </paragraph><paragraph id="id8AFF470A67A445E6BB2512DA9C28F100"><enum>(2)</enum><text>prevent a covered individual who is detailed under subsection (a)(2)(B) from serving as an instructor at an institution of higher education or a research institution during that period of detail.</text>
 </paragraph></subsection><subsection id="id2FCF98D2DDC740F59A92C235A47D3F3E"><enum>(c)</enum><header>Definitions</header><text>In this section—</text> <paragraph id="id18544436632D41208D97DA4548A4A714"><enum>(1)</enum><text>the term <term>appropriate committees of Congress</term> means—</text>
 <subparagraph id="id3B4D3D1398F142C197E080A74BB8ACAB"><enum>(A)</enum><text>with respect to the Director of National Intelligence—</text> <clause id="idC175E154D2F74D3C8842A8F64F5A6723"><enum>(i)</enum><text>the Select Committee on Intelligence of the Senate; and</text>
 </clause><clause commented="no" display-inline="no-display-inline" id="idDDEEAAE83DEC4CCF853426604860D24C"><enum>(ii)</enum><text>the Permanent Select Committee on Intelligence of the House of Representatives;</text> </clause></subparagraph><subparagraph id="id52FE79A349E045CEB65E182BA257A60D"><enum>(B)</enum><text>with respect to the Secretary of Defense—</text>
 <clause id="idB4BDF7644FAD46FDA08DCBF730CFC600"><enum>(i)</enum><text>the Committee on Armed Services of the Senate; and</text> </clause><clause id="id25028D415DFC48CFA81D9D7E7BB2ABBD"><enum>(ii)</enum><text>the Committee on Armed Services of the House of Representatives;</text>
 </clause></subparagraph><subparagraph id="id73BD11DB74C345C99EAEC5BB04A19328"><enum>(C)</enum><text>with respect to the Secretary of Homeland Security—</text> <clause id="id849DD0CCA63A45809A67590D17A6146B"><enum>(i)</enum><text>the Committee on Homeland Security and Governmental Affairs of the Senate; and</text>
 </clause><clause commented="no" display-inline="no-display-inline" id="idC23E0C53089B418EB88ABD4DC4DAE6DB"><enum>(ii)</enum><text>the Committee on Oversight and Reform of the House of Representatives;</text> </clause></subparagraph><subparagraph id="idA5DB332F60A049C79DEE7050E5070291"><enum>(D)</enum><text>with respect to the Secretary of Energy—</text>
 <clause id="id51F6E51A41084ADC8A28112F5C389FBF"><enum>(i)</enum><text>the Committee on Armed Services of the Senate;</text> </clause><clause id="idAB5D9552BEDB48628AAD08EBA480C436"><enum>(ii)</enum><text>the Committee on Energy and Natural Resources of the Senate;</text>
 </clause><clause id="idE240BA9B5ED9495A9999EDBE7AF0FBDE"><enum>(iii)</enum><text>the Committee on Armed Services of the House of Representatives; and</text> </clause><clause id="idDF408D31FBD84E4380F7A9D4DE423DA4"><enum>(iv)</enum><text>the Committee on Energy and Commerce of the House of Representatives; and</text>
 </clause></subparagraph><subparagraph id="id7238E127B2B24F8AA2A98DA923F99D83"><enum>(E)</enum><text>with respect to the Attorney General—</text> <clause id="id1377D9B125C742038B19253801515FFB"><enum>(i)</enum><text>the Committee on the Judiciary of the Senate; and</text>
 </clause><clause commented="no" display-inline="no-display-inline" id="id926152C2072E479092168E2A95A7F5E5"><enum>(ii)</enum><text>the Committee on the Judiciary of the House of Representatives;</text> </clause></subparagraph></paragraph><paragraph id="id4D6632C92EEC4615A652D5EC7DD3180A"><enum>(2)</enum><text>the term <term>covered individual</term> means an individual who has demonstrated expertise and work experience in cybersecurity or a related discipline;</text>
 </paragraph><paragraph id="idE1C89B3CDDB34995B3CC5B35B3611F77"><enum>(3)</enum><text>the term <term>cybersecurity or a related discipline</term>—</text> <subparagraph id="id2331CB4D6E3A4F4BB7C4AEFE4AE7B7AD"><enum>(A)</enum><text>means a discipline relating to cybersecurity; and</text>
 </subparagraph><subparagraph id="id032D4867EA5F4DA9870892858F0D7FC3"><enum>(B)</enum><text>includes—</text> <clause id="idD3F802CD8DEC4BED99DC5B9771CA358C"><enum>(i)</enum><text>a field or discipline relating to—</text>
 <subclause id="id8090AB4B8BCD4B6E91E84EE808A3DC2A"><enum>(I)</enum><text>intrusion detection;</text> </subclause><subclause id="idA15B963E9035479E9E9A895B952FC35A"><enum>(II)</enum><text>secure software development;</text>
 </subclause><subclause id="idC4F7193C1FEA4286A64DAF7847BE7E9B"><enum>(III)</enum><text>attack mitigation;</text> </subclause><subclause id="idED9A7E10089C4B50936F12AF6ED07191"><enum>(IV)</enum><text>system administration;</text>
 </subclause><subclause id="id8AE60F898B3D4BDD80A0DE53338DA10E"><enum>(V)</enum><text>network services;</text> </subclause><subclause id="id1A4211A5CB4B47D4A59583878C425569"><enum>(VI)</enum><text>operating systems;</text>
 </subclause><subclause id="id52FBF3AD63B44905A8BCA0C2A57D6883"><enum>(VII)</enum><text>software application;</text> </subclause><subclause id="id0AD7D786A7884EB485CD68D24DBB2D76"><enum>(VIII)</enum><text>enterprise architecture;</text>
 </subclause><subclause id="idC378481893434365A52CC10B53CDBC50"><enum>(IX)</enum><text>internet services;</text> </subclause><subclause id="id8ABB256D352F4D53856BD237130EA591"><enum>(X)</enum><text>data management;</text>
 </subclause><subclause id="id2ED62C203B6646EE8CDB684E6F47E297"><enum>(XI)</enum><text>system analysis; or</text> </subclause><subclause id="idD79C9D50DE404D9B89E187FFF5A297AD"><enum>(XII)</enum><text>malware analysis; and</text>
 </subclause></clause><clause id="idCD16D6ACDE1E40659DBB81EF50A928AA"><enum>(ii)</enum><text>any other field or discipline that the Director of National Intelligence, the Secretary of Defense, the Secretary of Homeland Security, the Secretary of Energy, or the Attorney General determines appropriate for the purposes of the applicable program established by that agency head under subsection (a)(2);</text>
 </clause></subparagraph></paragraph><paragraph id="id5520552ACD4A43E298C9E064824215F8"><enum>(4)</enum><text>the term <term>institution of higher education</term> has the meaning given the term in section 101 of the Higher Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/1001">20 U.S.C. 1001</external-xref>);</text>
 </paragraph><paragraph id="id8733CF479B814896BB79F92B8C042FB2"><enum>(5)</enum><text>the term <term>intelligence community</term> has the meaning given the term in section 3 of the National Security Act of 1947 (<external-xref legal-doc="usc" parsable-cite="usc/50/3003">50 U.S.C. 3003</external-xref>); and</text>
 </paragraph><paragraph id="id27BCDB0B23F64D76A3CB20961E44082A"><enum>(6)</enum><text>the term <term>private sector institution</term> includes—</text> <subparagraph id="idEE7FFF63AA2942B68AC7577A8E0F3CFF"><enum>(A)</enum><text>a nonpublic or commercial person or business;</text>
 </subparagraph><subparagraph id="idA82A3EAA2CB9409AA83805315E3A551D"><enum>(B)</enum><text>a research institution;</text> </subparagraph><subparagraph id="idAAE98FC6D0F44327A01C4C187E981976"><enum>(C)</enum><text>an institution of higher education; and</text>
 </subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idBD64FA288E79454E8C3EA49287480052"><enum>(D)</enum><text>any other institution that the Director of National Intelligence, the Secretary of Defense, the Secretary of Homeland Security, the Secretary of Energy, or the Attorney General determines appropriate for the purposes of the applicable program established by that agency head under subsection (a)(2).</text></subparagraph></paragraph></subsection></section></legis-body>
</bill>


