<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" bill-type="olc" dms-id="H0D46355917E84BC381CF7389574793BE" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 HR 5823 RH: State and Local Cybersecurity Improvement Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2020-08-18</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">IB</distribution-code><calendar display="yes">Union Calendar No. 384</calendar><congress display="yes">116th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 5823</legis-num><associated-doc role="report" display="yes">[Report No. 116–478]</associated-doc><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20200210">February 10, 2020</action-date><action-desc><sponsor name-id="R000588">Mr. Richmond</sponsor> (for himself, <cosponsor name-id="K000386">Mr. Katko</cosponsor>, <cosponsor name-id="K000381">Mr. Kilmer</cosponsor>, <cosponsor name-id="M001157">Mr. McCaul</cosponsor>, <cosponsor name-id="R000576">Mr. Ruppersberger</cosponsor>, <cosponsor name-id="T000193">Mr. Thompson of Mississippi</cosponsor>, <cosponsor name-id="R000575">Mr. Rogers of Alabama</cosponsor>, <cosponsor name-id="S001208">Ms. Slotkin</cosponsor>, <cosponsor name-id="R000613">Mr. Rose of New York</cosponsor>, <cosponsor name-id="P000604">Mr. Payne</cosponsor>, <cosponsor name-id="W000822">Mrs. Watson Coleman</cosponsor>, <cosponsor name-id="L000559">Mr. Langevin</cosponsor>, <cosponsor name-id="C001061">Mr. Cleaver</cosponsor>, <cosponsor name-id="U000040">Ms. Underwood</cosponsor>, and <cosponsor name-id="T000468">Ms. Titus</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name></action-desc></action><action display="yes"><action-date date="20200818">August 18, 2020</action-date><action-desc>Additional sponsors: <cosponsor name-id="E000215">Ms. Eshoo</cosponsor>, <cosponsor name-id="S001185">Ms. Sewell of Alabama</cosponsor>, and <cosponsor name-id="J000032">Ms. Jackson Lee</cosponsor></action-desc></action><action display="yes"><action-date date="20200818">August 18, 2020</action-date><action-desc>Reported with an amendment; committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction><action-instruction>For text of introduced bill, see copy of bill as introduced on February 10, 2020</action-instruction></action><action><action-desc><pagebreak></pagebreak></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To establish a program to make grants to States to address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments, and for other purposes.<pagebreak></pagebreak></official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause" changed="added" style="OLC" committee-id="HHM00" reported-display-style="italic" id="H8012BF0DACAC44AA945DE8981549AB7C"><section id="H6F77E9B5E5624ED18BD9A734E3D95F0C" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>State and Local Cybersecurity Improvement Act</short-title></quote>.</text></section><section id="H2CA1055E0DCD467C891F316C2C4BE987"><enum>2.</enum><header>State and Local Cybersecurity Grant Program</header><subsection commented="no" id="H28E181965E134049B893FA93A09097B9"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651</external-xref> et seq.) is amended by adding at the end the following new sections:</text><quoted-block id="H1B7ED5D6E2ED4C749866144491D7568E" style="OLC" changed="added" reported-display-style="italic" committee-id="HHM00"><section commented="no" id="H708DCD29904C4CB595421D6185D04CF8"><enum>2215.</enum><header>State and Local Cybersecurity Grant Program</header><subsection commented="no" id="H957F86E6C23243F9AAB1C843662656C6"><enum>(a)</enum><header>Establishment</header><text>The Secretary, acting through the Director, shall establish a program to make grants to States to address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments (referred to as the <quote>State and Local Cybersecurity Grant Program</quote> in this section).</text></subsection><subsection commented="no" id="H8BD6A34FD0344E75AAA459591FEC3098"><enum>(b)</enum><header>Baseline requirements</header><text>A grant awarded under this section shall be used in compliance with the following:</text><paragraph commented="no" id="HE6B3359C170241DCA3CCE9435B1F1B64"><enum>(1)</enum><text>The Cybersecurity Plan required under subsection (d) and approved pursuant to subsection (g).</text></paragraph><paragraph commented="no" id="H1DE5A1BEC3A447B2B9F9F07DA5107B86"><enum>(2)</enum><text>The Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments required in accordance with section 2210, when issued.</text></paragraph></subsection><subsection commented="no" id="H900461ECFA61490FA15BC71B7A26560B"><enum>(c)</enum><header>Administration</header><text display-inline="yes-display-inline">The State and Local Cybersecurity Grant Program shall be administered in the same program office that administers grants made under sections 2003 and 2004.</text></subsection><subsection commented="no" id="HD914EBDEC8254A10A3825CCDD74E9CD4"><enum>(d)</enum><header>Eligibility</header><paragraph commented="no" id="H893045BFD63940539EF19260E5863445"><enum>(1)</enum><header>In general</header><text>A State applying for a grant under the State and Local Cybersecurity Grant Program shall submit to the Secretary a Cybersecurity Plan for approval. Such plan shall—</text><subparagraph commented="no" id="HF01D5CFDC369421BB34FB2820DF08A9E"><enum>(A)</enum><text>incorporate, to the extent practicable, any existing plans of such State to protect against cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments;</text></subparagraph><subparagraph commented="no" id="HA2C42696D05440F6BBD748CBC5569E5D"><enum>(B)</enum><text>describe, to the extent practicable, how such State shall—</text><clause commented="no" id="HABC5959272E449618E2E1AEF421B0EC2"><enum>(i)</enum><text>enhance the preparation, response, and resiliency of information systems owned or operated by such State or, if appropriate, by local, Tribal, or territorial governments, against cybersecurity risks and cybersecurity threats;</text></clause><clause commented="no" id="H80D9F4ED745B46C58D9C9AB0CD208BCD"><enum>(ii)</enum><text display-inline="yes-display-inline">implement a process of continuous cybersecurity vulnerability assessments and threat mitigation practices prioritized by degree of risk to address cybersecurity risks and cybersecurity threats in information systems of such State, local, Tribal, or territorial governments;</text></clause><clause commented="no" id="H3A328FC409904567925305AD17C6CB0B"><enum>(iii)</enum><text>ensure that State, local, Tribal, and territorial governments that own or operate information systems within the State adopt best practices and methodologies to enhance cybersecurity, such as the practices set forth in the cybersecurity framework developed by the National Institute of Standards and Technology;</text></clause><clause id="H477B201D3F2245F885E5EE31CE293CAE"><enum>(iv)</enum><text display-inline="yes-display-inline">promote the delivery of safe, recognizable, and trustworthy online services by State, local, Tribal, and territorial governments, including through the use of the .gov internet domain;</text></clause><clause commented="no" id="H429129E55485480AA82C87C8718DE5F1"><enum>(v)</enum><text>mitigate any identified gaps in the State, local, Tribal, or territorial government cybersecurity workforces, enhance recruitment and retention efforts for such workforces, and bolster the knowledge, skills, and abilities of State, local, Tribal, and territorial government personnel to address cybersecurity risks and cybersecurity threats;</text></clause><clause commented="no" id="H018887F0FCB045BC9C9F495BE5E4ABC9"><enum>(vi)</enum><text>ensure continuity of communications and data networks within such State between such State and local, Tribal, and territorial governments that own or operate information systems within such State in the event of an incident involving such communications or data networks within such State;</text></clause><clause commented="no" id="HD13F7E670B8849F7B943481133D51F2B"><enum>(vii)</enum><text>assess and mitigate, to the greatest degree possible, cybersecurity risks and cybersecurity threats related to critical infrastructure and key resources, the degradation of which may impact the performance of information systems within such State;</text></clause><clause commented="no" id="H3E79F98524154C78B13732674B88E5BD"><enum>(viii)</enum><text>enhance capability to share cyber threat indicators and related information between such State and local, Tribal, and territorial governments that own or operate information systems within such State; and</text></clause><clause commented="no" id="H060DC416BD284CD1981B4076CAE57FCD"><enum>(ix)</enum><text>develop and coordinate strategies to address cybersecurity risks and cybersecurity threats in consultation with—</text><subclause commented="no" id="H098FD87EE7E14D9B9A76935104AC1F3E"><enum>(I)</enum><text>local, Tribal, and territorial governments within the State; and</text></subclause><subclause commented="no" id="H2BF58FB6AB3D414A976481B25D6D91AA"><enum>(II)</enum><text>as applicable—</text><item commented="no" id="HF5EB6131A1A24C70AE7965AFACB03A18"><enum>(aa)</enum><text>neighboring States or, as appropriate, members of an information sharing and analysis organization; and</text></item><item commented="no" id="H8F4C07C171084BC3BC1DCF0ACFEF8FB4"><enum>(bb)</enum><text>neighboring countries; and</text></item></subclause></clause></subparagraph><subparagraph commented="no" id="HA208DEAB316044C48BCA0A13E0BB22C0"><enum>(C)</enum><text>include, to the extent practicable, an inventory of the information technology deployed on the information systems owned or operated by such State or by local, Tribal, or territorial governments within such State, including legacy information technology that is no longer supported by the manufacturer.</text></subparagraph></paragraph></subsection><subsection commented="no" id="H298A6301CFCB4AF5A327C4CB62D0C59C"><enum>(e)</enum><header>Planning committees</header><paragraph commented="no" id="HD41E370A37B0463BB181830AF92CF160"><enum>(1)</enum><header>In general</header><text>A State applying for a grant under this section shall establish a cybersecurity planning committee to assist in the following:</text><subparagraph commented="no" id="HF60E5F6191B9488A8CA04B5B82335A5A"><enum>(A)</enum><text>The development, implementation, and revision of such State’s Cybersecurity Plan required under subsection (d).</text></subparagraph><subparagraph commented="no" id="H216EFF72051E4F65805417BECF3F0FFD"><enum>(B)</enum><text>The determination of effective funding priorities for such grant in accordance with subsection (f).</text></subparagraph></paragraph><paragraph commented="no" id="H1353555D57D446DD8FA8736D328681DC"><enum>(2)</enum><header>Composition</header><text>Cybersecurity planning committees described in paragraph (1) shall be comprised of representatives from counties, cities, towns, and Tribes within the State receiving a grant under this section, including, as appropriate, representatives of rural, suburban, and high-population jurisdictions.</text></paragraph><paragraph commented="no" id="H5B1FD07944DC4C9A9E78FD3CBB79568C"><enum>(3)</enum><header>Rule of construction regarding existing planning committees</header><text display-inline="yes-display-inline">Nothing in this subsection may be construed to require that any State establish a cybersecurity planning committee if such State has established and uses a multijurisdictional planning committee or commission that meets the requirements of this paragraph.</text></paragraph></subsection><subsection commented="no" id="HB75CCD7C644E443086F3B0659D141F96"><enum>(f)</enum><header>Use of funds</header><text display-inline="yes-display-inline">A State that receives a grant under this section shall use the grant to implement such State’s Cybersecurity Plan, or to assist with activities determined by the Secretary, in consultation with the Director, to be integral to address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments, as the case may be.</text></subsection><subsection commented="no" id="H80A161EC13B64BF5993A2CAE74084003"><enum>(g)</enum><header>Approval of plans</header><paragraph commented="no" id="H5A83CA34459940BDAB9451B14F0185F6"><enum>(1)</enum><header>Approval as condition of grant</header><text>Before a State may receive a grant under this section, the Secretary, acting through the Director, shall review and approve such State’s Cybersecurity Plan required under subsection (d).</text></paragraph><paragraph commented="no" id="HDE6EFC1BFF8E4214AEC3F0405C7CE22C"><enum>(2)</enum><header>Plan requirements</header><text>In approving a Cybersecurity Plan under this subsection, the Director shall ensure such Plan—</text><subparagraph commented="no" id="HDC24FD07CD4640D8B73A74EA9D85E27E"><enum>(A)</enum><text>meets the requirements specified in subsection (d); and</text></subparagraph><subparagraph commented="no" id="H60E7B42C88114A058EBF161B6C483184"><enum>(B)</enum><text>upon issuance of the Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments authorized pursuant to section 2210, complies, as appropriate, with the goals and objectives of such Strategy.</text></subparagraph></paragraph><paragraph commented="no" id="H227180EEE61D4BAC881FEFA7C64DD6EF"><enum>(3)</enum><header>Approval of revisions</header><text display-inline="yes-display-inline">The Secretary, acting through the Director, may approve revisions to a Cybersecurity Plan as the Director determines appropriate.</text></paragraph><paragraph commented="no" id="H76017705DE594965BB262345340D2379"><enum>(4)</enum><header>Exception</header><text>Notwithstanding the requirement under subsection (d) to submit a Cybersecurity Plan as a condition of apply for a grant under this section, such a grant may be awarded to a State that has not so submitted a Cybersecurity Plan to the Secretary if—</text><subparagraph commented="no" id="H78BA36B2EAE14E86AD541A75337837DB"><enum>(A)</enum><text>such State certifies to the Secretary that it will submit to the Secretary a Cybersecurity Plan for approval by September 30, 2022;</text></subparagraph><subparagraph commented="no" id="H2B8E67578938465A862117200A8BD0B2"><enum>(B)</enum><text display-inline="yes-display-inline">such State certifies to the Secretary that the activities that will be supported by such grant are integral to the development of such Cybersecurity Plan; or</text></subparagraph><subparagraph commented="no" id="H1779472406E9475B96189BAE0DE57DB2"><enum>(C)</enum><text>such State certifies to the Secretary, and the Director confirms, that the activities that will be supported by the grant will address imminent cybersecurity risks or cybersecurity threats to the information systems of such State or of a local, Tribal, or territorial government in such State.</text></subparagraph></paragraph></subsection><subsection commented="no" id="HBC9A1D87EE9B4C2BA4F681C0DB83219A"><enum>(h)</enum><header>Limitations on uses of funds</header><paragraph commented="no" id="HCACF6D2497C74A158E72D71781916513"><enum>(1)</enum><header>In general</header><text>A State that receives a grant under this section may not use such grant—</text><subparagraph commented="no" id="H143DE76801D24DB1952DF2EBF83CFF76"><enum>(A)</enum><text>to supplant State, local, Tribal, or territorial funds;</text></subparagraph><subparagraph commented="no" id="HF7FF4A438D0E40309736FB164E7F94E7"><enum>(B)</enum><text>for any recipient cost-sharing contribution;</text></subparagraph><subparagraph commented="no" id="H7F396094FCA641E1A2BA459F4930DDF2"><enum>(C)</enum><text display-inline="yes-display-inline">to pay a demand for ransom in an attempt to regain access to information or an information system of such State or of a local, Tribal, or territorial government in such State;</text></subparagraph><subparagraph commented="no" id="H3692540F7B2F4DEC8BBE1444293021C4"><enum>(D)</enum><text>for recreational or social purposes; or</text></subparagraph><subparagraph commented="no" id="HC27107C9F5334A61863B78489B1A0210"><enum>(E)</enum><text>for any purpose that does not directly address cybersecurity risks or cybersecurity threats on an information systems of such State or of a local, Tribal, or territorial government in such State.</text></subparagraph></paragraph><paragraph commented="no" id="HDD138D47E4414062874EC64F002C189B"><enum>(2)</enum><header>Penalties</header><text>In addition to other remedies available, the Secretary may take such actions as are necessary to ensure that a recipient of a grant under this section is using such grant for the purposes for which such grant was awarded.</text></paragraph></subsection><subsection commented="no" id="H3D02B00D331F4ADD9D462E125F3EDA2F"><enum>(i)</enum><header>Opportunity To amend applications</header><text>In considering applications for grants under this section, the Secretary shall provide applicants with a reasonable opportunity to correct defects, if any, in such applications before making final awards.</text></subsection><subsection commented="no" id="H209364C46BE24415B29D8415EB5D9C71"><enum>(j)</enum><header>Apportionment</header><text>For fiscal year 2020 and each fiscal year thereafter, the Secretary shall apportion amounts appropriated to carry out this section among States as follows:</text><paragraph commented="no" id="HA3185561E18E4516967867C5A93B5FE3"><enum>(1)</enum><header>Baseline amount</header><text>The Secretary shall first apportion 0.25 percent of such amounts to each of American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, and the Virgin Islands, and 0.75 percent of such amounts to each of the remaining States.</text></paragraph><paragraph commented="no" id="HD9FE76AF8EBB49589F1BCB254D0C4A29"><enum>(2)</enum><header>Remainder</header><text>The Secretary shall apportion the remainder of such amounts in the ratio that—</text><subparagraph commented="no" id="H9186EA05FE80466DB611329D334F15F3"><enum>(A)</enum><text>the population of each State; bears to</text></subparagraph><subparagraph commented="no" id="H6140C9CCDA264677B07CA074F0A6B904"><enum>(B)</enum><text>the population of all States.</text></subparagraph></paragraph></subsection><subsection commented="no" id="HF06D83F539164202B91A14B419ADA576"><enum>(k)</enum><header>Federal share</header><text>The Federal share of the cost of an activity carried out using funds made available under the program may not exceed the following percentages:</text><paragraph commented="no" id="H3C627D127D2947E4902B479CFB48EE35"><enum>(1)</enum><text>For fiscal year 2021, 90 percent.</text></paragraph><paragraph commented="no" id="H40BF576D295A47739C717E91AD5E2BFD"><enum>(2)</enum><text>For fiscal year 2022, 80 percent.</text></paragraph><paragraph commented="no" id="HEA9DD6B798BD4E3EA9CC1FEFC6A054A4"><enum>(3)</enum><text>For fiscal year 2023, 70 percent.</text></paragraph><paragraph commented="no" id="H8FD507D66DB14D5FAD9E3E682A4F06AC"><enum>(4)</enum><text>For fiscal year 2024, 60 percent.</text></paragraph><paragraph commented="no" id="H3D81EF88988D436F96DE2CFC31C7F58D"><enum>(5)</enum><text>For fiscal year 2025 and each subsequent fiscal year, 50 percent.</text></paragraph></subsection><subsection commented="no" id="HBB8F1F247A724179B448B27F26F1FEC1"><enum>(l)</enum><header>State responsibilities</header><paragraph commented="no" id="H9BA31923E1A84BE8B8D48AF92C67618A"><enum>(1)</enum><header>Certification</header><text>Each State that receives a grant under this section shall certify to the Secretary that the grant will be used for the purpose for which the grant is awarded and in compliance with the Cybersecurity Plan or other purpose approved by the Secretary under subsection (g).</text></paragraph><paragraph commented="no" id="H08B8E9AB5FC54E59978CB92B5610ACF1"><enum>(2)</enum><header>Availability of funds to local, Tribal, and territorial governments</header><text display-inline="yes-display-inline">Not later than 45 days after a State receives a grant under this section, such State shall, without imposing unreasonable or unduly burdensome requirements as a condition of receipt, obligate or otherwise make available to local, Tribal, and territorial governments in such State, consistent with the applicable Cybersecurity Plan—</text><subparagraph commented="no" id="H7688650ED46F4A98BD58548946BAC772"><enum>(A)</enum><text>not less than 80 percent of funds available under such grant;</text></subparagraph><subparagraph commented="no" id="HC6F09CA5B5524AD5B6520B21891737F1"><enum>(B)</enum><text>with the consent of such local, Tribal, and territorial governments, items, services, capabilities, or activities having a value of not less than 80 percent of the amount of the grant; or</text></subparagraph><subparagraph commented="no" id="HECFACCEA0C7D452696F240166F524204"><enum>(C)</enum><text display-inline="yes-display-inline">with the consent of the local, Tribal, and territorial governments, grant funds combined with other items, services, capabilities, or activities having the total value of not less than 80 percent of the amount of the grant.</text></subparagraph></paragraph><paragraph commented="no" id="H6BEFC413655D43DEBFB72738B2C629D5"><enum>(3)</enum><header>Certifications regarding distribution of grant funds to local, Tribal, territorial governments</header><text>A State shall certify to the Secretary that the State has made the distribution to local, Tribal, and territorial governments required under paragraph (2).</text></paragraph><paragraph commented="no" id="H5A78B5CEDFC14331956FC191F83DD275"><enum>(4)</enum><header>Extension of period</header><text>A State may request in writing that the Secretary extend the period of time specified in paragraph (2) for an additional period of time. The Secretary may approve such a request if the Secretary determines such extension is necessary to ensure the obligation and expenditure of grant funds align with the purpose of the grant program.</text></paragraph><paragraph commented="no" id="HFF29066A4E02493B8ADECDA562102705"><enum>(5)</enum><header>Exception</header><text>Paragraph (2) shall not apply to the District of Columbia, the Commonwealth of Puerto Rico, American Samoa, the Commonwealth of the Northern Mariana Islands, Guam, or the Virgin Islands.</text></paragraph><paragraph commented="no" id="H1C145C2811BC435B979D05F10EC5FF26"><enum>(6)</enum><header>Direct funding</header><text>If a State does not make the distribution to local, Tribal, or territorial governments in such State required under paragraph (2), such a local, Tribal, or territorial government may petition the Secretary.</text></paragraph><paragraph commented="no" id="H6D713074729143638D5B904739C77243"><enum>(7)</enum><header>Penalties</header><text>In addition to other remedies available to the Secretary, the Secretary may terminate or reduce the amount of a grant awarded under this section to a State or transfer grant funds previously awarded to such State directly to the appropriate local, Tribal, or territorial government if such State violates a requirement of this subsection.</text></paragraph></subsection><subsection commented="no" id="H2AB6F14961EA498CAEA1BC9B4ADE61CC"><enum>(m)</enum><header>Advisory committee</header><paragraph commented="no" id="H7E8896EB1633474192D12792B19E14A6"><enum>(1)</enum><header>Establishment</header><text>The Director shall establish a State and Local Cybersecurity Resiliency Committee to provide State, local, Tribal, and territorial stakeholder expertise, situational awareness, and recommendations to the Director, as appropriate, regarding how to—</text><subparagraph commented="no" id="H87B120D30B2946758594424FD9360F38"><enum>(A)</enum><text>address cybersecurity risks and cybersecurity threats to information systems of State, local, Tribal, or territorial governments; and</text></subparagraph><subparagraph commented="no" id="H7308389A777F492EB41FA5D835FB0738"><enum>(B)</enum><text>improve the ability of such governments to prevent, protect against, respond, mitigate, and recover from cybersecurity risks and cybersecurity threats.</text></subparagraph></paragraph><paragraph commented="no" id="HAA89366AA9934DA0B6C850C301195780"><enum>(2)</enum><header>Duties</header><text>The State and Local Cybersecurity Resiliency Committee shall—</text><subparagraph commented="no" id="HAF14F16CF5E54035809F252CFC0D9870"><enum>(A)</enum><text>submit to the Director recommendations that may inform guidance for applicants for grants under this section;</text></subparagraph><subparagraph commented="no" id="HE77D11517868427D91166556A109D218"><enum>(B)</enum><text>upon the request of the Director, provide to the Director technical assistance to inform the review of Cybersecurity Plans submitted by applicants for grants under this section, and, as appropriate, submit to the Director recommendations to improve such Plans prior to the Director’s determination regarding whether to approve such Plans;</text></subparagraph><subparagraph commented="no" id="H1EC1021D3CE946C4A36C6B9F2FBEE840"><enum>(C)</enum><text>advise and provide to the Director input regarding the Homeland Security Strategy to Improve Cybersecurity for State, Local, Tribal, and Territorial Governments required under section 2210; and</text></subparagraph><subparagraph commented="no" id="H6874949966884B1FB59A1DA7E9DE6033"><enum>(D)</enum><text>upon the request of the Director, provide to the Director recommendations, as appropriate, regarding how to—</text><clause commented="no" id="H82D8C48A193F4061BC75B4037D3E4DD4"><enum>(i)</enum><text>address cybersecurity risks and cybersecurity threats on information systems of State, local, Tribal, or territorial governments; and</text></clause><clause commented="no" id="H03F950C16A28433285EFC63DFEAA279E"><enum>(ii)</enum><text>improve the cybersecurity resilience of such governments.</text></clause></subparagraph></paragraph><paragraph commented="no" id="H7E50D1C6B24A42458700A58CB30BC844"><enum>(3)</enum><header>Membership</header><subparagraph commented="no" id="HC0B22F419E1F4C5B89F0769EC7CFC435"><enum>(A)</enum><header>Number and appointment</header><text>The State and Local Cybersecurity Resiliency Committee shall be composed of 15 members appointed by the Director, as follows:</text><clause commented="no" id="H31F6360564A546FC98FB868B45D1E388"><enum>(i)</enum><text>Two individuals recommended to the Director by the National Governors Association.</text></clause><clause commented="no" id="H492959B76B4D476ABCABC1531CC01E9D"><enum>(ii)</enum><text>Two individuals recommended to the Director by the National Association of State Chief Information Officers.</text></clause><clause commented="no" id="H4B8B331B833443E0A1ED5D73D66D1FDA"><enum>(iii)</enum><text>One individual recommended to the Director by the National Guard Bureau.</text></clause><clause commented="no" id="H6139CF4E59DB41B4A1D38458BB229EAD"><enum>(iv)</enum><text>Two individuals recommended to the Director by the National Association of Counties.</text></clause><clause commented="no" id="H278A77FCC7A84BCDAC88760E727C2269"><enum>(v)</enum><text>Two individuals recommended to the Director by the National League of Cities.</text></clause><clause id="H196DA4309BD241E5BD6460B5906DCD61"><enum>(vi)</enum><text display-inline="yes-display-inline">One individual recommended to the Director by the United States Conference of Mayors.</text></clause><clause commented="no" id="H1A1C0160594B481096517B39B28B589E"><enum>(vii)</enum><text>One individual recommended to the Director by the Multi-State Information Sharing and Analysis Center.</text></clause><clause commented="no" id="H6C4809C34E2F4807AF467D0E3BB6D5FB"><enum>(viii)</enum><text>Four individuals who have educational and professional experience related to cybersecurity analysis or policy.</text></clause></subparagraph><subparagraph commented="no" id="H69F82307D37749C8921B5CDE70F13567"><enum>(B)</enum><header>Terms</header><text display-inline="yes-display-inline">Each member of the State and Local Cybersecurity Resiliency Committee shall be appointed for a term of two years, except that such term shall be three years only in the case of members who are appointed initially to the Committee upon the establishment of the Committee. Any member appointed to fill a vacancy occurring before the expiration of the term for which the member’s predecessor was appointed shall be appointed only for the remainder of such term. A member may serve after the expiration of such member’s term until a successor has taken office. A vacancy in the Commission shall be filled in the manner in which the original appointment was made.</text></subparagraph><subparagraph commented="no" id="H5A0EF8AA36944F54B42CA9357C1E10AC"><enum>(C)</enum><header>Pay</header><text display-inline="yes-display-inline">Members of the State and Local Cybersecurity Resiliency Committee shall serve without pay.</text></subparagraph></paragraph><paragraph commented="no" id="H73EE99610C2E48E9BD5FC4ACCCE183EC"><enum>(4)</enum><header>Chairperson; vice chairperson</header><text display-inline="yes-display-inline">The members of the State and Local Cybersecurity Resiliency Committee shall select a chairperson and vice chairperson from among Committee members.</text></paragraph><paragraph commented="no" id="HAE7FB74E3DB04C7F9DF0826F3FFE525F"><enum>(5)</enum><header>Federal advisory committee act</header><text>The Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to the State and Local Cybersecurity Resilience Committee.</text></paragraph></subsection><subsection commented="no" id="HCD7C37A6238949769BBC7FC554ADBDC1"><enum>(n)</enum><header>Reports</header><paragraph commented="no" id="HA13F26FAC81F4A1DB0E6E6944EB8A1A8"><enum>(1)</enum><header>Annual reports by State grant recipients</header><text display-inline="yes-display-inline">A State that receives a grant under this section shall annually submit to the Secretary a report on the progress of the State in implementing the Cybersecurity Plan approved pursuant to subsection (g). If the State does not have a Cybersecurity Plan approved pursuant to subsection (g), the State shall submit to the Secretary a report describing how grant funds were obligated and expended to develop a Cybersecurity Plan or improve the cybersecurity of information systems owned or operated by State, local, Tribal, or territorial governments in such State. The Secretary, acting through the Director, shall make each such report publicly available, including by making each such report available on the internet website of the Agency, subject to any redactions the Director determines necessary to protect classified or other sensitive information.</text></paragraph><paragraph commented="no" id="H9637D7AAF3494D55838601E1CEB605FD"><enum>(2)</enum><header>Annual reports to Congress</header><text display-inline="yes-display-inline">At least once each year, the Secretary, acting through the Director, shall submit to Congress a report on the use of grants awarded under this section and any progress made toward the following:</text><subparagraph commented="no" id="H17DD00BD00DB4F1F92840B818AFC309D"><enum>(A)</enum><text>Achieving the objectives set forth in the Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments, upon the strategy’s issuance under section 2210.</text></subparagraph><subparagraph commented="no" id="HB03B241D691A4B309110AA6C35C89B51"><enum>(B)</enum><text>Developing, implementing, or revising Cybersecurity Plans.</text></subparagraph><subparagraph commented="no" id="HAEBC448912DC45D3B32A1013D8A477AC"><enum>(C)</enum><text>Reducing cybersecurity risks and cybersecurity threats to information systems owned or operated by State, local, Tribal, and territorial governments as a result of the award of such grants.</text></subparagraph></paragraph></subsection><subsection commented="no" id="HAD167E2FBA0740DB9C47C35FB4600A3E"><enum>(o)</enum><header>Authorization of appropriations</header><text>There are authorized to be appropriated for grants under this section—</text><paragraph commented="no" id="H84265644C4964EA6A420B3298E5A2374"><enum>(1)</enum><text>for each of fiscal years 2021 through 2025, $400,000,000; and</text></paragraph><paragraph commented="no" id="H70DE12155A65465FAFB730B22BA2570D"><enum>(2)</enum><text>for each subsequent fiscal year, such sums as may be necessary.</text></paragraph></subsection><subsection commented="no" id="H640CDEA905DC4C1E8148733F5B407EE0"><enum>(p)</enum><header>Definitions</header><text>In this section:</text><paragraph commented="no" id="HA09AF81070BC4A4BB26F92167646A16F"><enum>(1)</enum><header>Critical infrastructure</header><text display-inline="yes-display-inline">The term <quote>critical infrastructure</quote> has the meaning given that term in section 2.</text></paragraph><paragraph commented="no" id="H2229F76C782E4C198701555273F74F1D"><enum>(2)</enum><header>Cyber threat indicator</header><text>The term <quote>cyber threat indicator</quote> has the meaning given such term in section 102 of the Cybersecurity Act of 2015.</text></paragraph><paragraph commented="no" id="H81462DDA229C4E10B826C7E8B2DDBA91"><enum>(3)</enum><header>Director</header><text>The term <quote>Director</quote> means the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph><paragraph commented="no" id="HC295F455816B46DA9B7CB0E5202F7654"><enum>(4)</enum><header>Incident</header><text>The term <quote>incident</quote> has the meaning given such term in section 2209.</text></paragraph><paragraph commented="no" id="HA4BAA6E15B394D36A10215CD2E43604E"><enum>(5)</enum><header>Information sharing and analysis organization</header><text>The term <quote>information sharing and analysis organization</quote> has the meaning given such term in section 2222.</text></paragraph><paragraph commented="no" id="H798E7CC6AA924CA89F5186B46C8854F9"><enum>(6)</enum><header>Information system</header><text display-inline="yes-display-inline">The term <quote>information system</quote> has the meaning given such term in section 102(9) of the Cybersecurity Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501(9)</external-xref>).</text></paragraph><paragraph commented="no" id="H15E985A23CE4402FAEA511F2DE06A2A2"><enum>(7)</enum><header>Key resources</header><text>The term <quote>key resources</quote> has the meaning given that term in section 2.</text></paragraph><paragraph id="H3F56E97D47304598ADEF6B12D677863B"><enum>(8)</enum><header>Online service</header><text display-inline="yes-display-inline">The term <quote>online service</quote> means any internet-facing service, including a website, email, virtual private network, or custom application.</text></paragraph><paragraph commented="no" id="H7906FC5BF8754CA48356D295B5CE7A16"><enum>(9)</enum><header>State</header><text>The term <quote>State</quote>—</text><subparagraph id="HD5B8C7CED584481C8B656015A4AEA03A"><enum>(A)</enum><text>means each of the several States, the District of Colombia, and the territories and possessions of the United States; and</text></subparagraph><subparagraph commented="no" id="HC945618CEA744688A06ECA2D5FE991FB"><enum>(B)</enum><text display-inline="yes-display-inline">includes any federally recognized Indian tribe that notifies the Secretary, not later than 120 days after the date of the enactment of this section or not later than 120 days before the start of any fiscal year in which a grant under this section is awarded, that the tribe intends to develop a Cybersecurity Plan and agrees to forfeit any distribution under subsection (l)(2).</text></subparagraph></paragraph></subsection></section><section id="HADED796BEDB045228F85390626539D18"><enum>2216.</enum><header>Cybersecurity resource guide development for State, local, Tribal, and territorial government officials</header><text display-inline="no-display-inline">The Secretary, acting through the Director, shall develop a resource guide for use by State, local, Tribal, and territorial government officials, including law enforcement officers, to help such officials identify, prepare for, detect, protect against, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents (as such term is defined in section 2209).</text></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="H557EB74CE2AF409E8BF93FCFBBC37C5E"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 2214 the following new items:</text><quoted-block style="OLC" id="HE96C6E16B69E45C2B6DE30ABBA01BA48" display-inline="no-display-inline" changed="added" reported-display-style="italic" committee-id="HHM00"><toc regeneration="no-regeneration" changed="added" reported-display-style="italic" committee-id="HHM00"><toc-entry level="section">Sec. 2215. State and Local Cybersecurity Grant Program. </toc-entry><toc-entry level="section">Sec. 2216. Cybersecurity resource guide development for State, local, Tribal, and territorial government officials.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section><section id="H41E766126008483C987FC721806002BD"><enum>3.</enum><header>Strategy</header><subsection commented="no" id="H9B0D8F7C9E784BE89A9EAD12FC6C8E76"><enum>(a)</enum><header>Homeland Security Strategy To Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments</header><text display-inline="yes-display-inline">Section 2210 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/660">6 U.S.C. 660</external-xref>) is amended by adding at the end the following new subsection:</text><quoted-block id="H31806612DCC448F6A927A031B84B70A8" style="OLC" changed="added" reported-display-style="italic" committee-id="HHM00"><subsection commented="no" id="HF902641C055E4AD49BA7C36D582DA654"><enum>(e)</enum><header>Homeland Security Strategy To Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments</header><paragraph commented="no" id="H18E534B6770B47DD874E69FD63866516"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 270 days after the date of the enactment of this subsection, the Secretary, acting through the Director, shall, in coordination with appropriate Federal departments and agencies, State, local, Tribal, and territorial governments, the State and Local Cybersecurity Resilience Committee (established under section 2215), and other stakeholders, as appropriate, develop and make publicly available a Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments that provides recommendations regarding how the Federal Government should support and promote the ability State, local, Tribal, and territorial governments to identify, protect against, detect respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents (as such term is defined in section 2209) and establishes baseline requirements and principles to which Cybersecurity Plans under such section shall be aligned.</text></paragraph><paragraph commented="no" id="HB4964A532B4840B694ABA7DC7080E9C7"><enum>(2)</enum><header>Contents</header><text>The Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments required under paragraph (1) shall—</text><subparagraph commented="no" id="HC786B4697105426AA43D6E1117B828C4"><enum>(A)</enum><text display-inline="yes-display-inline">identify capability gaps in the ability of State, local, Tribal, and territorial governments to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents;</text></subparagraph><subparagraph commented="no" id="H9AC581472C164BA683A5E8E93B8EF646"><enum>(B)</enum><text display-inline="yes-display-inline">identify Federal resources and capabilities that are available or could be made available to State, local, Tribal, and territorial governments to help such governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents;</text></subparagraph><subparagraph commented="no" id="H695C05DCBE1B4AE9855651655DB1A218"><enum>(C)</enum><text display-inline="yes-display-inline">identify and assess the limitations of Federal resources and capabilities available to State, local, Tribal, and territorial governments to help such governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents, and make recommendations to address such limitations;</text></subparagraph><subparagraph commented="no" id="HBBAFC3F4E9A942E4BFD9406D365B86B2"><enum>(D)</enum><text>identify opportunities to improve the Agency’s coordination with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center, to improve incident exercises, information sharing and incident notification procedures, the ability for State, local, Tribal, and territorial governments to voluntarily adapt and implement guidance in Federal binding operational directives, and opportunities to leverage Federal schedules for cybersecurity investments under section 502 of title 40, United States Code;</text></subparagraph><subparagraph commented="no" id="H573934E4933F42F3ACE1A341A6D0B5EC"><enum>(E)</enum><text display-inline="yes-display-inline">recommend new initiatives the Federal Government should undertake to improve the ability of State, local, Tribal, and territorial governments to help such governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents;</text></subparagraph><subparagraph commented="no" id="HA6FE90FA246C471DB48CD432CCCB7DE3"><enum>(F)</enum><text display-inline="yes-display-inline">set short-term and long-term goals that will improve the ability of State, local, Tribal, and territorial governments to help such governments identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents; and</text></subparagraph><subparagraph commented="no" id="H3B47A859D7EA45C89D4082CA346EDB98"><enum>(G)</enum><text display-inline="yes-display-inline">set dates, including interim benchmarks, as appropriate for State, local, Tribal, territorial governments to establish baseline capabilities to identify, protect against, detect, respond to, and recover from cybersecurity risks, cybersecurity threats, and incidents.</text></subparagraph></paragraph><paragraph commented="no" id="H82B0AB1EE8894D08AB1B9389BA14751E"><enum>(3)</enum><header>Considerations</header><text display-inline="yes-display-inline">In developing the Homeland Security Strategy to Improve the Cybersecurity of State, Local, Tribal, and Territorial Governments required under paragraph (1), the Director, in coordination with appropriate Federal departments and agencies, State, local, Tribal, and territorial governments, the State and Local Cybersecurity Resilience Committee, and other stakeholders, as appropriate, shall consider—</text><subparagraph commented="no" id="HCCF1C61E35B548BF9A66D80EC7844A70"><enum>(A)</enum><text>lessons learned from incidents that have affected State, local, Tribal, and territorial governments, and exercises with Federal and non-Federal entities;</text></subparagraph><subparagraph commented="no" id="H203003E024B84D64A25466A9A272DAD7"><enum>(B)</enum><text>the impact of incidents that have affected State, local, Tribal, and territorial governments, including the resulting costs to such governments;</text></subparagraph><subparagraph commented="no" id="H9C01632916954CDD98F0403A1829C616"><enum>(C)</enum><text>the information related to the interest and ability of state and non-state threat actors to compromise information systems owned or operated by State, local, Tribal, and territorial governments;</text></subparagraph><subparagraph commented="no" id="H8B652628F6B24AF892C8E7DD23DFC368"><enum>(D)</enum><text>emerging cybersecurity risks and cybersecurity threats to State, local, Tribal, and territorial governments resulting from the deployment of new technologies; and</text></subparagraph><subparagraph commented="no" id="H69BD6E0BAF0F448184C0C36A662A0946"><enum>(E)</enum><text>recommendations made by the State and Local Cybersecurity Resilience Committee.</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="H0895B0BC504F4B579EEB1EFC443E3946"><enum>(b)</enum><header>Responsibilities of the Director of the Cybersecurity and Infrastructure Security Agency</header><text>Subsection (c) of section 2202 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/652">6 U.S.C. 652</external-xref>) is amended—</text><paragraph id="H23019E7936D84A8FAD9DCD3D7C3752C4"><enum>(1)</enum><text>by redesignating paragraphs (6) through (11) as paragraphs (11) through (16), respectively; and</text></paragraph><paragraph id="HBA575A701BD24A05AC31714B0EF3667A"><enum>(2)</enum><text>by inserting after paragraph (5) the following new paragraphs:</text><quoted-block id="H77A298472B2E4B71998041BEF89A051C" style="OLC" changed="added" reported-display-style="italic" committee-id="HHM00"><paragraph id="H1D364521F1964F9DB7C4891076165880"><enum>(6)</enum><text>develop program guidance, in consultation with the State and Local Government Cybersecurity Resiliency Committee established under section 2215, for the State and Local Cybersecurity Grant Program under such section or any other homeland security assistance administered by the Department to improve cybersecurity;</text></paragraph><paragraph commented="no" id="H68006D20113A404B96749FE17FF6DC51"><enum>(7)</enum><text>review, in consultation with the State and Local Cybersecurity Resiliency Committee, all cybersecurity plans of State, local, Tribal, and territorial governments developed pursuant to any homeland security assistance administered by the Department to improve cybersecurity;</text></paragraph><paragraph commented="no" id="H8611E55C948D4A9596BAC512BA0B24F6"><enum>(8)</enum><text>provide expertise and technical assistance to State, local, Tribal, and territorial government officials with respect to cybersecurity;</text></paragraph><paragraph id="H742D23C52C304A4CAC975B58FD21EDE3"><enum>(9)</enum><text display-inline="yes-display-inline">provide education, training, and capacity development to enhance the security and resilience of cybersecurity and infrastructure security;</text></paragraph><paragraph id="HB2248F04B5C74A0ABE448C4A2D971630"><enum>(10)</enum><text display-inline="yes-display-inline">provide information to State, local, Tribal, and territorial governments on the security benefits of .gov domain name registration services;</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="HC12172152F7B45C1BAE835DD76126652"><enum>(c)</enum><header>Feasibility study</header><text display-inline="yes-display-inline">Not later than 180 days after the date of the enactment of this Act, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall conduct a study to assess the feasibility of implementing a short-term rotational program for the detail of approved State, local, Tribal, and territorial government employees in cyber workforce positions to the Agency.</text></subsection></section></legis-body><endorsement display="yes"><action-date>August 18, 2020</action-date><action-desc>Reported with an amendment; committed to the Committee of the Whole House on the State of the Union and ordered to be printed</action-desc></endorsement></bill> 

