<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BAG23C20-K72-H8-P90"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S2201 RS: American Cybersecurity Literacy Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-12-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 291</calendar><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 2201</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230622">June 22, 2023</action-date><action-desc><sponsor name-id="S311">Ms. Klobuchar</sponsor> (for herself and <cosponsor name-id="S303">Mr. Thune</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20231213">December 13, 2023</action-date><action-desc>Reported by <sponsor name-id="S275">Ms. Cantwell</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To increase knowledge and awareness of best practices to reduce cybersecurity risks in the United States.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>American Cybersecurity Literacy Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" section-type="subsequent-section" id="id689e8a3cd7994fcfa19df7c98b3043e2" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>2.</enum><header>Cybersecurity literacy campaign</header><subsection id="id2b7bb4b2a1c5430786dfd28dd94beb72"><enum>(a)</enum><header>In general</header><text>The Secretary of Commerce, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall develop and conduct a cybersecurity literacy campaign described in subsection (b), which the Secretary of Commerce shall make available in multiple languages and formats, if practicable, to increase the knowledge and awareness of citizens of the United States of best practices to reduce cybersecurity risks.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="idf4b8d4b785c14d779ec67a90b406d023"><enum>(b)</enum><header>Elements</header><text>In carrying out subsection (a), the Secretary of Commerce, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall—</text><paragraph id="id8dc8e473e19145139192107771adc038"><enum>(1)</enum><text>educate citizens of the United States with respect to how to prevent and mitigate a cyberattack or cybersecurity risk, including by—</text><subparagraph id="id6d2704f0b9ca4d779cb78e2092ff043f"><enum>(A)</enum><text>instructing citizens of the United States with respect to how to identify—</text><clause id="id73230d9ee39a491a865f094a4372cf21"><enum>(i)</enum><text>a phishing email or message; and</text></clause><clause id="idfbdd3ea20b62408a9487e9220c1a57be"><enum>(ii)</enum><text>a secure website;</text></clause></subparagraph><subparagraph id="ide940f08ff4204f60bbf0b7ea763d1094"><enum>(B)</enum><text>instructing citizens of the United States about the benefits of changing default passwords on any hardware or software technology;</text></subparagraph><subparagraph id="id294d2e2446bf4442b9c80ba6860bd9ac"><enum>(C)</enum><text>encouraging the use of cybersecurity tools, including—</text><clause id="id7576a915f5124426abb45faf6aa9c646"><enum>(i)</enum><text>multi-factor authentication;</text></clause><clause id="id0e085bdcb616462eb87b86bed58b066f"><enum>(ii)</enum><text>a complex password;</text></clause><clause id="idc2207d7929374eeea650aef6ddc1c451"><enum>(iii)</enum><text>anti-virus software;</text></clause><clause id="id9e0869f8520e4ef59edfa971fd620401"><enum>(iv)</enum><text>patching or updating software and applications; and</text></clause><clause id="id6f15623e0f4c4e6db1efe75e099ac2ac"><enum>(v)</enum><text>a virtual private network;</text></clause></subparagraph><subparagraph id="id8cf9515b81544916a33dc61b1b3be172"><enum>(D)</enum><text>identifying a device that could pose possible cybersecurity risks, including—</text><clause id="idb6a796c82371458eb177a02371427f51"><enum>(i)</enum><text>a personal computer;</text></clause><clause id="idb953080fea314329bf9e10d0815e7991"><enum>(ii)</enum><text>a smartphone;</text></clause><clause id="idfe25e6c73d77472aa334e583665f8639"><enum>(iii)</enum><text>a tablet;</text></clause><clause id="idc012cf994f2645d786cdd607ec3d4a5f"><enum>(iv)</enum><text>a Wi-Fi router;</text></clause><clause id="ide81e35d3469d427a900db0c8f3d4ea54"><enum>(v)</enum><text>a smart home appliance;</text></clause><clause id="idd74e9a238468495abdb159109b698b30"><enum>(vi)</enum><text>a webcam;</text></clause><clause id="id24f41ed0857e43f4af1a038e5fa44d0a"><enum>(vii)</enum><text>an internet-connected monitor; or</text></clause><clause id="idbaae0028c2f74e9bbd5a99680570aee0"><enum>(viii)</enum><text>any other device that can be connected to the internet, including any mobile device other than a smartphone or tablet;</text></clause></subparagraph><subparagraph id="id57ff01671915485da65c1fa2dbb4fc24"><enum>(E)</enum><text>encouraging citizens of the United States to—</text><clause id="id25226432a59140198fc43f7ce7a918b9"><enum>(i)</enum><text>regularly review mobile application permissions;</text></clause><clause id="idfc579f25f1f54d8995aed30b99386dac"><enum>(ii)</enum><text>decline any privilege request from a mobile application that is unnecessary;</text></clause><clause id="id1f201efda85e444aa5baf3f8ecfc6d59"><enum>(iii)</enum><text>download an application only from a trusted vendor or source; and</text></clause><clause id="id8f557ad713904c5092662d4da17c3f62"><enum>(iv)</enum><text>consider the life cycle of a product and the commitment of a developer to providing security updates during the expected period of use of a connected device; and</text></clause></subparagraph><subparagraph id="id867b136f50dd46abbb2b936d19bccac2"><enum>(F)</enum><text>identifying any potential cybersecurity risk related to using a publicly available Wi-Fi network and any method a user may use to limit such risks; and</text></subparagraph></paragraph><paragraph id="id5afacf7d65964cc29ee6a50cd05a6c74"><enum>(2)</enum><text>encourage citizens of the United States to use any resource to help mitigate the cybersecurity risks described in this subsection.</text></paragraph></subsection></section></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section section-type="section-one" id="id42de84cb-f737-40a5-b963-08b892844afa" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>American Cybersecurity Literacy Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" section-type="subsequent-section" id="id0fc09ed1-269b-4095-9981-8f76ce64164d" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>2.</enum><header>Cybersecurity literacy campaign</header><subsection id="id6c78406c-db2e-4f0a-87d6-205e9f392ad3" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>(a)</enum><header>In general</header><text>The Director of the National Institute of Standards and Technology shall, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, develop and conduct a cybersecurity literacy campaign described in subsection (b), which the Director of the National Institute of Standards and Technology shall make available in multiple languages and formats, if practicable, to increase the knowledge and awareness of citizens of the United States of best practices to reduce cybersecurity risks.</text></subsection><subsection commented="no" display-inline="no-display-inline" id="id26c451df-a192-4e2f-bf96-a56716780ced" changed="added" reported-display-style="italic" committee-id="SSCM00"><enum>(b)</enum><header>Elements</header><text>In carrying out subsection (a), the Director of the National Institute of Science and Technology, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency, shall—</text><paragraph id="id5b9d0f11-c5d5-4822-85a7-5c58c163d700"><enum>(1)</enum><text>educate citizens of the United States with respect to how to prevent and mitigate a cyberattack or cybersecurity risk, including by—</text><subparagraph id="id99bc4a7a-ca34-4a04-a333-d267b176b448"><enum>(A)</enum><text>instructing citizens of the United States with respect to how to identify—</text><clause id="idf5a0ca93-1fef-483d-a583-3b3c47f855f4"><enum>(i)</enum><text>a phishing email or message; and</text></clause><clause id="id1dc0cc21-be5f-4f0f-a876-0d7d612a85ec"><enum>(ii)</enum><text>a secure website;</text></clause></subparagraph><subparagraph id="idb0612d53-4eee-4c70-8f31-1c15a07cd82c"><enum>(B)</enum><text>instructing citizens of the United States about the benefits of changing default passwords on any hardware or software technology;</text></subparagraph><subparagraph id="id595f89ac-e4ef-4b32-81a1-456f747db0e8"><enum>(C)</enum><text>encouraging the use of cybersecurity tools, including—</text><clause id="id05eb303a-8b8c-45d2-b0ba-e3637d4fd93a"><enum>(i)</enum><text>multi-factor authentication;</text></clause><clause id="iddcdcd475-b159-41de-b2db-bce05a3c4bab"><enum>(ii)</enum><text>a complex password;</text></clause><clause id="id7b9dcb07-c470-4394-9d08-1215a47c5f1b"><enum>(iii)</enum><text>anti-virus software;</text></clause><clause id="id2edeb163-15ee-451e-b586-5e84ba8fb2b8"><enum>(iv)</enum><text>patching or updating software and applications; and</text></clause><clause id="idfb4e846a-18c4-4dd2-a413-ed69c4a6aaa4"><enum>(v)</enum><text>a virtual private network;</text></clause></subparagraph><subparagraph id="id13767d7d-b195-4b32-9b94-a99cc3445904"><enum>(D)</enum><text>identifying a device that could pose possible cybersecurity risks, including—</text><clause id="idc6f083ff-41b9-4310-a26f-f980c224c52f"><enum>(i)</enum><text>a personal computer;</text></clause><clause id="id07ea637c-fe6a-4660-9752-982ce9a10917"><enum>(ii)</enum><text>a smartphone;</text></clause><clause id="id25ded564-08de-4f9a-b33d-f54bbb7df3ce"><enum>(iii)</enum><text>a tablet;</text></clause><clause id="idb3b96880-4865-446f-ac18-0948194d4bf8"><enum>(iv)</enum><text>a Wi-Fi router;</text></clause><clause id="id9f7cf6dd-a61d-4496-9e31-38f70fb92b31"><enum>(v)</enum><text>a smart home appliance;</text></clause><clause id="idf6e7ed8b-cd7e-41cc-a6ac-5690f0bacbc6"><enum>(vi)</enum><text>a webcam;</text></clause><clause id="id190db12d-461e-4688-836f-47adf28deea8"><enum>(vii)</enum><text>an internet-connected monitor; or</text></clause><clause id="id27492533-8987-4029-9778-971844d0b115"><enum>(viii)</enum><text>any other device that can be connected to the internet, including any mobile device other than a smartphone or tablet;</text></clause></subparagraph><subparagraph id="id242c9a2c-0dec-4a21-9910-d9bb3d298abd"><enum>(E)</enum><text>encouraging citizens of the United States to—</text><clause id="ided65d427-efa4-4fdd-aafb-4f9156dbd14d"><enum>(i)</enum><text>regularly review mobile application permissions;</text></clause><clause id="id1437c770-4ac6-4c8a-af65-2c4380578d86"><enum>(ii)</enum><text>decline any privilege request from a mobile application that is unnecessary;</text></clause><clause id="ide398936c-0920-4246-8c72-500bc00f2a9b"><enum>(iii)</enum><text>download an application only from a trusted vendor or source; and</text></clause><clause id="id01233d72-4039-4c9d-89f4-3731d17aaf03"><enum>(iv)</enum><text>consider the life cycle of a product and the commitment of a developer to providing security updates during the expected period of use of a connected device; and</text></clause></subparagraph><subparagraph id="id5f524662-7c62-4017-aa9a-c7e5facf961e"><enum>(F)</enum><text>identifying any potential cybersecurity risk related to using a publicly available Wi-Fi network and any method a user may use to limit such risks; and</text></subparagraph></paragraph><paragraph id="id2b1ec9b1-f115-47dc-bf0b-e9dea985bd46"><enum>(2)</enum><text>encourage citizens of the United States to use any resource that is developed as a result of this literacy campaign to help mitigate the cybersecurity risks described in this subsection.</text></paragraph></subsection><subsection id="id1fcb017214204ff88ef67ea4b1cd8364" changed="added" reported-display-style="italic"><enum>(c)</enum><header>Existing authorized amounts</header><text>No additional funds are authorized to be appropriated for the purpose of carrying out this Act. </text></subsection></section></legis-body><endorsement><action-date date="20231213">December 13, 2023</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

