<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H46743C90D4D642C2A5E3A8648C959C6C" public-private="public" key="H" bill-type="olc">
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 8965 IH: Spacecraft Cybersecurity Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-07-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code>
<congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session>
<legis-num display="yes">H. R. 8965</legis-num>
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
<action display="yes">
<action-date date="20240709">July 9, 2024</action-date>
<action-desc><sponsor name-id="F000476">Mr. Frost</sponsor> (for himself and <cosponsor name-id="B001292">Mr. Beyer</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HSY00">Committee on Science, Space, and Technology</committee-name></action-desc>
</action>
<legis-type>A BILL</legis-type>
<official-title display="yes">To promote the development of certain plans, policies, and standards for managing cybersecurity risks and protecting sensitive technology relating to National Aeronautics and Space Administration spacecraft systems, and for other purposes.</official-title>
</form>
<legis-body id="H7AE63285E7D34926AEE4416557650BAC" style="OLC">
<section id="H31D637937D3244BBB831175C864A81D2" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Spacecraft Cybersecurity Act</short-title></quote>.</text></section> <section id="H35B2B8EA336A4E7FB7317E24F9B22210"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
<paragraph id="H88A9837564FE4808A706B39A2690E611"><enum>(1)</enum><text display-inline="yes-display-inline">Malicious actors have targeted sensitive technology data maintained at certain National Aeronautics and Space Administration (NASA) centers.</text></paragraph> <paragraph id="HC276B152504E4264B9C07811A5309015"><enum>(2)</enum><text>A 2019 NASA Inspector General audit reported that potential infiltration into NASA’s space flight systems to acquire launch codes and flight trajectories of spacecraft remains a particular concern of NASA’s information technology security managers.</text></paragraph>
<paragraph id="H1D6DDAD3D0A6490491966A29E67BED8D"><enum>(3)</enum><text>The 2011 United States–China Economic and Security Commission’s annual report stated that <quote>at least two U.S. Government satellites have each experienced at least two separate instances of interference apparently consistent with cyber activities against their command and control systems.</quote>.</text></paragraph> <paragraph id="H6741AF7C3EAB45CB8EF72239057BEFA6"><enum>(4)</enum><text>Space Policy Directive-5 on <quote>Cybersecurity Principles for Space Systems</quote> issued guidance that Federal departments and agencies support practices within the Federal Government and across the commercial space industry <quote>that protect space assets and their supporting infrastructure from cyber threats and ensure continuity of operations.</quote>.</text></paragraph>
<paragraph id="H2F9D6674EBBD480AB005DDED6F73AA54"><enum>(5)</enum><text>NASA relies on industry contractors and commercial entities to carry out development of its advanced space systems and to provide services such as transporting NASA crew to and from the International Space Station.</text></paragraph> <paragraph id="HC9FD8BCF9FDA48A590B4FEDAA60BB5EB"><enum>(6)</enum><text>A 2024 Government Accountability Office audit found that NASA lacks a plan and time frames to update its acquisition policies and standards to address cybersecurity controls.</text></paragraph></section>
<section id="H6832D5931D5A4C368931044AC50EB53D"><enum>3.</enum><header>Plan and policy reviews</header>
<subsection id="HE395BDBBD43841D59817B07FA6612ABF"><enum>(a)</enum><header>Sense of Congress</header><text>It is the sense of Congress that the Administrator of the National Aeronautics and Space Administration (NASA) should take every action to ensure that robust cybersecurity measures are in place to protect sensitive technology data relating to space systems developed within NASA, at NASA contractors, or under commercial services arrangements.</text></subsection> <subsection id="HE044E166F6C7445B923D6DAB341CC362"><enum>(b)</enum><header>In general</header><text>The Administrator shall ensure that NASA’s acquisition policies and standards for space systems and services—</text>
<paragraph id="HC3CA5C77E2364FE8B214C06809DB6889" commented="no"><enum>(1)</enum><text display-inline="yes-display-inline">include guidelines and controls for managing cybersecurity risks to such systems and services, consistent with Space Policy Directive-5 on <quote>Cybersecurity Principles for Space Systems</quote>; and</text></paragraph> <paragraph id="H77B993196F9B4A93BC53E6D2896D3716" commented="no"><enum>(2)</enum><text display-inline="yes-display-inline">are updated, as appropriate, to address changing cybersecurity threats to such systems and services.</text></paragraph></subsection>
<subsection id="H2547ABA83E9749D58124CF7AE6C02560" commented="no"><enum>(c)</enum><header>Implementation plan</header><text>Not later than 270 days after the date of the enactment of the Act, the Administrator of NASA shall complete an implementation plan to update NASA’s acquisition policies and standards for space systems and services, and incorporate guidelines and controls required to protect against cybersecurity risk and cybersecurity threats to such systems and services. The Administrator shall ensure the participation and input of the Chief Engineer, Chief Information Officer, and the Principal Advisor for Enterprise Protection of NASA in the development of such plan. Such plan shall include the following:</text> <paragraph id="H5C4A5DFB2420452D949680ED82208A8F" commented="no"><enum>(1)</enum><text>Milestone dates for completing such updates.</text></paragraph>
<paragraph id="H759469631A8A405EA957DBC73A592D61" commented="no"><enum>(2)</enum><text>A process and frequency for reviewing NASA’s cybersecurity policies, procedures, and controls for spacecraft programs to address changing cybersecurity risks and cybersecurity threats to such systems and services.</text></paragraph> <paragraph id="H0BF1EE1D87C64C3C8562A6E2932323DF" commented="no"><enum>(3)</enum><text>An estimate of the resources required for carrying out the updates and reviews under paragraphs (1) and (2), respectively.</text></paragraph></subsection>
<subsection id="H6DFF1EE3B6B844D3B8E3EEE7C73E1450"><enum>(d)</enum><header>Briefing</header><text>Not later than 30 days after the completion of the implementation plan under subsection (c), the Administrator of NASA shall brief the Committee on Science, Space, and Technology of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate on such plan. Such briefing shall also address how such plan can inform the development of a cybersecurity risk management framework for spacecraft developed or used by NASA in pursuit of its missions that encompasses end-to-end mission systems and operations.</text></subsection></section> </legis-body> </bill> 

