<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="HA1CF5597EE5C480AAD4999321314FD99" public-private="public" bill-type="olc"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>109 HR 285 IH: Department of Homeland Security Cybersecurity Enhancement Act of 2005</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2005-01-06</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form> 
<distribution-code display="yes">I</distribution-code> 
<congress>109th CONGRESS</congress> <session>1st Session</session> 
<legis-num>H. R. 285</legis-num> 
<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<action> 
<action-date date="20050106">January 6, 2005</action-date> 
<action-desc><sponsor name-id="T000238">Mr. Thornberry</sponsor> (for himself and <cosponsor name-id="L000397">Ms. Zoe Lofgren of California</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Select Committee on Homeland Security</committee-name></action-desc> 
</action> 
<legis-type>A BILL</legis-type> 
<official-title>To amend the Homeland Security Act of 2002 to enhance cybersecurity, and for other purposes.</official-title> 
</form> 
<legis-body id="HA71A6526FE774AEE83BA74BDC920BC6F" style="OLC"> 
<section section-type="section-one" id="HF2642AA3375B47CC9546CA99EEB51F24" display-inline="no-display-inline"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Department of Homeland Security Cybersecurity Enhancement Act of 2005</short-title></quote>.</text></section> 
<section id="HAB674B0DE9DD47C3A7FD348E50A45785"><enum>2.</enum><header>Assistant Secretary for Cybersecurity</header> 
<subsection id="H859C954C4DA540EABE2FB47FCAA390E0"><enum>(a)</enum><header>In general</header><text>Subtitle A of title II of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/121">6 U.S.C. 121 et seq.</external-xref>) is amended by adding at the end the following:</text> 
<quoted-block id="H6CB34F178AC74F88AFB6BC45D0458CF"> 
<section id="HAB0D7CCE7FB644EEADDFAEBA34E7639C"><enum>203.</enum><header>Assistant Secretary for Cybersecurity</header> 
<subsection id="H6151FB7AE15E4F6291DA15C0CF86BE17"><enum>(a)</enum><header>In general</header><text>There shall be in the Directorate for Information Analysis and Infrastructure Protection a National Cybersecurity Office headed by an Assistant Secretary for Cybersecurity (in this section referred to as the <quote>Assistant Secretary</quote>), who shall assist the Secretary in promoting cybersecurity for the Nation.</text></subsection> 
<subsection id="H882262E3ABF74AC186986CA6D402167C"><enum>(b)</enum><header>General authority</header><text>The Assistant Secretary, subject to the direction and control of the Secretary, shall have primary authority within the Department for all cybersecurity-related critical infrastructure protection programs of the Department, including with respect to policy formulation and program management.</text></subsection> 
<subsection id="HB6493FE05B24420C9795EFA4073747E4"><enum>(c)</enum><header>Responsibilities</header><text>The responsibilities of the Assistant Secretary shall include the following:</text> 
<paragraph id="HAAD2C5BC2E6F45AB8C478F00A78F5918"><enum>(1)</enum><text>To establish and manage—</text> 
<subparagraph id="HB790DADC32F14F17804C09DCBA731F3"><enum>(A)</enum><text>a national cybersecurity response system that includes the ability to—</text> 
<clause id="H42F3A5532689430EAA2561BA9107586F"><enum>(i)</enum><text>analyze the effect of cybersecurity threat information on national critical infrastructure; and</text></clause> 
<clause id="HBDF3178B6A4B4A05A12D04A068E217FB"><enum>(ii)</enum><text>aid in the detection and warning of attacks on, and in the restoration of, cybersecurity infrastructure in the aftermath of such attacks;</text></clause></subparagraph> 
<subparagraph id="H2AF48FEB69AF4E48ABCA227158E91FAF"><enum>(B)</enum><text>a national cybersecurity threat and vulnerability reduction program that identifies cybersecurity vulnerabilities that would have a national effect on critical infrastructure, performs vulnerability assessments on information technologies, and coordinates the mitigation of such vulnerabilities;</text></subparagraph> 
<subparagraph id="HABEDAB36F88D4A348397DB46D2E1FC71"><enum>(C)</enum><text>a national cybersecurity awareness and training program that promotes cybersecurity awareness among the public and the private sectors and promotes cybersecurity training and education programs;</text></subparagraph> 
<subparagraph id="H458CA62C25CD4E9EAE6E2B62DB069C92"><enum>(D)</enum><text>a government cybersecurity program to coordinate and consult with Federal, State, and local governments to enhance their cybersecurity programs; and</text></subparagraph> 
<subparagraph id="H0AB9C76522B945E0929F74A15D0D733"><enum>(E)</enum><text>a national security and international cybersecurity cooperation program to help foster Federal efforts to enhance international cybersecurity awareness and cooperation.</text></subparagraph></paragraph> 
<paragraph id="H23D9095DC51D463D86FE4820E4963200"><enum>(2)</enum><text>To coordinate with the private sector on the program under paragraph (1) as appropriate, and to promote cybersecurity information sharing, vulnerability assessment, and threat warning regarding critical infrastructure.</text></paragraph> 
<paragraph id="H8975EAE20866417695C7B107016CDAEA"><enum>(3)</enum><text>To coordinate with other directorates and offices within the Department on the cybersecurity aspects of their missions.</text></paragraph> 
<paragraph id="HEE381EDCFF3F4D4BA9A2E21F11E766E9"><enum>(4)</enum><text>To coordinate with the Under Secretary for Emergency Preparedness and Response to ensure that the National Response Plan developed pursuant to section 502(6) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/312">6 U.S.C. 312(6)</external-xref>) includes appropriate measures for the recovery of the cybersecurity elements of critical infrastructure.</text></paragraph> 
<paragraph id="HE111D5040708497D873359C715E8165F"><enum>(5)</enum><text>To develop processes for information sharing with the private sector, consistent with section 214, that—</text> 
<subparagraph id="HA39C2B37871F403A9EA6C00F9F1A4E9"><enum>(A)</enum><text>promote voluntary cybersecurity best practices, standards, and benchmarks that are responsive to rapid technology changes and to the security needs of critical infrastructure; and</text></subparagraph> 
<subparagraph id="H71F88A41A0654FC6BF477B7E6318F4C0"><enum>(B)</enum><text>consider roles of Federal, State, local, and foreign governments and the private sector, including the insurance industry and auditors.</text></subparagraph></paragraph> 
<paragraph id="H8DD107F9767145F1A34E8E3B51F0EA08"><enum>(6)</enum><text>To coordinate with the Chief Information Officer of the Department in establishing a secure information sharing architecture and information sharing processes, including with respect to the Department’s operation centers.</text></paragraph> 
<paragraph id="H098122425F9C4299906FB220F07B0961"><enum>(7)</enum><text>To consult with the Electronic Crimes Task Force of the United States Secret Service on private sector outreach and information activities.</text></paragraph> 
<paragraph id="HB8856E6999D64B49AEEE85C4CAFFE53"><enum>(8)</enum><text>To consult with the Office for Domestic Preparedness to ensure that realistic cybersecurity scenarios are incorporated into tabletop and recovery exercises.</text></paragraph> 
<paragraph id="H235D51709AC24AF4B803B84D97FC963E"><enum>(9)</enum><text>To consult and coordinate, as appropriate, with other Federal agencies on cybersecurity-related programs, policies, and operations.</text></paragraph> 
<paragraph id="H4DFF283C5F4B48ACA7512EDCF5530046"><enum>(10)</enum><text>To consult and coordinate within the Department and, where appropriate, with other relevant Federal agencies, on security of digital control systems, such as Supervisory Control and Data Acquisition (SCADA) systems.</text></paragraph></subsection> 
<subsection id="HE0E548DCC60E4AE09E13C0CD1FECE21"><enum>(d)</enum><header>Authority over the National Communications System</header><text>The Assistant Secretary shall have primary authority within the Department over the National Communications System.</text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection> 
<subsection id="HD5EE29D3A16A4C9B8169029149EA5BA"><enum>(b)</enum><header>Clerical amendment</header><text>The table of contents in section 1(b) of such Act is amended by adding at the end of the items relating to subtitle A of title II the following:</text> 
<quoted-block style="USC" id="H612FA604B99C4517B720A7E413E93E7F"> 
<toc regeneration="no-regeneration"> 
<toc-entry level="section">203. Assistant Secretary for Cybersecurity</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section> 
<section id="HCD42D56C26184E5F9B4F7063D8B6244D"><enum>3.</enum><header>Cybersecurity defined</header><text display-inline="no-display-inline">Section 2 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/101">6 U.S.C. 101</external-xref>) is amended by adding at the end the following:</text> 
<quoted-block id="H18F255B9F48049D7BCCF1B00DCC15AF"> 
<paragraph id="H4AB55440C3CB423E8139A700FD500010"><enum>(17)</enum>
<subparagraph id="HB2E4A7A8047342958D5570C7B2DF699B" display-inline="yes-display-inline"><enum>(A)</enum><text display-inline="yes-display-inline">The term <term>cybersecurity</term> means the prevention of damage to, the protection of, and the restoration of computers, electronic communications systems, electronic communication services, wire communication, and electronic communication, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation</text> </subparagraph>
<subparagraph indent="up1" id="H45AA439F1BEF4E1B9E6F2E65F1DE7C30"><enum>(B)</enum><text>In this paragraph—</text> 
<clause id="H2FE07C9D5C864BE400ABECF920BC6CC4"><enum>(i)</enum><text>each of the terms <term>damage</term> and <term>computer</term> has the meaning that term has in <external-xref legal-doc="usc" parsable-cite="usc/18/1030">section 1030</external-xref> of title 18, United States Code; and</text></clause> 
<clause id="HDA7BA73621954535804BEDAA8963DAED"><enum>(ii)</enum><text>each of the terms <term>electronic communications system</term>, <term>electronic communication service</term>, <term>wire communication</term>, and <term>electronic communication</term> has the meaning that term has in <external-xref legal-doc="usc" parsable-cite="usc/18/2510">section 2510</external-xref> of title 18, United States Code.</text></clause></subparagraph></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></section> 
</legis-body> 
</bill> 


