<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H2E6F98AEC4C948C5A0DE35D8E3375BFB" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>H. R. 2165</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20090429">April 29, 2009</action-date>
			<action-desc><sponsor name-id="B001252">Mr. Barrow</sponsor> (for
			 himself, <cosponsor name-id="M000133">Mr. Markey of Massachusetts</cosponsor>,
			 and <cosponsor name-id="W000215">Mr. Waxman</cosponsor>) introduced the
			 following bill; which was referred to the <committee-name committee-id="HIF00">Committee on Energy and
			 Commerce</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend Part II of the Federal Power Act to address
		  known cybersecurity threats to the reliability of the bulk power system, and to
		  provide emergency authority to address future cybersecurity threats to the
		  reliability of the bulk power system, and for other purposes.</official-title>
	</form>
	<legis-body id="H9229B63FAEEF43D79FFE2FF500F51BF5" style="OLC">
		<section id="HF6D2E9EC360E4712BA0022561C58A146" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Bulk Power System Protection Act of
			 2009</short-title></quote>.</text>
		</section><section id="HB32F8FF9C81743BF8CD2071CBD6358F8"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">The Congress finds that—</text>
			<paragraph id="HFE51C0A744A14B8292EB38BFF8374F86"><enum>(1)</enum><text>it is in the
			 public interest to require the Federal Energy Regulatory Commission to promptly
			 order measures to address known cybersecurity threats to the reliability of the
			 electric bulk power system; and</text>
			</paragraph><paragraph id="H80230619919A45D095701DF46C2800C6"><enum>(2)</enum><text>the Commission
			 must have the necessary emergency authority to respond promptly to future
			 cybersecurity threats that could compromise reliability of the bulk power
			 system.</text>
			</paragraph></section><section id="HFA9B22814B0F4BFD8B51D1458B5EBFE8"><enum>3.</enum><header>Protection of
			 bulk power system from cybersecurity threats</header>
			<subsection id="H324A1333B0FE4A11A8A8A6A8C1A525A9"><enum>(a)</enum><header>In
			 general</header><text>Part II of the Federal Power Act is amended by adding the
			 following new section after section 215:</text>
				<quoted-block display-inline="no-display-inline" id="H864B025E004F4DB7BDB73EFE51804959" style="OLC">
					<section id="H2DBF2FC262804057891D3717EB615FB2"><enum>215A.</enum><header>Emergency
				authority to address cybersecurity threats to the bulk power system</header>
						<subsection id="H75693D34348C44ECA1A5C253797825DB"><enum>(a)</enum><header>Definitions</header><text>For
				purposes of this section:</text>
							<paragraph id="HDEE35C609157473E866C766F8FB8BBE"><enum>(1)</enum><text>The terms
				<quote>reliability standard</quote>, <quote>bulk power system</quote>,
				<quote>reliable operation</quote>, <quote>cybersecurity incident</quote>,
				<quote>Electric Reliability Organization</quote>, <quote>regional
				entity</quote>, and <quote>owners, users or operators</quote> shall have the
				same meaning as when used in section 215.</text>
							</paragraph><paragraph id="H1D38DAF4A1284F43AEBD894050A4E492"><enum>(2)</enum><text>The term
				<quote>cybersecurity threat</quote> means that there is credible information or
				evidence of—</text>
								<subparagraph id="HC7DA6B3992F24A9A821FB1C51E5301B5"><enum>(A)</enum><text>a likelihood of a
				malicious act that could disrupt the operation of those programmable electronic
				devices and communications networks including hardware, software and data that
				are essential to the reliable operation of the bulk power system; and</text>
								</subparagraph><subparagraph id="H09FA1F551A394399A0D1060346ED1FB4"><enum>(B)</enum><text>a substantial
				possibility of disruption to the operation of such devices and networks in the
				event of such a malicious act.</text>
								</subparagraph></paragraph><paragraph id="HE7E1E8E17D854CC80035992B5EBD0411"><enum>(3)</enum><header>Classified
				information</header><text>The term <quote>classified information</quote> means
				any information that has been determined pursuant to Executive Order 12958, as
				amended, or successor orders, or the Atomic Energy Act of 1954, to require
				protection against unauthorized disclosure and that is so designated.</text>
							</paragraph><paragraph id="HD4E4D49D2BAB48EDBC1CFF48102740D9"><enum>(4)</enum><header>Sensitive
				cybersecurity information</header><text>The term <quote>sensitive cybersecurity
				information</quote> means unclassified information that, if an unauthorized
				disclosure is made, could be used in a malicious manner to impair the
				reliability or operations of the bulk power system or the supply of electricity
				to the bulk power system.</text>
							</paragraph><paragraph id="H7D603D348FA94BC4A73F361BD5481967"><enum>(5)</enum><text>The term
				<quote>Secretary</quote> means the Secretary of Energy.</text>
							</paragraph></subsection><subsection id="HF84B76C16C6F426ABAD192F5598F9B92"><enum>(b)</enum><header>Interim
				authority To address existing cybersecurity threats</header>
							<paragraph id="HAF4A5553B47B41A4BF6FABE0358CEF6"><enum>(1)</enum><header>In
				general</header><text>After notice and opportunity for comment, and after
				consultation with appropriate governmental authorities in Canada and Mexico
				(subject to adequate protections against inappropriate disclosure of
				security-sensitive information), the Commission shall establish, by rule or
				order, within 120 days after enactment of this section, such measures or
				actions as are necessary to protect the reliability of the bulk power system
				against the cybersecurity threats resulting from—</text>
								<subparagraph id="HC6472063EFFB4C32855CAD08AD398C75"><enum>(A)</enum><text>the
				vulnerabilities identified in the June 21, 2007, communication to certain
				<quote>Electricity Sector Owners and Operators</quote> from the North American
				Electric Reliability Corporation, acting in its capacity as the Electricity
				Sector Information Sharing and Analysis Center; and</text>
								</subparagraph><subparagraph id="HDD603186917146FF9E7118739404A3F2"><enum>(B)</enum><text>related remote
				access issues.</text>
								</subparagraph><continuation-text continuation-text-level="paragraph">Such
				measures or actions may be required of any owner, user, or operator of the bulk
				power system within the United States.</continuation-text></paragraph><paragraph id="HCE350EFF33B641FCA04745BF3D61818E"><enum>(2)</enum><header>Additional
				orders</header><text>Until such time as the interim reliability measures or
				actions ordered under this subsection are replaced by cybersecurity reliability
				standards developed, approved, and implemented pursuant to section 215, the
				Commission may issue additional orders to supplement the initial rule or order
				issued under this subsection only if, based on subsequent information or
				petition from an affected entity, the Commission determines that clarification
				or refinements to the originally ordered measures or actions are necessary to
				ensure that the threats are adequately and appropriately addressed. Any such
				additional orders shall be preceded by notice and opportunity for
				comment.</text>
							</paragraph></subsection><subsection id="HFDC9407EDEB1438BACEEACC21856953B"><enum>(c)</enum><header>Future
				emergencies involving imminent cybersecurity threats</header>
							<paragraph id="HE7DCF46898BB41BC9FA241F4ED76519E"><enum>(1)</enum><header>Authority to
				address imminent cybersecurity threats</header><text>Whenever the President
				issues and provides to the Commission (either directly or through the
				Secretary) a written directive or determination that an imminent cybersecurity
				threat to the reliability of the bulk power system exists, the Commission may
				on its own motion, with or without notice, hearing, or report issue such orders
				for emergency measures or actions as are necessary in its judgment to protect
				the reliability of the bulk power system against such threat.</text>
							</paragraph><paragraph id="HB86D2F68A8A94C0D8B8753F08CA0E9C5"><enum>(2)</enum><header>Consultation</header><text>Before
				acting under this subsection, to the extent feasible, taking into account the
				nature of the threat and urgency of need for action, the Commission shall
				consult with appropriate governmental authorities in Canada and Mexico (subject
				to adequate protections against inappropriate disclosure of security-sensitive
				information), entities described in paragraph (3), and officials at other
				Federal agencies, including the Secretary, as appropriate, regarding
				implementation of measures or actions that will effectively address the
				identified threat.</text>
							</paragraph><paragraph id="H8FD27649358E4D058DE78BD414C206D9"><enum>(3)</enum><header>Application of
				emergency measures</header><text>An order for emergency actions or measures
				under this subsection may apply to—</text>
								<subparagraph id="H984E351C69F44AE48D13152E5C3500DD"><enum>(A)</enum><text>the Electric
				Reliability Organization referred to in section 215,</text>
								</subparagraph><subparagraph id="H56EBC4C4EA404065BB65C4F2391C76B"><enum>(B)</enum><text>a regional entity
				with respect to the United States operations of the Electric Reliability
				Organization,</text>
								</subparagraph><subparagraph id="H139139B826B64BD3AF5F3026A4C93536"><enum>(C)</enum><text>the regional
				entity, or</text>
								</subparagraph><subparagraph id="H54A3732D211E49D0AEB938FF00F82748"><enum>(D)</enum><text>any owner, user,
				or operator of the bulk power system within the United States.</text>
								</subparagraph></paragraph></subsection><subsection id="H004D4B0D170348E9A62626820482765B"><enum>(d)</enum><header>Discontinuance
				of interim measures</header><text>The Commission shall issue an order
				discontinuing any measures or actions ordered under subsection (b) upon the
				earliest of the following:</text>
							<paragraph id="H89FDEAD709794EAA899D68DF39F65EF8"><enum>(1)</enum><text>When the President
				(either directly or through the Secretary of Energy) issues a written order or
				directive provided to the Commission to the effect that the threat to the bulk
				power system that requires such measures, or actions no longer exists.</text>
							</paragraph><paragraph id="H36D817B01F9545429160D9EB6D054920"><enum>(2)</enum><text>When the
				Commission determines in writing that the ordered measures or actions are no
				longer needed to address the identified threat.</text>
							</paragraph><paragraph id="HB0770173F7C04164879F4F28146FC856"><enum>(3)</enum><text>When a reliability
				standard developed and approved pursuant to section 215 is implemented to
				address the identified threat.</text>
							</paragraph><paragraph id="HB32213DBC07A4560B0007EAB44A53F2C"><enum>(4)</enum><text>One year after the
				issuance of an order under subsections (b) unless the President (either
				directly or through the Secretary) issues a determination affirming the
				continuing nature of the threat. A determination issued under this paragraph
				shall expire upon the implementation of a standard under section 215 to address
				the identified threat.</text>
							</paragraph><continuation-text continuation-text-level="subsection">The
				Commission shall issue such order to be effective within 30 days of the
				relevant triggering event set out in paragraphs (1) through (4).</continuation-text></subsection><subsection id="H201C3506BDBB4DF9877F1C4E696164D7"><enum>(e)</enum><header>Discontinuance
				of emergency measures</header><text>The Commission shall issue an order
				discontinuing any measures or actions ordered under subsection (c) upon the
				earliest of the following:</text>
							<paragraph id="HE0FA2135D799401AB1B3AB2131C0D1"><enum>(1)</enum><text>When the President
				(either directly or through the Secretary of Energy) issues a written order or
				directive provided to the Commission to the effect that the threat to the bulk
				power system that requires such measures, or actions no longer exists.</text>
							</paragraph><paragraph id="HD87F24C1FFEB4E1AB97E007B5EAC05F3"><enum>(2)</enum><text>When the
				Commission determines in writing that the ordered measures or actions are no
				longer needed to address the identified threat.</text>
							</paragraph><paragraph id="HE3EFC43B8F8C46F1AC8FA0745100E73E"><enum>(3)</enum><text>When a reliability
				standard developed and approved pursuant to section 215 is implemented to
				address the identified threat.</text>
							</paragraph><paragraph id="HFF7C6364EC3E4805AFDBAEB15C008173"><enum>(4)</enum><text>With respect to
				orders under subsection (c), one year after the issuance of an order unless the
				President (either directly or through the Secretary) issues a determination
				reaffirming the continuing nature of the threat. A determination issued under
				this paragraph shall expire upon the implementation of a standard under section
				215 to address the identified threat.</text>
							</paragraph><continuation-text continuation-text-level="subsection">The
				Commission shall issue such order to be effective within 30 days of the
				relevant triggering event set out in paragraphs (1) through (4).</continuation-text></subsection><subsection id="HF473853BD7DC40CCADD0EAFA5BE21462"><enum>(f)</enum><header>Protection of
				unclassified sensitive cybersecurity information</header>
							<paragraph id="HCD59FE8C3F9547BDA100FE57E4E11D5"><enum>(1)</enum><header>Confidentiality
				procedures</header><text>After notice and opportunity for comment, the
				Commission shall promulgate rules and procedures to prohibit the unauthorized
				disclosure of unclassified sensitive cybersecurity information—</text>
								<subparagraph id="HC5E6C4C346D744BC8522B7E3B329E3F7"><enum>(A)</enum><text>which was
				developed or used in connection with the implementation of this section,</text>
								</subparagraph><subparagraph id="H75A833752D4A412400D9ECF568FF8F82"><enum>(B)</enum><text>which specifically
				discusses cybersecurity threats, vulnerabilities, mitigation plans or security
				procedures, and</text>
								</subparagraph><subparagraph id="HA57BA59429644389868D4922006DAD5D"><enum>(C)</enum><text>the unauthorized
				disclosure of which could be used in a malicious manner to impair the
				reliability or operations of the bulk power system or the supply of electricity
				to the bulk power system.</text>
								</subparagraph><continuation-text continuation-text-level="paragraph">Such rules
				and procedures shall require the inventory and safeguarding of such information
				during its creation, storage and transmittal by the Commission or by any other
				entity, including any vendor, contractor or consultant.</continuation-text></paragraph><paragraph id="H2C853E6038A74EBBB4ADD7681C2BF44"><enum>(2)</enum><header> Limited
				disclosure to entities subject to commission action</header><text display-inline="yes-display-inline">In the rules and procedures promulgated
				under paragraph (1), the Commission shall authorize the release of sensitive
				cybersecurity information to entities subject to Commission action under this
				section and to their employees, contractors and third-party representatives, to
				the extent necessary to enable such entities to implement Commission rules,
				orders or measures. Entities originating, receiving or possessing such
				information shall comply with Commission rules and procedures to limit
				disclosure of such information to any other entities that have been determined
				to have a need to know, have executed non disclosure agreements, and have been
				deemed by the entity to be trustworthy and reliable. Any entity which signed
				such non disclosure agreement and was found by the Commission or by another
				entity subject to this section to have improperly disclosed sensitive
				cybersecurity information shall thereafter be denied access to such
				information, and the Commission shall suspend ability of the entity disclosing
				such information to appear before the Commission. The sanctions under this
				paragraph against any individual or other entity shall be in addition to, and
				not in lieu of, any other actions Commission is authorized to take pursuant to
				section 316A for failure to comply with the rules or procedures established by
				the Commission under this section. Information designated sensitive
				cybersecurity information pursuant to this section shall not be subject to
				disclosure under the Freedom of Information Act (5 U.S.C. 552).</text>
							</paragraph><paragraph id="H3CD6C7B0138C48808705DA0090005B98"><enum>(3)</enum><header>Limitations</header>
								<subparagraph id="HC3A429DD72374E26ACC3F40C9F04E7C"><enum>(A)</enum><text display-inline="yes-display-inline">The Commission shall consult with national
				security or national intelligence agencies, as appropriate, for purposes of
				designating certain information as sensitive cybersecurity information, but
				shall not designate as sensitive cybersecurity information any information that
				has been classified by another Federal agency.</text>
								</subparagraph><subparagraph id="HD2C41AAF71CE4C569B1E4941D0E627FC"><enum>(B)</enum><text>Nothing in this
				section shall be construed to authorize the withholding of information from the
				committees of the Congress with jurisdiction over the Commission or the
				Comptroller General.</text>
								</subparagraph><subparagraph id="H5348FB1A89ED4E9A91F6D9AAC4749583"><enum>(C)</enum><text display-inline="yes-display-inline">In promulgating and implementing rules and
				procedures under this section, the Commission shall protect from disclosure
				only the minimum amount of sensitive cybersecurity information necessary to
				protect the reliability or operations of the bulk power system or the supply of
				electricity to the bulk power system. The Commission shall segregate sensitive
				cybersecurity information within documents, electronic communications, and
				rules, orders or records associated with such rules and orders, wherever
				feasible, to facilitate disclosure of information which is not designated as
				sensitive cybersecurity information.</text>
								</subparagraph><subparagraph id="HBA4C3EF38F2949DF9FEBE117E7FCB56D"><enum>(D)</enum><text>Information may
				not be designated as sensitive cybersecurity information for longer than 10
				years, unless specifically redesignated by the Commission.</text>
								</subparagraph><subparagraph id="HB15B60E76C7E48F9A3E602F100557C19"><enum>(E)</enum><text>The Commission is
				authorized to remove the designation of sensitive cybersecurity information, in
				whole or in part, from a document or electronic communication if the
				unauthorized disclosure could not be used to impair the reliability or
				operations of the bulk power system or the supply of electricity to the bulk
				power system.</text>
								</subparagraph></paragraph><paragraph id="H9D795124B6164698B4A61DF66E6346B4"><enum>(4)</enum><header>Consistency of
				markings</header><text>The Commission is authorized to place markings on
				documents, in whole or in part, which designate the degree of sensitivity and
				limitations on dissemination. Regulations and related procedures may be
				modified, as appropriate, to ensure consistency with applicable Executive
				Orders or laws pertaining to controlled unclassified information.</text>
							</paragraph><paragraph id="H13AC7722F57C42AB87336B81002B9700"><enum>(5)</enum><header>Nondisclosure of
				sensitive cybersecurity information in rules or orders</header><text>If a rule
				or order issued pursuant to this section contains sensitive cybersecurity
				information or if information in the record associated with such rule or order
				constitutes sensitive cybersecurity information, the Commission may make the
				rule, order or information non-public in whole or in part. The Commission may
				disclose such non-public rule, order or information to entities other than the
				recipient of the rule or order, as the Commission deems necessary, to carry out
				the rule or order and protect the reliability of the bulk power system.</text>
							</paragraph><paragraph id="H3218F2D1BC17491CBA9BD2752725FA60"><enum>(6)</enum><header>Judicial review
				of designations</header><text>Any determination by the Commission concerning
				the designation of sensitive cybersecurity information shall be subject to
				judicial review pursuant to subsection (a)(4)(B) of section 552 of title 5 of
				the United States Code.</text>
							</paragraph></subsection><subsection id="H1BAFA5A0CB6D4F6F93B9FEA32E22FE"><enum>(g)</enum><header>Review</header><text>The
				Commission shall act expeditiously to resolve all applications for rehearing of
				orders issued pursuant to this section which are filed under section 313(a).
				Any person or other entity seeking judicial review pursuant to section 313 may
				obtain such review only in the United States Court of Appeals for the District
				of Columbia Circuit. In the case of any petition for review involving rules or
				orders containing or relating to security-sensitive information, the Commission
				and parties shall develop with the court appropriate measures to ensure the
				confidentiality of such information, including, but not limited to, court
				filings under seal or otherwise in non-public form, or judicial review in
				camera.</text>
						</subsection><subsection id="H83C7C39F60874F84A8877CCBAA7B45E"><enum>(h)</enum><header>Enforcement
				discretion</header><text display-inline="yes-display-inline">The Commission is
				authorized to impose penalties pursuant to section 316A for any violation of a
				rule or order of the Commission under this section. The Commission shall
				exercise its discretion in engaging in enforcement actions under this section
				to recognize good faith efforts to comply with directives of the
				Commission.</text>
						</subsection><subsection id="H7D95CFCFE481436BA5A08C79A01C7149"><enum>(i)</enum><header>Paperwork
				reduction</header><text>Chapter 35 of title 44, United States Code (44 U.S.C.
				3501 et seq.) (commonly referred to as the <quote>Paperwork Reduction
				Act</quote>) shall not apply to collections of information that relate to
				measures or actions described in this section.</text>
						</subsection><subsection id="HDD318FD0D4464689AD07F4BA5CC1C783"><enum>(j)</enum><header>Provision of
				assistance to industry in meeting cybersecurity protection needs</header>
							<paragraph id="H160CE0345A7745089D21A1C67C73752"><enum>(1)</enum><header>Expertise and
				resources</header><text display-inline="yes-display-inline">The Secretary shall
				establish a program to develop expertise and identify technical and electronic
				resources, including hardware, software and system equipment, helpful to
				cybersecurity protection of the electric grid and all electric systems,
				including distribution-level electric systems.</text>
							</paragraph><paragraph id="HBBF11CD672C14D2DA0974E34B7A5EE8F"><enum>(2)</enum><header>Sharing
				expertise</header><text display-inline="yes-display-inline">The Secretary shall
				offer to share such expertise through consultation and assistance with any
				owner, operator, or user of the bulk power system, to any owner or operator of
				an electricity distribution system located in the United States whether or not
				connected to the bulk power system, and specifically to any owner or operator
				of an electricity distribution system that may provide electricity to national
				defense and other critical-infrastructure facilities of the United
				States.</text>
							</paragraph><paragraph id="H44EBE9BE2FC7433FB1875529B1472239"><enum>(3)</enum><header>Priority</header><text>The
				Secretary shall consult with the Commission, the Secretary of Defense, the
				Secretary of Homeland Security, and other Federal agencies to confirm the
				identity of States and electric systems serving such national defense and
				critical-infrastructure facilities, and shall assign higher priority to such
				States and systems in offering such support.</text>
							</paragraph><paragraph id="H20976455880544CEB60427E4A8B5F6EF"><enum>(4)</enum><header>Clearances</header><text>The
				Secretary shall facilitate the acquisition by key security personnel of any
				electric entity affected by this subsection of sufficient security clearances
				to allow such personnel access to information that would enable optimum
				understanding of cybersecurity threats and ability to respond.</text>
							</paragraph><paragraph id="HE1DB065B93C74DD9B0A650AE572D27DC"><enum>(5)</enum><header>Defense
				facilities</header><text>Within one year of the date of enactment of this
				section, the States of Alaska and Hawaii and the Territory of Guam shall
				prepare, in consultation with the Secretary of Energy, the Secretary of
				Defense, and the electric utilities that serve national defense facilities in
				those jurisdictions, a comprehensive plan, to be implemented by the relevant
				State and territorial governmental authorities, identifying the emergency
				measures or actions that will be taken to protect the reliability of the
				electric power supply of the national defense facilities located in those
				jurisdictions in the event of an imminent cybersecurity threat. A copy of each
				such plan shall be provided to the Secretary of Energy and the Secretary of
				Defense.</text>
							</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HFEB909FBA0E640E6A1AE89C42E58922F"><enum>(b)</enum><header>Conforming
			 amendment</header><text display-inline="yes-display-inline">Section 201(b)(2)
			 of the Federal Power Act is amended by inserting <quote>215A</quote> after
			 <quote>215</quote>.</text>
			</subsection></section></legis-body>
</bill>
