<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="H98A24B2E3BB14E618B646DA3EF0C9C6A" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 6351</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20100929">September 29, 2010</action-date>
			<action-desc><sponsor name-id="L000559">Mr. Langevin</sponsor> (for
			 himself, <cosponsor name-id="R000576">Mr. Ruppersberger</cosponsor>, and
			 <cosponsor name-id="B000208">Mr. Bartlett</cosponsor>) introduced the following
			 bill; which was referred to the <committee-name committee-id="HHM00">Committee
			 on Homeland Security</committee-name>, and in addition to the Committee on
			 <committee-name committee-id="HGO00">Oversight and Government
			 Reform</committee-name>, for a period to be subsequently determined by the
			 Speaker, in each case for consideration of such provisions as fall within the
			 jurisdiction of the committee concerned</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To establish the Executive Cyber Director in the
		  Executive Office of the President, to clarify the authority of the Secretary of
		  Homeland Security and the Executive Cyber Director with respect to critical
		  information infrastructure policy creation, verification, and enforcement
		  measures, and for other purposes.</official-title>
	</form>
	<legis-body id="HDDF205CF37E34E1E95445760C09A0D11" style="OLC">
		<section id="H42B3C6E8077046E3BA57764BEA2BC4C4" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Strengthening Cybersecurity for
			 Critical Infrastructure Act</short-title></quote>.</text>
		</section><section id="HF3274D219E704E8EBCA7E8190425E003" section-type="subsequent-section"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act—</text>
			<paragraph id="HC1C3EF23C5C6438888753F6A0D367EB2"><enum>(1)</enum><text display-inline="yes-display-inline">the term <term>critical information
			 infrastructure</term> means the electronic information and communications
			 systems, software, and assets that control, protect, process, transmit,
			 receive, program, or store information in any form, including data, voice, and
			 video, relied upon by critical infrastructure, industrial control systems such
			 as, but not limited to, supervisory control and data acquisition systems, and
			 programmable logic controllers. This shall also include such systems of the
			 Federal Government;</text>
			</paragraph><paragraph id="H44A61A43F7F840EC8AE546CDD2B7C7EC"><enum>(2)</enum><text>the term
			 <term>critical infrastructure</term> has the meaning given that term in section
			 2 of the Homeland Security Act of 2002 (6 U.S.C. 101); and</text>
			</paragraph><paragraph id="H92AE315F879949D5BA305FD7A4FDBA81"><enum>(3)</enum><text>the term
			 <term>Secretary</term> means the Secretary of Homeland Security.</text>
			</paragraph></section><section id="H6EED3913BE414E8C878484C96066B221"><enum>3.</enum><header>Authority of
			 Secretary</header>
			<subsection id="H2BE5BBBB81D149029B9A768F798DEC33"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The Secretary shall
			 have primary authority in the executive branch of the Federal Government in
			 creation, verification, and enforcement of measures with respect to the
			 protection of critical information infrastructure, including promulgating
			 risk-informed information security practices and standards applicable to
			 critical information infrastructures that are not owned by or under the direct
			 control of the Federal Government. These efforts shall be carried out with the
			 consultation of appropriate private sector bodies, including private owners and
			 operators of the infrastructure affected by these measures.</text>
			</subsection><subsection id="H6A5B08966F7E40A7ADA8845C4CE91785"><enum>(b)</enum><header>Other Federal
			 agencies</header><text display-inline="yes-display-inline">In establishing
			 measures with respect to the protection of critical information infrastructure
			 the Secretary shall—</text>
				<paragraph id="H1026F95A7BDE4060A9B1635A9CBCB14B"><enum>(1)</enum><text display-inline="yes-display-inline">consult with the Secretary of Commerce, the
			 Secretary of Defense, the National Institute of Standards and Technology, and
			 other sector specific Federal regulatory agencies in exercising the authority
			 referred to in subsection (a); and</text>
				</paragraph><paragraph id="H354AB21AA2D143EA9D124573F1D9FD88"><enum>(2)</enum><text>coordinate,
			 through the Executive Office of the President, with sector specific Federal
			 regulatory agencies, including the Federal Energy Regulatory Commission, in
			 establishing enforcement mechanisms under the authority referred to in
			 subsection (a).</text>
				</paragraph></subsection><subsection id="HB1024D2AB35C41ECBA083BED31B4746F"><enum>(c)</enum><header>Auditing
			 authority</header><text display-inline="yes-display-inline">The Secretary
			 may—</text>
				<paragraph id="H6BF15AE8F18F4FB985A907F554393DD6"><enum>(1)</enum><text display-inline="yes-display-inline">conduct such audits as are necessary to
			 ensure that appropriate measures are taken to secure critical information
			 infrastructure;</text>
				</paragraph><paragraph id="HA3482F14B0924DC48EF369D5AA775FB5"><enum>(2)</enum><text>issue such
			 subpoenas as are necessary to determine compliance with Federal regulatory
			 requirements for securing critical information infrastructure; and</text>
				</paragraph><paragraph id="H14F64C53A3F3421E90D337973DD511B5"><enum>(3)</enum><text display-inline="yes-display-inline">authorize sector specific Federal
			 regulatory agencies to undertake such audits.</text>
				</paragraph></subsection></section><section id="H7B43D138974F43A797A61178486EE555"><enum>4.</enum><header>Establishment and
			 authority of Executive Cyber Director</header>
			<subsection id="H7B18F6A99D6745238A44524D7683F963"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">There is established within the Executive
			 Office of the President an office to be known as the National Office for
			 Cyberspace. There shall be at the head of the Office the Executive Cyber
			 Director, who shall be appointed by the President by and with the advice and
			 consent of the Senate.</text>
			</subsection><subsection id="HBEA4FCB83F6E454FBB877BA9D98195BB"><enum>(b)</enum><header>Authority</header><text display-inline="yes-display-inline">The Executive Cyber Director shall have
			 primary authority in the executive branch of the Federal Government in leading
			 interagency coordination on security policies relating to the creation,
			 verification, and enforcement of measures to protect critical information
			 infrastructure.</text>
			</subsection></section></legis-body>
</bill>
