<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 3538</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20100624">June 24, 2010</action-date>
			<action-desc><sponsor name-id="S200">Mr. Bond</sponsor> (for himself
			 and <cosponsor name-id="S118">Mr. Hatch</cosponsor>) introduced the following
			 bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To improve the cyber security of the United States and
		  for other purposes.</official-title>
	</form>
	<legis-body>
		<section id="id2D76644974A846D99E03B55098F55409" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>National Cyber Infrastructure
			 Protection Act of 2010</short-title></quote>.</text>
		</section><section id="id429A0E099FEC47BFA0A0E88370BAD4E9" section-type="subsequent-section"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="ID1d19ef368d3941e88c7d62f61c461c7c"><enum>(1)</enum><header>Appropriate
			 congressional committees</header><text>The term <term>appropriate congressional
			 committees</term> means—</text>
				<subparagraph id="idDB894B20C3874DC599843157231F1654"><enum>(A)</enum><text>the Committee on
			 Armed Services, the Committee on Commerce, Science, and Transportation, the
			 Committee on Energy and Natural Resources, the Committee on Homeland Security
			 and Governmental Affairs, and the Select Committee on Intelligence of the
			 Senate; and</text>
				</subparagraph><subparagraph id="id8C1403E8873C4DFFB5EBEBDFF645A163"><enum>(B)</enum><text>the Committee on
			 Armed Services, the Committee on Energy and Commerce, the Committee on Homeland
			 Security, and the Permanent Select Committee on Intelligence of the House of
			 Representatives.</text>
				</subparagraph></paragraph><paragraph id="ID44f50a0c3e3d45ea886c0004fe21ac95"><enum>(2)</enum><header>Critical
			 infrastructure</header><text>The term <term>critical infrastructure</term> has
			 the meaning given that term in section 1016 of the Critical Infrastructures
			 Protection Act of 2001 (42 U.S.C. 5195c).</text>
			</paragraph><paragraph id="IDd4632b8b3be147d986bc3a9cba8ec847"><enum>(3)</enum><header>Cyber security
			 activities</header><text>The term <term>cyber security activities</term> means
			 a class or collection of similar cyber security operations of a Federal agency
			 that involves personally identifiable data that is—</text>
				<subparagraph id="ID30b0ca3b64e945aaafca97dd11bdaad5"><enum>(A)</enum><text>screened by a
			 cyber security system outside of the Federal agency that was the intended
			 recipient of the personally identifiable data;</text>
				</subparagraph><subparagraph id="ID52a3ff88c57e40b2a78cb9e61a710aba"><enum>(B)</enum><text>transferred, for
			 the purpose of cyber security, outside such Federal agency; or</text>
				</subparagraph><subparagraph id="ID7899602af07a4589ae920ee088d517bf"><enum>(C)</enum><text>transferred, for
			 the purpose of cyber security, to an element of the intelligence
			 community.</text>
				</subparagraph></paragraph><paragraph commented="no" id="IDfd4f35ee4d7143b3b942c1cde7ff347f"><enum>(4)</enum><header>Federal
			 agency</header><text>The term <quote>Federal agency</quote> has the meaning
			 given the term <quote>Executive agency</quote> in section 105 of title 5,
			 United States Code.</text>
			</paragraph><paragraph id="ID3690d7a96c8047d1857fefa96be29b3e"><enum>(5)</enum><header>Intelligence
			 community</header><text>The term <term>intelligence community</term> has the
			 meaning given that term in section 3(4) of the National Security Act of 1947
			 (50 U.S.C. 401a(4)).</text>
			</paragraph><paragraph id="ID2a444f5b4191465c9ad6cf3133464161"><enum>(6)</enum><header>Local
			 government</header><text>The term <term>local government</term> has the meaning
			 given that term in section 2 of the Homeland Security Act of 2002 (6 U.S.C.
			 101).</text>
			</paragraph><paragraph id="id8EFA0DEFA99742AB838D63936B15AAA8"><enum>(7)</enum><header>National Cyber
			 Security Program</header><text>The term “National Cyber Security Program” means
			 the programs, projects, and activities of the Federal Government to protect and
			 defend Federal Government information networks and to facilitate the protection
			 and defense of United States information networks.</text>
			</paragraph><paragraph id="id813B3DB7BD5A49AA82DFE29BBBB899F1"><enum>(8)</enum><header>Network</header><text>The
			 term <quote>network</quote> has the meaning given that term by section 4(5) of
			 the High-Performance Computing Act of 1991 (15 U.S.C. 5503(5)).</text>
			</paragraph><paragraph commented="no" id="IDf805e6e312f6405eb9e2b3248715477b"><enum>(9)</enum><header>State</header><text>The
			 term <quote>State</quote> means—</text>
				<subparagraph commented="no" id="IDd42890bf32dd4907803a8a582fe0cb87"><enum>(A)</enum><text>a State;</text>
				</subparagraph><subparagraph commented="no" id="ID72f927e7906e4ffea3e59020698b5673"><enum>(B)</enum><text>the District of
			 Columbia;</text>
				</subparagraph><subparagraph commented="no" id="ID1e5493e1cb3f484f8efbbc9ade3049cd"><enum>(C)</enum><text>the Commonwealth
			 of Puerto Rico; and</text>
				</subparagraph><subparagraph commented="no" id="ID8674c614eb0b4fb0b40a9bcc13090a05"><enum>(D)</enum><text>any other
			 territory or possession of the United States.</text>
				</subparagraph></paragraph></section><title id="id52520C6207D5409EBEAEBE717A385F74"><enum>I</enum><header>National Cyber
			 Center</header>
			<section id="ID920e4a536d3c4083bb106113534d015b"><enum>101.</enum><header>Director
			 defined</header><text display-inline="no-display-inline">In this title, except
			 as otherwise specifically provided, the term <quote>Director</quote> means the
			 Director of the National Cyber Center appointed under section 103.</text>
			</section><section id="id626A3940764B4336AA6670BB8E546DBE"><enum>102.</enum><header>Establishment
			 of the National Cyber Center</header>
				<subsection id="id66C392FF3CC643CABB66B79C381FF9EA"><enum>(a)</enum><header>In
			 general</header><text>There is within the Department of Defense a National
			 Cyber Center.</text>
				</subsection><subsection id="id70595AFABA9842FF8EFE93A862EDBAA5"><enum>(b)</enum><header>Administrative
			 and logistical support</header><text>Except as otherwise specifically provided
			 in this Act, the Secretary of Defense shall provide only administrative and
			 logistical support for the daily operation of the National Cyber Center.</text>
				</subsection></section><section id="ID6450bfc6c81b45358766b988d92c0a63"><enum>103.</enum><header>Director of
			 the National Cyber Center</header>
				<subsection id="id62299ED555994DA7ADB55D592B130FF7"><enum>(a)</enum><header>In
			 general</header><text>The head of the National Cyber Center is the Director of
			 the National Cyber Center, who shall be appointed by the President, by and with
			 the advice and consent of the Senate.</text>
				</subsection><subsection id="id80091B3FCD9A43308C556ECB9126E5D0"><enum>(b)</enum><header>Term and
			 conditions of appointment</header><text>A Director shall serve for a term not
			 to exceed five years and during such term may not simultaneously serve in any
			 other capacity in the Executive branch.</text>
				</subsection><subsection id="idF147F488036D4C7D940921C40BE49A90"><enum>(c)</enum><header>Reporting and
			 placement</header>
					<paragraph id="id584E98BD01194CA8B59258E11EB39D0C"><enum>(1)</enum><header>Reporting</header><text>The
			 Director shall report directly to the President.</text>
					</paragraph><paragraph id="id0E6FE816CA444AB088188C4F327EF80C"><enum>(2)</enum><header>Placement</header><text>The
			 position of the Director shall not be located within the Executive Office of
			 the President.</text>
					</paragraph></subsection><subsection id="IDbc0fc46d3d484e4d8ee1d8fbcb47c1f8"><enum>(d)</enum><header>Duties of the
			 Director</header><text>The Director shall—</text>
					<paragraph id="IDcc1ec948620f4ecfaf3603ac9d6534a8"><enum>(1)</enum><text>coordinate
			 Federal Government defensive operations, intelligence collection and analysis,
			 and activities to protect and defend Federal Government information
			 networks;</text>
					</paragraph><paragraph id="IDf5a8dbb5f2704b5cb938ebe6fc9f92a6"><enum>(2)</enum><text>act as the
			 principal adviser to the President, the National Security Council, and to the
			 heads of Federal agencies on matters relating to the protection and defense of
			 Federal Government information networks;</text>
					</paragraph><paragraph id="IDf71deb5e57f14c6591870920b800d83d"><enum>(3)</enum><text>coordinate, and
			 ensure the adequacy of, the National Cyber Security Program budgets for Federal
			 agencies;</text>
					</paragraph><paragraph id="IDdd79025c278949b78787032de3efa5a1"><enum>(4)</enum><text>maintain and
			 disperse funds from the National Cyber Defense Contingency Fund in accordance
			 with section 108;</text>
					</paragraph><paragraph id="id8CEB354E8346433589388A93B14BB391"><enum>(5)</enum><text>ensure
			 appropriate coordination within the Federal Government for the implementation
			 of any cyber security activities conducted by a Federal agency;</text>
					</paragraph><paragraph id="IDb8612c35768047a284a41448e7f31c88"><enum>(6)</enum><text>ensure
			 appropriate coordination within the Federal Government for the conduct of any
			 operations, strategies, and intelligence collection and analysis relating to
			 the protection and defense of Federal Government information networks;</text>
					</paragraph><paragraph id="IDf04c0e0e9c4d4c39b452c678ee47f3aa"><enum>(7)</enum><text>provide
			 recommendations, on an ongoing basis, to Federal agencies, private sector
			 entities, and public and private sector entities operating critical
			 infrastructure for procedures to be implemented in the event of an imminent
			 cyber attack that will protect critical infrastructure by mitigating network
			 vulnerabilities;</text>
					</paragraph><paragraph id="IDb7bb508fc36a4c9abf20bd5a9acd2435"><enum>(8)</enum><text>provide
			 assistance to, and cooperate with, the Cyber Defense Alliance established under
			 section 202, including the development of partnerships with public and private
			 sector entities, and academic institutions that encourage cooperation,
			 research, development, and cyber security education and training;</text>
					</paragraph><paragraph id="IDce45f6e60c9c4846bb51fc388db9b3f9"><enum>(9)</enum><text>develop plans and
			 policies for the security of Federal Government information networks to be
			 implemented by the appropriate Federal agency;</text>
					</paragraph><paragraph id="IDd2528523e774424492796f4eba2545ac"><enum>(10)</enum><text>participate in
			 the process to develop reliability standards pursuant to section 215 of the
			 Federal Power Act (16 U.S.C. 824o);</text>
					</paragraph><paragraph id="ID92b1a8d87a294971a3e22c2bb7c0182d"><enum>(11)</enum><text>develop plans
			 and policies for the sharing of cyber threat-related information among
			 appropriate Federal agencies, and to the extent consistent with the protection
			 of national security sources and methods, with State, tribal, and local
			 government departments, agencies, and entities, and public and private sector
			 entities that operate critical infrastructure;</text>
					</paragraph><paragraph id="ID639b1fc3943e4b569365f6dbbd82b9b7"><enum>(12)</enum><text>develop policies
			 and procedures to ensure the continuity of Federal Government operations in the
			 event of a national cyber crisis; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID90f5fcafe93f4f17bc28d35ccbf743d9"><enum>(13)</enum><text>perform such
			 other functions as may be directed by the President.</text>
					</paragraph></subsection></section><section id="IDa71dc2e9a1c84dd28d71244439648261"><enum>104.</enum><header>Missions of
			 the National Cyber Center</header>
				<subsection id="id977C564746B04C0991BBAC9483F3CA19"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">The National Cyber
			 Center shall—</text>
					<paragraph id="id4D60BCE3D8B84B6E93B715EC1CD063C2"><enum>(1)</enum><text>serve as the
			 primary organization for coordinating Federal Government defensive operations,
			 intelligence collection and analysis, and activities to protect and defend
			 Federal Government information networks;</text>
					</paragraph><paragraph id="id7B9EC02A9C6747969EFBFB6EFA02821F"><enum>(2)</enum><text>develop policies
			 and procedures for implementation across the Federal Government on matters
			 relating to the protection and defense of Federal Government information
			 networks;</text>
					</paragraph><paragraph id="id24DA332064D84721BFF12EA4157ED836"><enum>(3)</enum><text>provide a process
			 for resolving conflicts among Federal agencies relating to the implementation
			 of cyber security activities or the conduct of operations, strategies, and
			 intelligence collection and analysis relating to the protection and defense of
			 Federal Government information networks;</text>
					</paragraph><paragraph id="idBC57E7EFFA104E23BF9833341C6E9047"><enum>(4)</enum><text>assign roles and
			 responsibilities to Federal agencies, as appropriate, for the protection and
			 defense of Federal Government information networks that are consistent with
			 applicable law; and</text>
					</paragraph><paragraph id="id939B4A27F45942D396F788483EFC381A"><enum>(5)</enum><text>ensure that, as
			 appropriate, Federal agencies have access to, and receive, information,
			 including appropriate private sector information, regarding cyber threats to
			 Federal Government information networks.</text>
					</paragraph></subsection><subsection id="ID0ad92de109fe499aac29b1b4c4294d0e"><enum>(b)</enum><header>Access to
			 intelligence</header><text>The Director shall have access to all intelligence
			 relating to cyber security collected by any Federal agency—</text>
					<paragraph id="id5CF2C251CC1A44A8B40EA732456D913F"><enum>(1)</enum><text>except as
			 otherwise provided by law;</text>
					</paragraph><paragraph id="id78064F1834D445C1AC668A71829D68E9"><enum>(2)</enum><text>unless otherwise
			 directed by the President; or</text>
					</paragraph><paragraph id="idB5213ABC7728487F8F541FE5BCE49AB1"><enum>(3)</enum><text>unless the
			 Attorney General and the Director agree on guidelines to limit such
			 access.</text>
					</paragraph></subsection></section><section id="IDc650e7f34c014d58847c638c72b93055"><enum>105.</enum><header>Composition of
			 National Cyber Center</header>
				<subsection id="idF896A07CB5A645F49B51AF8703566F2E"><enum>(a)</enum><header>Integration of
			 resources</header><text>Not later than 90 days after the date of the
			 confirmation of the initial Director, the Secretary of Defense, the Secretary
			 of Homeland Security, the Director of National Intelligence, and the Director
			 of the Federal Bureau of Investigation shall, in consultation with the
			 Director, collocate and integrate within the National Cyber Center such
			 elements, offices, task forces, and other components of the Department of
			 Defense, the Department of Homeland Security, the intelligence community, and
			 the Federal Bureau of Investigation that are necessary to carry out the
			 missions of the National Cyber Center.</text>
				</subsection><subsection id="ID36c4ac3d39034469a20f63c58afe6247"><enum>(b)</enum><header>Participation
			 of Federal agencies</header><text>Any Federal agency not referred to in
			 subsection (a) may participate in the National Cyber Center if the head of such
			 Federal agency and the Director agree on the level and type of such
			 participation.</text>
				</subsection><subsection id="ID1723ddf46f5840818c8cf1f916744fe8"><enum>(c)</enum><header>Recommendations
			 for consolidation</header><text>In order to reduce duplication of Federal
			 Government efforts, the Director may recommend that the President transfer to,
			 and consolidate within, the National Cyber Center activities that relate to the
			 protection and defense of Federal Government information networks.</text>
				</subsection><subsection id="ID98b4939ba6da41489909fbdae779912d"><enum>(d)</enum><header>Integration of
			 information networks</header><text>The Director shall, in coordination with the
			 appropriate head of a Federal agency, oversee the integration within the
			 National Cyber Center of information relating to the protection and defense of
			 Federal Government information networks, including to the extent necessary and
			 consistent with the protection of sources and methods, databases containing
			 such information.</text>
				</subsection></section><section id="ID4693ad1d6c6d443a9f5a00a669f5d96b"><enum>106.</enum><header>National Cyber
			 Center officials</header>
				<subsection id="id9F014170E2CD4FC592C281AAF9344E6B"><enum>(a)</enum><header>Deputy
			 Director</header>
					<paragraph id="idFE19447396EF4872BCBC1306B606BCFB"><enum>(1)</enum><header>In
			 general</header><text>There is a Deputy Director of the National Cyber Center
			 who shall be appointed by the Director.</text>
					</paragraph><paragraph id="id3D72FA3C531842EA8C2027CE201BE237"><enum>(2)</enum><header>Appointment
			 criteria</header><text>An individual appointed Deputy Director of the National
			 Cyber Center shall have extensive cyber security and management
			 expertise.</text>
					</paragraph><paragraph id="idA1ACB42ACE4F4204A01F55FFED63F287"><enum>(3)</enum><header>Duties</header><text>The
			 Deputy Director shall—</text>
						<subparagraph id="id030B92B45CBD4D79A628F7B28A83CE2C"><enum>(A)</enum><text>assist the
			 Director in carrying out the duties and responsibilities of the Director;
			 and</text>
						</subparagraph><subparagraph id="id67D90254B2414C9E91BA4C8D484378A9"><enum>(B)</enum><text>act for, and
			 exercise the powers of, the Director during the absence or disability of the
			 Director or during a vacancy in the position of Director.</text>
						</subparagraph></paragraph></subsection><subsection id="ID21734b1ce6714f219e6ef3125e018fd3"><enum>(b)</enum><header>General
			 Counsel</header>
					<paragraph id="idC78EB6B957154F55BFF3E2103310D8D7"><enum>(1)</enum><header>In
			 general</header><text>There is a General Counsel of the National Cyber Center
			 who shall be appointed by the Director.</text>
					</paragraph><paragraph id="id67EB999350664CC5900478DFA5C64655"><enum>(2)</enum><header>Duties</header><text>The
			 General Counsel is the chief legal officer of the National Cyber Center and
			 shall perform such functions as the Director may prescribe.</text>
					</paragraph></subsection><subsection id="ID8d7a3b72d212406e86f586ccf99a4616"><enum>(c)</enum><header>Other
			 officials</header><text>The Director may designate such other officials in the
			 National Cyber Center as the Director determines appropriate.</text>
				</subsection><subsection id="ID5855642b2ecb45bea62486b561b1b5d0"><enum>(d)</enum><header>Staff</header><text>To
			 assist the Director in fulfilling the duties and responsibilities of the
			 Director, the Director shall employ and utilize a professional staff having
			 expertise in matters relating to the mission of the National Cyber Center, and
			 may establish permanent positions and appropriate rates of pay with respect to
			 such staff.</text>
				</subsection></section><section id="ID9167063ff49c4c00a1885dfd69b18a08"><enum>107.</enum><header>National cyber
			 security program budget</header>
				<subsection id="ID0ce6d890edf243d68f10cf55d14891e9"><enum>(a)</enum><header>Submission of
			 cyber budget request to the Director</header><text>For each fiscal year, the
			 head of each Federal agency with responsibilities for matters relating to the
			 protection and defense of Federal Government information networks shall
			 transmit to the Director a copy of the proposed National Cyber Security Program
			 budget request of the agency prior to the submission of such proposed budget
			 request to the Office of Management and Budget in the preparation of the budget
			 of the President submitted to Congress under section 1105(a) of title 31,
			 United States Code.</text>
				</subsection><subsection id="ID8e9b19f35ec2410ab9419765d1bb51a5"><enum>(b)</enum><header>Review and
			 certification of budget requests and budget submissions</header>
					<paragraph id="IDb5887a32305246c7aabe869e91317bda"><enum>(1)</enum><header>In
			 general</header><text>The Director shall review each budget request submitted
			 to the Director under subsection (a).</text>
					</paragraph><paragraph id="IDe548f55941bb43c5b70e59436038374b"><enum>(2)</enum><header>Review of
			 budget requests</header>
						<subparagraph id="IDc33617da5ada44b0ae2ce8e317c1de8f"><enum>(A)</enum><header>Inadequate
			 requests</header><text>If the Director concludes that a budget request
			 submitted under subsection (a) for a Federal agency is inadequate to accomplish
			 the protection and defense of Federal Government information networks, or to
			 facilitate the protection and defense of United States information networks,
			 with respect to such Federal agency for the year for which the request is
			 submitted, the Director shall submit to the head of such Federal agency a
			 written description of funding levels and specific initiatives that would, in
			 the determination of the Director, make the request adequate to accomplish the
			 protection and defense of such information networks.</text>
						</subparagraph><subparagraph id="ID40da0ae5309b4c3a887344627a409cfd"><enum>(B)</enum><header>Adequate
			 requests</header><text>If the Director concludes that a budget request
			 submitted under subsection (a) for a Federal agency is adequate to accomplish
			 the protection and defense of Federal Government information networks, or to
			 facilitate the protection and defense of United States information networks,
			 with respect to such Federal agency for the year for which the request is
			 submitted, the Director shall submit to the head of such Federal agency a
			 written statement confirming the adequacy of the request.</text>
						</subparagraph><subparagraph id="IDac93f57b5f7444c79880b7eb60abc864"><enum>(C)</enum><header>Record</header><text>The
			 Director shall maintain a record of each description submitted under
			 subparagraph (A) and each statement submitted under subparagraph (B).</text>
						</subparagraph></paragraph><paragraph id="IDad3f09f267a44cc48182346db5d1d44e"><enum>(3)</enum><header>Agency
			 response</header>
						<subparagraph id="ID864bf6e63efe4b5ea985e6bff51eda2a"><enum>(A)</enum><header>In
			 general</header><text>The head of a Federal agency that receives a description
			 under paragraph (2)(A) shall include the funding levels and initiatives
			 described by the Director in the National Cyber Security Program budget
			 submission for such Federal agency to the Office of Management and
			 Budget.</text>
						</subparagraph><subparagraph id="IDcdce6856b8e14733b04bea0bff315eb2"><enum>(B)</enum><header>Impact
			 statement</header><text>If the head of a Federal agency alters the National
			 Cyber Security Program budget submission of such agency based on a description
			 received under paragraph (2)(A), such head shall include as an appendix to the
			 budget submitted to the Office of Management and Budget for such agency an
			 impact statement that summarizes—</text>
							<clause id="ID7a685894cc6f4de38bd8e48587a9ee74"><enum>(i)</enum><text>the
			 changes made to the budget based on such description; and</text>
							</clause><clause id="ID7dc80a38c7af4a419ef549da0e0ef239"><enum>(ii)</enum><text>the impact of
			 such changes on the ability of such agency to perform its other
			 responsibilities, including any impact on specific missions or programs of such
			 agency.</text>
							</clause></subparagraph></paragraph><paragraph id="ID054d26b30f894fcdba271e68e99ed02a"><enum>(4)</enum><header>Congressional
			 notification</header><text>The head of a Federal agency shall submit to
			 Congress a copy of any impact statement prepared under paragraph (3)(B) at the
			 time the National Cyber Security Program budget for such agency is submitted to
			 Congress under section 1105(a) of title 31, United States Code.</text>
					</paragraph><paragraph id="ID0837ab622959412eafd50cd9196bda5c"><enum>(5)</enum><header>Certification
			 of National Cyber Security Program budget submissions</header>
						<subparagraph id="ID56f9ce8abbcc4a429e083f30c79157a5"><enum>(A)</enum><header>In
			 general</header><text>At the time the head of a Federal agency submits a
			 National Cyber Security Program budget request for such agency for a fiscal
			 year to the Office of Management and Budget, such head shall submit a copy of
			 the National Cyber Security Program budget request to the Director.</text>
						</subparagraph><subparagraph id="IDd26b2cffaf7449c38e5cf4093299c421"><enum>(B)</enum><header>Decertification</header>
							<clause id="IDacc2a204d2d045db8ca42268c4f0cb1f"><enum>(i)</enum><header>In
			 general</header><text>The Director shall review each National Cyber Security
			 Program budget request submitted under subparagraph (A).</text>
							</clause><clause id="IDeb79034b8e344efe9477f76fe1f1c54c"><enum>(ii)</enum><header>Budget
			 decertification</header><text>If, based on the review under clause (i), the
			 Director concludes that such budget request does not include the funding levels
			 and specific initiatives that would, in the determination of the Director, make
			 the request adequate to accomplish the protection and defense of Federal
			 Government information networks, or to facilitate the protection and defense of
			 United States information networks, the Director may issue a written
			 decertification of such Federal agency's budget.</text>
							</clause><clause id="ID5d21d390657941ceb42b50a1eb489854"><enum>(iii)</enum><header>Submission to
			 Congress</header><text>In the case of a decertification of a budget request
			 issued under clause (ii), the Director shall submit to Congress a copy
			 of—</text>
								<subclause id="IDbfaf8cd9f9874002b730a6602e600864"><enum>(I)</enum><text>such National
			 Cyber Security Program budget request;</text>
								</subclause><subclause id="id381C38B262354FD5A6B4501CF3008014"><enum>(II)</enum><text>such
			 decertification; and</text>
								</subclause><subclause id="ID511f87c8e17d47919cfaf1320aa223de"><enum>(III)</enum><text>the description
			 made for the budget request under paragraph (2)(B).</text>
								</subclause></clause></subparagraph></paragraph></subsection><subsection id="IDdcebeeac44e74d948a9db72a9959873b"><enum>(c)</enum><header>Consolidated
			 National Cyber Security Program budget proposal</header><text>For each fiscal
			 year, following the transmission of proposed National Cyber Security Program
			 budget requests for Federal agencies to the Director under subsection (a), the
			 Director shall, in consultation with the head of such Federal agencies—</text>
					<paragraph id="IDb504f6d873ca447bb15cfd6a08f9ada7"><enum>(1)</enum><text>develop a
			 consolidated National Cyber Security Program budget proposal;</text>
					</paragraph><paragraph id="IDe2f87ed8478c44778d6d3c08b22745a4"><enum>(2)</enum><text>submit the
			 consolidated budget proposal to the President; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDa6830ad2e52b48c99ce3a9b64d53ba71"><enum>(3)</enum><text>after making the
			 submission required by paragraph (2), submit the consolidated budget proposal
			 to Congress.</text>
					</paragraph></subsection></section><section id="ID4ee6124939c44254ab625324956b21b3"><enum>108.</enum><header>National cyber
			 defense contingency fund</header>
				<subsection id="IDeb512d3582d34d9dbb753ff4621a09fb"><enum>(a)</enum><header>Establishment
			 of Fund</header><text>There is established within the National Cyber Security
			 Program Budget a fund to be known as the <quote>National Cyber Defense
			 Contingency Fund,</quote> which shall consist of amounts appropriated to the
			 Fund for the purpose of providing financial assistance and technical and
			 operational support in the event of a significant cyber incident.</text>
				</subsection><subsection id="IDc1dbb456c63944fe914b7b28baec71db"><enum>(b)</enum><header>Administration</header><text>The
			 Director shall be responsible for the administration and management of the
			 amounts in the National Cyber Defense Contingency Fund.</text>
				</subsection><subsection id="ID218fd740e2d941ee9c8e98fb29adc53e"><enum>(c)</enum><header>Use</header><text>In
			 response to a significant cyber incident involving Federal Government or United
			 States information networks, the Director may distribute amounts from the
			 National Cyber Defense Contingency Fund to appropriate Federal agencies.</text>
				</subsection><subsection id="IDc1a77d1e3b564167a69e8c4acbb01f42"><enum>(d)</enum><header>Notification</header><text>Prior
			 to distributing amounts under this section, the Director shall notify the
			 appropriate congressional committees.</text>
				</subsection><subsection id="ID3b7f4cc673ec4b9b86fddbda34752e2d"><enum>(e)</enum><header>Significant
			 cyber incident defined</header><text>In this section, the term
			 <quote>significant cyber incident</quote> means a malicious act, suspicious
			 event, or accident that—</text>
					<paragraph id="idE58121FFF7D74988BF08BC3562E49AB9"><enum>(1)</enum><text>causes a
			 disruption of Federal Government or United States information networks;</text>
					</paragraph><paragraph id="id440035B368C649918CCFF23822015D62"><enum>(2)</enum><text>affects one or
			 more Federal agencies or public or private sector entities operating critical
			 infrastructure;</text>
					</paragraph><paragraph id="id162C4A10AD5C4D7B97D19567CC042E6B"><enum>(3)</enum><text>affects more than
			 one State or a substantial number of residents in one or more States;
			 and</text>
					</paragraph><paragraph id="id39E73F0598D747509BAFA629085CC1BA"><enum>(4)</enum><text>results in a
			 substantial likelihood of harm or financial loss to the United States or its
			 citizens.</text>
					</paragraph></subsection></section><section commented="no" id="IDa8c2ba0f085d408ab83f4784991478e6"><enum>109.</enum><header>Program budget
			 submission</header>
				<subsection id="id3DC2CF82993C43D6A0D565F435C91D11"><enum>(a)</enum><header>Submission</header><text display-inline="yes-display-inline">Section 1105(a) of title 31, United States
			 Code, is amended by adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idBE0CD566B1304C249A74E76049708A1D" style="OLC">
						<paragraph id="ID0ead13951b1142219fe6ca97cf7c1fe7"><enum>(38)</enum><text>a separate
				statement of the combined and individual amounts of appropriations requested
				for the National Cyber Security Program, including a separate statement of the
				amounts of appropriations requested by the Secretary of Defense for the
				operation and activities of the National Cyber Center and a separate statement
				of the amounts of appropriations requested by the Secretary of Energy for the
				operation and activities of the Cyber Defense
				Alliance.</text>
						</paragraph><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="id516E459E2AFE4B9F866C30500BB309AD"><enum>(b)</enum><header>Technical
			 amendments</header><text>Section 1105(a) of title 31, United States Code, as
			 amended by subsection (a), is further amended—</text>
					<paragraph id="id05AF19C7795240C2A6995FE9EA4CC9F3"><enum>(1)</enum><text>by redesignating
			 the paragraph (33) added by section 889 of the Homeland Security Act of 2002
			 (Public Law 107–296; 116 Stat. 2250) as paragraph (35);</text>
					</paragraph><paragraph id="id80FAA4AF37BB4031B0CA281C2298BD05"><enum>(2)</enum><text>by redesignating
			 the paragraph (35) added by section 203 of the Emergency Economic Stabilization
			 Act of 2008 (division A of Public Law 110–343; 122 Stat. 3765) as paragraph
			 (36); and</text>
					</paragraph><paragraph id="idCF03CEA870524217A36AD8207E4C6219"><enum>(3)</enum><text>by redesignating
			 the paragraph (36) added by section 2 of the Veterans Health Care Budget Reform
			 and Transparency Act of 2009 (Public Law 111–81; 123 Stat. 2137) as paragraph
			 (37).</text>
					</paragraph></subsection></section><section id="ID8e14058659914d529b9643d06a8b5302"><enum>110.</enum><header>Construction</header><text display-inline="no-display-inline">Except as otherwise specifically provided,
			 nothing in this title shall be construed as terminating, altering, or otherwise
			 affecting any authority of the head of a Federal agency collocated within or
			 otherwise participating in the National Cyber Center.</text>
			</section><section id="id8B9BFF751C144605AE2A09E3D58748FB"><enum>111.</enum><header>Congressional
			 oversight</header><text display-inline="no-display-inline">The Director shall
			 keep the appropriate congressional committees fully and currently informed of
			 the significant activities of the National Cyber Center relating to ensuring
			 the security of Federal Government information networks.</text>
			</section></title><title id="idCBFA3D8D7B3B41FEA57649D463A37A79"><enum>II</enum><header>Cyber defense
			 alliance</header>
			<section id="id3FDD00A68A1841E1A64516C6EEB33C95"><enum>201.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="idDE9A07E582D040B2A9CCDC3C6BE9676A"><enum>(1)</enum><header>Board</header><text>The
			 term <quote>Board</quote> means the Board of Directors of the Cyber Defense
			 Alliance established pursuant to section 204(a).</text>
				</paragraph><paragraph id="idBA124185ED5C44F88BD5DB6BDF8F6A53"><enum>(2)</enum><header>National
			 Laboratory</header><text>The term <quote>National Laboratory</quote> has the
			 meaning given that term in section 2 of the Energy Policy Act of 2005 (42
			 U.S.C. 15801).</text>
				</paragraph></section><section id="id52C5AAD026F74B668D62EDA7DCBCDA6A"><enum>202.</enum><header>Cyber Defense
			 Alliance</header>
				<subsection id="id20A140C1956A44F48E34FC12FFF6BC4E"><enum>(a)</enum><header>Charter</header><text>There
			 is within a National Laboratory a public and private partnership for sharing
			 cyber threat information and exchanging technical assistance, advice, and
			 support to be known as the Cyber Defense Alliance.</text>
				</subsection><subsection id="IDbf891f6ea41a4402a8d915f4d94f88a7"><enum>(b)</enum><header>Establishment</header><text>The
			 Secretary of Energy, in coordination with the Director of the National Cyber
			 Center, the Director of National Intelligence, the Secretary of Defense, the
			 Secretary of Homeland Security, and the Director of the Federal Bureau of
			 Investigation, shall determine the appropriate location for, and establish, the
			 Cyber Defense Alliance.</text>
				</subsection><subsection id="ID6bf0e4eb23b94c73988c9071f3d9e1fd"><enum>(c)</enum><header>Criteria</header><text>The
			 criteria to be used in selecting a National Laboratory under subsection (a)
			 shall include the following:</text>
					<paragraph id="ID832942f1c3f84c708af961797cf522c6"><enum>(1)</enum><text>Whether the
			 National Laboratory has received recognition from members of the intelligence
			 community, the Secretary of Homeland Security, or the Secretary of Defense for
			 its cyber capabilities.</text>
					</paragraph><paragraph id="IDbea98b4d7157407caea881c272bfe39d"><enum>(2)</enum><text>Whether the
			 National Laboratory has demonstrated the ability to address cyber-related
			 issues involving varying levels of classified information.</text>
					</paragraph><paragraph id="IDa4ff1730d0df4b719cedb3d3b2761d0d"><enum>(3)</enum><text>Whether the
			 National Laboratory has demonstrated the capability to develop cooperative
			 relationships with the private sector on cyber-related issues.</text>
					</paragraph></subsection><subsection id="ID3034e60a3a8840988d44a99b17847a56"><enum>(d)</enum><header>Partnership</header><text>If
			 the Secretary of Energy, the Director of the National Cyber Center, the
			 Director of National Intelligence, the Secretary of Defense, the Secretary of
			 Homeland Security, and the Director of the Federal Bureau of Investigation
			 determine that the missions and activities of the Cyber Defense Alliance may
			 only be accomplished through a partnership of two or more National Laboratories
			 acting jointly to support the Alliance, then the Alliance may be established
			 and located within such National Laboratories.</text>
				</subsection></section><section id="ID81105f53690840c1900c6c81129f33da"><enum>203.</enum><header>Mission and
			 activities</header><text display-inline="no-display-inline">The Cyber Defense
			 Alliance shall—</text>
				<paragraph id="id53876C46A1C94CEA8348662E3C83AF46"><enum>(1)</enum><text display-inline="yes-display-inline">facilitate the exchange of ideas and
			 technical assistance and support related to the security of public, private,
			 and critical infrastructure information networks;</text>
				</paragraph><paragraph id="IDf33ad894953e44f1bdeac9ec0f81e4be"><enum>(2)</enum><text>promote research
			 and development, including the advancement of private funding for research and
			 development, related to ensuring the security of public, private, and critical
			 infrastructure information networks;</text>
				</paragraph><paragraph id="ID008ddaeff42b4565aca38ee267b2131f"><enum>(3)</enum><text>serve as a
			 national clearinghouse for the exchange of cyber threat information for the
			 benefit of the private sector, educational institutions, State, tribal, and
			 local governments, public and private sector entities operating critical
			 infrastructure, and the Federal Government in order to enhance the ability of
			 recipients of such information to ensure the protection and defense of public,
			 private, and critical infrastructure information networks; and</text>
				</paragraph><paragraph id="ID1ca987db73514e818fdab516edee4f06"><enum>(4)</enum><text>coordinate with
			 the private sector, State, tribal, and local governments, the governments of
			 foreign countries, international organizations, and academic institutions in
			 developing and encouraging the use of voluntary standards for enhancing the
			 security of information networks.</text>
				</paragraph></section><section id="ID801cffa35b9347dbb3cfd20346ea2f17"><enum>204.</enum><header>Board of
			 Directors</header>
				<subsection id="IDfeb2876c8f59489db123d34df6aa30e5"><enum>(a)</enum><header>In
			 general</header><text>The Cyber Defense Alliance shall have a Board of
			 Directors which shall be responsible for—</text>
					<paragraph id="idB9A0A5D6D736430B84CF822C908E18C3"><enum>(1)</enum><text>the executive and
			 administrative operation of the Alliance, including matters relating to funding
			 and promotion of the Alliance; and</text>
					</paragraph><paragraph id="id7737E00F72E34283BF66FA5D3F860DFC"><enum>(2)</enum><text>ensuring and
			 facilitating compliance by members of the Alliance with the requirements of
			 this title.</text>
					</paragraph></subsection><subsection id="id193507E6227D456EA711792913017C6D"><enum>(b)</enum><header>Composition</header><text>The
			 Board shall be composed of the following members:</text>
					<paragraph id="IDcb24a88a31534bc0ba94f6eb10c1db11"><enum>(1)</enum><text>One
			 representative of the Department of Energy.</text>
					</paragraph><paragraph id="id723EBDB367394782B57938581F411F48"><enum>(2)</enum><text>Four
			 representatives of Federal agencies, other than the Department of Energy, that
			 have significant responsibility for the protection or defense of government
			 information networks.</text>
					</paragraph><paragraph id="IDb11282aa5ba14eafb885bd86dcd33eb7"><enum>(3)</enum><text>Two
			 representatives from the private sector.</text>
					</paragraph><paragraph id="ID1090781c0a254f43a91df6e84a41462f"><enum>(4)</enum><text>Two
			 representatives of State, tribal, and local government departments, agencies,
			 or entities.</text>
					</paragraph><paragraph id="id20A0D00497F841C097A15F9A343A1395"><enum>(5)</enum><text>Two
			 representatives from the financial sector.</text>
					</paragraph><paragraph id="IDc8cd41b7c047470096b214b63ff9a9af"><enum>(6)</enum><text>Two
			 representatives from electronic communication service providers.</text>
					</paragraph><paragraph id="ID23b4f04dd60b4e449af0f0b0b404eb84"><enum>(7)</enum><text>Two
			 representatives from the transportation industry.</text>
					</paragraph><paragraph id="ID31c89d2964704322a9f30d7bae90e0e9"><enum>(8)</enum><text>Two
			 representatives from the chemical industry.</text>
					</paragraph><paragraph id="ID276090438c1c407ca23a8cb7a5903f56"><enum>(9)</enum><text>Two
			 representatives from a public or private electric utility company or other
			 generators of power.</text>
					</paragraph><paragraph id="ID21c309772ca4406181fca3281dc08573"><enum>(10)</enum><text>One
			 representative from an academic institution with established expertise in
			 cyber-related matters.</text>
					</paragraph><paragraph id="IDe82291219cca4a10ad68d932c2b19b99"><enum>(11)</enum><text>One additional
			 representative with considerable expertise in cyber-related matters.</text>
					</paragraph></subsection><subsection id="IDf3c9c935ca524c2aba0effc9da5323fa"><enum>(c)</enum><header>Initial
			 appointment</header><text>Not later than 30 days after the date of the
			 enactment of this Act, the Director of the National Cyber Center, the Secretary
			 of Energy, the Director of National Intelligence, the Secretary of Defense, the
			 Secretary of Homeland Security, and the Director of the Federal Bureau of
			 Investigation shall jointly appoint the members of the Board described under
			 subsection (b).</text>
				</subsection><subsection id="ID158ee02a13fa403798a2e88b59592ea2"><enum>(d)</enum><header>Terms</header>
					<paragraph id="id2D1B84619F00496FB0597149E790CB06"><enum>(1)</enum><header>Representatives
			 of certain Federal agencies</header><text>Each member of the Board described in
			 subsection (b)(1) shall serve for a term that is—</text>
						<subparagraph id="idD53B7F470CE7447EA9AD3983D44D8D8B"><enum>(A)</enum><text>not longer than
			 three years from the date of the member's appointment; and</text>
						</subparagraph><subparagraph id="idD21C5633002C46C1BEB388F0E84887A6"><enum>(B)</enum><text>determined
			 jointly by the Director of the National Cyber Center, the Secretary of Energy,
			 the Director of National Intelligence, the Secretary of Defense, the Secretary
			 of Homeland Security, and the Director of the Federal Bureau of
			 Investigation.</text>
						</subparagraph></paragraph><paragraph id="IDb82339c900a34e8d92ff6d0a2449e2c5"><enum>(2)</enum><header>Other
			 representatives</header><text>The original members of the Board described in
			 paragraphs (3) through (11) of subsection (b) shall serve an initial term of
			 one year from the date of appointment under subsection (c), at which time the
			 members of the Cyber Defense Alliance shall conduct elections in accordance
			 with the procedures established under subsection (e).</text>
					</paragraph></subsection><subsection id="IDe242b3506af949b4bacf4c22282649f4"><enum>(e)</enum><header>Rules and
			 procedures</header><text>Not later than 90 days after the date of the enactment
			 of this Act, the Board shall establish rules and procedures for the election
			 and service of members of the Board described in paragraphs (3) through (11) of
			 subsection (b).</text>
				</subsection><subsection id="ID532062de41844b56b1d17e08f6502d49"><enum>(f)</enum><header>Leadership</header><text>The
			 Board shall elect from among its members a chair and co-chair of the Board, who
			 shall serve under such terms and conditions as the Board may establish.</text>
				</subsection><subsection id="IDd333dd5bfb2042a2a5a80e35a247283f"><enum>(g)</enum><header>Sub-Boards</header><text>The
			 Board shall have the authority to constitute such sub-Boards, or other advisory
			 groups or panels, from among the members of the Board as may be necessary to
			 assist the Board in carrying out its functions under this section.</text>
				</subsection></section><section id="ID2de184af615a49e38fbdf289e70fdb23"><enum>205.</enum><header>Cyber Defense
			 Alliance membership</header>
				<subsection id="id780D6368CE884F2A8089771E55E5762E"><enum>(a)</enum><header>Requirement for
			 procedures</header><text>Not later than 90 days after the date of the enactment
			 of this Act, the Board shall establish procedures for the voluntary membership
			 by State, tribal, and local government departments, agencies, and entities,
			 private sector businesses and organizations, and academic institutions in the
			 Cyber Defense Alliance.</text>
				</subsection><subsection id="idB281147692064DB68A0F00503BCCBCB0"><enum>(b)</enum><header>Participation
			 by Federal agencies</header><text>The Director of the National Cyber Center, in
			 coordination with the Secretary of Energy, the Director of National
			 Intelligence, the Secretary of Defense, the Secretary of Homeland Security, the
			 Director of the Federal Bureau of Investigation, and the heads of other
			 appropriate Federal agencies, may provide for the participation and cooperation
			 of such Federal agencies in the Cyber Defense Alliance.</text>
				</subsection></section><section id="IDc7c87e24a5904f0a84270dbe67b6baa0"><enum>206.</enum><header>Funding</header>
				<subsection id="idF54BE0978A4947F1BB3BE8F201E0CCFF"><enum>(a)</enum><header>Initial
			 expenses</header><text>Administrative and logistical expenses associated with
			 the initial establishment of the Cyber Defense Alliance shall be paid by the
			 Secretary of Energy and shall be included within the National Cyber Security
			 Program budget request for the Department of Energy.</text>
				</subsection><subsection id="ID08cd31ad539646f3b57770d92decd877"><enum>(b)</enum><header>Other
			 expenses</header>
					<paragraph id="id2DA174049134424499D5FBCF21101DF7"><enum>(1)</enum><header>In
			 general</header><text>Except as provided in paragraph (2), annual
			 administrative and operational expenses for the Cyber Defense Alliance shall be
			 paid by the members of such Alliance, as determined by the Board.</text>
					</paragraph><paragraph id="id0A1A7535DBEA4B83BB6E2CF23FF9AAB9"><enum>(2)</enum><header>Maximum Federal
			 contribution</header><text>Not more than 15 percent of the annual expenses
			 referred to in paragraph (1) may be paid by the Federal Government. Such amount
			 shall be provided under the direction of the Secretary of Energy and shall be
			 included within the National Cyber Security Program budget request for the
			 Department of Energy.</text>
					</paragraph></subsection></section><section id="ID8c11fd718a8a44af910879eb2ab08800"><enum>207.</enum><header>Classified
			 information</header><text display-inline="no-display-inline">Consistent with
			 the protection of sensitive intelligence sources and methods, the Director of
			 National Intelligence shall facilitate—</text>
				<paragraph id="id461AE2C4DA074C7CA6764AF635FD26AF"><enum>(1)</enum><text display-inline="yes-display-inline">the sharing of classified information in
			 the possession of a Federal agency related to threats to information networks
			 with appropriately cleared members of the Alliance, including representatives
			 of the private sector and of public and private sector entities operating
			 critical infrastructure; and</text>
				</paragraph><paragraph id="id3727B147F0624F25B23AFFC05B661B35"><enum>(2)</enum><text display-inline="yes-display-inline">the declassification and sharing of
			 information in the possession of a Federal agency related to threats to
			 information networks with members of the Alliance.</text>
				</paragraph></section><section id="ID9fd1f2cd65404be5a5e89dcc7b84bd42"><enum>208.</enum><header>Voluntary
			 information sharing</header>
				<subsection id="id0AED7BEE19EE4DC2A1C90EF6C2EFBFE0"><enum>(a)</enum><header>Uses of shared
			 information</header>
					<paragraph id="idDA3B7871CE1F4984A61A9A919DA0A81C"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Notwithstanding any
			 other provision of law and subject to paragraph (2), information shared with or
			 provided to the Cyber Defense Alliance or to a Federal agency through such
			 Alliance by any member of the Cyber Defense Alliance that is not a Federal
			 agency in furtherance of the mission and activities of the Alliance as
			 described in section 203—</text>
						<subparagraph id="ID5cfc096582634f81a74f66b2ad25da5f"><enum>(A)</enum><text>shall be exempt
			 from disclosure under section 552 of title 5, United States Code (commonly
			 referred to as the Freedom of Information Act);</text>
						</subparagraph><subparagraph id="IDab303b1ed8714ddab9af2305508d2a9b"><enum>(B)</enum><text>shall not be
			 subject to the rules of any Federal agency or any judicial doctrine regarding
			 ex parte communications with a decision-making official;</text>
						</subparagraph><subparagraph id="ID8afbdda389fe44118be29ebaaff618f2"><enum>(C)</enum><text>shall not,
			 without the written consent of the person or entity submitting such
			 information, be used directly by any Federal agency, any other Federal, State,
			 tribal, or local authority, or any third party, in any civil action arising
			 under Federal or State law if such information is submitted to the Cyber
			 Defense Alliance in good faith and for the purpose of facilitating the missions
			 of such Alliance;</text>
						</subparagraph><subparagraph id="IDf7453e850ed64f878dc0a8e1e2d68ad2"><enum>(D)</enum><text>shall not,
			 without the written consent of the person or entity submitting such
			 information, be used or disclosed by any officer or employee of the United
			 States for purposes other than the purposes of this title, except—</text>
							<clause id="id92D3D9A718FE4D7C80B38E626183AD4A"><enum>(i)</enum><text>in
			 furtherance of an investigation or the prosecution of a criminal act; or</text>
							</clause><clause id="id373F208FAC514D6699AEF1587A257626"><enum>(ii)</enum><text>the disclosure
			 of the information to the appropriate congressional committee;</text>
							</clause></subparagraph><subparagraph id="ID2c12ea8a4520496fafc582e95615481e"><enum>(E)</enum><text>shall not, if
			 subsequently provided to a State, tribal, or local government or government
			 agency—</text>
							<clause id="idB89F4AF0BECF42E7996536E14BC15D48"><enum>(i)</enum><text>be
			 made available pursuant to any State, tribal, or local law requiring disclosure
			 of information or records;</text>
							</clause><clause id="id8E8DEBB13BED4D2FA6917A28307FFF92"><enum>(ii)</enum><text>otherwise be
			 disclosed or distributed to any party by such State, tribal, or local
			 government or government agency without the written consent of the person or
			 entity submitting such information; or</text>
							</clause><clause id="id4F58D803ECD24D3991C7D179C27438CA"><enum>(iii)</enum><text>be used other
			 than for the purpose of protecting information systems, or in furtherance of an
			 investigation or the prosecution of a criminal act; and</text>
							</clause></subparagraph><subparagraph id="ID806590a0c8954c4185bbf9214103548a"><enum>(F)</enum><text>does not
			 constitute a waiver of any applicable privilege or protection provided under
			 law, such as trade secret protection.</text>
						</subparagraph></paragraph><paragraph id="id337E3223E8564C07A5573FE9ABB0C822"><enum>(2)</enum><header>Application</header><text>Paragraph
			 (1) shall only apply to information shared with or provided to the Cyber
			 Defense Alliance or to a Federal agency through such Alliance by a member of
			 the Cyber Defense Alliance that is not a Federal agency if such information is
			 accompanied by an express statement requesting that such paragraph
			 apply.</text>
					</paragraph></subsection><subsection id="ID18751fcdb6a54659aca6466b9b4cc8de"><enum>(b)</enum><header>Limitation</header><text>The
			 Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to any
			 communication of information to a Federal agency made pursuant to this
			 title.</text>
				</subsection><subsection id="ID0abd8389bf52439a8181c53297122ef8"><enum>(c)</enum><header>Procedures</header>
					<paragraph id="id04534FABE88949789A164658365BE4A3"><enum>(1)</enum><header>In
			 general</header><text>Not later than 90 days after the date of the enactment of
			 this Act, the Director of National Intelligence shall, in consultation with the
			 heads of appropriate Federal agencies, establish uniform procedures for the
			 receipt, care, and storage by such agencies of information that is voluntarily
			 submitted to the Federal Government through the Cyber Defense Alliance.</text>
					</paragraph><paragraph id="IDa135da953c9e4086af5c355361ea9ffa"><enum>(2)</enum><header>Elements</header><text>The
			 procedures established under paragraph (1) shall include procedures for—</text>
						<subparagraph id="ID07e057613de04fdfa19c26ec37a28666"><enum>(A)</enum><text>the
			 acknowledgment of receipt by a Federal agency of cyber threat information that
			 is voluntarily submitted to the Federal Government;</text>
						</subparagraph><subparagraph id="ID3489fedf0bf441e9911cf80b7eef1b2d"><enum>(B)</enum><text>the maintenance
			 of the identification of such information;</text>
						</subparagraph><subparagraph id="ID2c33e4f481a943b88c4cd8e24c623cdf"><enum>(C)</enum><text>the care and
			 storage of such information;</text>
						</subparagraph><subparagraph id="ID44e674594c9a48faad971524ac7ea3d0"><enum>(D)</enum><text>limiting
			 subsequent dissemination of such information to ensure that such information is
			 not used for an unauthorized purpose;</text>
						</subparagraph><subparagraph id="IDfe74c1ae878e41019f3cd0ab56479171"><enum>(E)</enum><text>the protection of
			 the constitutional and statutory rights of any individuals who are subjects of
			 such information; and</text>
						</subparagraph><subparagraph id="ID7bcca1592e794b2dbbb92f27c0758fb9"><enum>(F)</enum><text>the protection
			 and maintenance of the confidentiality of such information so as to permit the
			 sharing of such information within the Federal Government and with State,
			 tribal, and local governments, and the issuance of notices and warnings related
			 to the protection of information networks, in such manner as to protect from
			 public disclosure the identity of the submitting person or entity, or
			 information that is proprietary, business sensitive, relates specifically to
			 the submitting person or entity, and is otherwise not appropriately in the
			 public domain.</text>
						</subparagraph></paragraph></subsection><subsection id="ID8af9dcd0518d4a57bb53ad5dbeda5798"><enum>(d)</enum><header>Independently
			 obtained information</header><text>Nothing in this section shall be construed
			 to limit or otherwise affect the ability of a Federal agency, a State, tribal,
			 or local government or government agency, or any third party—</text>
					<paragraph id="id0BB83132505F449CB53F01BDB56DFDBB"><enum>(1)</enum><text>to obtain cyber
			 threat information in a manner other than through the Cyber Defense Alliance,
			 including obtaining any information lawfully and properly disclosed generally
			 or broadly to the public; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idCE8A0CD85ECB40CD820C0887673811B7"><enum>(2)</enum><text>to use such
			 information in any manner permitted by law.</text>
					</paragraph></subsection></section><section id="IDc63ec90902214249896c467136d12ed9"><enum>209.</enum><header>Penalties</header>
				<subsection id="id59E6F1BD6A68430B9ED6A57B93C9D96C"><enum>(a)</enum><header>In
			 general</header><text>It shall be unlawful for any officer or employee of the
			 United States or of any Federal agency to knowingly publish, divulge, disclose,
			 or make known in any manner or to any extent not authorized by law, any cyber
			 threat information protected from disclosure by this title coming to such
			 officer or employee in the course of the employee's employment or official
			 duties or by reason of any examination or investigation made by, or return,
			 report, or record made to or filed with, such officer, employee, or
			 agency.</text>
				</subsection><subsection id="idC30F04D18B5A4C7F8260D8FA7647111B"><enum>(b)</enum><header>Penalty</header><text>Any
			 person who violates subsection (a) shall be fined under title 18, United States
			 Code, imprisoned for not more than 1 year, or both, and shall be removed from
			 office or employment.</text>
				</subsection></section><section id="ID54f56d0e66a34bcfa3f6124ef63292a1"><enum>210.</enum><header>Authority To
			 issue warnings</header><text display-inline="no-display-inline">The Federal
			 Government may provide advisories, alerts, and warnings to relevant companies,
			 targeted sectors, other government entities, or the general public regarding
			 potential threats to information networks as appropriate. In issuing a warning,
			 the Federal Government shall take appropriate actions to protect from
			 disclosure—</text>
				<paragraph id="ID77731b707a924282b5e33661b740f95a"><enum>(1)</enum><text>the source of any
			 voluntarily submitted information that forms the basis for the warning;
			 and</text>
				</paragraph><paragraph id="ID5c3a4a983e24489e969433f3e6c44158"><enum>(2)</enum><text>information that
			 is proprietary, business sensitive, relates specifically to the submitting
			 person or entity, or is otherwise not appropriately in the public
			 domain.</text>
				</paragraph></section><section id="ID4f6b79ad239c453c977b14e593fe5b27"><enum>211.</enum><header>Exemption from
			 antitrust prohibitions</header><text display-inline="no-display-inline">The
			 exchange of information by and between private sector members of the Cyber
			 Defense Alliance, in furtherance of the mission and activities of the Cyber
			 Defense Alliance, shall not be considered a violation of any provision of the
			 antitrust laws (as defined in the first section of the Clayton Act (15 U.S.C.
			 12)).</text>
			</section><section id="ID6f276cfb99034233be8db4257dc16d9c"><enum>212.</enum><header>Duration</header><text display-inline="no-display-inline">The Cyber Defense Alliance shall cease to
			 exist on December 31, 2020.</text>
			</section></title></legis-body>
</bill>
