<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 4021</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20101209">December 9, 2010</action-date>
			<action-desc><sponsor name-id="S308">Mr. Cardin</sponsor> (for himself
			 and <cosponsor name-id="S316">Mr. Whitehouse</cosponsor>) introduced the
			 following bill; which was read twice and referred to the
			 <committee-name committee-id="SSCM00">Committee on Commerce, Science, and
			 Transportation</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To reduce the ability of terrorists, spies, criminals,
		  and other malicious actors to compromise, disrupt, damage, and destroy computer
		  networks, critical infrastructure, and key resources, and for other purposes.
		  </official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Internet and Cybersecurity Safety
			 Standards Act</short-title></quote>.</text>
		</section><section id="id0C3508CB0F084445837A4038DBCAB9BF"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="idF9B3F03F87554F12B278F5DA15D82D29"><enum>(1)</enum><header>Computers</header><text>Except
			 as otherwise specifically provided, the term <term>computers</term> means
			 computers and other devices that connect to the Internet.</text>
			</paragraph><paragraph id="idEF7EFAD0CF4747F8B9BB6BBAE2EE0FFD"><enum>(2)</enum><header>Providers</header><text>The
			 term <term>providers</term> means Internet service providers, communications
			 service providers, electronic messaging providers, electronic mail providers,
			 and other persons who provide a service or capability to enable computers to
			 connect to the Internet.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3E5B4B3D8CE74D3980D38F29BF2D8FF4"><enum>(3)</enum><header>Secretary</header><text>Except
			 as otherwise specifically provided, the term <term>Secretary</term> means the
			 Secretary of Homeland Security.</text>
			</paragraph></section><section id="IDc70b6de9a8cc40b88d904270e8b3941b"><enum>3.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
			<paragraph id="ID667e449ec3564d3bac2ffa6cd029ac11"><enum>(1)</enum><text>While the
			 Internet has had a profound impact on the daily lives of the people of the
			 United States by enhancing communications, commerce, education, and
			 socialization between and among persons regardless of their location, computers
			 may be used, exploited, and compromised by terrorists, criminals, spies, and
			 other malicious actors, and, therefore, computers pose a risk to computer
			 networks, critical infrastructure, and key resources in the United States.
			 Indeed, users of computers are generally unaware that their computers may be
			 used, exploited, and compromised by others with spam, viruses, and other
			 malicious software and agents.</text>
			</paragraph><paragraph id="ID05ef9d318ba644f7b89b76448988fd58"><enum>(2)</enum><text>Since computer
			 networks, critical infrastructure, and key resources of the United States are
			 at risk of being compromised, disrupted, damaged, or destroyed by terrorists,
			 criminals, spies, and other malicious actors who use computers, Internet and
			 cybersecurity safety is an urgent homeland security issue that needs to be
			 addressed by providers, technology companies, and persons who use
			 computers.</text>
			</paragraph><paragraph id="IDc967af54f51c4a56b1c629624b371687"><enum>(3)</enum><text>The Government
			 and the private sector need to work together to develop and enforce minimum
			 Internet and cybersecurity safety standards for users of computers to prevent
			 terrorists, criminals, spies, and other malicious actors from compromising,
			 disrupting, damaging, or destroying the computer networks, critical
			 infrastructure, and key resources of the United States.</text>
			</paragraph></section><section id="id9DBA95B1775B40648881CDE7E9F1C00D"><enum>4.</enum><header>Cost-benefit
			 analysis</header>
			<subsection id="id2A66D63F7D4E460C893A4C4F506F6461"><enum>(a)</enum><header>Requirement for
			 analysis</header><text display-inline="yes-display-inline">The Secretary, in
			 consultation with the Attorney General and the Secretary of Commerce, shall
			 conduct an analysis to determine the costs and benefits of requiring providers
			 to develop and enforce minimum Internet and cybersecurity safety standards for
			 users of computers to prevent terrorists, criminals, spies, and other malicious
			 actors from compromising, disrupting, damaging, or destroying computer
			 networks, critical infrastructure, and key resources.</text>
			</subsection><subsection id="id76150D8EDC084956BA283B88A282DC4F"><enum>(b)</enum><header>Factors</header><text display-inline="yes-display-inline">In conducting the analysis required by
			 subsection (a), the Secretary shall consider all relevant factors, including
			 the effect that the development and enforcement of minimum Internet and
			 cybersecurity safety standards may have on homeland security, the global
			 economy, innovation, individual liberty, and privacy.</text>
			</subsection></section><section id="id9E8403CECB9649E293CB412A618017C9"><enum>5.</enum><header>Consultation</header><text display-inline="no-display-inline">In conducting the analysis required by
			 section 4, the Secretary, in consultation with the Attorney General and the
			 Secretary of Commerce, shall consult with relevant stakeholders in the
			 Government and the private sector, including the academic community, groups, or
			 other institutions, that have scientific and technical expertise related to
			 standards for computer networks, critical infrastructure, or key
			 resources.</text>
		</section><section id="id7C77E5BC351443BA80F045E23FC2F659"><enum>6.</enum><header>Report</header>
			<subsection id="ID86a7d403187149a4bfa6fc2bb6ec6ea9"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of the enactment of
			 this Act, the Secretary shall submit to the appropriate committees of Congress
			 a final report on the results of the analysis required by section 4. Such
			 report shall include the consensus recommendations, if any, for minimum
			 voluntary or mandatory Internet and cybersecurity safety standards that should
			 be developed and enforced for users of computers to prevent terrorists,
			 criminals, spies, and other malicious actors from compromising, disrupting,
			 damaging, or destroying computer networks, critical infrastructure, and key
			 resources</text>
			</subsection><subsection id="ID1ac9d65dcad84d1792ecf2e9ec138561"><enum>(b)</enum><header>Appropriate
			 committees of Congress</header><text>In this section, the term
			 <term>appropriate committees of Congress</term> means—</text>
				<paragraph id="idA62F2409DB7B4430BD588C6E0E362C2A"><enum>(1)</enum><text>the Committee on
			 Commerce, Science, and Transportation, the Committee on Homeland Security and
			 Governmental Affairs, and the Committee on the Judiciary of the Senate;
			 and</text>
				</paragraph><paragraph id="idCC0E6A7887594A2683750950C4BB3AD3"><enum>(2)</enum><text>the Committee on
			 Energy and Commerce, the Committee on Homeland Security, the Committee on the
			 Judiciary, and the Committee on Oversight and Government Reform of the House of
			 Representatives.</text>
				</paragraph></subsection></section></legis-body>
</bill>
