<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>111th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 946</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20090430">April 30, 2009</action-date>
			<action-desc><sponsor name-id="S210">Mr. Lieberman</sponsor> introduced
			 the following bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend the Federal Power Act to provide additional
		  legal authorities to adequately protect the critical electric infrastructure
		  against cyber attack, and for other purposes.</official-title>
	</form>
	<legis-body>
		<section id="idDD54574C135A44FCA96190E2B47FF4B4" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Critical Electric Infrastructure
			 Protection Act of 2009</short-title></quote>.</text>
		</section><section id="H18C10AC095654EF59C8538956793FEAE"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds that—</text>
			<paragraph id="H80D45AD875914C6FAC0967E7B261CC9D"><enum>(1)</enum><text>the critical
			 electric infrastructure of the United States and Canada has more than
			 $1,000,000,000,000 in asset value, more than 200,000 miles of transmission
			 lines, and more than 800,000 megawatts of generating capability, serving over
			 300,000,000 people;</text>
			</paragraph><paragraph id="HDB2124815C0C4EAC8DDFACE47984644C"><enum>(2)</enum><text>the effective
			 functioning of electric infrastructure is highly dependent on computer-based
			 control systems that are used to monitor and manage sensitive processes and
			 physical functions;</text>
			</paragraph><paragraph id="HCD97C403225E4862BB01C2BB18A8C524"><enum>(3)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="id0941261C941B40E692582B3017B8806D"><enum>(A)</enum><text>control systems are
			 becoming increasingly connected to open networks, such as corporate intranets
			 and the Internet; and</text>
				</subparagraph><subparagraph id="idB3EAC7E026BB4C7F822AA9261046C8D2" indent="up1"><enum>(B)</enum><text>according to the United States
			 Computer Emergency Readiness Team of the Department of Homeland Security, the
			 transition towards widely used technologies and open connectivity exposes
			 control systems to the ever-present cyber risks that exist in the information
			 technology world in addition to control system specific risks;</text>
				</subparagraph></paragraph><paragraph id="H25109400BC63436293D500563D31CB8D"><enum>(4)</enum><text>malicious actors
			 pose a significant risk to the electric infrastructure;</text>
			</paragraph><paragraph id="idD2C3AB7CCD91465FB3D95D97E779F5D9"><enum>(5)</enum><text>the Federal
			 Bureau of Investigation has identified multiple sources of threats to the
			 critical electric infrastructure, including foreign nation states, domestic
			 criminals and hackers, and disgruntled employees;</text>
			</paragraph><paragraph id="ID28cd48512e0944aba1fb946b00370ee0"><enum>(6)</enum><text>foreign electric
			 infrastructure has been repeatedly subject to cyber attack;</text>
			</paragraph><paragraph id="id7D4647663CC24D6E8B0DFC5FA291441C"><enum>(7)</enum><text>the Commission to
			 Assess the Threat to the United States from Electromagnetic Pulse Attack
			 reported in 2008 that an electromagnetic pulse attack could cause significant
			 damage or disruption to critical electric infrastructure and other critical
			 infrastructure, due to the widespread use of supervisory control and data
			 acquisition systems;</text>
			</paragraph><paragraph id="IDb6e91fe8bc9143c48b4eeb511ed69a0c"><enum>(8)</enum><text>the Control
			 Systems Security Program of the Department of Homeland Security is designed to
			 increase the reliability, security, and resilience of control systems
			 by—</text>
				<subparagraph id="ID4b684c4286d342238b720c87e73c8591"><enum>(A)</enum><text>developing
			 voluntary cyber risk reduction products;</text>
				</subparagraph><subparagraph id="IDafc9ad00ad5841afa2764c34389dd13b"><enum>(B)</enum><text>supporting the
			 Industrial Control Systems Computer Emergency Response Team of the Department
			 of Homeland Security in developing vulnerability mitigation recommendations and
			 strategies; and</text>
				</subparagraph><subparagraph id="ID8d24dec1a6a246b2af6f434f4d6b773b"><enum>(C)</enum><text>coordinating and
			 leveraging activities for improving the critical infrastructure security
			 posture of the United States;</text>
				</subparagraph></paragraph><paragraph id="H05DA95B5705A40EC804CC4B860B393A1"><enum>(9)</enum><text>in the interest of
			 national and homeland security, a statutory mechanism is necessary to protect
			 the critical electric infrastructure against cyber security threats; and</text>
			</paragraph><paragraph id="HFDB2989C3FF84B9FB584CB65C918F12E"><enum>(10)</enum><text>on May 21, 2008,
			 in testimony before the Committee on Homeland Security of the House of
			 Representatives, Joseph Kelliher, then-Chairman of the Federal Energy
			 Regulatory Commission, stated that the Commission is in need of additional
			 legal authorities to adequately protect the electric power system against cyber
			 attack.</text>
			</paragraph></section><section id="H13FC0AACD3944764842AAC714903F2F0"><enum>3.</enum><header>Investigation of
			 cyber compromise of critical electric infrastructure</header>
			<subsection id="idD4D9E43EDDF64C5AA1A062343EEF2CC3"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Pursuant to section
			 201 of the Homeland Security Act of 2002 (6 U.S.C. 121), the Secretary of
			 Homeland Security, working with other national security and intelligence
			 agencies, shall conduct an investigation to determine if the security of
			 Federally owned programmable electronic devices and communication networks
			 (including hardware, software, and data) essential to the reliable operation of
			 critical electric infrastructure have been compromised.</text>
			</subsection><subsection id="H64B9FDE54AB04518A4C6ABABFFF5E601"><enum>(b)</enum><header>Focus</header><text>The
			 investigation under this section shall focus on—</text>
				<paragraph id="id3B97CFE46D9845209D8B7594CC7A9BF0"><enum>(1)</enum><text>the extent of
			 compromise;</text>
				</paragraph><paragraph id="id07A97ECC4DA0427D8AA473373B906CD4"><enum>(2)</enum><text>the
			 identification of attackers;</text>
				</paragraph><paragraph id="id0C21042E125944D684F20B35B6BB44A3"><enum>(3)</enum><text>the method of
			 penetration;</text>
				</paragraph><paragraph id="id57A2183CA5CB4DC2A0E6E157AD5BA8B8"><enum>(4)</enum><text>the ramifications
			 of the compromise on future operations of critical electric
			 infrastructure;</text>
				</paragraph><paragraph id="id133B6172B0D74C4F9EC7E1F0E0F16241"><enum>(5)</enum><text>the secondary
			 ramifications of the compromise on other critical infrastructure sectors and
			 the functioning of civil society;</text>
				</paragraph><paragraph id="id4922B00F886B4076A31C97C4990CB109"><enum>(6)</enum><text>the ramifications
			 of the compromise on national security, including war fighting capability;
			 and</text>
				</paragraph><paragraph id="idBB4A5C8DAB7440FBB732BBC54803FC56"><enum>(7)</enum><text>recommended
			 mitigation activities.</text>
				</paragraph></subsection><subsection id="H09A24253B07B42298F13C38E69E62D94"><enum>(c)</enum><header>Report</header><text>The
			 Secretary of Homeland Security shall submit to the appropriate committees of
			 Congress (including the Committee on Homeland Security of the House of
			 Representatives and the Homeland Security and Governmental Affairs Committee of
			 the Senate) a report on findings of the investigation, including (at the option
			 of the Secretary) a classified annex.</text>
			</subsection></section><section id="HEAD952C7E4F24870968C6B10C3074E4D"><enum>4.</enum><header>Critical
			 infrastructure</header><text display-inline="no-display-inline">Part II of the
			 Federal Power Act (16 U.S.C. 824 et seq.) is amended by adding at the end the
			 following:</text>
			<quoted-block display-inline="no-display-inline" id="idF91B8C6023964A1C98FEF7D62CF7C5E2" style="OLC">
				<section id="H358B4926BDBA494F83DD38233029B16"><enum>224.</enum><header>Critical
				infrastructure</header>
					<subsection id="HB63A9C55D08B43C9A4EF6873E81F62B7"><enum>(a)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text>
						<paragraph id="H307ACFE3482F4B88B468A2E106BB88"><enum>(1)</enum><header>Critical electric
				infrastructure</header><text display-inline="yes-display-inline">The term
				<term>critical electric infrastructure</term> means systems and assets, whether
				physical or cyber, used for the generation, transmission, distribution, or
				metering of electric energy in interstate commerce that are so vital to the
				United States that the incapacity or destruction of the systems and assets,
				either alone or in combination with the failure of other assets, would have a
				debilitating impact on the security of the United States, national or regional
				economic security, or national or regional public health or safety.</text>
						</paragraph><paragraph id="HDFF139740AF849E4B706AEE4115F6373"><enum>(2)</enum><header>Critical
				electric infrastructure information</header><text>The term <term>critical
				electric infrastructure information</term> means critical infrastructure
				information related to critical electric infrastructure.</text>
						</paragraph><paragraph id="H4051AD5806424D08A62F444632C7B3EB"><enum>(3)</enum><header>Critical
				infrastructure information</header><text>The term <term>critical infrastructure
				information</term> has the same meaning given the term in section 212 of the
				Critical Infrastructure Information Act of 2002 (6 U.S.C. 131).</text>
						</paragraph><paragraph id="HBF6352D5F7624AEAB87226A3FADF63E4"><enum>(4)</enum><header>Cyber
				threat</header><text>The term <term>cyber threat</term> means any act that
				disrupts, attempts to disrupt, or poses a significant risk of disruption to the
				operation of programmable electronic devices and communication networks
				(including hardware, software, and data) essential to the reliable operation of
				critical electric infrastructure.</text>
						</paragraph><paragraph id="H0928BDB1A78840AE934CDC59877B1179"><enum>(5)</enum><header>Cyber
				vulnerability</header><text>The term <term>cyber vulnerability</term> means any
				weakness that, if exploited, poses a significant risk of disruption to the
				operation of programmable electronic devices and communication networks
				(including hardware, software, and data) essential to the reliable operation of
				critical electric infrastructure.</text>
						</paragraph></subsection><subsection id="HFAD9DA20699A4596B09386638F6E9F27"><enum>(b)</enum><header>Assessment,
				report, and determination of vulnerability or threat to critical electric
				infrastructure</header>
						<paragraph id="H4CB6307EDDB04A9A9293697D042F44F9"><enum>(1)</enum><header>In
				general</header><text>Pursuant to section 201 of the Homeland Security Act of
				2002 (6 U.S.C. 121), the Secretary of Homeland Security shall—</text>
							<subparagraph id="id3C1F1F7E647C4A019E4566CDB9BE1A71"><enum>(A)</enum><text>assess cyber
				vulnerabilities and cyber threats to critical infrastructure, including
				critical electric infrastructure and advanced metering infrastructure, on an
				ongoing basis; and</text>
							</subparagraph><subparagraph id="idAFB007C9851548A2A401EE3D5FA39266"><enum>(B)</enum><text>produce reports,
				including recommendations, on a periodic basis.</text>
							</subparagraph></paragraph><paragraph id="H371FFCC1322041769849D99E5AE16859"><enum>(2)</enum><header>Elements of
				reports</header><text>The Secretary shall—</text>
							<subparagraph id="H1F8195EF55174C7F8D20EE7C4C0C2EE4"><enum>(A)</enum><text>include in the
				reports under this section findings regarding cyber vulnerabilities and cyber
				threats to critical electric infrastructure; and</text>
							</subparagraph><subparagraph id="HBE2F73BE28E4491EAEDB17555AF5475F"><enum>(B)</enum><text>provide
				recommendations regarding actions that may be performed by the Federal
				Government or the private sector to enhance individualized and collective
				domestic preparedness and response to the cyber vulnerability or cyber
				threat.</text>
							</subparagraph></paragraph><paragraph id="H9EC5958595204C59B7641E38D5EFE3D8"><enum>(3)</enum><header>Submission of
				report</header><text display-inline="yes-display-inline">The Secretary of
				Homeland Security shall submit to the Commission and the appropriate committees
				of Congress (including the Committee on Homeland Security of the House of
				Representatives and the Committee on Homeland Security and Governmental Affairs
				of the Senate) reports prepared in response to the cyber vulnerability or cyber
				threat that describe the determinations of the Secretary, including (at the
				option of the Secretary) a classified annex.</text>
						</paragraph><paragraph id="ID08934d3e2f4f4ddaa5e39f6c6aabe96b"><enum>(4)</enum><header>Timely
				determination</header>
							<subparagraph id="idE9508C2752A5477183E55E7372CF6705"><enum>(A)</enum><header>In
				general</header><text>In carrying out the assessment required under paragraph
				(1), if the Secretary of Homeland Security determines that a significant cyber
				vulnerability or cyber threat to critical electric infrastructure has been
				identified, the Secretary shall communicate the determination to the Commission
				in a timely manner.</text>
							</subparagraph><subparagraph id="idE99902A8B5914570AD3538F5A6FEEBD7"><enum>(B)</enum><header>Information</header><text>The
				Secretary of Homeland Security may incorporate intelligence or information
				received from other national security or intelligence agencies in making the
				determination.</text>
							</subparagraph></paragraph></subsection><subsection id="HB9F7D6047508475E98E800C5A9C4536"><enum>(c)</enum><header>Commission
				authority</header>
						<paragraph id="H1523C78A29464815B7A6901FFF1FC44D"><enum>(1)</enum><header>Issuance of
				rules or orders</header><text>Following receipt of a finding under subsection
				(b), the Commission shall promulgate or issue (and from time to time amend)
				such rules or orders as are necessary to protect critical electric
				infrastructure against cyber vulnerabilities or cyber threats.</text>
						</paragraph><paragraph id="H6D9571C09073491EA851C7FF5B3F5664"><enum>(2)</enum><header>Emergency
				procedures</header><text>The Commission may issue, in consultation with the
				Secretary of Homeland Security, a rule or order under this section without
				prior notice or hearing if the Commission determines the rule or order must be
				issued immediately to protect critical electric infrastructure from an imminent
				threat or vulnerability.</text>
						</paragraph></subsection><subsection id="HAE2EDE8E9DF44F6183D5D72EABD94C59"><enum>(d)</enum><header>Duration of
				emergency rules or orders</header><text>Any rule or order promulgated or issued
				by the Commission without prior notice or hearing under subsection (c)(2) shall
				remain effective for a period of not more than 90 days unless, during the
				90-day period, the Commission—</text>
						<paragraph id="idA33129BA93394A7889E7B0D04A7A754B"><enum>(1)</enum><text>gives interested
				persons an opportunity to submit written data, views, or arguments (with or
				without opportunity for oral presentation); and</text>
						</paragraph><paragraph id="id1D1438FED13C477FB2FF4ACF3F374B42"><enum>(2)</enum><text>affirms, amends,
				or repeals the rule or order.</text>
						</paragraph></subsection><subsection id="H085731923C60452F86125C2FDF4D5BCD"><enum>(e)</enum><header>Jurisdiction</header>
						<paragraph id="idD0BF0A4D7C34474CACEF7871C681D11C"><enum>(1)</enum><header>In
				general</header><text>Notwithstanding section 201, this section shall apply to
				any entity that owns, controls, or operates critical electric
				infrastructure.</text>
						</paragraph><paragraph id="idB4031D80A81C4052AFB8D60D6B3A2FBD"><enum>(2)</enum><header>Covered
				entities</header>
							<subparagraph id="idC3E952B9BA084121934EC9775504D38D"><enum>(A)</enum><header>In
				general</header><text>An entity described in paragraph (1) shall be subject to
				the jurisdiction of the Commission for purposes of—</text>
								<clause id="idEBB9BDCBE19040168B484FB4E3A1284A"><enum>(i)</enum><text>carrying out this
				section; and</text>
								</clause><clause id="id25C8D3949C3A44E5B8235AFA57327567"><enum>(ii)</enum><text>applying the
				enforcement authorities of this Act with respect to this section.</text>
								</clause></subparagraph><subparagraph id="id790CF65896C342229BAFB39C744D2699"><enum>(B)</enum><header>Jurisdiction</header><text>This
				subsection shall not make an electric utility or any other entity subject to
				the jurisdiction of the Commission for any other purposes.</text>
							</subparagraph></paragraph></subsection><subsection id="H89986FB3A8E4455FB88E6B00234471A1"><enum>(f)</enum><header>Protection of
				critical electric infrastructure information</header><text>Section 214 of the
				Homeland Security Act of 2002 (6 U.S.C. 133) shall apply to critical electric
				infrastructure information submitted to the Commission under this section to
				the same extent as that section applies to critical infrastructure information
				voluntarily submitted to the Department of Homeland Security under that Act (6
				U.S.C. 101 et seq.).</text>
					</subsection><subsection id="id41BDCBCD4F3645F9977B5C2927E905FB"><enum>(g)</enum><header>Protection
				against known cyber vulnerabilities or cyber threats to critical electric
				infrastructure</header>
						<paragraph id="idC2E576040B724120A7E5BDE34DAB7D45"><enum>(1)</enum><header>Interim
				measures</header>
							<subparagraph id="id623C1562910A41B3BCAD9B35B89471BE"><enum>(A)</enum><header>In
				general</header><text display-inline="yes-display-inline">After notice and
				opportunity for comment, the Commission shall establish, in consultation with
				the Secretary of Homeland Security, by rule or order, not later than 120 days
				after the date of enactment of this Act, such mandatory interim measures as are
				necessary to protect against known cyber vulnerabilities or cyber threats to
				the reliable operation of the critical electric infrastructure of the United
				States.</text>
							</subparagraph><subparagraph id="idFFB06F1AE678406F8A39588FEED1660D"><enum>(B)</enum><header>Administration</header><text display-inline="yes-display-inline">The interim reliability measures—</text>
								<clause id="id471D326209B5494392E5D6190723A04B"><enum>(i)</enum><text>shall serve to
				supplement, replace, or modify cybersecurity reliability standards that, as of
				the date of enactment of this section, were in effect pursuant to this Act, but
				that are determined by the Commission, in consultation with the Secretary of
				Homeland Security and other national security agencies, to be inadequate to
				address known cyber vulnerabilities or cyber threats; and</text>
								</clause><clause id="id2B992F85B1404B40BDCA23AB2CCE09B5"><enum>(ii)</enum><text>may be replaced
				by new cybersecurity reliability standards that are developed and approved
				pursuant to this Act following the date of enactment of this section.</text>
								</clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idF8A1C10856784AE483C126C168F59EDE"><enum>(2)</enum><header>Plans</header><text>The
				rule or order issued under this subsection may require any owner, user, or
				operator of critical electric infrastructure in the United States—</text>
							<subparagraph commented="no" display-inline="no-display-inline" id="idA4D00ED67D574FA8A5D23BDF6E7EA51E"><enum>(A)</enum><text>to develop a plan
				to address cyber vulnerabilities or cyber threats identified by the Commission;
				and</text>
							</subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0320840869884A4A8A8F502E5BC045CD"><enum>(B)</enum><text>to submit the
				plan to the Commission for
				approval.</text>
							</subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
		</section></legis-body>
</bill>
