<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-House" bill-type="olc" dms-id="H78A8BEEB1BED4906895491E34C51FDE2" public-private="public">
	<form>
		<distribution-code display="yes">IB</distribution-code>
		<calendar display="yes">Union Calendar No. 501</calendar>
		<congress display="yes">112th CONGRESS</congress>
		<session display="yes">2d Session</session>
		<legis-num>H. R. 3674</legis-num>
		<associated-doc display="yes" role="report">[Report No. 112–592, Part
		  I]</associated-doc>
		<current-chamber display="yes">IN THE HOUSE OF
		  REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20111215">December 15, 2011</action-date>
			<action-desc><sponsor name-id="L000517">Mr. Daniel E. Lungren of
			 California</sponsor> (for himself, <cosponsor name-id="K000210">Mr. King of New
			 York</cosponsor>, <cosponsor name-id="M001157">Mr. McCaul</cosponsor>,
			 <cosponsor name-id="B001257">Mr. Bilirakis</cosponsor>,
			 <cosponsor name-id="M001150">Mrs. Miller of Michigan</cosponsor>,
			 <cosponsor name-id="W000798">Mr. Walberg</cosponsor>,
			 <cosponsor name-id="M001179">Mr. Marino</cosponsor>,
			 <cosponsor name-id="L000576">Mr. Long</cosponsor>, <cosponsor name-id="T000471">Mr. Turner of New York</cosponsor>,
			 <cosponsor name-id="S001187">Mr. Stivers</cosponsor>, and
			 <cosponsor name-id="L000559">Mr. Langevin</cosponsor>) introduced the following
			 bill; which was referred to the
			 <committee-name added-display-style="italic" committee-id="HHM00" deleted-display-style="strikethrough">Committee on Homeland
			 Security</committee-name>, and in addition to the Committees on
			 <committee-name committee-id="HGO00">Oversight and Government
			 Reform</committee-name>, <committee-name committee-id="HSY00">Science, Space,
			 and Technology</committee-name>, <committee-name committee-id="HJU00">the
			 Judiciary</committee-name>, and Select Intelligence (Permanent Select), for a
			 period to be subsequently determined by the Speaker, in each case for
			 consideration of such provisions as fall within the jurisdiction of the
			 committee concerned</action-desc>
		</action>
		<action>
			<action-date date="20120711">July 11, 2012</action-date>
			<action-desc>Reported from the
			 <committee-name added-display-style="italic" committee-id="HHM00" deleted-display-style="strikethrough">Committee on Homeland
			 Security</committee-name> with an amendment</action-desc>
			<action-instruction>Strike out all after the enacting clause and insert
			 the part printed in italic</action-instruction>
		</action>
		<action>
			<action-date date="20120711">July 11, 2012</action-date>
			<action-desc>The Committees on <committee-name committee-id="HGO00">Oversight and Government Reform</committee-name>,
			 <committee-name committee-id="HSY00">Science, Space, and
			 Technology</committee-name>, <committee-name committee-id="HJU00">the
			 Judiciary</committee-name>, and the <committee-name committee-id="HIG00">Permanent Select Committee on
			 Intelligence</committee-name> discharged; referred to the
			 <committee-name committee-id="HIF00">Committee on Energy and
			 Commerce</committee-name> for a period ending not later than September 21,
			 2012, for consideration of such provisions of the bill and amendment as fall
			 within the jurisdiction of that committee pursuant to clause 1(f) of rule
			 X.</action-desc>
		</action>
		<action>
			<action-desc><pagebreak></pagebreak></action-desc>
		</action>
		<action>
			<action-date date="20120921">September 21, 2012</action-date>
			<action-desc>Additional sponsor: <cosponsor name-id="M001181">Mr.
			 Meehan</cosponsor></action-desc>
		</action>
		<action>
			<action-date date="20120921">September 21, 2012</action-date>
			<action-desc>Deleted sponsor: <cosponsor name-id="L000559">Mr.
			 Langevin</cosponsor> (added December 15, 2011; deleted April 25, 2012)
			 </action-desc>
		</action>
		<action>
			<action-date date="20120921">September 21, 2012</action-date>
			<action-desc>The <committee-name committee-id="HIF00">Committee on
			 Energy and Commerce</committee-name> discharged; committed to the Committee of
			 the Whole House on the State of the Union and ordered to be
			 printed</action-desc>
			<action-instruction>For text of introduced bill, see copy of bill as
			 introduced on December 15, 2011</action-instruction>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title display="yes">To amend the Homeland Security Act of 2002
		  to make certain improvements in the laws relating to cybersecurity, and for
		  other purposes.<pagebreak></pagebreak></official-title>
	</form>
	<legis-body changed="added" committee-id="HHM00" display-enacting-clause="yes-display-enacting-clause" id="HAC5A6C86B162432C99E488EA96F04DDD" reported-display-style="italic" style="OLC">
		<section id="H91CE6905BCB34BBF9953891C1F581566" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Promoting and Enhancing Cybersecurity
			 and Information Sharing Effectiveness Act of 2012</short-title></quote> or the
			 <quote><short-title>PRECISE Act of
			 2012</short-title></quote>.</text>
		</section><section id="H3A6F0F3BE7914DE1A31D1428AC196C78"><enum>2.</enum><header>Department of Homeland
			 Security cybersecurity activities</header>
			<subsection id="H048143CD0102488597FF39FEB138B0C0"><enum>(a)</enum><header>In
			 general</header><text>Subtitle C of title II of the Homeland Security Act of
			 2002 is amended by adding at the end the following new sections:</text>
				<quoted-block changed="added" committee-id="HHM00" id="H5830DAABB47D484DA3EB6EACCFDF7B92" reported-display-style="italic" style="OLC">
					<section id="H62CCE416AE504B679EF53F531E42934B"><enum>226.</enum><header>Department of Homeland
				Security cybersecurity activities</header>
						<subsection id="H651730DDC93E49F5AFC54179CB49B0D6"><enum>(a)</enum><header>In
				general</header><text>The Secretary shall perform necessary activities to help
				facilitate the protection of Federal systems and, solely upon the request of
				critical infrastructure owners and operators, assist such critical
				infrastructure owners and operators in protecting their critical infrastructure
				information systems to include—</text>
							<paragraph id="H79719578241C42A6A885E6C942D7D019"><enum>(1)</enum><text>conduct risk assessments,
				subject to the availability of resources and, solely upon request from critical
				infrastructure owners and operators, critical infrastructure information
				systems;</text>
							</paragraph><paragraph id="HC4B3365DFD8C482FA2836CDF74479A44"><enum>(2)</enum><text>assist in fostering the
				development, in conjunction with the National Institute of Standards and
				Technology and other Federal departments and agencies and the private sector,
				of essential information security technologies and capabilities for protecting
				Federal systems and critical infrastructure information systems, including
				comprehensive protective capabilities and other technological solutions;</text>
							</paragraph><paragraph id="HAB2A986E03ED47FEAA581169DC54B222"><enum>(3)</enum><text>assist in efforts to
				mitigate communications and information technology supply chain
				vulnerabilities;</text>
							</paragraph><paragraph id="H01835833C4A64DAF8E1019EE8E0DACC5"><enum>(4)</enum><text>support nationwide
				awareness and outreach efforts, to include participation in appropriate
				interagency cybersecurity awareness and education programs, to educate the
				public;</text>
							</paragraph><paragraph id="H5B80A8B08FC44A11B4EA0000298ACB40"><enum>(5)</enum><text>conduct exercises,
				simulations, and other activities designed to support and evaluate the national
				cyber incident response plan; and</text>
							</paragraph><paragraph id="H57104B71ED6B4D51985A24F6613E1AFE"><enum>(6)</enum><text>subject to the
				availability of resources and, upon request of critical infrastructure owners
				and operators, provide technical assistance, including sending on-site teams,
				to such critical infrastructure owners and operators.</text>
							</paragraph></subsection><subsection id="H7E2D7CBDE93F4065BBD7ADFE93A10CCF"><enum>(b)</enum><header>Interagency
				duties</header><text display-inline="yes-display-inline">At the direction of
				the Office of Management and Budget pursuant to subchapter II of chapter 35 of
				title 44, United States Code, the Secretary shall—</text>
							<paragraph id="HFF5CF588163243D18C4635CBE656A062"><enum>(1)</enum><text>conduct targeted risk
				assessments and operational evaluations, in conjunction with the heads of other
				agencies, for Federal systems that may include threat, vulnerability, and
				impact assessments and penetration testing;</text>
							</paragraph><paragraph id="H77542344E36A4F49BA5C1F93D02C4BA3"><enum>(2)</enum><text display-inline="yes-display-inline">in conjunction with the National Institute
				of Standards and Technology and appropriate Federal departments and agencies,
				as well as the private sector, provide for the use of consolidated intrusion
				detection, prevention, or other protective capabilities and use associated
				countermeasures for the purpose of protecting Federal systems from
				cybersecurity threats;</text>
							</paragraph><paragraph id="H453F3794F13E4AABA609AFD58033AC52"><enum>(3)</enum><text>in conjunction with other
				agencies and the private sector, assess and foster the development of
				information security technologies and capabilities for use and dissemination
				throughout the Department of Homeland Security and to be made available across
				multiple agencies;</text>
							</paragraph><paragraph id="H87E09D03923041388954E439BB53F19B"><enum>(4)</enum><text>designate an entity
				within the Department of Homeland Security to receive reports and information
				about cybersecurity incidents, threats, and vulnerabilities affecting Federal
				systems; and</text>
							</paragraph><paragraph id="HD0DB5D2BBD3946BA9122E4D18A9FD6CF"><enum>(5)</enum><text>provide incident
				detection, analysis, mitigation, and response information and remote or on-site
				technical assistance for Federal systems.</text>
							</paragraph></subsection><subsection display-inline="no-display-inline" id="H53C48D51D85C4C028F38447816AA5A6A"><enum>(c)</enum><header>Cybersecurity
				operational activity</header>
							<paragraph id="H63C09F3B649942F5A4089096E9A98F33"><enum>(1)</enum><header>In
				general</header><text display-inline="yes-display-inline">While carrying out
				the responsibilities authorized in paragraphs (2) and (3) of subsection (b),
				the Secretary is authorized, notwithstanding any other provision of law, to
				acquire, intercept, retain, use, and disclose communications and other system
				traffic that are transiting to or from or stored on Federal systems and to
				deploy countermeasures with regard to such communications and system traffic
				for cybersecurity purposes if the Secretary certifies that—</text>
								<subparagraph id="HB2CA7D7500C04EF092FB5DED0456B7B5"><enum>(A)</enum><text>such acquisitions,
				interceptions, and countermeasures are reasonably necessary for the purpose of
				protecting Federal systems from cybersecurity threats;</text>
								</subparagraph><subparagraph id="H0B69E0BFF9844AC2BF3F4C44A284F367"><enum>(B)</enum><text>the content of
				communications will be collected and retained only when the communication is
				associated with a known or reasonably suspected cybersecurity threat and
				communications and system traffic will not be subject to the operation of a
				countermeasure unless associated with such threats;</text>
								</subparagraph><subparagraph id="HAB017A3F198F434DBC9BEC939FAD29A9"><enum>(C)</enum><text>information obtained
				pursuant to activities authorized under this subsection will only be retained,
				used, or disclosed to protect Federal systems from cybersecurity threats,
				mitigate against such threats, or, with the approval of the Attorney General,
				for law enforcement purposes when the information is evidence of a crime which
				has been, is being, or is about to be committed;</text>
								</subparagraph><subparagraph id="H2D379A9A4283403AA08F796CE863B444"><enum>(D)</enum><text>notice has been provided
				to users of Federal systems concerning the potential for acquisition,
				interception, retention, use, and disclosure of communications and other system
				traffic; and</text>
								</subparagraph><subparagraph id="HEC7CB2D4EB3E442689F670CEC5935054"><enum>(E)</enum><text>such activities are
				implemented pursuant to policies and procedures governing the acquisition,
				interception, retention, use, and disclosure of communications and other system
				traffic that have been reviewed and approved by the Attorney General.</text>
								</subparagraph></paragraph><paragraph id="H38206CF09F6046849740295B526DE818"><enum>(2)</enum><header>Obtaining
				assistance</header><text>The Secretary may enter into contracts or other
				agreements, or otherwise request and obtain the assistance of, private entities
				that provide electronic communication or cybersecurity services to acquire,
				intercept, retain, use, and disclose communications and other system traffic
				consistent with paragraph (1).</text>
							</paragraph><paragraph id="H88D2495824AB400C98A24F79EFE0E365"><enum>(3)</enum><header>Permission by other
				agencies</header><text>Agencies are authorized to permit the Secretary, or a
				private entity providing assistance to the Secretary under paragraph (2), to
				acquire, intercept, retain, use, or disclose communications, system traffic,
				records, or other information transiting to or from or stored on a Federal
				system, notwithstanding any other provision of law, for the purpose of
				protecting Federal systems from cybersecurity threats or mitigating such
				threats in connection with activities under this subsection.</text>
							</paragraph><paragraph id="H412C5D3575E745BAABC86219A3B75112"><enum>(4)</enum><header>Privileged
				communications</header><text>No otherwise privileged communication obtained in
				accordance with, or in violation of, this subtitle shall lose its privileged
				character.</text>
							</paragraph></subsection><subsection id="HBD485118CC794C4E92DFDBB59E8B0846"><enum>(d)</enum><header>Coordination</header>
							<paragraph id="HFD29522E18A84C2589E422F76DCAA75B"><enum>(1)</enum><header>Coordination with other
				entities</header><text>In carrying out cybersecurity activities subsection (a),
				the Secretary shall coordinate, as appropriate, with—</text>
								<subparagraph id="HB2F92024671840FAA401251F8302E2FA"><enum>(A)</enum><text>the head of relevant
				Federal departments or agencies;</text>
								</subparagraph><subparagraph id="HDE42F338B4404110A2FD50C71CEA6D8F"><enum>(B)</enum><text>representatives of State
				and local governments;</text>
								</subparagraph><subparagraph id="HB84BA5FF4B7F4B21BBD08D9994E5A0A3"><enum>(C)</enum><text>owners and operators of
				critical infrastructure;</text>
								</subparagraph><subparagraph id="H44CDC160F8DC4D0DB97717F2F2E5A134"><enum>(D)</enum><text>suppliers of technology
				for owners and operators of critical infrastructure;</text>
								</subparagraph><subparagraph id="H3E618D4CD7534CC5A8064C5EE967A4B3"><enum>(E)</enum><text>academia; and</text>
								</subparagraph><subparagraph id="HE412DC8E9C3D499C80D38635B28B6C5B"><enum>(F)</enum><text>international
				organizations and foreign partners.</text>
								</subparagraph></paragraph><paragraph id="H237956BAFA2A42E88172F9D2BC2D04D1"><enum>(2)</enum><header>Lead DHS cybersecurity
				official</header><text>The Secretary shall designate a lead cybersecurity
				official within the Department to provide leadership to the cybersecurity
				activities of the Department and to ensure that the Department’s cybersecurity
				activities under this subtitle are coordinated with all other infrastructure
				protection and cyber-related programs and activities of the Department,
				including those of any intelligence or law enforcement components or entities
				within the Department.</text>
							</paragraph><paragraph id="H03E6CBB8ABF84687A149AC75B2D45BC0"><enum>(3)</enum><header>Reports to
				congress</header><text>The lead DHS cybersecurity official shall make annual
				reports to the appropriate committees of Congress on the coordination of
				cyber-related programs across the Department.</text>
							</paragraph></subsection><subsection id="H3F334179E89E499DBFB465FB8EE1619D"><enum>(e)</enum><header>Strategy</header><text>In
				carrying out the cybersecurity activities of the Department under subsection
				(a), the Secretary shall develop and maintain a strategy that—</text>
							<paragraph id="H8B23CCC991D5430AA5DF8096CB31C698"><enum>(1)</enum><text>articulates the actions
				of the Department that are necessary to assure the readiness, reliability,
				continuity, integrity, and resilience of Federal systems and critical
				infrastructure information systems;</text>
							</paragraph><paragraph id="H5ED3796D24804F5D8F9C75D23608A450"><enum>(2)</enum><text>includes explicit goals
				and objectives for the Department as well as specific timeframes for
				achievement of stated goals and objectives by the Department;</text>
							</paragraph><paragraph id="H480C192E64464911B45A7C3CECA279F8"><enum>(3)</enum><text>fosters the continued
				superiority and reliability of the United States information technology and
				communications sectors; and</text>
							</paragraph><paragraph id="H990E4A416E834047A44A001108BECEC8"><enum>(4)</enum><text>ensures that activities
				of the Department are undertaken in a manner that protects statutory privacy
				rights and civil liberties of United States persons.</text>
							</paragraph></subsection><subsection id="H8F9714BB4CD944C5AA76567E1477D2E7"><enum>(f)</enum><header>No right or
				benefit</header><text>The provision of assistance or information to critical
				infrastructure owners and operators, upon request of such critical
				infrastructure owners and operators, under this section shall be at the
				discretion of the Secretary and subject to the availability of resources. The
				provision of certain assistance or information to one critical infrastructure
				owner or and operator pursuant to this section shall not create a right or
				benefit, substantive or procedural, to similar assistance or information for
				any other critical infrastructure owner or and operator.</text>
						</subsection><subsection id="HFF41422436B7484A9312B0BFDB39CDC0"><enum>(g)</enum><header>Privacy officer
				oversight</header><text display-inline="yes-display-inline">The Privacy Officer
				of the Department of Homeland Security shall review on an ongoing basis, and
				prepare, as necessary, privacy impact assessments on, the cybersecurity
				policies, programs, and activities of the Department of Homeland Security for
				such purposes as ensuring compliance with all relevant constitutional and legal
				protections.</text>
						</subsection><subsection id="HCACAB37086604F30AC632077C847E720"><enum>(h)</enum><header>Savings
				clause</header><text>Nothing in this subtitle shall be interpreted to—</text>
							<paragraph id="H027D4DAA0A4148DEB5FF35B785161497"><enum>(1)</enum><text>alter or amend the
				authorities of any Federal department or agency other than the Department of
				Homeland Security, including the law enforcement or intelligence authorities of
				any such Federal department or agency or the authority of any such Federal
				department or agency to protect sources and methods and the national
				security;</text>
							</paragraph><paragraph id="H20F72B6BF2154EDB940823541761D1A7"><enum>(2)</enum><text>limit or modify an
				existing information sharing or other relationship;</text>
							</paragraph><paragraph id="H915158F649284C15B19B16D17906AACA"><enum>(3)</enum><text>prohibit a new
				information sharing or other relationship;</text>
							</paragraph><paragraph id="H23D2255064CF42DDBFBAE84050266697"><enum>(4)</enum><text>require a new information
				sharing or other relationship between the Federal Government and a private
				sector entity;</text>
							</paragraph><paragraph id="H609FA4B65D91434F8B1AD896FEB60AAA"><enum>(5)</enum><text display-inline="yes-display-inline">alter or otherwise limit the authority of
				any Federal department or agency to also undertake any activities that the
				Department of Homeland Security is authorized to undertake pursuant to this
				section; or</text>
							</paragraph><paragraph id="H5681E3C7D29D4377B281F8BD8DA8CE28"><enum>(6)</enum><text>provide additional
				authority to, or modify an existing authority of the Department of Homeland
				Security to control, modify, require, or otherwise direct the cybersecurity
				efforts of a private-sector entity or a component of the Federal Government or
				a State, local, or tribal government.</text>
							</paragraph></subsection><subsection id="H6287B1DA45F04AA9BB71D77F08E39B02"><enum>(i)</enum><header>Definitions</header><text>In
				this section:</text>
							<paragraph id="H6DBF76698F884EAEB68874AF509B0ECD"><enum>(1)</enum><text display-inline="yes-display-inline">The term <quote>countermeasure</quote>
				means automated actions with defensive intent to modify or block data packets
				associated with electronic or wire communications, internet traffic, program
				code, or other system traffic transiting to or from or stored on an information
				system for the purpose of protecting the information system from cybersecurity
				threats.</text>
							</paragraph><paragraph id="HFC6D21CF6D8F4A079CDEB3A7E5062611"><enum>(2)</enum><text display-inline="yes-display-inline">The term <quote>Federal systems</quote>
				means information systems owned, operated, leased, or otherwise controlled by a
				Federal department or agency, or on behalf of a Federal department or agency,
				except for national security systems or those information systems under the
				control of, used by, or storing information of the Department of Defense or any
				element of the Intelligence Community, including any information systems used
				or operated by a contractor of the Department of Defense or any element of the
				Intelligence Community, or other organization on behalf of the Department of
				Defense or any element of the Intelligence Community.</text>
							</paragraph><paragraph id="HF9B44BCABA3A46CAA1200FA9085CB6D5"><enum>(3)</enum><text>The term <quote>critical
				infrastructure information systems</quote> means any information system that
				is—</text>
								<subparagraph id="HF4EDE236182843ECAF65BBF5FBFA90F8"><enum>(A)</enum><text>vital to the functioning
				of critical infrastructure as defined in section 5195c(e) of title 42, United
				States Code; or</text>
								</subparagraph><subparagraph id="HECEDB400B0534CE688FE7212B529F15E"><enum>(B)</enum><text>owned or operated by or
				on behalf of a State or local government entity that is necessary to ensure
				essential government operations continue.</text>
								</subparagraph></paragraph><paragraph id="H8762ED48FDE3442DB24E64FBC17751DD"><enum>(4)</enum><text>The term
				<quote>information system</quote> means any equipment or interconnected system
				or subsystem of equipment that is used in the automatic acquisition, storage,
				manipulation, management, movement, control, display, switching, interchange,
				transmission, or reception of data or information, and includes—</text>
								<subparagraph id="HEDEDEF81F5C3456AB6B2B66CFE3F5329"><enum>(A)</enum><text>computers and computer
				networks;</text>
								</subparagraph><subparagraph id="HF3BE4624926E4C9EBF2DA4D3173D86AB"><enum>(B)</enum><text>ancillary
				equipment;</text>
								</subparagraph><subparagraph id="HB5E9CD7BD56B4AD384F33ADD68976502"><enum>(C)</enum><text>software, firmware, and
				related procedures;</text>
								</subparagraph><subparagraph id="H0416E3FA461E422FA32D72BC37E09521"><enum>(D)</enum><text>services, including
				support services; and</text>
								</subparagraph><subparagraph id="HAB9467F296664229ABEBF5F8B1464B0B"><enum>(E)</enum><text>related resources.</text>
								</subparagraph></paragraph><paragraph id="HCAE2D06AF5A64E3FACD9E30E10EB2A5E"><enum>(5)</enum><text>The term <quote>national
				security system</quote> means any information infrastructure (including any
				telecommunications system) used or operated by an agency, by a contractor of an
				agency, or by another organization on behalf of an agency—</text>
								<subparagraph id="H52AC0202F90A49ADADC0B7E9091456B5"><enum>(A)</enum><text>the function, operation,
				or use of which—</text>
									<clause id="H48D069B106FD4EAEA103AF54BCE03A8A"><enum>(i)</enum><text>involves intelligence
				activities or intelligence-related activities;</text>
									</clause><clause id="HDF053CD258C4471A80B7A8B43383C32B"><enum>(ii)</enum><text>involves cryptologic
				activities related to national security;</text>
									</clause><clause id="H7F426BD61C1747969FA007F4134892FF"><enum>(iii)</enum><text>involves command and
				control of military forces;</text>
									</clause><clause id="H248C2C2D83AE41128FCFDBA1CE9FF8BD"><enum>(iv)</enum><text>involves equipment that
				is an integral part of a weapon or weapons system; or</text>
									</clause><clause id="H91EFF482558249EA8D7FF63FF52EFEE9"><enum>(v)</enum><text>is critical to the direct
				fulfillment of military or intelligence missions;</text>
									</clause></subparagraph><subparagraph id="HB36CD948E943407F8A87BBD7CAC2421B"><enum>(B)</enum><text>that contains information
				related to the activities and other matters set forth in subparagraph (A);
				or</text>
								</subparagraph><subparagraph id="H1E7DEE762010497A8B53AA95DF6AD5A1"><enum>(C)</enum><text>that is protected by
				procedures established for classified, national security, foreign policy,
				intelligence or intelligence-related, or other appropriate information.</text>
								</subparagraph></paragraph></subsection></section><section id="HB868424A0A6F486BB7620F60776018DD"><enum>227.</enum><header>Personnel authorities
				related to the Office of Cybersecurity and Communications</header>
						<subsection id="H07398C74684D4373894AFB0BF08C112A"><enum>(a)</enum><header>In
				general</header><text>In order to assure that the Department has the necessary
				resources to carry out the mission set forth in section 226, the Secretary may,
				as necessary, convert competitive service positions, and the incumbents of such
				positions, within the Office of Cybersecurity and Communications to excepted
				service, or may establish new positions within the Office of Cybersecurity and
				Communications in the excepted service, to the extent that the Secretary
				determines such positions are necessary to carry out the cybersecurity
				functions of the Department.</text>
						</subsection><subsection id="H206E86D87ADA44E09A6ADB421068232F"><enum>(b)</enum><header>Compensation</header><text>The
				Secretary may—</text>
							<paragraph id="H455AD6A3697340369727C3D9B718E415"><enum>(1)</enum><text>fix the compensation of
				individuals who serve in positions referred to in subsection (a) in relation to
				the rates of pay provided for comparable positions in the Department and
				subject to the same limitations on maximum rates of pay established for
				employees of the Department by law or regulations; and</text>
							</paragraph><paragraph id="H59F53BEA438C4B9692BF9D6BF5D3CDB9"><enum>(2)</enum><text>provide additional forms
				of compensation, including benefits, incentives, and allowances, that are
				consistent with and not in excess of the level authorized for comparable
				positions authorized under title 5, United States Code.</text>
							</paragraph></subsection><subsection id="H21DBDB377E4D447B9AD77BDFF1A856A2"><enum>(c)</enum><header>Retention
				bonuses</header><text>Notwithstanding any other provision of law, the Secretary
				may pay a retention bonus to any employee appointed under this section, if the
				Secretary determines that the bonus is needed to retain essential personnel.
				Before announcing the payment of a bonus under this subsection, the Secretary
				shall submit a written explanation of such determination to the Committee on
				Homeland Security of the House of Representatives and the Committee on Homeland
				Security and Governmental Affairs of the Senate.</text>
						</subsection><subsection id="HC947CDBDE8F84987A6BCA4F85B97F9E4"><enum>(d)</enum><header>Annual
				report</header><text>Not later than one year after the date of the enactment of
				this section, and annually thereafter, the Secretary shall submit to
				appropriate Congressional committees a detailed report that includes, for the
				period covered by the report—</text>
							<paragraph id="H08D247458C1048B890D490C14D86E593"><enum>(1)</enum><text>a discussion the
				Secretary’s use of the flexible authority authorized under this section to
				recruit and retain qualified employees;</text>
							</paragraph><paragraph id="HD0B7674C8AC14BCFB6EAACFA113FDE03"><enum>(2)</enum><text>metrics on relevant
				personnel actions, including—</text>
								<subparagraph id="H3C41FFD6BE1344AAAE108F6B4C4B71A1"><enum>(A)</enum><text>the number of qualified
				employees hired by occupation and grade, level, or pay band;</text>
								</subparagraph><subparagraph id="H748670716EEC4B5290731C3C64DE94F3"><enum>(B)</enum><text>the total number of
				veterans hired;</text>
								</subparagraph><subparagraph id="HA0BC832092D344F5A1B400D33775FF90"><enum>(C)</enum><text>the number of separations
				of qualified employees;</text>
								</subparagraph><subparagraph id="H6E05BA58D6C34705A6C177B88D5728DD"><enum>(D)</enum><text>the number of retirements
				of qualified employees; and</text>
								</subparagraph><subparagraph id="H88EA3B44CB0340B49C9FCA762BE53F30"><enum>(E)</enum><text>the number and amounts of
				recruitment, relocation, and retention incentives paid to qualified employees
				by occupation and grade, level, or pay band; and</text>
								</subparagraph></paragraph><paragraph id="H3E86C9D6D6274B67945E90172558C102"><enum>(3)</enum><text>long-term and short-term
				strategic goals to address critical skills deficiencies, including an analysis
				of the numbers of and reasons for attrition of employees and barriers to
				recruiting and hiring individuals qualified in cybersecurity.</text>
							</paragraph></subsection></section><section id="H4D7BB83697384BEE98CC0DAC7FBBF183"><enum>228.</enum><header>Federal preemption,
				exclusivity, and law enforcement and intelligence activities</header>
						<subsection id="H5F8A0D8F4E7F420F8351BA55ED16270C"><enum>(a)</enum><header>Preemption</header><text display-inline="yes-display-inline">This subtitle supersedes any statute of a
				State or political subdivision of a State that restricts or otherwise expressly
				regulates the acquisition, interception, retention, use, or disclosure of
				communications, records, or other information by private entities or
				governmental entities to the extent such statute is inconsistent with this
				subtitle.</text>
						</subsection><subsection id="H4319143FA1C54170B01F119CD4EEFE5C"><enum>(b)</enum><header>Additional exclusive
				means</header><text>Section 226(c) constitutes an additional exclusive means
				for the domestic interception of wire or electronic communications, in
				accordance with the provisions of law codified at section 1812(b) of title 50,
				United States Code.</text>
						</subsection><subsection id="HEF28EFF04CB24B4C92646E931FAC6F69"><enum>(c)</enum><header>Limitation</header><text>This
				subtitle does not authorize the Secretary to engage in law enforcement or
				intelligence activities that the Department is not otherwise authorized to
				conduct under existing
				law.</text>
						</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HB6C5061B852C458B97BC9539A2A51AA0"><enum>(b)</enum><header>Clerical
			 amendment</header><text>The table of contents in section 1(b) of such Act is
			 amended by inserting after the item relating to section 225 the following new
			 items:</text>
				<quoted-block changed="added" committee-id="HHM00" display-inline="no-display-inline" id="H27366DC662E74F1EAEE055D816EEF010" reported-display-style="italic" style="OLC">
					<toc changed="added" committee-id="HHM00" container-level="quoted-block-container" idref="H5830DAABB47D484DA3EB6EACCFDF7B92" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration" reported-display-style="italic">
						<toc-entry idref="H62CCE416AE504B679EF53F531E42934B" level="section">Sec. 226. Department of Homeland Security
				cybersecurity activities.</toc-entry>
						<toc-entry idref="HB868424A0A6F486BB7620F60776018DD" level="section">Sec. 227. Personnel authorities related to the
				Office of Cybersecurity and Communications.</toc-entry>
						<toc-entry idref="H4D7BB83697384BEE98CC0DAC7FBBF183" level="section">Sec. 228. Federal preemption, exclusivity, and
				law enforcement and intelligence
				activities.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HA9670B07C84A4445A468F54D7A33EE16"><enum>(c)</enum><header>Plan for execution of
			 authorities</header><text>Not later than 120 days after the date of the
			 enactment of this Act, the Secretary of Homeland Security shall submit to the
			 Committee on Homeland Security of the House of Representatives and the
			 Committee on Homeland Security and Governmental Affairs of the Senate a report
			 containing a plan for the execution of the authorities contained in the
			 amendment made by subsection (a).</text>
			</subsection></section><section id="H49DF45F97343410D8EFAA94179EF4AB7"><enum>3.</enum><header>Department of Homeland
			 Security cybersecurity information sharing</header>
			<subsection id="H7534F88C60C648008EFF6650EF5962EA"><enum>(a)</enum><header>Department of Homeland
			 Security cybersecurity information sharing</header>
				<paragraph id="H5AE1E0C16D394A62A43DE1EE608A32C7"><enum>(1)</enum><header>In
			 general</header><text>Title II of the Homeland Security Act of 2002, as amended
			 by section 2, is further amended by adding at the end the following:</text>
					<quoted-block changed="added" committee-id="HHM00" display-inline="no-display-inline" id="H691CCF39FB1445C3BC94F46A3AB0D6FA" reported-display-style="italic" style="OLC">
						<subtitle id="H996521CE9A9C4CCD9E453D3D026343F5"><enum>E</enum><header>Department of Homeland
				Security Cybersecurity Information Sharing</header>
							<section id="H11EAE9E25A6247659394AF194BB2D2DA"><enum>241.</enum><header>Information
				sharing</header><text display-inline="no-display-inline">The Secretary shall
				make appropriate cyber threat information obtained by the Department pursuant
				to title XI of the National Security Act of 1947 or other information
				appropriately in the possession of the Department available to appropriate
				owners and operators of critical infrastructure on a timely basis consistent
				with the statutory and other appropriate restrictions on the dissemination of
				such information and with the responsibilities of the Secretary under this
				title.</text>
							</section><section id="H6949D505A11647AE83FEEABECEB7D05B"><enum>242.</enum><header>Establishment of
				National Cybersecurity and Communications Integration Center</header>
								<subsection id="HCE94CB535617417DB81C483480D4BDD0"><enum>(a)</enum><header>Establishment</header><text>There
				is established within the Department the National Cybersecurity and
				Communications Integration Center.</text>
								</subsection><subsection id="HD95EB9FF03034F2591A32C67B3FDB382"><enum>(b)</enum><header>Purpose</header><text>The
				center established pursuant to subsection (a) shall be the primary entity
				within the Department for sharing timely cyber threat information and
				exchanging technical assistance, advice, and support with appropriate entities
				pursuant to the Department’s authorities.</text>
								</subsection></section><section id="HD8CF6036FA33461BB3CDDAE7DA8A7B67"><enum>243.</enum><header>Board of
				advisors</header>
								<subsection id="H84219127A0FE41FBB0E9DAC40F6F99C3"><enum>(a)</enum><header>In
				general</header><text>The National Cybersecurity and Communications Integration
				Center shall have a board of advisors which shall advise the Secretary on the
				efficient operation of the National Cybersecurity and Communications
				Integration Center.</text>
								</subsection><subsection id="HE0CE7B58639941F58033D99A65F48A5E"><enum>(b)</enum><header>Composition</header><text>The
				board shall be composed of 13 members, including the following:</text>
									<paragraph id="H64C13085498645DEBAAD5FA900AACD6F"><enum>(1)</enum><text>Eleven representatives
				from the critical infrastructure sectors enumerated in the National
				Infrastructure Protection Plan, of which at least one member shall represent a
				small business interest and at least one member shall represent each of the
				following sectors:</text>
										<subparagraph id="H8F87CE2A38AE4DBF9037A1FD63B6E5A3"><enum>(A)</enum><text>Banking and
				finance.</text>
										</subparagraph><subparagraph id="H68E4E1B044334B9ABD45694A5B1E6A17"><enum>(B)</enum><text>Communications.</text>
										</subparagraph><subparagraph id="H60D417FB2A9B4F86BFF61B2AEFD92A9F"><enum>(C)</enum><text>Defense industrial
				base.</text>
										</subparagraph><subparagraph id="H559C9EF0F34A4CE483513762FB66EA4E"><enum>(D)</enum><text>Energy, electricity
				subsector.</text>
										</subparagraph><subparagraph id="H7A7285FA21B54418B2FF88F018E88726"><enum>(E)</enum><text>Energy, oil, and natural
				gas subsector.</text>
										</subparagraph><subparagraph id="H9C3BDEF8E4CD4F70AF1DA0F93127B7CF"><enum>(F)</enum><text>Heath care and public
				health.</text>
										</subparagraph><subparagraph id="HA44CCECB70FE4196944718CC3F10C278"><enum>(G)</enum><text>Information
				technology.</text>
										</subparagraph><subparagraph id="H69920F4C860B4E19BC944AA4614CEFDD"><enum>(H)</enum><text>Water.</text>
										</subparagraph><subparagraph id="H978CC6F3210547DB95A9CD906D1C2ACC"><enum>(I)</enum><text>Chemical.</text>
										</subparagraph></paragraph><paragraph id="HB8A1A8467A424B638A9FE2C56DFFDA4C"><enum>(2)</enum><text>Two representatives from
				the privacy and civil liberties community.</text>
									</paragraph><paragraph id="H31853F803A8944C8B3AC34F3C7031909"><enum>(3)</enum><text>The Chair of the National
				Council of Information Sharing and Analysis Centers.</text>
									</paragraph></subsection><subsection id="HD5B0063335D042B4B826755474AE6911"><enum>(c)</enum><header>Initial
				Appointment</header><text>Not later than 30 days after the date of the
				enactment of this subtitle, the Secretary of Homeland Security, in consultation
				with the heads of the sector specific agencies of the critical infrastructure
				sectors enumerated in the National Infrastructure Protection Plan, shall
				appoint the members of the board described under subsection (b) from
				individuals identified by the sector coordinating councils of the critical
				infrastructure sectors enumerated in the National Infrastructure Protection
				Plan.</text>
								</subsection><subsection id="H1E18EBBC610E4A8F8AB280668FB2CDBC"><enum>(d)</enum><header>Terms</header>
									<paragraph id="H330BE67EDA2D49A28E632F88D4275D5E"><enum>(1)</enum><header>Critical infrastructure
				representatives</header><text>Each member of the board described in subsection
				(b)(1) shall be appointed for a term that is not less than one year and not
				longer than three years from the date of the member’s appointment, as
				determined by the member’s sector coordinating council.</text>
									</paragraph><paragraph id="HE3814968CBB3411EA971621BEDB66B53"><enum>(2)</enum><header>Other
				representatives</header><text>Each member of the board described in subsection
				(b)(2) or (3) shall serve an initial term that is not less than two years and
				not longer than three years from the date of the member’s appointment, and each
				such member shall select the member’s successor.</text>
									</paragraph></subsection><subsection id="H0EF999C4E90249E78AFE3EA5D59910F5"><enum>(e)</enum><header>Duties</header><text>The
				board shall—</text>
									<paragraph id="HC47046D9E8934606A97162B61D2FD411"><enum>(1)</enum><text>meet not less frequently
				than quarterly;</text>
									</paragraph><paragraph id="H491F4C37369448C984F124A42C66112D"><enum>(2)</enum><text>act as an advocate on
				behalf of the private sector in improving the operations of the National
				Cybersecurity Communications Integration Center; and</text>
									</paragraph><paragraph id="H698AEA80688F4829AF28942C68697BD0"><enum>(3)</enum><text>submit to the Secretary
				and the appropriate committees of Congress the annual report described in
				section 247.</text>
									</paragraph></subsection><subsection id="HCF59AA138E5F463BB8A69A5BE801FEDF"><enum>(f)</enum><header>Access to
				information</header><text>The members of the board shall, subject to the laws
				and procedures applicable to national security background investigations and
				security clearances, be provided with the appropriate security clearances and
				have access to appropriate information shared with the National Cybersecurity
				and Communications Integration Center and shall be subject to all of the
				limitations on the use of such information.</text>
								</subsection><subsection id="H5585C8E0327149CFB348D46E9E73C0C6"><enum>(g)</enum><header>Sub-boards</header><text>The
				board shall have the authority to constitute such sub-boards, or other advisory
				groups or panels, as may be necessary to assist the board in carrying out its
				functions under this section.</text>
								</subsection></section><section id="H76E47CC6CD254296BED6149C208DCF7A"><enum>244.</enum><header>Charter</header><text display-inline="no-display-inline">The Secretary shall develop a charter to
				govern the operations and administration of the National Cybersecurity and
				Communications Integration Center consistent with the requirements of title XI
				of the National Security Act of 1947. The charter shall include each of the
				following:</text>
								<paragraph id="H9A35F90E89C54DB5AFFF4BD4FD698CE0"><enum>(1)</enum><text>The organizational
				structure of the National Cybersecurity and Communications Integration Center,
				including a delineation of the mission expectations and responsibilities of the
				various elements assigned to the Center.</text>
								</paragraph><paragraph id="H7F363F9A4E194CFAA1767E463E23B797"><enum>(2)</enum><text>A mission statement of
				the National Cybersecurity and Communications Integration Center.</text>
								</paragraph><paragraph id="H92DE634C7A4C4E59B13A7431B84C2AF9"><enum>(3)</enum><text>A plan that promotes
				broad participation by large, medium, and small business owners and operators
				of networks or systems in the private sector, entities operating critical
				infrastructure, educational institutions, State, tribal, and local governments,
				and the Federal Government.</text>
								</paragraph><paragraph id="H0ABC418654354373B78C29ED51A73E58"><enum>(4)</enum><text display-inline="yes-display-inline">Procedures for making appropriate cyber
				incident information available to outside groups for academic research and
				insurance actuarial purposes.</text>
								</paragraph></section><section id="H61D2FABB41974BD38BEBB8F2B32EBA67"><enum>245.</enum><header>Participation</header><text display-inline="no-display-inline">Not later than 90 days after the date of the
				enactment of this subtitle, the Secretary shall publish the criteria and
				procedures for voluntary participation and voluntary physical collocation by
				appropriate Federal, State and local government departments, agencies and
				entities, and private sector businesses and organizations within the National
				Cybersecurity and Communications Integration Center.</text>
							</section><section id="H399962FECD0D475A928C5A4E47046FD6"><enum>246.</enum><header>Annual
				report</header><text display-inline="no-display-inline">The board of advisors
				of the National Cybersecurity Communications Integration Center shall submit to
				the Secretary and the appropriate committees of Congress an annual report on
				the status of the National Cybersecurity Communications Integration Center and
				how the Center accomplished its purpose under section 242 during the year
				covered by the report. Each such report shall include, for the year covered by
				the report—</text>
								<paragraph id="HFD1C08DBFD124A13A01225DE25CF874C"><enum>(1)</enum><text>information on the amount
				and nature of information shared by and through the Center;</text>
								</paragraph><paragraph id="HF7C4E12127A943F6AA41668C800115F6"><enum>(2)</enum><text>the number of violations
				of statutory information sharing restrictions and the procedures established
				for the Center and any steps taken by the Center to reduce and eliminate such
				violations;</text>
								</paragraph><paragraph id="H60B7AE1A14C546A787ABA286B976C5EC"><enum>(3)</enum><text>any changes to the
				Center’s charter as agreed upon by the board and the membership; and</text>
								</paragraph><paragraph id="H7C18BBC668164FC2A6EFC737F518F877"><enum>(4)</enum><text>proposed ways to improve
				information sharing by and through the Center.</text>
								</paragraph></section><section id="H2BBB5C3C82B442669F20CAB5C3765176"><enum>247.</enum><header>Authority to issue
				warnings</header><text display-inline="no-display-inline">The Secretary may, in
				coordination with appropriate Federal departments and agencies, provide
				advisories, alerts, and warnings to relevant companies, targeted sectors, other
				government entities, or the general public regarding potential cybersecurity
				threats as appropriate. In issuing such an advisory, alert, or warning, the
				Secretary shall not disclose—</text>
								<paragraph id="H82045FB7AECF4925A79954964DFA4770"><enum>(1)</enum><text>without the express
				consent of an entity voluntarily sharing information with the Federal
				Government pursuant to title XI of the National Security Act of 1947 and the
				Federal department or agency that initially received such information, any such
				information that forms the basis for the advisory, alert, or warning or the
				source of such information;</text>
								</paragraph><paragraph id="HB437A5AFF9CF442D9147D587CB0E172C"><enum>(2)</enum><text>information that is
				proprietary, business sensitive, relates specifically to the submitting person
				or entity, or is otherwise not appropriate for disclosure in the public domain;
				and</text>
								</paragraph><paragraph id="H1884CEC46BC74CDCA97530EEB9695618"><enum>(3)</enum><text>any information that is
				restricted by statute, rule, or regulation, including information restricted
				from disclosure under title XI of the National Security Act of 1947, and
				information relating to sources and methods and the national security of the
				United States.</text>
								</paragraph></section><section id="HC634BA908DE54FFD9F9E480AEF6457C2"><enum>248.</enum><header>Definitions</header><text display-inline="no-display-inline">In this subtitle:</text>
								<paragraph id="H0000E426B6B744558F5D6B36D1765205"><enum>(1)</enum><header>Cyber threat
				information</header><text>The term <quote>cyber threat information</quote>
				means the information directly pertaining to a vulnerability of, or threat to,
				a system or network of a government or private entity, including information
				pertaining to the protection of a system or network from—</text>
									<subparagraph id="H203A57F2856F4FD79D17337A59A86F53"><enum>(A)</enum><text>efforts to degrade,
				disrupt, or destroy such system or network; or</text>
									</subparagraph><subparagraph id="H3483DA8160A34CE6ABBD81457B607209"><enum>(B)</enum><text>efforts to gain
				unauthorized access to a system or network, including efforts to gain such
				unauthorized access to steal or misappropriate private or government
				information.</text>
									</subparagraph></paragraph><paragraph id="H948BA83ED50840D894405BAA5F4EAFA3"><enum>(2)</enum><header>Cybersecurity
				threat</header><text>The term <quote>cybersecurity threat</quote> means a
				vulnerability of, or threat to, a system or network of a government or private
				entity, including—</text>
									<subparagraph id="HDEC39D31EED5429D97C88F6D013D6C13"><enum>(A)</enum><text>efforts to degrade,
				disrupt, or destroy such system or network; or</text>
									</subparagraph><subparagraph id="H6C1A6B7F610A4AC9A3FA043F4BA6AACA"><enum>(B)</enum><text>efforts to gain
				unauthorized access to a system or network, including efforts to gain such
				unauthorized access to steal or misappropriate private or government
				information.</text>
									</subparagraph></paragraph></section><section id="H56D0745E78CA4BAF90E47166AFB31B3E"><enum>249.</enum><header>Savings
				clause</header><text display-inline="no-display-inline">Nothing in this
				subtitle shall be interpreted to—</text>
								<paragraph id="H61C1E158156640549CFD205BD952414B"><enum>(1)</enum><text>alter or amend the
				authorities of any Federal department or agency other than the Department of
				Homeland Security, including the law enforcement or intelligence authorities of
				any such Federal department or agency or the authority of any such Federal
				department or agency to protect sources and methods and the national
				security;</text>
								</paragraph><paragraph id="HE7BAB3276F6B4D21A05A50FD30130EB9"><enum>(2)</enum><text>limit or modify an
				existing information sharing or other relationship;</text>
								</paragraph><paragraph id="HCB1D16A751B648B8A994EB1C1D9398C0"><enum>(3)</enum><text>prohibit a new
				information sharing or other relationship;</text>
								</paragraph><paragraph id="HBBA0E3A2360040B29A05E995AF9AA7DD"><enum>(4)</enum><text>require a new information
				sharing or other relationship between the Federal Government and a private
				sector entity;</text>
								</paragraph><paragraph id="H1221129B18E14AAC90D5E9E711555BC9"><enum>(5)</enum><text display-inline="yes-display-inline">alter or otherwise limit the authority of
				any Federal department or agency to also undertake any activities that the
				Department of Homeland Security is authorized to undertake pursuant to this
				section; or</text>
								</paragraph><paragraph id="HCB430A08A52B40E0AE66A809DD445F43"><enum>(6)</enum><text>provide additional
				authority to, or modify an existing authority of the Department of Homeland
				Security to control, modify, require, or otherwise direct the cybersecurity
				efforts of a private-sector entity or a component of the Federal Government or
				a State, local, or tribal
				government.</text>
								</paragraph></section></subtitle><after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph><paragraph id="HA9F393201C0B4439888B868861BE4B54"><enum>(2)</enum><header>Clerical
			 amendment</header><text>The table of contents in section 1(b) of such Act, as
			 amended by section 2, is further amended by adding at the end of the items
			 relating to title II the following new items:</text>
					<quoted-block changed="added" committee-id="HHM00" display-inline="no-display-inline" id="HC1DB17684CC34A44BC96033D9FAA2EA0" reported-display-style="italic" style="OLC">
						<toc changed="added" committee-id="HHM00" container-level="quoted-block-container" idref="H691CCF39FB1445C3BC94F46A3AB0D6FA" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration" reported-display-style="italic">
							<toc-entry idref="H996521CE9A9C4CCD9E453D3D026343F5" level="subtitle">Subtitle E—Department of Homeland Security
				Cybersecurity Information Sharing</toc-entry>
							<toc-entry idref="H11EAE9E25A6247659394AF194BB2D2DA" level="section">Sec. 241. Information sharing.</toc-entry>
							<toc-entry idref="H6949D505A11647AE83FEEABECEB7D05B" level="section">Sec. 242. Establishment of National
				Cybersecurity and Communications Integration Center.</toc-entry>
							<toc-entry idref="HD8CF6036FA33461BB3CDDAE7DA8A7B67" level="section">Sec. 243. Board of advisors.</toc-entry>
							<toc-entry idref="H76E47CC6CD254296BED6149C208DCF7A" level="section">Sec. 244. Charter.</toc-entry>
							<toc-entry idref="H61D2FABB41974BD38BEBB8F2B32EBA67" level="section">Sec. 245. Participation.</toc-entry>
							<toc-entry idref="H399962FECD0D475A928C5A4E47046FD6" level="section">Sec. 246. Annual report.</toc-entry>
							<toc-entry idref="H2BBB5C3C82B442669F20CAB5C3765176" level="section">Sec. 247. Authority to issue
				warnings.</toc-entry>
							<toc-entry idref="HC634BA908DE54FFD9F9E480AEF6457C2" level="section">Sec. 248. Definitions.</toc-entry>
							<toc-entry idref="H56D0745E78CA4BAF90E47166AFB31B3E" level="section">Sec. 249. Savings
				clause.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</paragraph></subsection><subsection id="HAC7232488D084206AA3D31AD681A3BED"><enum>(b)</enum><header>Authorization of
			 appropriation for the national cybersecurity and communications integration
			 center</header><text>There is authorized to be appropriated $4,000,000 for each
			 of fiscal years 2013, 2014, and 2015 for the administration and management of
			 the National Cybersecurity and Communications Integration Center.</text>
			</subsection></section><section id="HF7B5B0E8191F400CB0464008AB3A293B"><enum>4.</enum><header>Cybersecurity research
			 and development</header>
			<subsection id="HC0A499A9021A4142979328B87A4101D5"><enum>(a)</enum><header>In
			 general</header><text>Title III of the Homeland Security Act of 2002 is amended
			 by adding at the end the following:</text>
				<quoted-block changed="added" committee-id="HHM00" id="H5E89518E2A084E569CF081909A19FD54" reported-display-style="italic" style="OLC">
					<section id="H19E3B99537874AF28972C71E3704A55C"><enum>318.</enum><header>Cybersecurity research
				and development</header>
						<subsection id="HDE15D1D583C04164A85CD1AE3BF10E9F"><enum>(a)</enum><header>In
				general</header><text>The Under Secretary for Science and Technology shall
				support research, development, testing, evaluation, and transition of
				cybersecurity technology. Such support shall include fundamental, long-term
				research to improve the ability of the United States to prevent, protect
				against, detect, respond to, and recover from acts of terrorism and cyber
				attacks, with an emphasis on research and development relevant to attacks that
				would cause a debilitating impact on national security, national economic
				security, or national public health and safety.</text>
						</subsection><subsection id="HA821DB7C39854CBF9D013832E3AEF052"><enum>(b)</enum><header>Activities</header><text>The
				research and development testing, evaluation, and transition supported under
				subsection (a) shall include work to—</text>
							<paragraph id="H172214BACF3643D0ADA66CE4A70F6A73"><enum>(1)</enum><text>advance the development
				and accelerate the deployment of more secure versions of fundamental Internet
				protocols and architectures, including for the domain name system and routing
				protocols;</text>
							</paragraph><paragraph id="H4EF9FB19835D46D3875D5F2AFFB4C160"><enum>(2)</enum><text>improve, create, and
				advance the research and development of techniques and technologies for
				proactive detection and identification of threats, attacks, and acts of
				terrorism before they occur;</text>
							</paragraph><paragraph id="H7718E2052A12444583871402CEFDAFE6"><enum>(3)</enum><text>advance technologies for
				detecting attacks or intrusions, including real-time monitoring and real-time
				analytic technologies;</text>
							</paragraph><paragraph id="H8D64C9B20E98438589F3862D85251293"><enum>(4)</enum><text>improve and create
				mitigation and recovery methodologies, including techniques and policies for
				real-time containment of attacks and development of resilient networks and
				systems;</text>
							</paragraph><paragraph id="H025067F716954B3D835A9A9D7B897590"><enum>(5)</enum><text>develop and support
				infrastructure and tools to support cybersecurity research and development
				efforts, including modeling, test beds, and data sets for assessment of new
				cybersecurity technologies;</text>
							</paragraph><paragraph id="HDAB6CEF86EFB419280DB256F257D202F"><enum>(6)</enum><text>assist in the development
				and support of technologies to reduce vulnerabilities in process control
				systems;</text>
							</paragraph><paragraph id="H7FD550B9D59E4A5D90CDD97A0E6F8B17"><enum>(7)</enum><text>develop and support cyber
				forensics and attack attribution;</text>
							</paragraph><paragraph id="H2C16281FCEF54C349B0BD6CFEA3A2675"><enum>(8)</enum><text>test, evaluate, and
				facilitate the transfer of technologies associated with the engineering of less
				vulnerable software and securing the information technology software
				development lifecycle;</text>
							</paragraph><paragraph id="HFE122A8AEFCA421DB854B0598961C0BF"><enum>(9)</enum><text>ensure new cybersecurity
				technology is scientifically and operationally validated; and</text>
							</paragraph><paragraph id="HBFFFAC88F32C4010AEBF98472EF833EC"><enum>(10)</enum><text>facilitate the planning,
				development, and implementation of international cooperative activities (as
				defined in section 317) to address cybersecurity and energy infrastructure with
				foreign public or private entities, governmental organizations, businesses
				(including small business concerns and social and economically disadvantaged
				small business concerns (as those terms are defined in sections 3 and 8 of the
				Small Business Act (15 U.S.C. 632 and 637) respectively)), federally funded
				research and development centers and universities from countries that may
				include Israel, the United Kingdom, Canada, Australia, Singapore, Germany, New
				Zealand, and other allies, as determined by the Secretary, in research and
				development of technologies, best practices, and other means to protect
				critical infrastructure, including the national electric grid.</text>
							</paragraph></subsection><subsection id="H5A32281DA9684E9880E85A5E26F9D70E"><enum>(c)</enum><header>Coordination</header><text>In
				carrying out this section, the Under Secretary shall coordinate all activities
				with—</text>
							<paragraph id="H14845764082246A5A6BFF4A4B0F3D638"><enum>(1)</enum><text>the Under Secretary for
				National Protection and Programs Directorate; and</text>
							</paragraph><paragraph id="H3333758FA8D444AA88757A69CF0B0F3F"><enum>(2)</enum><text>the heads of other
				relevant Federal departments and agencies, including the National Science
				Foundation, the Defense Advanced Research Projects Agency, the Information
				Assurance Directorate of the National Security Agency, the National Institute
				of Standards and Technology, the Department of Commerce, academic institutions,
				the Networking and Information Technology Research and Development Program, and
				other appropriate working groups established by the President to identify unmet
				needs and cooperatively support activities, as
				appropriate.</text>
							</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HD56BDD9F8C064FF5A27909299B3C6335"><enum>(b)</enum><header>Clerical
			 amendment</header><text>The table of contents in section 1(b) of such Act, as
			 amended by sections 2 and 3, is further amended by inserting after the item
			 relating to section 317 the following new item:</text>
				<quoted-block changed="added" committee-id="HHM00" display-inline="no-display-inline" id="HF78BDD5ACBA54AEAA0A1C37A55891A37" reported-display-style="italic" style="OLC">
					<toc changed="added" committee-id="HHM00" container-level="quoted-block-container" idref="H5E89518E2A084E569CF081909A19FD54" lowest-bolded-level="division-lowest-bolded" lowest-level="section" quoted-block="no-quoted-block" regeneration="yes-regeneration" reported-display-style="italic">
						<toc-entry idref="H19E3B99537874AF28972C71E3704A55C" level="section">Sec. 318. Cybersecurity research and
				development.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section><section id="HB1D8F944397F43E9910C7C8812C2259B"><enum>5.</enum><header>Report on support for
			 regional cybersecurity cooperatives</header>
			<subsection id="H1124DF221BFC414195469B9CD1045554"><enum>(a)</enum><header>In
			 general</header><text>Not later than 180 days after the date of the enactment
			 of this Act, the Secretary of Homeland Security shall submit to the Committee
			 on Homeland Security of the House of Representatives and the Committee on
			 Homeland Security and Governmental Affairs of the Senate a report on what
			 support, if any, the Department of Homeland Security might provide to regional,
			 State, and local grassroots cyber cooperatives.</text>
			</subsection><subsection id="HD1D1651ABF864051B22EF196CC9F48C5"><enum>(b)</enum><header>Contents</header><text>The
			 report shall include an analysis of the progress in establishing the <quote>NET
			 Guard</quote> authorized under section 224 of the Homeland Security Act of 2002
			 (6 U.S.C. 144) to build a national technology guard for cyber response
			 capabilities and an assessment of whether a grant process for pilot regional,
			 State, or local cyber cooperatives would be beneficial. Such assessment
			 should—</text>
				<paragraph id="H676412CE02C74FED9C7FEB1AE52CEEEC"><enum>(1)</enum><text>evaluate whether the
			 grant process should include a methodology of identifying recognized national
			 experts in relevant areas of science and technology, including agreed upon
			 metrics measuring the expertise and demonstrated capabilities of such experts;
			 and</text>
				</paragraph><paragraph id="H9627FC84D8B948A0A3D2DF7D1B1620B6"><enum>(2)</enum><text>address the
			 following:</text>
					<subparagraph id="H7C0EBA9C693A4756A08260E2886A2F37"><enum>(A)</enum><text>The appropriateness of
			 the establishment and maintenance of a national volunteer experts registry
			 system comprised of the demonstrated national experts described in this
			 paragraph, together with information relating to their particular areas of
			 expertise and who may be called upon to respond to a cyber incident.</text>
					</subparagraph><subparagraph id="H40422A46A83E4324A76ED9AAF93D41B7"><enum>(B)</enum><text>The need to identify and
			 leverage existing capabilities of cyber response and cyber workforce challenge
			 programs in States, local governments, private sector entities, and non-profit
			 organizations to potentially accelerate the implementation of the NET
			 Guard.</text>
					</subparagraph><subparagraph id="HAB99105ABBBC4E338D6B3996F4773F3C"><enum>(C)</enum><text>The requirements for the
			 implementation of a plan to improve national capability with minimum
			 descriptions of the following:</text>
						<clause id="H84EB3C086C2A4ADFAA0678EF78336688"><enum>(i)</enum><text>How to evaluate the
			 demonstrated national experts in relevant areas of science and
			 technology.</text>
						</clause><clause id="HA874A02C220149FA9223550B08FFE9FD"><enum>(ii)</enum><text>How to establish and
			 maintain the national volunteer experts registry system.</text>
						</clause><clause id="H44B4F54A7B1E4E75B7B40C09A9B2DB36"><enum>(iii)</enum><text>Potential funding
			 models incorporating private sector funding.</text>
						</clause></subparagraph></paragraph></subsection></section><section id="H26F73C07D47D4899B710187C5EA4E6EA"><enum>6.</enum><header>Cybersecurity Domestic
			 Preparedness Consortium and cybersecurity training center</header>
			<subsection id="H10F74F8E344341B79CE18EB0C040C7C7"><enum>(a)</enum><header>Cybersecurity domestic
			 preparedness consortium</header>
				<paragraph id="H6E56D2C9E2FB4BA3ADF076F4490FF611"><enum>(1)</enum><header>In
			 general</header><text>The Secretary of Homeland Security may establish a
			 consortium to be known as the <quote>Cybersecurity Domestic Preparedness
			 Consortium</quote>.</text>
				</paragraph><paragraph id="H8DBFFEADFDDB46CF930464973E4EF0AA"><enum>(2)</enum><header>Functions</header><text>The
			 Consortium established under paragraph (1) may—</text>
					<subparagraph id="HA186A721554E42C49BCA130F953E864F"><enum>(A)</enum><text>provide training to State
			 and local first responders and officials specifically for preparing and
			 responding to cybersecurity attacks;</text>
					</subparagraph><subparagraph id="H943188825E614A5594BFEEF5FD909A87"><enum>(B)</enum><text>develop and update a
			 curriculum utilizing the DHS National Cyber Security Division sponsored
			 Community Cyber Security Maturity Model (CCSMM) for State and local first
			 responders and officials;</text>
					</subparagraph><subparagraph id="H6D62A746E2BD4DDB95F8E441F1CF7661"><enum>(C)</enum><text>provide technical
			 assistance services to build and sustain capabilities in support of
			 cybersecurity preparedness and response; and</text>
					</subparagraph><subparagraph id="H1FEB255C806B46EEA71FD3582DE469CD"><enum>(D)</enum><text>conduct cybersecurity
			 training and simulation exercises to defend from and respond to cyber
			 attacks.</text>
					</subparagraph></paragraph><paragraph id="HEE3172489CF449EA9353F2710DB3E432"><enum>(3)</enum><header>Members</header><text>The
			 Consortium shall consist of academic, nonprofit, and government partners that
			 develop, update, and deliver cybersecurity training in support of homeland
			 security.</text>
				</paragraph></subsection><subsection id="HCDE660878BEE4E4485349BD518023A15"><enum>(b)</enum><header>Cybersecurity training
			 center</header><text>As a part of the Cybersecurity Domestic Preparedness
			 Consortium, the Secretary may establish where appropriate one or more
			 cybersecurity training centers to provide training courses and other resources
			 for State and local first responders and officials to improve preparedness and
			 response capabilities.</text>
			</subsection><subsection id="HBE47CCB5718E490FA0F2E5F5E9C93AAC"><enum>(c)</enum><header>Plan for fusion
			 centers</header><text>The Cybersecurity Domestic Preparedness Consortium shall
			 develop a plan to implement as one of the Cybersecurity Training Centers a
			 one-year voluntary pilot program to test and assess the feasibility, costs, and
			 benefits of providing cybersecurity training to State and local law enforcement
			 personnel through the national network of fusion centers.</text>
			</subsection><subsection id="H80B30942F3394E918D61491C82636A09"><enum>(d)</enum><header>Pilot program</header>
				<paragraph id="H97583D00F8D5419A9343C05E6A334B0E"><enum>(1)</enum><header>In
			 general</header><text>Not later than one year after the date of the enactment
			 of the Act, the Secretary shall implement a one-year voluntary pilot program to
			 train State and local law enforcement personnel in the national network of
			 fusion centers in cyber security standards, procedures, and best
			 practices.</text>
				</paragraph><paragraph id="HAA9DA2CA98444D07A2EF428AEED3F881"><enum>(2)</enum><header>Curriculum and
			 personnel</header><text>In creating the curriculum for the training program and
			 conducting the program, the Secretary may assign personnel from the Department
			 of Homeland Security, including personnel from the Office of Cybersecurity and
			 Communications.</text>
				</paragraph><paragraph id="HED269BC6AC42454C99C0A994D372A04E"><enum>(3)</enum><header>Coordination</header><text>The
			 curriculum for the training and for conducting the program will be coordinated
			 with that of the Cyber Security Domestic Preparedness Consortium.</text>
				</paragraph></subsection></section><section id="H0C17563F60D540ACAF7359900319D16A"><enum>7.</enum><header>Savings
			 clause</header><text display-inline="no-display-inline">Nothing in this Act
			 shall be interpreted to—</text>
			<paragraph id="HB2FE9F9D765C4D05BBF38D8278D9AA1B"><enum>(1)</enum><text>alter or amend the
			 authorities of any Federal department or agency other than the Department of
			 Homeland Security, including the law enforcement or intelligence authorities of
			 any such Federal department or agency or the authority of any such Federal
			 department or agency to protect sources and methods and the national
			 security;</text>
			</paragraph><paragraph id="HA987402E507E42B086598BF61CB0CFC0"><enum>(2)</enum><text>alter or otherwise limit
			 the authority of any Federal department or agency to also undertake any
			 activities that the Department of Homeland Security is authorized to undertake
			 pursuant to this section; or</text>
			</paragraph><paragraph id="H3AF4394F982147ACB45599073AF5E862"><enum>(3)</enum><text>provide additional
			 authority to, or modify an existing authority of the Department of Homeland
			 Security to control, modify, require, or otherwise direct the cybersecurity
			 efforts of a private-sector entity or a component of the Federal Government or
			 a State, local, or tribal government.</text>
			</paragraph></section></legis-body>
	<endorsement display="yes">
		<action-date date="20120921">September 21, 2012</action-date>
		<action-desc>The <committee-name committee-id="HIF00">Committee on Energy
		  and Commerce</committee-name> discharged; committed to the Committee of the
		  Whole House on the State of the Union and ordered to be printed</action-desc>
	</endorsement>
</bill>
