<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HA8925F117B914C5793079488186D12A4" public-private="public">
	<form>
		<distribution-code display="yes">I</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>H. R. 6221</legis-num>
		<current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber>
		<action>
			<action-date date="20120726">July 26, 2012</action-date>
			<action-desc><sponsor name-id="C001067">Ms. Clarke of New
			 York</sponsor> (for herself and <cosponsor name-id="L000517">Mr. Daniel E.
			 Lungren of California</cosponsor>) introduced the following bill; which was
			 referred to the <committee-name committee-id="HHM00">Committee on Homeland
			 Security</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To amend the Homeland Security Act of 2002 to require the
		  Secretary of Homeland Security to research, identify, and evaluate
		  cybersecurity risks to critical infrastructure, and for other
		  purposes.</official-title>
	</form>
	<legis-body id="HBE713A516FE24F4BB4B6711744EE09D6" style="OLC">
		<section id="HF2C9DD81FBC54B90B6CB24F672FC4930" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the
			 <quote><short-title>Identifying Cybersecurity Risks to
			 Critical Infrastructure Act of 2012</short-title></quote>.</text>
		</section><section id="H8F113326148A4C33B6A3FE47B441937A"><enum>2.</enum><header>Identification of
			 sector-specific cybersecurity risks</header>
			<subsection id="HE9D0D9474329455EBC572C7D43605360"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Subtitle C of title
			 II of the Homeland Security Act of 2002 (6 U.S.C. 141 et seq.) is amended by
			 adding at the end the following new section:</text>
				<quoted-block id="H656C0AF6AB764E66B87D4C7B1AAA0615">
					<section id="HCADB87D468034F1394151DD67924F638"><enum>226.</enum><header>Identification
				of sector-specific cybersecurity risks</header>
						<subsection id="HD6890F05EAFC46D5AE5719AD4F995EAE"><enum>(a)</enum><header>In
				general</header><text>The Secretary shall, on a continuous and sector-by-sector
				basis, research, identify, and evaluate cybersecurity risks to critical
				infrastructure. In carrying out this subsection, the Secretary shall
				coordinate, as appropriate, with the following:</text>
							<paragraph commented="no" id="H2B709056365741A3B2A226EE89DC810B"><enum>(1)</enum><text display-inline="yes-display-inline">The heads of sector specific
				agencies.</text>
							</paragraph><paragraph id="H84032DFA857F49F69E9D3D9EB7699A90"><enum>(2)</enum><text>The owners and
				operators of critical infrastructure.</text>
							</paragraph><paragraph commented="no" id="HAB630579EA5B4C2798EDD29C04C1436C"><enum>(3)</enum><text display-inline="yes-display-inline">Any private sector entity engaged in
				ensuring the security or resilience of critical infrastructure, as determined
				appropriate by the Secretary.</text>
							</paragraph></subsection><subsection id="H4A2DBB7B7D434A3FADE58118045E11C9"><enum>(b)</enum><header>Evaluation of
				risks</header><text>The Secretary, in coordination with the individuals and
				entities referred to in subsection (a), shall evaluate the cybersecurity risks
				researched and identified under such subsection by taking into account each of
				the following:</text>
							<paragraph id="H669CB974D6F941EEB7E47E4FCD82E4B9"><enum>(1)</enum><text>The actual or
				assessed threat, including a consideration of adversary capabilities and
				intent, preparedness, target attractiveness, and deterrence
				capabilities.</text>
							</paragraph><paragraph id="H9FCAD0E6357842C49C4210713C1BE647"><enum>(2)</enum><text>The extent and
				likelihood of death, injury, or serious adverse effects to human health and
				safety caused by a disruption, destruction, or unauthorized use of critical
				infrastructure.</text>
							</paragraph><paragraph id="HFA0D62E6F2324DA0AB34E9CE79A8B4C2"><enum>(3)</enum><text>The threat to
				national security caused by the disruption, destruction, or unauthorized use of
				critical infrastructure.</text>
							</paragraph><paragraph id="H51D2391E2E404E59AA8457806417AFB0"><enum>(4)</enum><text>The harm to the
				economy that would result from the disruption, destruction, or unauthorized use
				of critical infrastructure.</text>
							</paragraph><paragraph commented="no" id="HA1AD0B8C0C6B40B9B48BDD5002216867"><enum>(5)</enum><text>Other risk-based
				security factors that the Secretary determines appropriate to protect public
				health and safety, critical infrastructure, or national and economic security,
				in consultation with the following:</text>
								<subparagraph id="HA0B7D42EC7744738B229BE279EDF66AB"><enum>(A)</enum><text>The heads of
				sector specific agencies.</text>
								</subparagraph><subparagraph commented="no" id="HAD84DA64D5D644E3A16973AF4B6ED623"><enum>(B)</enum><text>Any private sector
				entity determined appropriate by the Secretary.</text>
								</subparagraph></paragraph></subsection><subsection id="HA4FEEFAA981A4CBFBB136623E456E854"><enum>(c)</enum><header>Availability of
				identified risks</header><text display-inline="yes-display-inline">The
				Secretary shall ensure that information relating to the risks researched,
				identified, and evaluated under this section for each sector described in
				subsection (a) is disseminated, to the maximum extent possible, in an
				unclassified version, to owners and operators of critical infrastructure within
				each such sector. If the Secretary determines that such information, in whole
				or in part should be classified, the Secretary shall share such information, as
				the Secretary determines appropriate, with such owners and operators if such
				owners and operators possess the appropriate security clearances.</text>
						</subsection><subsection id="H056CBD52CDFD44378B94A52D116F5A4F"><enum>(d)</enum><header>Periodic reports
				to Congress</header><text display-inline="yes-display-inline">The Secretary
				shall periodically, but not less often than semiannually, report to the
				appropriate congressional committees on the cybersecurity risks to critical
				infrastructure researched, identified, and evaluated pursuant to subsection
				(a).</text>
						</subsection><subsection id="H094065A5110F4D76940BA346BD9F2B0E"><enum>(e)</enum><header>Critical
				infrastructure defined</header><text display-inline="yes-display-inline">In
				this section, the term <quote>critical infrastructure</quote> has the meaning
				given such term under section 1016(e) of the Uniting and Strengthening America
				by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism
				(USA PATRIOT ACT) Act of 2001 (42 U.S.C. 5195c(e); Public Law
				107–56).</text>
						</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection><subsection id="HCAAF579A9524488CACFAF23AF285EE7E"><enum>(b)</enum><header>Clerical
			 amendment</header><text>Subsection (b) of section 1 of the Homeland Security
			 Act of 2002 (6 U.S.C. 101) is amended by adding after the item relating to
			 section 225 the following new item:</text>
				<quoted-block display-inline="no-display-inline" id="H8D9EE2F4F57C4A9B928BCAA4743B991A" style="OLC">
					<toc regeneration="no-regeneration">
						<toc-entry level="section">Sec. 226. Identification of
				sector-specific cybersecurity
				risks.</toc-entry>
					</toc>
					<after-quoted-block>.</after-quoted-block></quoted-block>
			</subsection></section></legis-body>
</bill>
