<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Placed-on-Calendar-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<calendar>Calendar No. 470</calendar>
		<congress>112th CONGRESS</congress>
		<session>2d Session</session>
		<legis-num>S. 3414</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20120719">July 19, 2012</action-date>
			<action-desc><sponsor name-id="S210">Mr. Lieberman</sponsor> (for
			 himself, <cosponsor name-id="S252">Ms. Collins</cosponsor>,
			 <cosponsor name-id="S176">Mr. Rockefeller</cosponsor>,
			 <cosponsor name-id="S221">Mrs. Feinstein</cosponsor>, and
			 <cosponsor name-id="S277">Mr. Carper</cosponsor>) introduced the following
			 bill; which was read the first time</action-desc>
		</action>
		<action>
			<action-date>July 23, 2012</action-date>
			<action-desc>Read the second time and placed on the
			 calendar</action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To enhance the security and resiliency of the cyber and
		  communications infrastructure of the United States.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title; table of contents</header>
			<subsection id="idB53F9AA11E8A468BB49FEF8A6E2932DB"><enum>(a)</enum><header>Short
			 title</header><text display-inline="yes-display-inline">This Act may be cited
			 as the <quote><short-title>Cybersecurity Act of
			 2012</short-title></quote> or the <quote>CSA2012</quote>.</text>
			</subsection><subsection id="id1A8E70BB10A04A078C4552F20CBFA843"><enum>(b)</enum><header>Table of
			 contents</header><text>The table of contents for this Act is as follows:</text>
				<toc>
					<toc-entry idref="S1" level="section">Sec. 1. Short title; table of
				contents.</toc-entry>
					<toc-entry idref="id467d63c8e0794b4d8d20f5ae3737f56d" level="section">Sec. 2. Definitions.</toc-entry>
					<toc-entry idref="iddfe1da88a5814210865f1674c09e124a" level="title">TITLE I—Public-private partnership to protect critical
				infrastructure</toc-entry>
					<toc-entry idref="id6a77a92da8c64ed1989ef48f1513b2aa" level="section">Sec. 101. National Cybersecurity Council.</toc-entry>
					<toc-entry idref="ideb7a21a9cbca45c4b0db8d654adde995" level="section">Sec. 102. Inventory of critical infrastructure.</toc-entry>
					<toc-entry idref="idfdcc49ef4a7948e386b2c6640acaee14" level="section">Sec. 103. Voluntary cybersecurity practices.</toc-entry>
					<toc-entry idref="id383d5d6fda4c43248cafaa98de9f903c" level="section">Sec. 104. Voluntary cybersecurity program for critical
				infrastructure.</toc-entry>
					<toc-entry idref="idb97389a7d88d41c7a60423fae66f2b80" level="section">Sec. 105. Rules of construction.</toc-entry>
					<toc-entry idref="id3e9ed2e17061426088d3d75daf481b2c" level="section">Sec. 106. Protection of information.</toc-entry>
					<toc-entry idref="idebfbf182a5f846cb9cd975ec64f0ec6c" level="section">Sec. 107. Annual assessment of cybersecurity.</toc-entry>
					<toc-entry idref="ide9dcf21c9db24e888bb08678cadd7c85" level="section">Sec. 108. International cooperation.</toc-entry>
					<toc-entry idref="id3ed75fabd1864918b62228b02085df4c" level="section">Sec. 109. Effect on other laws.</toc-entry>
					<toc-entry idref="id4AAA4A7447004490A97E0744DC35CC74" level="section">Sec. 110. Definitions.</toc-entry>
					<toc-entry idref="id47ADCFA182B442FC8158764795081EE7" level="title">TITLE II—Federal information security management and
				consolidating resources</toc-entry>
					<toc-entry idref="idB8E6DBD0445A4F699A897BBEFB635C0E" level="section">Sec. 201. FISMA Reform.</toc-entry>
					<toc-entry idref="ID1f78ed935a9449098664d18aa30aabdc" level="section">Sec. 202. Management of information technology.</toc-entry>
					<toc-entry idref="ID0878d5bdfa38404bae793bf89eb098e7" level="section">Sec. 203. Savings provisions.</toc-entry>
					<toc-entry idref="ID3d57e7d77d5f46558b466ddec449d31c" level="section">Sec. 204. Consolidation of existing departmental cyber
				resources and authorities.</toc-entry>
					<toc-entry idref="id2487DB755B2240DA9CB1C2F2F611FC0D" level="title">TITLE III—Research and development</toc-entry>
					<toc-entry idref="idEEC57A3DCAF148769074670062EBE0B9" level="section">Sec. 301. Federal cybersecurity research and
				development.</toc-entry>
					<toc-entry idref="id21267FF88F3F4BCA90A5249056D20D28" level="section">Sec. 302. Homeland security cybersecurity research and
				development.</toc-entry>
					<toc-entry idref="id1af83532462c432f9cf9b9b9ba9e9ef1" level="section">Sec. 303. Research centers for cybersecurity.</toc-entry>
					<toc-entry idref="id7321EF5586294BC592054FED78C4F7DC" level="section">Sec. 304. Centers of excellence.</toc-entry>
					<toc-entry idref="id9e0069282f494ca08395913d6d91ef59" level="title">TITLE IV—Education, workforce, and awareness</toc-entry>
					<toc-entry idref="idd17e422beb2346b2a39fab74e4ec2a77" level="section">Sec. 401. Definitions.</toc-entry>
					<toc-entry idref="idA2C088BFDFDE409C9539B8D7328255EE" level="section">Sec. 402. Education and awareness.</toc-entry>
					<toc-entry idref="IDbf31f9a8885d4e57b1622cc760aba677" level="section">Sec. 403. National cybersecurity competition and
				challenge.</toc-entry>
					<toc-entry idref="ID8843459fc57a44ceba9b4e24983fa9e0" level="section">Sec. 404. Federal Cyber Scholarship-for-Service
				program.</toc-entry>
					<toc-entry idref="ID39f44a12e75e48818bb922681689b254" level="section">Sec. 405. Assessment of cybersecurity Federal
				workforce.</toc-entry>
					<toc-entry idref="ID9331158723ab46b3a429bd52095920d4" level="section">Sec. 406. Federal cybersecurity occupation
				classifications.</toc-entry>
					<toc-entry idref="ID1d3b542c748c4c3e988d293e2aba0f61" level="section">Sec. 407. Training and education of Federal
				employees.</toc-entry>
					<toc-entry idref="idb4c7cc289a1b4bf4899fa8696040df39" level="section">Sec. 408. National Center for Cybersecurity and Communications
				acquisition authorities.</toc-entry>
					<toc-entry idref="id1DFB1422EDC8475EB1A76115940EBFE0" level="section">Sec. 409. Reports on cyber incidents against Government
				networks.</toc-entry>
					<toc-entry idref="id9DD9775D1FD24DF3933B951C3DDD0A4C" level="section">Sec. 410. Reports on prosecution for cybercrime.</toc-entry>
					<toc-entry idref="IDec6b15807a434a079aadc4ba2fec9c12" level="section">Sec. 411. Report on research relating to secure
				domain.</toc-entry>
					<toc-entry idref="id816DAE20CBF14533927D138F96B9DFB2" level="section">Sec. 412. Report on preparedness of Federal courts to promote
				cybersecurity.</toc-entry>
					<toc-entry idref="id92FC6DCE76264D6EACED8FD07B5549F0" level="section">Sec. 413. Report on impediments to public
				awareness.</toc-entry>
					<toc-entry idref="idB800AA73B89A4703842A6653E02578C8" level="section">Sec. 414. Report on protecting the electrical grid of the
				United States.</toc-entry>
					<toc-entry idref="idFF7EC7032D444175B5EE17FA72A8DC36" level="section">Sec. 415. Marketplace information.</toc-entry>
					<toc-entry idref="id7694758327444028A1C1A12404E619ED" level="title">TITLE V—Federal acquisition risk management strategy</toc-entry>
					<toc-entry idref="IDa6fe930650cb41c7a95bfae9aae079a0" level="section">Sec. 501. Federal acquisition risk management
				strategy.</toc-entry>
					<toc-entry idref="ID2174a7c4b179421490defd3b4352ce5b" level="section">Sec. 502. Amendments to Clinger-Cohen provisions to enhance
				agency planning for information security needs.</toc-entry>
					<toc-entry idref="id1969E5C2828D4F5D93287BE784A4E085" level="title">TITLE VI—International cooperation</toc-entry>
					<toc-entry idref="id688CC43888544A3FAB7B7DFAA329DFED" level="section">Sec. 601. Definitions.</toc-entry>
					<toc-entry idref="idAF0CC11AC02742A5A2EBFFF09E085AB1" level="section">Sec. 602. Findings.</toc-entry>
					<toc-entry idref="idEBD16752E8F446E9B457FBC3362383AF" level="section">Sec. 603. Sense of Congress.</toc-entry>
					<toc-entry idref="id4793D0AB051E4C1DA85AA8168938AC34" level="section">Sec. 604. Coordination of international cyber issues within the
				United States Government.</toc-entry>
					<toc-entry idref="IDbcf1e8b7f0244650b2fa209f60e39942" level="section">Sec. 605. Consideration of cybercrime in foreign policy and
				foreign assistance programs.</toc-entry>
					<toc-entry idref="id3D53211210E34701AA5FA4526FE76BE0" level="title">TITLE VII—Information sharing</toc-entry>
					<toc-entry idref="id6788880658D441D1B43DC27ADF206724" level="section">Sec. 701. Affirmative authority to monitor and defend against
				cybersecurity threats.</toc-entry>
					<toc-entry idref="id3d58c2a6ca1a495bad35c9d044c67e94" level="section">Sec. 702. Voluntary disclosure of cybersecurity threat
				indicators among private entities.</toc-entry>
					<toc-entry idref="idbd74bf64d78342edbd226eacb886bfce" level="section">Sec. 703. Cybersecurity exchanges.</toc-entry>
					<toc-entry idref="idfb0d269052c849599d761ac9a9d70297" level="section">Sec. 704. Voluntary disclosure of cybersecurity threat
				indicators to a cybersecurity exchange.</toc-entry>
					<toc-entry idref="id5a94343ad9104cfe8c69577a3767e46a" level="section">Sec. 705. Sharing of classified cybersecurity threat
				indicators.</toc-entry>
					<toc-entry idref="id765bbb0cd3944786811c79e01531d934" level="section">Sec. 706. Limitation on liability and good faith defense for
				cybersecurity activities.</toc-entry>
					<toc-entry idref="idf400513ce6124eb69b9eb0e3f3903422" level="section">Sec. 707. Construction and federal preemption.</toc-entry>
					<toc-entry idref="id15083f7a4923427b8d28aad06663acac" level="section">Sec. 708. Definitions.</toc-entry>
				</toc>
			</subsection></section><section id="id467d63c8e0794b4d8d20f5ae3737f56d"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="id62dc7df33344494e967eb3b930bb03ba"><enum>(1)</enum><header>Category of
			 critical cyber infrastructure</header><text>The term <term>category of critical
			 cyber infrastructure</term> means a category identified by the Council as
			 critical cyber infrastructure in accordance with the procedure established
			 under section 102.</text>
			</paragraph><paragraph id="id2fed5385cfc5474bb5e496b4d4d5602f"><enum>(2)</enum><header>Commercial
			 information technology product</header><text>The term <term>commercial
			 information technology product</term> means a commercial item that organizes or
			 communicates information electronically.</text>
			</paragraph><paragraph id="idb18574d439d742a4a0f55f85e39463ee"><enum>(3)</enum><header>Commercial
			 item</header><text>The term <term>commercial item</term> has the meaning given
			 the term in section 103 of title 41, United States Code.</text>
			</paragraph><paragraph id="id672DA89972F9488CAC78CC858E758190"><enum>(4)</enum><header>Council</header><text>The
			 term <term>Council</term> means the National Cybersecurity Council established
			 under section 101.</text>
			</paragraph><paragraph id="id7753ea2df4b142cc8225c17a955ebd06"><enum>(5)</enum><header>Critical cyber
			 infrastructure</header><text>The term <term>critical cyber
			 infrastructure</term> means critical infrastructure identified by the Council
			 under section 102(b)(3)(A).</text>
			</paragraph><paragraph id="id804c14a5644a4c95a661194f2b5a3984"><enum>(6)</enum><header>Critical
			 infrastructure</header><text>The term <term>critical infrastructure</term> has
			 the meaning given that term in section 1016(e) of the USA PATRIOT Act (42
			 U.S.C. 5195c(e)).</text>
			</paragraph><paragraph id="id8e6baf88f10a432ca861af94b9ccec42"><enum>(7)</enum><header>Critical
			 Infrastructure Partnership Advisory Council</header><text>The term
			 <term>Critical Infrastructure Partnership Advisory Council</term> means the
			 Critical Infrastructure Partnership Advisory Council established by the
			 Department under section 871 of the Homeland Security Act of 2002 (6 U.S.C.
			 451) to coordinate critical infrastructure protection activities within the
			 Federal Government and with the private sector and State, local, territorial,
			 and tribal governments.</text>
			</paragraph><paragraph id="idf4ffe4a3e377409fb29ed4539b667a7b"><enum>(8)</enum><header>Department</header><text>The
			 term <term>Department</term> means the Department of Homeland Security.</text>
			</paragraph><paragraph id="id2e0be7ec588a4138b07ec38e922df514"><enum>(9)</enum><header>Federal
			 agency</header><text>The term <term>Federal agency</term> has the meaning given
			 the term <term>agency</term> in section 3502 of title 44, United States
			 Code.</text>
			</paragraph><paragraph id="id18fc5b40f59a49d29826a20d90dac774"><enum>(10)</enum><header>Federal
			 information infrastructure</header><text>The term <term>Federal information
			 infrastructure</term>—</text>
				<subparagraph id="idaa83957d7bf543f4885f11281114d9b0"><enum>(A)</enum><text>means information
			 and information systems that are owned, operated, controlled, or licensed for
			 use by, or on behalf of, any Federal agency, including information systems used
			 or operated by another entity on behalf of a Federal agency; and</text>
				</subparagraph><subparagraph id="id39188b3e88624a6cb6b642c6e7bd8096"><enum>(B)</enum><text>does not
			 include—</text>
					<clause id="id8c3a57e528c84c01a0bbf0bad23ff784"><enum>(i)</enum><text>a
			 national security system; or</text>
					</clause><clause id="ide799d00d457f4855a91069e5c02135a5"><enum>(ii)</enum><text>information and
			 information systems that are owned, operated, controlled, or licensed solely
			 for use by, or on behalf of, the Department of Defense, a military department,
			 or an element of the intelligence community.</text>
					</clause></subparagraph></paragraph><paragraph id="idb3023a929d2a437b920bac9381fff661"><enum>(11)</enum><header>Incident</header><text>The
			 term <term>incident</term> has the meaning given that term in section 3552 of
			 title 44, United States Code, as added by section 201 of this Act.</text>
			</paragraph><paragraph id="id43a20b4e444f4467934b8c9807bb40f3"><enum>(12)</enum><header>Information
			 infrastructure</header><text>The term <term>information infrastructure</term>
			 means the underlying framework that information systems and assets rely on to
			 process, transmit, receive, or store information electronically, including
			 programmable electronic devices, communications networks, and industrial or
			 supervisory control systems and any associated hardware, software, or
			 data.</text>
			</paragraph><paragraph id="id1b80800e99a94d56ba9974faf956a112"><enum>(13)</enum><header>Information
			 sharing and analysis organization</header><text>The term <term>Information
			 Sharing and Analysis Organization</term> has the meaning given that term in
			 section 212 of the Homeland Security Act of 2002 (6 U.S.C. 131).</text>
			</paragraph><paragraph id="id9e3b74165dc447bea5e3470a9541851c"><enum>(14)</enum><header>Information
			 system</header><text>The term <term>information system</term> has the meaning
			 given that term in section 3502 of title 44, United States Code.</text>
			</paragraph><paragraph id="id14a4b0e5b24942ef819c3aabfe2d8674"><enum>(15)</enum><header>Institution of
			 higher education</header><text>The term <term>institution of higher
			 education</term> has the meaning given that term in section 102 of the Higher
			 Education Act of 1965 (20 U.S.C. 1002).</text>
			</paragraph><paragraph id="id02ef7310d5794dbeaa12e0d45d59f623"><enum>(16)</enum><header>Intelligence
			 community</header><text>The term <term>intelligence community</term> has the
			 meaning given that term under section 3(4) of the National Security Act of 1947
			 (50 U.S.C. 401a(4)).</text>
			</paragraph><paragraph id="id9715c904d6534b6197e9d202f8c338c0"><enum>(17)</enum><header>Member
			 agency</header><text>The term <term>member agency</term> means a Federal agency
			 from which a member of the Council is appointed.</text>
			</paragraph><paragraph id="id49b74a1d541a48e5bc7ece22c7057d84"><enum>(18)</enum><header>National
			 information infrastructure</header><text>The term <term>national information
			 infrastructure</term> means information and information systems—</text>
				<subparagraph id="id7dbf55a519794c34b42eca4da4da4981"><enum>(A)</enum><text>that are owned,
			 operated, or controlled, in whole or in part, within or from the United States;
			 and</text>
				</subparagraph><subparagraph id="id79e1eef0bbee4fa38b5dda55fe76ddcb"><enum>(B)</enum><text>that are not
			 owned, operated, controlled, or licensed for use by a Federal agency.</text>
				</subparagraph></paragraph><paragraph id="idB03A1B05374947DB8BC5D11F1C980FBE"><enum>(19)</enum><header>National
			 laboratory</header><text>The term <term>national laboratory</term> has the
			 meaning given the term in section 2 of the Energy Policy Act of 2005 (42 U.S.C.
			 15801).</text>
			</paragraph><paragraph id="id6fee59c44dfa4535a451197fe8609398"><enum>(20)</enum><header>National
			 security system</header><text>The term <term>national security system</term>
			 has the meaning given that term in section 3552 of title 44, United States
			 Code, as added by section 201 of this Act.</text>
			</paragraph><paragraph id="idae1b4c29d35940c89b0053294a21e3eb"><enum>(21)</enum><header>Owner</header><text>The
			 term <term>owner</term>—</text>
				<subparagraph id="idce1047d20a8f4d4583a936d7a55d87ce"><enum>(A)</enum><text>means an entity
			 that owns critical infrastructure; and</text>
				</subparagraph><subparagraph id="id813a911d80c34570b23e1193bfb3ffcd"><enum>(B)</enum><text>does not include
			 a company contracted by the owner to manage, run, or operate that critical
			 infrastructure, or to provide a specific information technology product or
			 service that is used or incorporated into that critical infrastructure.</text>
				</subparagraph></paragraph><paragraph id="id1d76317b54b94488abb3b166b8ca531e"><enum>(22)</enum><header>Operator</header><text>The
			 term <term>operator</term>—</text>
				<subparagraph id="id09561527b00e41d0a598ab1cf49ae1dd"><enum>(A)</enum><text>means an entity
			 that manages, runs, or operates, in whole or in part, the day-to-day operations
			 of critical infrastructure; and</text>
				</subparagraph><subparagraph id="id3421d7e2a0e24aaab7bdd5d1ac53dbbd"><enum>(B)</enum><text>may include the
			 owner of critical infrastructure.</text>
				</subparagraph></paragraph><paragraph id="id29441f8276fc4b1fa3d19c04ee4bcd9c"><enum>(23)</enum><header>Secretary</header><text>The
			 term <term>Secretary</term> means the Secretary of Homeland Security.</text>
			</paragraph><paragraph id="id2bd1f30c6d7a4ea69b16ef496092c27f"><enum>(24)</enum><header>Significant
			 cyber incident</header><text>The term <term>significant cyber incident</term>
			 means an incident resulting in, or an attempted to cause an incident that, if
			 successful, would have resulted in—</text>
				<subparagraph id="idc8a493219a384975bfb4839eb246a3b0"><enum>(A)</enum><text>the exfiltration
			 of data that is essential to the operation of critical cyber infrastructure;
			 or</text>
				</subparagraph><subparagraph id="id032daf3ff01142e8bb4d9ff79cdbeca0"><enum>(B)</enum><text>the defeat of an
			 operational control or technical control, as those terms are defined in section
			 708, essential to the security or operation of critical cyber
			 infrastructure.</text>
				</subparagraph></paragraph></section><title id="iddfe1da88a5814210865f1674c09e124a"><enum>I</enum><header>Public-private
			 partnership to protect critical infrastructure</header>
			<section id="id6a77a92da8c64ed1989ef48f1513b2aa"><enum>101.</enum><header>National
			 Cybersecurity Council</header>
				<subsection id="idd6213df01a9e4ba795d352d6f712de19"><enum>(a)</enum><header>In
			 general</header><text>There is established a National Cybersecurity
			 Council.</text>
				</subsection><subsection id="id0ba9a1da2bc449179ffb9374a0760188"><enum>(b)</enum><header>Responsibilities</header><text>The
			 Council shall—</text>
					<paragraph id="id7D2A179615A54CC086BA80D495378123"><enum>(1)</enum><text>conduct
			 sector-by-sector risk assessments in partnership with owners and operators,
			 private sector entities, relevant Federal agencies, and appropriate
			 non-governmental entities and institutions of higher education;</text>
					</paragraph><paragraph id="id67254a51710e4a40be6616f800d3f1ed"><enum>(2)</enum><text>identify
			 categories of critical cyber infrastructure, in partnership with relevant
			 Federal agencies, owners and operators, other appropriate private sector
			 entities, and appropriate non-governmental entities and institutions of higher
			 education;</text>
					</paragraph><paragraph id="id9aee0ccf2cf14869aac412bc6c96cac3"><enum>(3)</enum><text>coordinate the
			 adoption of private-sector recommended voluntary outcome-based cybersecurity
			 practices with owners and operators, private sector entities, relevant Federal
			 agencies, the Critical Infrastructure Partnership Advisory Council,
			 institutions of higher education, and appropriate non-governmental
			 cybersecurity experts, in accordance with this title;</text>
					</paragraph><paragraph id="id8453f95d0b714d82adb69231c4b6297f"><enum>(4)</enum><text>establish an
			 incentives-based voluntary cybersecurity program for critical infrastructure to
			 encourage owners to adopt voluntary outcome-based cybersecurity practices under
			 section 103;</text>
					</paragraph><paragraph id="idf60b98ea52d04d7391e102ca5d1b8354"><enum>(5)</enum><text>develop
			 procedures to inform owners and operators of cyber threats, vulnerabilities,
			 and consequences; and</text>
					</paragraph><paragraph id="id27017966791e45c7b5b87c13ff090bb8"><enum>(6)</enum><text>upon request and
			 to the maximum extent possible, provide any technical guidance or assistance to
			 owners and operators consistent with this title.</text>
					</paragraph></subsection><subsection id="id1304e46edd5047e4a842d7b9a276647c"><enum>(c)</enum><header>Procedures</header><text>The
			 President shall establish procedures, consistent with this section, for the
			 operation of the Council, which shall include procedures that—</text>
					<paragraph id="id9749F524874F4C40BB2A3EAFA9E5257A"><enum>(1)</enum><text>prescribe the
			 responsibilities of the Council and the member agencies;</text>
					</paragraph><paragraph id="id8df8012d64be4284a3e2a3b0179b6076"><enum>(2)</enum><text>ensure the timely
			 implementation of decisions of the Council;</text>
					</paragraph><paragraph id="idfea44c94711f4541b4dc50bdf3732f83"><enum>(3)</enum><text>delegate
			 authority to the Chairperson to take action to fulfill the responsibilities of
			 the Council if—</text>
						<subparagraph id="ide008eb22dd0b402bb40e32ea2f56565d"><enum>(A)</enum><text>the Council is
			 not fulfilling the responsibilities of the Council in a timely fashion;
			 or</text>
						</subparagraph><subparagraph id="idfa35fca4e2954fd6a5817d146d5123cb"><enum>(B)</enum><text>necessary to
			 prevent or mitigate an imminent cybersecurity threat.</text>
						</subparagraph></paragraph></subsection><subsection id="id29e920608c3d48a99982b7e39242d676"><enum>(d)</enum><header>Membership</header><text>The
			 Council shall be comprised of appropriate representatives appointed by the
			 President from—</text>
					<paragraph id="id4ff5e9050c864618a2e57ee97962c0aa"><enum>(1)</enum><text>the Department of
			 Commerce;</text>
					</paragraph><paragraph id="id39044b9491934fa492b933aea4571cc7"><enum>(2)</enum><text>the Department of
			 Defense;</text>
					</paragraph><paragraph id="id546895CB83AF40A99124DB4533ABBCD6"><enum>(3)</enum><text>the Department of
			 Justice;</text>
					</paragraph><paragraph id="id28675935982E4C2197AB9C30C4B5A24B"><enum>(4)</enum><text>the intelligence
			 community;</text>
					</paragraph><paragraph id="id17f1ed88793e4d1aaa017c470863f0f5"><enum>(5)</enum><text>sector-specific
			 Federal agencies, as appropriate;</text>
					</paragraph><paragraph id="idd0f9c7cf7f0b402a95156cfc6c3f0dcb"><enum>(6)</enum><text>Federal agencies
			 with responsibility for regulating the security of critical cyber
			 infrastructure, as appropriate; and</text>
					</paragraph><paragraph id="id2bbd1f936f7544e58bc36d9e3fec5692"><enum>(7)</enum><text>the
			 Department.</text>
					</paragraph></subsection><subsection id="id7334bf05fb8243329273cc01016607c8"><enum>(e)</enum><header>Coordination</header><text>The
			 Council shall coordinate the activities of the Council with—</text>
					<paragraph id="id4AD2D1537FFE44F4A6C1FCF9E0F6E4F2"><enum>(1)</enum><text>appropriate
			 representatives of the private sector; and</text>
					</paragraph><paragraph id="id53EE92C1A05244C9B19D3F1B64E71CC0"><enum>(2)</enum><text>owners and
			 operators.</text>
					</paragraph></subsection><subsection id="ideb8331488f8a4a99bbf2bd833aa91cf0"><enum>(f)</enum><header>Chairperson</header>
					<paragraph id="id151333B5ECB0468787CA8CD66C70E009"><enum>(1)</enum><header>In
			 general</header><text>The Secretary shall serve as Chairperson of the Council
			 (referred to in this section as the <quote>Chairperson</quote>).</text>
					</paragraph><paragraph id="id97fc0c1c084e42c587c15067d5668454"><enum>(2)</enum><header>Responsibilities
			 of the Chairperson</header><text>The Chairperson shall—</text>
						<subparagraph id="id1d42b60c6a934af6b83f5db704195cc8"><enum>(A)</enum><text>ensure the
			 responsibilities of the Council are expeditiously fulfilled;</text>
						</subparagraph><subparagraph id="id42964ea7e8e94f57aa2ccb87b883b5dc"><enum>(B)</enum><text>provide expertise
			 and support to the Council; and</text>
						</subparagraph><subparagraph id="idDE2F7B5D43E84E36A90C7FFBCE9982C4"><enum>(C)</enum><text>provide
			 recommendations to the Council.</text>
						</subparagraph></paragraph></subsection><subsection id="id2b2a34a0a45f4487b1e17d69276767b5"><enum>(g)</enum><header>Participation
			 of sector-specific Federal agencies and Federal regulatory
			 agencies</header><text>A sector-specific Federal agency and a Federal agency
			 with responsibility for regulating the security of critical cyber
			 infrastructure shall participate on the Council on matters directly relating to
			 the sector of critical infrastructure for which the Federal agency has
			 responsibility to ensure that any cybersecurity practice adopted by the Council
			 under section 103—</text>
					<paragraph id="idA87FFF1832CD4A978EAF2B60FA720232"><enum>(1)</enum><text>does not
			 contradict any regulation or compulsory standard in effect before the adoption
			 of the cybersecurity practice; and</text>
					</paragraph><paragraph id="idDD55850C3F04481590893F60B33BE0B1"><enum>(2)</enum><text>to the extent
			 possible, complements or otherwise improves the regulation or compulsory
			 standard described in paragraph (1).</text>
					</paragraph></subsection></section><section id="ideb7a21a9cbca45c4b0db8d654adde995"><enum>102.</enum><header>Inventory of
			 critical infrastructure</header>
				<subsection id="id4bd996d208b64d6f816f869c444755b1"><enum>(a)</enum><header>Risk
			 assessments</header>
					<paragraph id="id472f913a34a94bc9a2c65222bd2f5c91"><enum>(1)</enum><header>In
			 general</header>
						<subparagraph id="id03350E81CBAD4E14BFD2B07CE2C01382"><enum>(A)</enum><header>Designation of
			 member agency</header><text>The Council shall designate a member agency to
			 conduct top-level cybersecurity assessments of cyber risks to critical
			 infrastructure with voluntary participation from private sector
			 entities.</text>
						</subparagraph><subparagraph id="id1060044FA42E4075B49A0F662CBA95CF"><enum>(B)</enum><header>Rule of
			 construction</header><text>Nothing in this subsection shall be construed to
			 give new authority to a Federal agency to require owners or operators to
			 provide information to the Federal Government.</text>
						</subparagraph></paragraph><paragraph id="id884bed5031374e0b91deabbdd5fdf491"><enum>(2)</enum><header>Responsibility</header><text>The
			 member agency designated under paragraph (1), in consultation with owners and
			 operators, the Critical Infrastructure Partnership Advisory Council, and
			 appropriate Information Sharing and Analysis Organizations, and in coordination
			 with other member agencies, the intelligence community, and the Department of
			 Commerce, shall—</text>
						<subparagraph id="id6ac1a2fa35e44f1c8593901ebc534c93"><enum>(A)</enum><text>not later than
			 180 days after the date of enactment of this Act, conduct a top-level
			 assessment of the cybersecurity threats, vulnerabilities, and consequences and
			 the probability of a catastrophic incident and associated risk across all
			 critical infrastructure sectors to determine which sectors pose the greatest
			 immediate risk, in order to guide the allocation of resources for the
			 implementation of this Act; and</text>
						</subparagraph><subparagraph id="idd1aa77e883624948a34322fd650b90e3"><enum>(B)</enum><text>beginning with
			 the highest priority sectors identified under subparagraph (A), conduct, on an
			 ongoing, sector-by-sector basis, cyber risk assessments of the threats to,
			 vulnerabilities of, and consequences of a cyber attack on critical
			 infrastructure.</text>
						</subparagraph></paragraph><paragraph id="idf948056b0a5f42cd9b198734e27215c3"><enum>(3)</enum><header>Voluntary input
			 of owners and operators</header><text>The member agency designated under
			 paragraph (1) shall—</text>
						<subparagraph id="id44f65c6c92dc4a59af8334cbc81c80a3"><enum>(A)</enum><text>establish a
			 process under which owners and operators and other relevant private sector
			 experts may provide input into the risk assessments conducted under this
			 section; and</text>
						</subparagraph><subparagraph id="idF0D844D3BC144BBD98A93CAD9F5FE13F"><enum>(B)</enum><text>seek and
			 incorporate private sector expertise available through established
			 public-private partnerships, including the Critical Infrastructure Partnership
			 Advisory Council and appropriate Information Sharing and Analysis
			 Organizations.</text>
						</subparagraph></paragraph><paragraph id="id615886e25f7c45d0bd38a52c50d9158d"><enum>(4)</enum><header>Protection of
			 information</header><text>Any information submitted as part of the process
			 established under paragraph (3) shall be protected in accordance with section
			 106.</text>
					</paragraph><paragraph id="idb796f81fea2b41139255d44be254fec8"><enum>(5)</enum><header>Submission of
			 risk assessments</header><text>The Council shall submit each risk assessment
			 conducted under this section, in a classified or unclassified form as
			 necessary, to—</text>
						<subparagraph id="id3883237a946d4abcbc44b998c513df7b"><enum>(A)</enum><text>the
			 President;</text>
						</subparagraph><subparagraph id="id728586158ba6487088f41d525138a82b"><enum>(B)</enum><text>appropriate
			 Federal agencies; and</text>
						</subparagraph><subparagraph id="id85be7e0d728e493099645105adcf55f7"><enum>(C)</enum><text>appropriate
			 congressional committees.</text>
						</subparagraph></paragraph></subsection><subsection id="id089389e9f7e74d368fafbc998e3aa32e"><enum>(b)</enum><header>Identification
			 of critical cyber infrastructure categories</header>
					<paragraph id="id618caafcd83b49d59439b038259ca026"><enum>(1)</enum><header>In
			 general</header><text>The Council, in consultation with owners and operators,
			 the Critical Infrastructure Partnership Advisory Council, appropriate
			 Information Sharing and Analysis Organizations, and other appropriate
			 representatives of State and local governments, shall establish procedures to
			 identify categories of critical cyber infrastructure within each sector of
			 critical infrastructure for the purposes of this Act.</text>
					</paragraph><paragraph id="id3e440b480445447f81b259f4a36cce80"><enum>(2)</enum><header>Duties</header><text>In
			 establishing the procedure under paragraph (1), the Council shall—</text>
						<subparagraph id="id2a52209aa12f4e618e269c3bcb22759e"><enum>(A)</enum><text>prioritize
			 efforts based on the prioritization established under subsection (a);</text>
						</subparagraph><subparagraph id="id93ebbb266dd9438fbb1dd3adb60f755d"><enum>(B)</enum><text>incorporate, to
			 the extent practicable, the input of owners and operators, the Critical
			 Infrastructure Partnership Advisory Council, appropriate Information Sharing
			 and Analysis Organizations, and other appropriate representatives of the
			 private sector and State and local governments;</text>
						</subparagraph><subparagraph id="idb591ebbd44244d56a5506f8567b6deda"><enum>(C)</enum><text>develop a
			 voluntary mechanism for owners to submit information to assist the Council in
			 making determinations under this section;</text>
						</subparagraph><subparagraph id="ida42f524204b94bd1bd41187187e98c30"><enum>(D)</enum><text>inform owners and
			 operators of the criteria used to identify categories of critical cyber
			 infrastructure;</text>
						</subparagraph><subparagraph id="id03fb6a505c814bb6a7874b2122a95509"><enum>(E)</enum><text>establish
			 procedures for an owner of critical infrastructure identified as critical cyber
			 infrastructure to challenge the identification;</text>
						</subparagraph><subparagraph id="id01cbb76695354448aaa3365e6273d453"><enum>(F)</enum><text>select a member
			 agency to make recommendations to the Council on the identification of
			 categories of critical cyber infrastructure; and</text>
						</subparagraph><subparagraph id="idae22db6ea5d54da2a0ddd7656499c46c"><enum>(G)</enum><text>periodically
			 review and update identifications under this subsection.</text>
						</subparagraph></paragraph><paragraph id="id22059b9794b24314b8c68aadf058fd83"><enum>(3)</enum><header>Identification
			 requirements</header><text>The Council shall—</text>
						<subparagraph id="id5289232225164db5ab9d954e3ebb67b2"><enum>(A)</enum><text>identify
			 categories of critical cyber infrastructure within each sector of critical
			 infrastructure and identify owners of critical infrastructure within each
			 category of critical cyber infrastructure;</text>
						</subparagraph><subparagraph id="id9ea92ca7168746babe46aa8a14e46dd4"><enum>(B)</enum><text>only identify a
			 category of critical infrastructure as critical cyber infrastructure if damage
			 to or unauthorized access to such critical infrastructure could reasonably
			 result in—</text>
							<clause id="ided0187c761704655b3f605548106ef4e"><enum>(i)</enum><text>the
			 interruption of life-sustaining services, including energy, water,
			 transportation, emergency services, or food, sufficient to cause—</text>
								<subclause id="ida1c404bca8bb4de5a868d05cebb019a3"><enum>(I)</enum><text>a mass casualty
			 event; or</text>
								</subclause><subclause id="id196f955335c34e1a95467d1f3935e470"><enum>(II)</enum><text>mass
			 evacuations;</text>
								</subclause></clause><clause id="id970f0a701bb54c0386ac63ecf7c021f2"><enum>(ii)</enum><text>catastrophic
			 economic damage to the United States including—</text>
								<subclause id="id822f0fa2972d4a67aa3177fb66d528d5"><enum>(I)</enum><text>failure or
			 substantial disruption of a financial market of the United States;</text>
								</subclause><subclause id="id01627d6049924884baf82775ba678971"><enum>(II)</enum><text>incapacitation
			 or sustained disruption of a transportation system; or</text>
								</subclause><subclause id="ida8b6812cd2d0452191f6a6599eed8e60"><enum>(III)</enum><text>other systemic,
			 long-term damage to the economy of the United States; or</text>
								</subclause></clause><clause id="ide5552a3f9a9f4fa0bff2947614b3eb74"><enum>(iii)</enum><text>severe
			 degradation of national security or national security capabilities, including
			 intelligence and defense functions; and</text>
							</clause></subparagraph><subparagraph id="id8db0f737203f4350ac2ab526e1454355"><enum>(C)</enum><text>consider the
			 sector-by-sector risk assessments developed in accordance with subsection
			 (a).</text>
						</subparagraph></paragraph><paragraph id="id558D81F069E94EAEA579F892E5066C61"><enum>(4)</enum><header>Incident
			 reporting</header><text>The Council shall establish procedures under which each
			 owner of critical cyber infrastructure shall report significant cyber incidents
			 affecting critical cyber infrastructure.</text>
					</paragraph><paragraph id="id69435e035aa04db49e6ac53bf21ce1c4"><enum>(5)</enum><header>Limitations</header><text>The
			 Council may not identify as a category of critical cyber infrastructure under
			 this section—</text>
						<subparagraph id="id57c4342191f0498595593671b2d3e48f"><enum>(A)</enum><text>critical
			 infrastructure based solely on activities protected by the first amendment to
			 the Constitution of the United States;</text>
						</subparagraph><subparagraph id="idaaf7df30c4fa4a258939da00a1ef6f8e"><enum>(B)</enum><text>an information
			 technology product based solely on a finding that the product is capable of, or
			 is actually, being used in critical cyber infrastructure; or</text>
						</subparagraph><subparagraph id="id8d974ee092f644938bca69424e5f0697"><enum>(C)</enum><text>a commercial item
			 that organizes or communicates information electronically.</text>
						</subparagraph></paragraph><paragraph id="id01ee6b4a34874e6f9507e2be2d9cd387"><enum>(6)</enum><header>Notification of
			 identification of category of critical cyber infrastructure</header><text>Not
			 later than 10 days after the Council identifies a category of critical cyber
			 infrastructure under this section, the Council shall notify the relevant owners
			 of the identified critical cyber infrastructure.</text>
					</paragraph><paragraph id="id5976af453103412686b6bac0f811f9af"><enum>(7)</enum><header>Definition</header><text>In
			 this subsection, the term <term>damage</term> has the meaning given that term
			 in section 1030(e) of title 18, United States Code.</text>
					</paragraph></subsection><subsection commented="no" id="idf2a534b343e94d98866ba7f05267a4f7"><enum>(c)</enum><header>Congressional
			 notice and opportunity for disapproval</header>
					<paragraph commented="no" id="idFCCEC8D9A2524D8092A5369785192D65"><enum>(1)</enum><header>Notification</header><text>Not
			 later than 10 days after the date on which the Council identifies a category of
			 critical infrastructure as critical cyber infrastructure under this section,
			 the Council shall—</text>
						<subparagraph commented="no" id="id74F5B932564A448E82D416D88C544F9E"><enum>(A)</enum><text>notify Congress
			 of the identification; and</text>
						</subparagraph><subparagraph commented="no" id="id01B4A11505844CB78C12CCE886734FBC"><enum>(B)</enum><text>submit to
			 Congress a report explaining the basis for the identification.</text>
						</subparagraph></paragraph><paragraph commented="no" id="idCCAC6CFE8E9E4C7D81DBCBA5E54DECEA"><enum>(2)</enum><header>Opportunity for
			 congressional review</header><text>The identification of a category of critical
			 infrastructure as critical cyber infrastructure shall not take effect for
			 purposes of this title until the date that is 60 days after the date on which
			 the Council notifies Congress under paragraph (1).</text>
					</paragraph></subsection></section><section id="idfdcc49ef4a7948e386b2c6640acaee14"><enum>103.</enum><header>Voluntary
			 cybersecurity practices</header>
				<subsection id="ide5edf45fbcf94bc79ff5c6d293b134ab"><enum>(a)</enum><header>Private sector
			 development of cybersecurity practices</header><text>Not later than 180 days
			 after the date of enactment of this Act, each sector coordinating council shall
			 propose to the Council voluntary outcome-based cybersecurity practices
			 (referred to in this section as <quote>cybersecurity practices</quote>)
			 sufficient to effectively remediate or mitigate cyber risks identified through
			 an assessment conducted under section 102(a) comprised of—</text>
					<paragraph id="id2e50d888749e4ec29891d69ad127d9cd"><enum>(1)</enum><text>industry best
			 practices, standards, and guidelines; or</text>
					</paragraph><paragraph id="id6c668e11101a4345a41507acf58b996d"><enum>(2)</enum><text>practices
			 developed by the sector coordinating council in coordination with owners and
			 operators, voluntary consensus standards development organizations,
			 representatives of State and local governments, the private sector, and
			 appropriate information sharing and analysis organizations.</text>
					</paragraph></subsection><subsection id="idf5efaf6896464ab78731ffca582a0c6d"><enum>(b)</enum><header>Review of
			 Cybersecurity Practices</header>
					<paragraph id="idd89ea0759a6b40c799a223f4aef5edc5"><enum>(1)</enum><header>In
			 general</header><text>The Council shall, in consultation with owners and
			 operators, the Critical Infrastructure Partnership Advisory Council, and
			 appropriate information sharing and analysis organizations, and in coordination
			 with appropriate representatives from State and local governments—</text>
						<subparagraph id="id33ba85e8ccd54da9945bf328c501ba75"><enum>(A)</enum><text>consult with
			 relevant security experts and institutions of higher education, including
			 university information security centers, appropriate nongovernmental
			 cybersecurity experts, and representatives from national laboratories;</text>
						</subparagraph><subparagraph id="idecc1a4e7441b48d9903264eceb097aab"><enum>(B)</enum><text>review relevant
			 regulations or compulsory standards or guidelines;</text>
						</subparagraph><subparagraph id="idfd37f50820844792a93744c447e89ea3"><enum>(C)</enum><text>review
			 cybersecurity practices proposed under subsection (a); and</text>
						</subparagraph><subparagraph id="id5eb95ada604a4dd59a23400e0605c0ae"><enum>(D)</enum><text>consider any
			 amendments to the cybersecurity practices and any additional cybersecurity
			 practices necessary to ensure adequate remediation or mitigation of the cyber
			 risks identified through an assessment conducted under section 102(a).</text>
						</subparagraph></paragraph><paragraph id="id40ef599e99774bc084cde97eba7ebe3d"><enum>(2)</enum><header>Adoption</header>
						<subparagraph id="id81162C619EC047B08CE87C1E1B139864"><enum>(A)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Council shall—</text>
							<clause id="ide4c7b26fe7b94386becc938c58b42b54"><enum>(i)</enum><text>adopt any
			 cybersecurity practices proposed under subsection (a) that adequately remediate
			 or mitigate identified cyber risks and any associated consequences identified
			 through an assessment conducted under section 102(a); and</text>
							</clause><clause id="id0577a1606ee749c19c995f0c736e6523"><enum>(ii)</enum><text>adopt any
			 amended or additional cybersecurity practices necessary to ensure the adequate
			 remediation or mitigation of the cyber risks identified through an assessment
			 conducted under section 102(a).</text>
							</clause></subparagraph><subparagraph id="id2f39e5ac5f964b7aa55b30b24de1ba17"><enum>(B)</enum><header>No submission
			 by sector coordinating council</header><text>If a sector coordinating council
			 fails to propose to the Council cybersecurity practices under subsection (a)
			 within 180 days of the date of enactment of this Act, not later than 1 year
			 after the date of enactment of this Act the Council shall adopt cybersecurity
			 practices that adequately remediate or mitigate identified cyber risks and
			 associated consequences identified through an assessment conducted under
			 section 102(a) for the sector.</text>
						</subparagraph></paragraph></subsection><subsection id="id24851125205f4500b21447d3dd73ef89"><enum>(c)</enum><header>Flexibility of
			 cybersecurity practices</header><text>Each sector coordinating council and the
			 Council shall periodically assess cybersecurity practices, but not less
			 frequently than once every 3 years, and update or modify cybersecurity
			 practices as necessary to ensure adequate remediation and mitigation of the
			 cyber risks identified through an assessment conducted under section
			 102(a).</text>
				</subsection><subsection id="id65253b1f087142da827821993a1a6b84"><enum>(d)</enum><header>Prioritization</header><text>Based
			 on the risk assessments performed under section 102(a), the Council shall
			 prioritize the development of cybersecurity practices to ensure the reduction
			 or mitigation of the greatest cyber risks.</text>
				</subsection><subsection id="idd6a9c1c55d55473ca2f97f5cf775500c"><enum>(e)</enum><header>Private sector
			 recommended measures</header><text>Each sector coordinating council shall
			 develop voluntary recommended cybersecurity measures that provide owners
			 reasonable and cost-effective methods of meeting any cybersecurity
			 practice.</text>
				</subsection><subsection id="id2dc336f9a1574a43adfcf44635cab347"><enum>(f)</enum><header>Technology
			 neutrality</header><text>No cybersecurity practice shall require—</text>
					<paragraph id="id1048c06959914d50a04fb40065ee06fa"><enum>(1)</enum><text>the use of a
			 specific commercial information technology product; or</text>
					</paragraph><paragraph id="id61b763a649bc4790b9e4cde6c05d98f6"><enum>(2)</enum><text>that a particular
			 commercial information technology product be designed, developed, or
			 manufactured in a particular manner.</text>
					</paragraph></subsection><subsection id="id30c76178061349d5b2ff8fc90cc63d2c"><enum>(g)</enum><header>Relationship to
			 existing regulations</header>
					<paragraph id="idce17af8334204de6b97293a0f8490439"><enum>(1)</enum><header>Inclusion in
			 regulatory regimes</header>
						<subparagraph id="id67d0469d77d141c3a5fee1fb928c0e91"><enum>(A)</enum><header>In
			 general</header><text>A Federal agency with responsibilities for regulating the
			 security of critical infrastructure may adopt the cybersecurity practices as
			 mandatory requirements.</text>
						</subparagraph><subparagraph id="id7d253fca5a8340fa930a663c01d20f6d"><enum>(B)</enum><header>Reports</header><text>If,
			 as of the date that is 1 year after the date of enactment of this Act, a
			 Federal agency with responsibilities for regulating the security of critical
			 infrastructure has not adopted the cybersecurity practices as mandatory
			 requirements, the agency shall submit to the appropriate congressional
			 committees a report on the reasons the agency did not do so, including a
			 description of whether the critical cyber infrastructure for which the Federal
			 agency has responsibility is maintaining practices sufficient to effectively
			 remediate or mitigate cyber risks identified through an assessment conducted
			 under section 102(a).</text>
						</subparagraph><subparagraph id="ide40ac88548ea4865b534bf0f8a439579"><enum>(C)</enum><header>Rule of
			 construction</header><text>Nothing in this subsection shall be construed to
			 provide a Federal agency with authority for regulating the security of critical
			 cyber infrastructure in addition or to a greater extent than the authority the
			 Federal agency has under other law.</text>
						</subparagraph></paragraph><paragraph id="id9fd1d33f0264414a93e22b90e7236b7c"><enum>(2)</enum><header>Avoidance of
			 conflict</header><text>No cybersecurity practice shall—</text>
						<subparagraph id="id10eea36fda6b40e3a0d9cdd592cc0e7d"><enum>(A)</enum><text>prevent an owner
			 (including a certified owner) from complying with any law or regulation;
			 or</text>
						</subparagraph><subparagraph id="id6313df7cf8e340d3880eb479786e149e"><enum>(B)</enum><text>require an owner
			 (including a certified owner) to implement cybersecurity measures that prevent
			 the owner from complying with any law or regulation.</text>
						</subparagraph></paragraph><paragraph id="idce6cbb9d9e5447f382cb336a8317fc2d"><enum>(3)</enum><header>Avoidance of
			 duplication</header><text>Where regulations or compulsory standards regulate
			 the security of critical cyber infrastructure, a cybersecurity practice shall,
			 to the greatest extent possible, complement or otherwise improve the
			 regulations or compulsory standards.</text>
					</paragraph></subsection><subsection id="idfa44785af0a047879387bf999a18a7b1"><enum>(h)</enum><header>Independent
			 review</header>
					<paragraph id="idD9D76DA3BCE746E184A9BD9A5E9B96CF"><enum>(1)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Each cybersecurity
			 practice shall be publicly reviewed by the relevant sector coordinating council
			 and the Critical Infrastructure Partnership Advisory Council, which may include
			 input from relevant institutions of higher education, including university
			 information security centers, national laboratories, and appropriate
			 non-governmental cybersecurity experts.</text>
					</paragraph><paragraph id="id75F4ADBF80FF4BDB8BBA836C3CE4E1A7"><enum>(2)</enum><header>Consideration
			 by Council</header><text>The Council shall consider any review conducted under
			 paragraph (1).</text>
					</paragraph></subsection><subsection id="id3fdea35fb96f42919f2019c0606bbb1e"><enum>(i)</enum><header>Voluntary
			 technical assistance</header><text display-inline="yes-display-inline">At the
			 request of an owner or operator of critical infrastructure, the Council shall
			 provide guidance on the application of cybersecurity practices to the critical
			 infrastructure.</text>
				</subsection></section><section id="id383d5d6fda4c43248cafaa98de9f903c"><enum>104.</enum><header>Voluntary
			 cybersecurity program for critical infrastructure</header>
				<subsection id="ide665b5c025d941a89dc3a9afccc94290"><enum>(a)</enum><header>Voluntary
			 Cybersecurity Program for Critical Infrastructure</header>
					<paragraph id="id68804b71767a4676918b4ed342ea773c"><enum>(1)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Council, in consultation with owners and operators and the Critical
			 Infrastructure Partnership Advisory Council, shall establish the Voluntary
			 Cybersecurity Program for Critical Infrastructure in accordance with this
			 section.</text>
					</paragraph><paragraph id="ided7bbfd4b9b941be8be5977d0bbf07d8"><enum>(2)</enum><header>Eligibility</header>
						<subparagraph id="id846efc907f184ba196b1f3d7bf6d5bbf"><enum>(A)</enum><header>In
			 general</header><text>An owner of critical cyber infrastructure may apply for
			 certification under the Voluntary Cybersecurity Program for Critical
			 Infrastructure.</text>
						</subparagraph><subparagraph id="id4f471e416f344f0d8a5e86aa64197bc7"><enum>(B)</enum><header>Criteria</header><text>The
			 Council shall establish criteria for owners of critical infrastructure that is
			 not critical cyber infrastructure to be eligible to apply for certification in
			 the Voluntary Cybersecurity Program for Critical Infrastructure.</text>
						</subparagraph></paragraph><paragraph id="id4eb0ae074a19409aa43354862a8adf10"><enum>(3)</enum><header>Application for
			 certification</header><text>An owner of critical cyber infrastructure or an
			 owner of critical infrastructure that meets the criteria established under
			 paragraph (2)(B) that applies for certification under this subsection
			 shall—</text>
						<subparagraph id="idb34200ea769d41919f7757cda943d354"><enum>(A)</enum><text>select and
			 implement cybersecurity measures of their choosing that satisfy the
			 outcome-based cybersecurity practices established under section 103; and</text>
						</subparagraph><subparagraph id="idb93050fc81f74295bb39cb99caab1ed3"><enum>(B)</enum><clause commented="no" display-inline="yes-display-inline" id="idFDA588BE1FCD4BF4AA0E76A668490B7A"><enum>(i)</enum><text>certify in writing and
			 under penalty of perjury to the Council that the owner has developed and
			 effectively implemented cybersecurity measures sufficient to satisfy the
			 outcome-based cybersecurity practices established under section 103; or</text>
							</clause><clause id="id09D5CA7777334955989C489E1339F56E" indent="up1"><enum>(ii)</enum><text>submit to the Council an
			 assessment verifying that the owner has developed and effectively implemented
			 cybersecurity measures sufficient to satisfy the outcome-based cybersecurity
			 practices established under section 103.</text>
							</clause></subparagraph></paragraph><paragraph id="id801d1271dd4549d68ed1704c343ef17e"><enum>(4)</enum><header>Certification</header><text>Upon
			 receipt of a self-certification under paragraph (3)(B)(i) or an assessment
			 under paragraph (3)(B)(ii) the Council shall certify an owner.</text>
					</paragraph><paragraph id="idc988ce548a1e43d59ccda8a9ac50ebd0"><enum>(5)</enum><header>Nonperformance</header><text>If
			 the Council determines that a certified owner is not in compliance with the
			 cybersecurity practices established under section 103, the Council
			 shall—</text>
						<subparagraph id="id10b62b0a7ca74716a84c64e1f2cb7a49"><enum>(A)</enum><text>notify the
			 certified owner of such determination; and</text>
						</subparagraph><subparagraph id="id89dcca91c58848fbb0ecd1a867de12b8"><enum>(B)</enum><text>work with the
			 certified owner to remediate promptly any deficiencies.</text>
						</subparagraph></paragraph><paragraph id="id964017be14024a11a7a5320b214a40fb"><enum>(6)</enum><header>Revocation</header><text>If
			 a certified owner fails to remediate promptly any deficiencies identified by
			 the Council, the Council shall revoke the certification of the certified
			 owner.</text>
					</paragraph><paragraph id="ida5968d3bfc5740218bff7e01b69d27f5"><enum>(7)</enum><header>Redress</header>
						<subparagraph id="id9c142d897f2347d4acc8eb1a5e7515e6"><enum>(A)</enum><header>In
			 general</header><text>If the Council revokes a certification under paragraph
			 (6), the Council shall—</text>
							<clause id="ida47af0cce9dd4ef58b44f517442c864b"><enum>(i)</enum><text>notify the owner
			 of such revocation; and</text>
							</clause><clause id="idee27bba3bd324e598a162a08dafcb5b1"><enum>(ii)</enum><text>provide the
			 owner with specific cybersecurity measures that, if implemented, would
			 remediate any deficiencies.</text>
							</clause></subparagraph><subparagraph id="ida8810ce8870c4595b9ba6492c5969efe"><enum>(B)</enum><header>Recertification</header><text>If
			 the Council determines that an owner has remedied any deficiencies and is in
			 compliance with the cybersecurity practices, the Council may recertify the
			 owner.</text>
						</subparagraph></paragraph></subsection><subsection id="id63088d8faca14e51b53c28128102d587"><enum>(b)</enum><header>Assessments</header>
					<paragraph id="id3b8b945a580b40ebaf176f867466f018"><enum>(1)</enum><header>Third-party
			 assessments</header><text>The Council, in consultation with owners and
			 operators and the Critical Infrastructure Protection Advisory Council, shall
			 enter into agreements with qualified third-party private entities, to conduct
			 assessments that use reliable, repeatable, performance-based evaluations and
			 metrics to assess whether an owner certified under subsection (a)(3)(B)(ii) is
			 in compliance with all applicable cybersecurity practices.</text>
					</paragraph><paragraph id="idf33e4cd90b88495e93e7dc897c172aa9"><enum>(2)</enum><header>Training</header><text>The
			 Council shall ensure that third party assessors described in paragraph (1)
			 undergo regular training and accreditation.</text>
					</paragraph><paragraph id="id7e369db246644cca96d5d558bf170062"><enum>(3)</enum><header>Other
			 assessments</header><text>Using the procedures developed under this section,
			 the Council may perform cybersecurity assessments of a certified owner based on
			 actual knowledge or a reasonable suspicion that the certified owner is not in
			 compliance with the cybersecurity practices or any other risk-based factors as
			 identified by the Council.</text>
					</paragraph><paragraph id="idaf608772d944433c81b747b13fc7d08e"><enum>(4)</enum><header>Notification</header><text>The
			 Council shall provide copies of any assessments by the Federal Government to
			 the certified owner.</text>
					</paragraph><paragraph id="id30103c4b7bb642349f6b9fc987d62dc4"><enum>(5)</enum><header>Access to
			 information</header>
						<subparagraph id="idf35d70d9abfd48c19722d0d2cff7c575"><enum>(A)</enum><header>In
			 general</header><text>For the purposes of an assessment conducted under this
			 subsection, a certified owner shall provide the Council, or a third party
			 assessor, any reasonable access necessary to complete an assessment.</text>
						</subparagraph><subparagraph id="id9de2fc589727479ab4ea54e9410e32ac"><enum>(B)</enum><header>Protection of
			 information</header><text>Information provided to the Council, the Council’s
			 designee, or any assessor during the course of an assessment under this section
			 shall be protected from disclosure in accordance with section 106.</text>
						</subparagraph></paragraph></subsection><subsection id="id762e75adbdcb4924b7ef5fcde91e1b1c"><enum>(c)</enum><header>Benefits of
			 certification</header>
					<paragraph id="id374415EF23F0480EA7DDACA57172E5B6"><enum>(1)</enum><header>Limitations on
			 civil liability</header>
						<subparagraph id="idA7C341FE410C48178BE3FF5F47BBA841"><enum>(A)</enum><header>In
			 general</header><text>In any civil action for damages directly caused by an
			 incident related to a cyber risk identified through an assessment conducted
			 under section 102(a), a certified owner shall not be liable for any punitive
			 damages intended to punish or deter if the certified owner is in substantial
			 compliance with the appropriate cybersecurity practices at the time of the
			 incident related to that cyber risk.</text>
						</subparagraph><subparagraph id="idd4428aa24b72446886ff0c66ac58174e"><enum>(B)</enum><header>Limitation</header><text>Subaragraph
			 (A) shall only apply to harm directly caused by the incident related to the
			 cyber risk and shall not apply to damages caused by any additional or
			 intervening acts or omissions by the owner.</text>
						</subparagraph></paragraph><paragraph id="ida111b088a45840e59c64b64d96939da6"><enum>(2)</enum><header>Expedited
			 security clearance process</header><text>The Council, in coordination with the
			 Office of the Director of National Intelligence, shall establish a procedure to
			 expedite the provision of security clearances to appropriate personnel employed
			 by a certified owner.</text>
					</paragraph><paragraph id="id51f22e60486a4d4b91a611d2dd831179"><enum>(3)</enum><header>Prioritized
			 technical assistance</header><text>The Council shall ensure that certified
			 owners are eligible to receive prioritized technical assistance.</text>
					</paragraph><paragraph id="id409ff67716d1454f8a067349fb58e684"><enum>(4)</enum><header>Provision of
			 cyber threat information</header><text>The Council shall develop, in
			 coordination with certified owners, a procedure for ensuring that certified
			 owners are, to the maximum extent practicable and consistent with the
			 protection of sources and methods, informed of relevant real-time cyber threat
			 information.</text>
					</paragraph><paragraph id="idb12b779af14e458eb7a2415a4f1b9071"><enum>(5)</enum><header>Public
			 recognition</header><text display-inline="yes-display-inline">With the approval
			 of a certified owner, the Council may publicly recognize the certified owner if
			 the Council determines such recognition does not pose a risk to the security of
			 critical cyber infrastructure.</text>
					</paragraph><paragraph id="idf4539f2d99f14a11be30bc38402673a6"><enum>(6)</enum><header>Study to
			 examine benefits of procurement preference</header>
						<subparagraph id="id18dc390c59ac429aab9f5ba0185cc05b"><enum>(A)</enum><header>In
			 general</header><text>The Federal Acquisition Regulatory Council, in
			 coordination with the Council and with input from relevant private sector
			 individuals and entities, shall conduct a study examining the potential
			 benefits of establishing a procurement preference for the Federal Government
			 for certified owners.</text>
						</subparagraph><subparagraph id="id0a50a52568c544dca64a56aa59779531"><enum>(B)</enum><header>Areas</header><text>The
			 study under subparagraph (A) shall include a review of—</text>
							<clause id="idfd74962f3f6345b09615e7abaa899176"><enum>(i)</enum><text>potential persons
			 and related property and services that could be eligible for preferential
			 consideration in the procurement process;</text>
							</clause><clause id="id20e50aeb0b8145008eacf2f07f694de1"><enum>(ii)</enum><text>development and
			 management of an approved list of categories of property and services that
			 could be eligible for preferential consideration in the procurement
			 process;</text>
							</clause><clause id="id0e8781537ce14498b7db7c1067d9b1f7"><enum>(iii)</enum><text>appropriate
			 mechanisms to implement preferential consideration in the procurement process,
			 including—</text>
								<subclause id="idEEC853B2842442569B4284EDAEDEE56E"><enum>(I)</enum><text>establishing a
			 policy encouraging Federal agencies to conduct market research and industry
			 outreach to identify property and services that adhere to relevant
			 cybersecurity practices;</text>
								</subclause><subclause id="id622543FEDBE04627B7A6C8F6B1AA0C28"><enum>(II)</enum><text>authorizing the
			 use of a mark for the Voluntary Cybersecurity Program for Critical
			 Infrastructure to be used for marketing property or services to the Federal
			 Government;</text>
								</subclause><subclause id="idAC8919AF7208410395D20EC315C3D2E7"><enum>(III)</enum><text>establishing a
			 policy of encouraging procurement of certain property and services from an
			 approved list;</text>
								</subclause><subclause id="id09AEB338805F42809D2D4DAD2C7B6C92"><enum>(IV)</enum><text>authorizing the
			 use of a preference by Federal agencies in the evaluation process; and</text>
								</subclause><subclause id="idCF2F592311B14A42900FAA77EF43B8FA"><enum>(V)</enum><text>authorizing a
			 requirement in certain solicitations that the person providing the property or
			 services be a certified owner; and</text>
								</subclause></clause><clause id="id2e9dc7bff77745369a0e7e335c1aa54b"><enum>(iv)</enum><text>benefits of and
			 impact on the economy and efficiency of the Federal procurement system, if
			 preferential consideration were given in the procurement process to encourage
			 the procurement of property and services that adhere to relevant baseline
			 performance goals establishing under the Voluntary Cybersecurity Program for
			 Critical Infrastructure.</text>
							</clause></subparagraph></paragraph></subsection></section><section id="idb97389a7d88d41c7a60423fae66f2b80"><enum>105.</enum><header>Rules of
			 construction</header><text display-inline="no-display-inline">Nothing in this
			 title shall be construed to—</text>
				<paragraph id="id7f768cb06bc248b0aa6584ab79c59260"><enum>(1)</enum><text>limit the ability
			 of a Federal agency with responsibilities for regulating the security of
			 critical infrastructure from requiring that the cybersecurity practices
			 developed under section 103 be met;</text>
				</paragraph><paragraph id="id7e0aa8bb45a54214be45101baf374097"><enum>(2)</enum><text>provide
			 additional authority for any sector-specific agency or any Federal agency that
			 is not a sector-specific agency with responsibilities for regulating the
			 security of critical infrastructure to establish standards or other
			 cybersecurity measures that are applicable to the security of critical
			 infrastructure not otherwise authorized by law;</text>
				</paragraph><paragraph id="id717AE822A7D24B72BB2573D9EDD220EC"><enum>(3)</enum><text>limit or restrict
			 the authority of the Department, or any other Federal agency, under any other
			 provision of law; or</text>
				</paragraph><paragraph id="id405aeb7ae49a4907b5addc233d99bf1f"><enum>(4)</enum><text>permit any owner
			 (including a certified owner) to fail to comply with any other law or
			 regulation, unless specifically authorized.</text>
				</paragraph></section><section id="id3e9ed2e17061426088d3d75daf481b2c"><enum>106.</enum><header>Protection of
			 information</header>
				<subsection id="ideac3c24dba2d4e80bcb434cb4bae319e"><enum>(a)</enum><header>Definitions</header><text>In
			 this section—</text>
					<paragraph id="idffbbbb8d0595403eac0b64d734c1c71c"><enum>(1)</enum><text>the term
			 <term>covered information</term> means any information—</text>
						<subparagraph id="id336d8e89a93a46b8b6768a9dd67647c8"><enum>(A)</enum><text>submitted as part
			 of the process established under section 102(a)(3);</text>
						</subparagraph><subparagraph id="id521e732e521d46799c681efa864cbda5"><enum>(B)</enum><text>submitted under
			 section 102(b)(2)(C);</text>
						</subparagraph><subparagraph id="id24612C27D4BF4D6B84FFA4496DCC7E3C"><enum>(C)</enum><text>required to be
			 submitted by owners under section 102(b)(4);</text>
						</subparagraph><subparagraph id="idfd4bdf02eebf40b6b78d2ede12e1d6b3"><enum>(D)</enum><text>provided to the
			 Secretary, the Secretary’s designee, or any assessor during the course of an
			 assessment under section 104; or</text>
						</subparagraph><subparagraph id="idd5cf429f466648f293775dda1a4b2603"><enum>(E)</enum><text>provided to the
			 Secretary or the Inspector General of the Department through the tip line or
			 another secure channel established under subsection (c); and</text>
						</subparagraph></paragraph><paragraph id="ide1783f4d1d194443ad4bd64933a2c630"><enum>(2)</enum><text>the term
			 <term>Inspector General</term> means an Inspector General described in
			 subparagraph (A), (B), or (I) of section 11(b)(1) of the Inspector General Act
			 of 1978 (5 U.S.C. App.), the Inspector General of the United States Postal
			 Service, the Inspector General of the Central Intelligence Agency, and the
			 Inspector General of the Intelligence Community.</text>
					</paragraph></subsection><subsection id="id391616885e554202abf9560881c56f2d"><enum>(b)</enum><header>Critical
			 infrastructure information</header>
					<paragraph id="id6c2b1bdacc1749adbc6effea10355473"><enum>(1)</enum><header>In
			 general</header><text>Covered information shall be treated as voluntarily
			 shared critical infrastructure information under section 214 of the Homeland
			 Security Act of 2002 (6 U.S.C. 133), except that the requirement of such
			 section 214 that the information be voluntarily submitted shall not be required
			 for protection of information under this section to apply.</text>
					</paragraph><paragraph id="id9e49933a2e444d8589606df948c381fd"><enum>(2)</enum><header>Savings clause
			 for existing whistleblower protections</header><text>With respect to covered
			 information, the rights and protections relating to disclosure by individuals
			 of voluntarily shared critical infrastructure information submitted under
			 subtitle B of title II of the Homeland Security Act of 2002 (6 U.S.C. 131 et
			 seq.) shall apply with respect to disclosure of the covered information by
			 individuals.</text>
					</paragraph></subsection><subsection id="idc449c55e1dde435b9636452f6ce4c15a"><enum>(c)</enum><header>Critical
			 infrastructure cyber security tip line</header>
					<paragraph id="id45015a5abb69465a80c8dabc90ececc5"><enum>(1)</enum><header>In
			 general</header><text>The Secretary shall establish and publicize the
			 availability of a Critical Infrastructure Cyber Security Tip Line (and any
			 other secure means the Secretary determines would be desirable to establish),
			 by which individuals may report—</text>
						<subparagraph id="idcb7a7588edd1418d87057812372f2679"><enum>(A)</enum><text>concerns
			 involving the security of covered critical infrastructure against cyber risks;
			 and</text>
						</subparagraph><subparagraph id="idcf467da842b544fbbec72e6491ceba88"><enum>(B)</enum><text>concerns (in
			 addition to any concerns described under subparagraph (A)) with respect to
			 programs and functions authorized or funded under this title involving—</text>
							<clause id="id0cf2d7df2002469195752611ae62c381"><enum>(i)</enum><text>a
			 possible violation of any law, rule, regulation or guideline;</text>
							</clause><clause id="id075cfec0c6624e839648511c4c559f8c"><enum>(ii)</enum><text>mismanagement;</text>
							</clause><clause id="idc660e71221404ca5a2e7f5cf8d893fdb"><enum>(iii)</enum><text>risk to public
			 health, safety, security, or privacy; or</text>
							</clause><clause id="idba8d1135a47648408bd574e8235d599d"><enum>(iv)</enum><text>other
			 misfeasance or nonfeasance.</text>
							</clause></subparagraph></paragraph><paragraph id="id3a604c67516c40dea513dd37feb62159"><enum>(2)</enum><header>Designation of
			 employees</header><text>The Secretary and the Inspector General of the
			 Department shall each designate employees authorized to receive concerns
			 reported under this subsection that include—</text>
						<subparagraph id="idca10c3e4cb9241d3bdf9b1e932713cdb"><enum>(A)</enum><text>disclosure of
			 covered information; or</text>
						</subparagraph><subparagraph id="id161be832703a42f9a5a059e3ecaa35f4"><enum>(B)</enum><text>any other
			 disclosure of information that is specifically prohibited by law or is
			 specifically required by Executive order to be kept secret in the interest of
			 national defense or the conduct of foreign affairs.</text>
						</subparagraph></paragraph><paragraph id="id7823f8155b164a4a81c0c49ea61aac23"><enum>(3)</enum><header>Handling of
			 certain concerns</header><text>A concern described in paragraph (1)(B)—</text>
						<subparagraph id="idfafae0ea190d4f819270758932f216b5"><enum>(A)</enum><text>shall be received
			 initially to the Inspector General of the Department;</text>
						</subparagraph><subparagraph id="id3b5195bd6d1b449b941bd3181fb6e3d3"><enum>(B)</enum><text>shall not be
			 provided initially to the Secretary; and</text>
						</subparagraph><subparagraph id="id026a92dcdd3c489394ecb6e779038930"><enum>(C)</enum><text>may be provided
			 to the Secretary if determined appropriate by the Inspector General of the
			 Department.</text>
						</subparagraph></paragraph></subsection><subsection id="ida1bb6a52d5074d4a9526d8327bcc9e8c"><enum>(d)</enum><header>Rules of
			 construction</header><text>Nothing in this section shall be construed
			 to—</text>
					<paragraph id="id3f9e035cd5964630bd2e922b8819b26a"><enum>(1)</enum><text>limit or
			 otherwise affect the right, ability, duty, or obligation of any entity to use
			 or disclose any information of that entity, including in the conduct of any
			 judicial or other proceeding;</text>
					</paragraph><paragraph id="idd8f8828835bb4859baeb967ede66c132"><enum>(2)</enum><text>prevent the
			 classification of information submitted under this section if that information
			 meets the standards for classification under Executive Order 12958, or any
			 successor thereto, or affect measures and controls relating to the protection
			 of classified information as prescribed by Federal statute or under Executive
			 Order 12958, or any successor thereto;</text>
					</paragraph><paragraph id="id51cef723f8fe465bb2bb2257f9757288"><enum>(3)</enum><text>limit or
			 otherwise affect the ability of an entity, agency, or authority of a State, a
			 local government, or the Federal Government or any other individual or entity
			 under applicable law to obtain information that is not covered information
			 (including any information lawfully and properly disclosed generally or broadly
			 to the public) and to use such information in any manner permitted by law,
			 including the disclosure of such information under—</text>
						<subparagraph id="id6c6a1de7e7f6494798da23bfa774bcfe"><enum>(A)</enum><text>section 552 or
			 2302(b)(8) of title 5, United States Code;</text>
						</subparagraph><subparagraph id="id6ed8f3138f68404f8d7e827a2d5ccfe9"><enum>(B)</enum><text>section 2409 of
			 title 10, United States Code; or</text>
						</subparagraph><subparagraph id="idd57d63b5c38745af8e7ac65635c1e7da"><enum>(C)</enum><text>any other
			 Federal, State, or local law, ordinance, or regulation that protects against
			 retaliation an individual who discloses information that the individual
			 reasonably believes evidences a violation of any law, rule, or regulation,
			 gross mismanagement, substantial and specific danger to public health, safety,
			 or security, or other misfeasance or nonfeasance;</text>
						</subparagraph></paragraph><paragraph id="id3f4b5f69dde34bc1af24b6aa9a910730"><enum>(4)</enum><text>prevent the
			 Secretary from using information required to be submitted under this Act for
			 enforcement of this title, including enforcement proceedings subject to
			 appropriate safeguards;</text>
					</paragraph><paragraph id="id9af42be32f0a4d529552f5b93cae446d"><enum>(5)</enum><text>authorize
			 information to be withheld from any committee of Congress, the Comptroller
			 General, or any Inspector General;</text>
					</paragraph><paragraph id="ida9d8685bf10f4d1e9840451526271eb2"><enum>(6)</enum><text>affect
			 protections afforded to trade secrets under any other provision of law;
			 or</text>
					</paragraph><paragraph id="id04a2f1a4e9234740a02581581dcc7dd3"><enum>(7)</enum><text>create a private
			 right of action for enforcement of any provision of this section.</text>
					</paragraph></subsection><subsection id="idd2394e37dd7a473bbc15a6af0fbb8a22"><enum>(e)</enum><header>Audit</header>
					<paragraph id="ida793c10a2a8f4a3e8311a2f90a08080d"><enum>(1)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Inspector General of the Department shall conduct an audit of the
			 management of covered information under this title and report the findings to
			 appropriate congressional committees.</text>
					</paragraph><paragraph id="ide6da0e0dddba460d9f573dab1725d2bf"><enum>(2)</enum><header>Contents</header><text>The
			 audit under paragraph (1) shall include assessments of—</text>
						<subparagraph id="id7b1eee54efd34d09be7c94ec10b5330b"><enum>(A)</enum><text>whether the
			 covered information is adequately safeguarded against inappropriate
			 disclosure;</text>
						</subparagraph><subparagraph id="id111d318d26244798b1cf99f4d4eaef6f"><enum>(B)</enum><text>the processes for
			 marking and disseminating the covered information and resolving any
			 disputes;</text>
						</subparagraph><subparagraph id="idddcc2b71d8e7447f85d2475b0e608818"><enum>(C)</enum><text>how the covered
			 information is used for the purposes of this title, and whether that use is
			 effective;</text>
						</subparagraph><subparagraph id="id14fdf12d37d14a16806c05c740b4819f"><enum>(D)</enum><text>whether sharing
			 of covered information has been effective to fulfill the purposes of this
			 title;</text>
						</subparagraph><subparagraph id="ide05fe78e885049e59cb2d564549dfe4a"><enum>(E)</enum><text>whether the kinds
			 of covered information submitted have been appropriate and useful, or overbroad
			 or overnarrow;</text>
						</subparagraph><subparagraph id="id256b2fb58b37463ebf0a69cb98538123"><enum>(F)</enum><text>whether the
			 protections of covered information allow for adequate accountability and
			 transparency of the regulatory, enforcement, and other aspects of implementing
			 this title; and</text>
						</subparagraph><subparagraph id="id3d0bb3223f474fa0851cfa46576e8225"><enum>(G)</enum><text>any other factors
			 at the discretion of the Inspector General of the Department.</text>
						</subparagraph></paragraph></subsection></section><section id="idebfbf182a5f846cb9cd975ec64f0ec6c"><enum>107.</enum><header>Annual
			 assessment of cybersecurity</header>
				<subsection id="id7fe074d3440f4169aed430a8a7e14d6c"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, and every year thereafter, the Council shall submit to the appropriate
			 congressional committees a report on the effectiveness of this title in
			 reducing the risk of cyber attack to critical infrastructure.</text>
				</subsection><subsection id="id6b188780b4a649478f0d214fefb43006"><enum>(b)</enum><header>Contents</header><text>Each
			 report submitted under subsection (a) shall include—</text>
					<paragraph id="id8d5c739c0299412cac471ccc9aa18f3a"><enum>(1)</enum><text>a discussion of
			 cyber risks and associated consequences and whether the cybersecurity practices
			 developed under section 103 are sufficient to effectively remediate and
			 mitigate cyber risks and associated consequences; and</text>
					</paragraph><paragraph id="id4670610D7FE3447BB74DCFB796692CF9"><enum>(2)</enum><text>an analysis
			 of—</text>
						<subparagraph id="idd738d9b6972f460aac6ca6d4e111ccf4"><enum>(A)</enum><text>whether owners of
			 critical cyber infrastructure are successfully implementing the cybersecurity
			 practices adopted under section 103;</text>
						</subparagraph><subparagraph id="ida55344d2d9a540348f1292abc7a486e6"><enum>(B)</enum><text>whether the
			 critical infrastructure of the United States is effectively secured from
			 cybersecurity threats, vulnerabilities, and consequences;</text>
						</subparagraph><subparagraph id="id83500B59012E4D4AB619BDA5439BA7C1"><enum>(C)</enum><text>whether Federal
			 agencies with responsibilities for regulating the security of critical
			 infrastructure are adequately adopting and enforcing the cybersecurity
			 practices adopted under section 103; and</text>
						</subparagraph><subparagraph id="ida890320beb14408580b2f9fc6c146709"><enum>(D)</enum><text>whether
			 additional legislative authority or other actions are needed to effectively
			 remediate or mitigate cyber risks and associated consequences.</text>
						</subparagraph></paragraph></subsection><subsection id="id9d33922d6e46466f9048f7a77da832da"><enum>(c)</enum><header>Form of
			 report</header><text>A report submitted under this subsection shall be
			 submitted in an unclassified form, but may include a classified annex, if
			 necessary.</text>
				</subsection></section><section id="ide9dcf21c9db24e888bb08678cadd7c85"><enum>108.</enum><header>International
			 cooperation</header>
				<subsection id="id9779de6d40d942fbbde93ea52f3c13f7"><enum>(a)</enum><header>In
			 general</header><text>The Secretary, in coordination with the Secretary of
			 State, the heads of appropriate sector-specific agencies, and the heads of any
			 appropriate Federal agency with responsibilities for regulating the security of
			 covered critical infrastructure, shall—</text>
					<paragraph id="ide8762b4e5cc349daafafb7f9bf0cb9f6"><enum>(1)</enum><text>consistent with
			 the protection of intelligence sources and methods and other sensitive matters,
			 inform the owner or operator of information infrastructure located outside the
			 United States the disruption of which could result in national or regional
			 catastrophic damage within the United States and the government of the country
			 in which the information infrastructure is located of any cyber risks to such
			 information infrastructure; and</text>
					</paragraph><paragraph id="id331413c6ca8c464594e2e572895f958a"><enum>(2)</enum><text>coordinate with
			 the government of the country in which such information infrastructure is
			 located and, as appropriate, the owner or operator of the information
			 infrastructure regarding the implementation of cybersecurity measures or other
			 measures to the information infrastructure to mitigate or remediate cyber
			 risks.</text>
					</paragraph></subsection><subsection id="ideedee38d945f47b2822f226981937a91"><enum>(b)</enum><header>International
			 agreements</header><text>The Secretary, in coordination with the Secretary of
			 State, including in particular with the interpretation of international
			 agreements, shall perform the functions prescribed by this section consistent
			 with applicable international agreements.</text>
				</subsection></section><section id="id3ed75fabd1864918b62228b02085df4c"><enum>109.</enum><header>Effect on
			 other laws</header><text display-inline="no-display-inline">Except as expressly
			 provided in section 104(c)(1) and section 106, nothing in this Act shall be
			 construed to preempt the applicability of any State law or requirement.</text>
			</section><section id="id4AAA4A7447004490A97E0744DC35CC74"><enum>110.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="id5A48B30FE7D74B69858ABBE80CC3BD8A"><enum>(1)</enum><header>Certified
			 owner</header><text>The term <term>certified owner</term> means an owner of
			 critical cyber infrastructure or an owner of critical infrastructure that is
			 certified by the Council under section 104(a)(4).</text>
				</paragraph><paragraph id="id9408D64FF6ED47BCA9D546A6401633B0"><enum>(2)</enum><header>Cyber
			 risk</header><text>The term <term>cyber risk</term> means any risk to
			 information infrastructure, including physical or personnel risks and security
			 vulnerabilities, that, if exploited or not mitigated, could pose a significant
			 risk of disruption to the operation of information infrastructure essential to
			 the reliable operation of critical infrastructure.</text>
				</paragraph><paragraph id="id2BDB3694A6974C1BABEB5A7E48308C1D"><enum>(3)</enum><header>Sector
			 coordinating council</header><text>The term <term>sector coordinating
			 council</term> means a private sector coordinating council comprised of
			 representatives of owners and operators within a particular sector of critical
			 infrastructure established by the National Infrastructure Protection
			 Plan.</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id0CB57C4A25AD4F44AAB3A920FC535F0D"><enum>(4)</enum><header>Sector-specific
			 agency</header><text>The term <term>sector-specific agency</term> means the
			 relevant Federal agency responsible for infrastructure protection activities in
			 a designated critical infrastructure sector or key resources category under the
			 National Infrastructure Protection Plan, or any other appropriate Federal
			 agency identified by the President after the date of enactment of this
			 Act.</text>
				</paragraph></section></title><title id="id47ADCFA182B442FC8158764795081EE7"><enum>II</enum><header>Federal
			 information security management and consolidating resources</header>
			<section id="idB8E6DBD0445A4F699A897BBEFB635C0E"><enum>201.</enum><header>FISMA
			 Reform</header>
				<subsection id="ID057dad156e784e99a57c8e1ecfc75ec2"><enum>(a)</enum><header>In
			 general</header><text>Chapter 35 of title 44, United States Code, is amended by
			 striking subchapters II and III and inserting the following:</text>
					<quoted-block display-inline="no-display-inline" id="id25ADF0647BDD4E58AE1ADCFE9B52BF48" style="USC">
						<subchapter id="id860D576E970C4A0A84DF9DADD66F6212"><enum>II</enum><header>Information
				security</header>
							<section id="id3BB7B7410F744A88987C767B601D23F2" section-type="subsequent-section"><enum>3551.</enum><header>Purposes</header><text display-inline="no-display-inline">The purposes of this subchapter are
				to—</text>
								<paragraph id="IDee295761b02a4efdbc4674a033746243"><enum>(1)</enum><text>provide a
				comprehensive framework for ensuring the effectiveness of information security
				controls over information resources that support Federal operations and
				assets;</text>
								</paragraph><paragraph id="ID93d168822698441f9e1517004b173b8a"><enum>(2)</enum><text>recognize the
				highly networked nature of the Federal computing environment and provide
				effective governmentwide management of policies, directives, standards, and
				guidelines, as well as effective and nimble oversight of and response to
				information security risks, including coordination of information security
				efforts throughout the Federal civilian, national security, and law enforcement
				communities;</text>
								</paragraph><paragraph id="IDa0cfb52eff9d4e0f9987fe21f9640f7b"><enum>(3)</enum><text>provide for
				development and maintenance of controls required to protect agency information
				and information systems and contribute to the overall improvement of agency
				information security posture; and</text>
								</paragraph><paragraph id="ID0963cd2d21764caf84d9d86c912d9f6c"><enum>(4)</enum><text>provide a
				mechanism to improve and continuously monitor the security of agency
				information security programs and systems through a focus on continuous
				monitoring of agency information systems and streamlined reporting requirements
				rather than overly prescriptive manual reporting.</text>
								</paragraph></section><section id="ID18c656f7bdd64b6fbe88a4bff412793d"><enum>3552.</enum><header>Definitions</header>
								<subsection id="ID88f7f7e8f0504a9cab0e6335954533f0"><enum>(a)</enum><header>In
				general</header><text>Except as provided under subsection (b), the definitions
				under section 3502 (including the definitions of the terms <term>agency</term>
				and <term>information system</term>) shall apply to this subchapter.</text>
								</subsection><subsection id="IDc423ac5a99fc4ef2876acddd424fca33"><enum>(b)</enum><header>Other
				terms</header><text>In this subchapter:</text>
									<paragraph id="ID05cc6ffd52214284b6bcf36d6d533223"><enum>(1)</enum><header>Adequate
				security</header><text>The term <term>adequate security</term> means security
				commensurate with the risk and impact resulting from the unauthorized access to
				or loss, misuse, destruction, or modification of information.</text>
									</paragraph><paragraph id="IDb8f49f61899247659b05d7ca955c1b50"><enum>(2)</enum><header>Continuous
				monitoring</header><text>The term <term>continuous monitoring</term> means the
				ongoing real time or near real-time process used to determine if the complete
				set of planned, required, and deployed security controls within an information
				system continue to be effective over time in light of rapidly changing
				information technology and threat development. To the maximum extent possible,
				this also requires automation of that process to enable cost effective,
				efficient, and consistent monitoring and provide a more dynamic view of the
				security state of those deployed controls.</text>
									</paragraph><paragraph id="idA17C42E6528C46F1AC9E246B68AAE709"><enum>(3)</enum><header>Countermeasure</header><text>The
				term <term>countermeasure</term> means automated or manual actions with
				defensive intent to modify or block data packets associated with electronic or
				wire communications, Internet traffic, program code, or other system traffic
				transiting to or from or stored on an information system for the purpose of
				protecting the information system from cybersecurity threats, conducted on an
				information system owned or operated by or on behalf of the party to be
				protected or operated by a private entity acting as a provider of electronic
				communication services, remote computing services, or cybersecurity services to
				the party to be protected.</text>
									</paragraph><paragraph id="ID62f1b9678f9a486ab45e5eb214f2ba5c"><enum>(4)</enum><header>Incident</header><text>The
				term <term>incident</term> means an occurrence that—</text>
										<subparagraph id="ID92c42dcd28c740cfa8d5c2c176d3ec90"><enum>(A)</enum><text>actually or
				imminently jeopardizes, without lawful authority, the integrity,
				confidentiality, or availability of information or an information system;
				or</text>
										</subparagraph><subparagraph id="ID4c3a2d969c034d98b50a1bd498c6e0f4"><enum>(B)</enum><text>constitutes a
				violation or imminent threat of violation of law, security policies, security
				procedures, or acceptable use policies.</text>
										</subparagraph></paragraph><paragraph id="ID9031e804b63b4b2189b6e32123b2cb75"><enum>(5)</enum><header>Information
				security</header><text>The term <term>information security</term> means
				protecting information and information systems from unauthorized access, use,
				disclosure, disruption, modification, or destruction in order to
				provide—</text>
										<subparagraph id="IDcc1b69bbd8564c32bc5a4f4eafd4ffd6"><enum>(A)</enum><text>integrity, which
				means guarding against improper information modification or destruction, and
				includes ensuring nonrepudiation and authenticity;</text>
										</subparagraph><subparagraph id="ID5d2e839fbed54076911cb425b06b1533"><enum>(B)</enum><text>confidentiality,
				which means preserving authorized restrictions on access and disclosure,
				including means for protecting personal privacy and proprietary information;
				and</text>
										</subparagraph><subparagraph id="IDbd27982da0e24b0f98db0c37cbffe161"><enum>(C)</enum><text>availability,
				which means ensuring timely and reliable access to and use of
				information.</text>
										</subparagraph></paragraph><paragraph id="ID5dfa5581d3504a20a287d916cb4882bb"><enum>(6)</enum><header>Information
				technology</header><text>The term <term>information technology</term> has the
				meaning given that term in section 11101 of title 40.</text>
									</paragraph><paragraph id="IDc549876fda874a47bea1abd15a77a285"><enum>(7)</enum><header>National
				security system</header>
										<subparagraph id="IDa8bae2f833d149ea977f9f8b115b6fdb"><enum>(A)</enum><header>In
				general</header><text>The term <term>national security system</term> means any
				information system (including any telecommunications system) used or operated
				by an agency or by a contractor of an agency, or other organization on behalf
				of an agency—</text>
											<clause id="ID5779f2bfad8941dea6c7acacdd617c75"><enum>(i)</enum><text>the function,
				operation, or use of which—</text>
												<subclause id="ID0a48c95f4b76453abe0d8257ac89dd02"><enum>(I)</enum><text>involves
				intelligence activities;</text>
												</subclause><subclause id="ID5b70b6b2884b4358a79f5a676b8f4775"><enum>(II)</enum><text>involves
				cryptologic activities related to national security;</text>
												</subclause><subclause id="ID937257a11c354f99ae2c71f2bc4fd3f2"><enum>(III)</enum><text>involves
				command and control of military forces;</text>
												</subclause><subclause id="ID54a2a8b5549141deaad9d03c0d681f19"><enum>(IV)</enum><text>involves
				equipment that is an integral part of a weapon or weapons system; or</text>
												</subclause><subclause id="IDc07cc2c4ce134d8bbe054bed55861536"><enum>(V)</enum><text>subject to
				subparagraph (B), is critical to the direct fulfillment of military or
				intelligence missions; or</text>
												</subclause></clause><clause id="IDcd08ea3fe7a740ffa7021e81e523dc81"><enum>(ii)</enum><text>that is
				protected at all times by procedures established for information that have been
				specifically authorized under criteria established by an Executive order or an
				Act of Congress to be kept classified in the interest of national defense or
				foreign policy.</text>
											</clause></subparagraph><subparagraph id="ID63178e4ff73145c092b0872f7cca482d"><enum>(B)</enum><header>Exclusion</header><text>Subparagraph
				(A)(i)(V) does not include a system that is to be used for routine
				administrative and business applications (including payroll, finance,
				logistics, and personnel management applications).</text>
										</subparagraph></paragraph><paragraph id="ID8c3a74e57e65450cb69bb9d103438177"><enum>(8)</enum><header>Secretary</header><text>The
				term <term>Secretary</term> means the Secretary of Homeland Security.</text>
									</paragraph></subsection></section><section id="ID7c9ab5fec0964a36b57f51932d5ca0ad"><enum>3553.</enum><header>Federal
				information security authority and coordination</header>
								<subsection id="IDf3da1efd7258457db0418e7c85154b3a"><enum>(a)</enum><header>In
				general</header><text>Except as provided in subsections (f) and (g), the
				Secretary shall oversee agency information security policies and practices,
				including the development and oversight of information security policies and
				directives and compliance with this subchapter.</text>
								</subsection><subsection id="ID2ef9a80dda6844adaa74f7fc2410e261"><enum>(b)</enum><header>Duties</header><text>The
				Secretary shall—</text>
									<paragraph id="ID12d1f46967254dae91b879fefc8d6913"><enum>(1)</enum><text>develop, issue,
				and oversee the implementation of information security policies and directives,
				which shall be compulsory and binding on agencies to the extent determined
				appropriate by the Secretary, including—</text>
										<subparagraph id="IDf9785587179346afaab36ddec05e0f0d"><enum>(A)</enum><text>policies and
				directives consistent with the standards promulgated under section 11331 of
				title 40 to identify and provide information security protections that are
				commensurate with the risk and impact resulting from the unauthorized access,
				use, disclosure, disruption, modification, or destruction of—</text>
											<clause id="ID1d13358bd31f40c29f7b0c5e13b78d5e"><enum>(i)</enum><text>information
				collected, created, processed, stored, disseminated, or otherwise used or
				maintained by or on behalf of an agency; or</text>
											</clause><clause id="IDb7b32e290ab64be1b5ad0bb1865b2800"><enum>(ii)</enum><text>information
				systems used or operated by an agency or by a contractor of an agency or other
				organization, such as a State government entity, on behalf of an agency;</text>
											</clause></subparagraph><subparagraph id="ID32a9ba6ea6bd47fcadf327491dcb48a0"><enum>(B)</enum><text>minimum
				operational requirements for network operations centers and security operations
				centers of agencies to facilitate the protection of and provide common
				situational awareness for all agency information and information
				systems;</text>
										</subparagraph><subparagraph id="IDb7e3d5f4e2224b018cce868233477419"><enum>(C)</enum><text>reporting
				requirements, consistent with relevant law, regarding information security
				incidents;</text>
										</subparagraph><subparagraph id="IDc42af3e08cb5435d98cc31b7d8fede98"><enum>(D)</enum><text>requirements for
				agencywide information security programs, including continuous monitoring of
				information security;</text>
										</subparagraph><subparagraph id="IDfec32ec2e8e348ff8b154bec37e41dee"><enum>(E)</enum><text>performance
				requirements and metrics for the security of agency information systems;</text>
										</subparagraph><subparagraph id="IDe6f45b1e4ab14b618c2658fc879fc26d"><enum>(F)</enum><text>training
				requirements to ensure that agencies are able to fully and timely comply with
				directions issued by the Secretary under this subchapter;</text>
										</subparagraph><subparagraph id="ID4360d5311c25436b8b7fa6c1048bbf47"><enum>(G)</enum><text>training
				requirements regarding privacy, civil rights, civil liberties, and information
				oversight for agency information security employees;</text>
										</subparagraph><subparagraph id="ID0b5ede98cb4b434c84e2bfab31b63a23"><enum>(H)</enum><text>requirements for
				the annual reports to the Secretary under section 3554(c); and</text>
										</subparagraph><subparagraph id="ID4d678b60157b4313bb84544666ec289a"><enum>(I)</enum><text>any other
				information security requirements as determined by the Secretary;</text>
										</subparagraph></paragraph><paragraph id="ID0a9414ed78c74416b3fce2c772397833"><enum>(2)</enum><text>review agency
				information security programs required to be developed under section
				3554(b);</text>
									</paragraph><paragraph id="IDced0418db73f4b91a4c695cbf260bca5"><enum>(3)</enum><text>develop and
				conduct targeted risk assessments and operational evaluations for agency
				information and information systems in consultation with the heads of other
				agencies or governmental and private entities that own and operate such
				systems, that may include threat, vulnerability, and impact assessments and
				penetration testing;</text>
									</paragraph><paragraph id="IDf6e3da367a9c4b24b1b5e3adc56b02d1"><enum>(4)</enum><text>operate
				consolidated intrusion detection, prevention, or other protective capabilities
				and use associated countermeasures for the purpose of protecting agency
				information and information systems from information security threats;</text>
									</paragraph><paragraph id="ID6b684c6d4c02479fa435972c88e47101"><enum>(5)</enum><text>in conjunction
				with other agencies and the private sector, assess and foster the development
				of information security technologies and capabilities for use across multiple
				agencies;</text>
									</paragraph><paragraph id="ID7b12817b25904ae5a247467a50332e15"><enum>(6)</enum><text>designate an
				entity to receive reports and information about information security incidents,
				threats, and vulnerabilities affecting agency information systems;</text>
									</paragraph><paragraph id="IDaae099bc83f24d43a4b7e70392531ce2"><enum>(7)</enum><text>provide incident
				detection, analysis, mitigation, and response information and remote or on-site
				technical assistance to the heads of agencies;</text>
									</paragraph><paragraph id="IDa754222effb548e7922e2cb18b934445"><enum>(8)</enum><text>coordinate with
				appropriate agencies and officials to ensure, to the maximum extent feasible,
				that policies and directives issued under paragraph (1) are complementary
				with—</text>
										<subparagraph id="IDdebb2c0c2a484bccb1b84e6b593bbd60"><enum>(A)</enum><text>standards and
				guidelines developed for national security systems; and</text>
										</subparagraph><subparagraph id="ID219da843aa9c427da1d6d6f0a7599250"><enum>(B)</enum><text>policies and
				directives issues by the Secretary of Defense, Director of the Central
				Intelligence Agency, and Director of National Intelligence under subsection
				(g)(1); and</text>
										</subparagraph></paragraph><paragraph id="idB7740F18BA554134828AD7F419E4755D"><enum>(9)</enum><text>not later than
				March 1 of each year, submit to Congress a report on agency compliance with the
				requirements of this subchapter, which shall include—</text>
										<subparagraph id="idC9CF5FD55370455B8B758889A96125E6"><enum>(A)</enum><text>a summary of the
				incidents described by the reports required in section 3554(c);</text>
										</subparagraph><subparagraph id="id994a290e2b404fd091ae963bb2d0d5f8"><enum>(B)</enum><text>a summary of the
				results of assessments required by section 3555;</text>
										</subparagraph><subparagraph id="id53e2f7b882ad4be7b1e504d8a40a835e"><enum>(C)</enum><text>a summary of the
				results of evaluations required by section 3556;</text>
										</subparagraph><subparagraph id="id47b44f60fb134564bba10b4f4784424d"><enum>(D)</enum><text>significant
				deficiencies in agency information security practices as identified in the
				reports, assessments, and evaluations referred to in subparagraphs (A), (B),
				and (C), or otherwise; and</text>
										</subparagraph><subparagraph id="id0d7f30c1fb574200bbf03a1eaaa2cd6e"><enum>(E)</enum><text>planned remedial
				action to address any deficiencies identified under subparagraph (D).</text>
										</subparagraph></paragraph></subsection><subsection id="ID57e7375c7a1e4f8b857b835ccebd87ee"><enum>(c)</enum><header>Issuing
				policies and directives</header><text>When issuing policies and directives
				under subsection (b), the Secretary shall consider any applicable standards or
				guidelines developed by the National Institute of Standards and Technology and
				issued by the Secretary of Commerce under section 11331 of title 40. The
				Secretary shall consult with the Director of the National Institute of
				Standards and Technology when such policies and directives implement standards
				or guidelines developed by National Institute of Standards and Technology. To
				the maximum extent feasible, such standards and guidelines shall be
				complementary with standards and guidelines developed for national security
				systems.</text>
								</subsection><subsection id="IDcf6dd4cfe8b2462f8cd7a964907c4348"><enum>(d)</enum><header>Communications
				and system traffic</header>
									<paragraph id="idF81FF41D59B046C5B02D93F53A49449D"><enum>(1)</enum><header>In
				general</header><text>Notwithstanding any other provision of law, in carrying
				out the responsibilities under paragraphs (3) and (4) of subsection (b), if the
				Secretary makes a certification described in paragraph (2), the Secretary may
				acquire, intercept, retain, use, and disclose communications and other system
				traffic that are transiting to or from or stored on agency information systems
				and deploy countermeasures with regard to the communications and system
				traffic.</text>
									</paragraph><paragraph id="idBC95CF3A3CF54808A9AA979FF078E3E6"><enum>(2)</enum><header>Certification</header><text>A
				certification described in this paragraph is a certification by the Secretary
				that—</text>
										<subparagraph id="ID18fc37f5ffe84022a57a573bb41fbe43"><enum>(A)</enum><text>the acquisitions,
				interceptions, and countermeasures are reasonably necessary for the purpose of
				protecting agency information systems from information security threats;</text>
										</subparagraph><subparagraph id="ID0de5325f4d6049a28b788581b33f84ba"><enum>(B)</enum><text>the content of
				communications will be collected and retained only when the communication is
				associated with a known or reasonably suspected information security threat,
				and communications and system traffic will not be subject to the operation of a
				countermeasure unless associated with the threats;</text>
										</subparagraph><subparagraph id="ID14991767086242d48aeccdfa83393735"><enum>(C)</enum><text>information
				obtained under activities authorized under this subsection will only be
				retained, used, or disclosed to protect agency information systems from
				information security threats, mitigate against such threats, or, with the
				approval of the Attorney General, for law enforcement purposes when—</text>
											<clause id="id887165120AE54B00842013BD70CA401C"><enum>(i)</enum><text>the information
				is evidence of a crime that has been, is being, or is about to be committed;
				and</text>
											</clause><clause id="id0F6159925AC549E79A834E4373B4A363"><enum>(ii)</enum><text>disclosure of
				the information to a law enforcement agency is not otherwise prohibited by
				law;</text>
											</clause></subparagraph><subparagraph id="ID4f0d6f00004941ad8b05669a68bc12d1"><enum>(D)</enum><text>notice has been
				provided to users of agency information systems concerning the potential for
				acquisition, interception, retention, use, and disclosure of communications and
				other system traffic; and</text>
										</subparagraph><subparagraph id="IDe2312313703543f69f4e43eada174a8a"><enum>(E)</enum><text>the activities
				are implemented pursuant to policies and procedures governing the acquisition,
				interception, retention, use, and disclosure of communications and other system
				traffic that have been reviewed and approved by the Attorney General.</text>
										</subparagraph></paragraph><paragraph id="IDed1542418db44c638c9675e9889a6149"><enum>(3)</enum><header>Private
				entities</header><text>The Secretary may enter into contracts or other
				agreements, or otherwise request and obtain the assistance of, private entities
				that provide electronic communication or information security services to
				acquire, intercept, retain, use, and disclose communications and other system
				traffic or to deploy countermeasures in accordance with this subsection.</text>
									</paragraph></subsection><subsection id="ID39d05502e08b45999d9c0d7f3f2e3782"><enum>(e)</enum><header>Directions to
				agencies</header>
									<paragraph id="ID99d78c93450a4006b36aa2658195a0c9"><enum>(1)</enum><header>Authority</header>
										<subparagraph id="ID36268b048d8a44e6942694309565a231"><enum>(A)</enum><header>In
				general</header><text>Notwithstanding section 3554, and subject to subparagraph
				(B), in response to a known or reasonably suspected information security
				threat, vulnerability, or incident that represents a substantial threat to the
				information security of an agency, the Secretary may direct other agency heads
				to take any lawful action with respect to the operation of the information
				systems, including those owned or operated by another entity on behalf of an
				agency, that collect, process, store, transmit, disseminate, or otherwise
				maintain agency information, for the purpose of protecting the information
				system from or mitigating an information security threat.</text>
										</subparagraph><subparagraph id="ID8d4fb32fb993405d9e998465434a3611"><enum>(B)</enum><header>Exception</header><text>The
				authorities of the Secretary under this subsection shall not apply to a system
				described in paragraph (2), (3), or (4) of subsection (g).</text>
										</subparagraph></paragraph><paragraph id="IDb48310a527ee4318b1b43e2f79026ad8"><enum>(2)</enum><header>Procedures for
				use of authority</header><text>The Secretary shall—</text>
										<subparagraph id="ID47b79b0919c34c4395e249aed2c066f9"><enum>(A)</enum><text>in coordination
				with the Director of the Office of Management and Budget and, as appropriate,
				in consultation with operators of information systems, establish procedures
				governing the circumstances under which a directive may be issued under this
				subsection, which shall include—</text>
											<clause id="IDf277cc079c7e4d90a3d3c5cee28b8d1e"><enum>(i)</enum><text>thresholds and
				other criteria;</text>
											</clause><clause id="ID6ab5233d2b044508a2f1b54eceda3e2d"><enum>(ii)</enum><text>privacy and
				civil liberties protections; and</text>
											</clause><clause id="IDb74e0d79c23a4b729f6cd42667fffd7b"><enum>(iii)</enum><text>providing
				notice to potentially affected third parties;</text>
											</clause></subparagraph><subparagraph id="ID242f5f63952245c6b5ae283fc8535127"><enum>(B)</enum><text>specify the
				reasons for the required action and the duration of the directive;</text>
										</subparagraph><subparagraph id="IDe98330aeda004c1f978d3819c7f01c56"><enum>(C)</enum><text>minimize the
				impact of directives under this subsection by—</text>
											<clause id="ID57004b6cc4f94afdb4ecb33f863d8de6"><enum>(i)</enum><text>adopting the
				least intrusive means possible under the circumstances to secure the agency
				information systems; and</text>
											</clause><clause id="ID2aae11bf07fd4065830fd04fd86135c1"><enum>(ii)</enum><text>limiting
				directives to the shortest period practicable; and</text>
											</clause></subparagraph><subparagraph id="ID119584030304419c8ebc1f3a95bff4bc"><enum>(D)</enum><text>notify the
				Director of the Office of Management and Budget and head of any affected agency
				immediately upon the issuance of a directive under this subsection.</text>
										</subparagraph></paragraph><paragraph id="ID1f484ac5230c4b98b86e06d25d88ab7a"><enum>(3)</enum><header>Imminent
				threats</header>
										<subparagraph id="ID496ce35b077d469f94bc80b1c8af04fb"><enum>(A)</enum><header>In
				general</header><text>If the Secretary determines that there is an imminent
				threat to agency information systems and a directive under this subsection is
				not reasonably likely to result in a timely response to the threat, the
				Secretary may authorize the use of protective capabilities under the control of
				the Secretary for communications or other system traffic transiting to or from
				or stored on an agency information system without prior consultation with the
				affected agency for the purpose of ensuring the security of the information or
				information system or other agency information systems.</text>
										</subparagraph><subparagraph id="ID0d6164534d8448468315f07aa2f20b25"><enum>(B)</enum><header>Limitation on
				delegation</header><text>The authority under this paragraph may not be
				delegated to an official in a position lower than Assistant Secretary or
				Director of the National Cybersecurity and Communications Integration
				Center.</text>
										</subparagraph><subparagraph id="ID75674c5b92884e3d9dbd65fbafe9d873"><enum>(C)</enum><header>Notice</header><text>The
				Secretary or designee of the Secretary shall immediately notify the Director of
				the Office of Management and Budget and the head and chief information officer
				(or equivalent official) of each affected agency of—</text>
											<clause id="IDeaa6e01712aa46339fbf82a9886d7f16"><enum>(i)</enum><text>any action taken
				under this subsection; and</text>
											</clause><clause id="ID1365da46007f48f5a80bb83d6c8928b5"><enum>(ii)</enum><text>the reasons for
				and duration and nature of the action.</text>
											</clause></subparagraph><subparagraph commented="no" id="ID59cc761410034b94ab2d7d17ab40d387"><enum>(D)</enum><header>Other
				law</header><text>The actions of the Secretary under this paragraph shall be
				consistent with applicable law.</text>
										</subparagraph></paragraph><paragraph id="ID44bfc234c55a4923b994bacb9a42b645"><enum>(4)</enum><header>Limitation</header><text>The
				Secretary may direct or authorize lawful action or protective capability under
				this subsection only to—</text>
										<subparagraph id="IDd9143cf0116d490684003d70336bae1c"><enum>(A)</enum><text>protect agency
				information from unauthorized access, use, disclosure, disruption,
				modification, or destruction; or</text>
										</subparagraph><subparagraph id="IDaf3dbfc8e02443efb81d4788d837de60"><enum>(B)</enum><text>require the
				remediation of or protect against identified information security risks with
				respect to—</text>
											<clause id="ID64bc002fc90d4256963bef3fada9872c"><enum>(i)</enum><text>information
				collected or maintained by or on behalf of an agency; or</text>
											</clause><clause id="ID767d5438775d4e2e80997fadc6db34e0"><enum>(ii)</enum><text>that portion of
				an information system used or operated by an agency or by a contractor of an
				agency or other organization on behalf of an agency.</text>
											</clause></subparagraph></paragraph></subsection><subsection id="idB03EB83C9C9E4516A79A71D27F4E2E50"><enum>(f)</enum><header>National
				security systems</header>
									<paragraph id="ID7329df9d8756497db6116285caf5a642"><enum>(1)</enum><header>In
				general</header><text>This section shall not apply to a national security
				system.</text>
									</paragraph><paragraph id="IDbe31297dc89f48dabcca2ef0d786d236"><enum>(2)</enum><header>Information
				security</header><text>Information security policies, directives, standards,
				and guidelines for national security systems shall be overseen as directed by
				the President and, in accordance with that direction, carried out under the
				authority of the heads of agencies that operate or exercise authority over
				national security systems.</text>
									</paragraph></subsection><subsection id="ID9a2f6725a2294aa78c847f38f07f4c1f"><enum>(g)</enum><header>Delegation of
				authorities</header>
									<paragraph id="ID6091272a014d4f79b2f0312d2cd7f203"><enum>(1)</enum><header>In
				general</header><text>The authorities of the Secretary described in paragraphs
				(1), (2), (3), and (4) of subsection (b) shall be delegated to—</text>
										<subparagraph id="ID515cdca2b4774ec4ae01833d290e22e7"><enum>(A)</enum><text>the Secretary of
				Defense in the case of systems described in paragraph (2);</text>
										</subparagraph><subparagraph id="ID51d928594d134cb08a10023a5129134e"><enum>(B)</enum><text>the Director of
				the Central Intelligence Agency in the case of systems described in paragraph
				(3); and</text>
										</subparagraph><subparagraph id="ID9e561a06c7b845328056375af535637f"><enum>(C)</enum><text>the Director of
				National Intelligence in the case of systems described in paragraph (4).</text>
										</subparagraph></paragraph><paragraph id="IDf9ded07580954447b7e8cfa56bf87a99"><enum>(2)</enum><header>Department of
				defense</header><text>The systems described in this paragraph are systems that
				are operated by the Department of Defense, a contractor of the Department of
				Defense, or another entity on behalf of the Department of Defense that process
				any information the unauthorized access, use, disclosure, disruption,
				modification, or destruction of which would have a debilitating impact on the
				mission of the Department of Defense.</text>
									</paragraph><paragraph id="ID8e9d6124903f43448c7cfcf79558ab31"><enum>(3)</enum><header>Central
				intelligence agency</header><text>The systems described in this paragraph are
				systems that are operated by the Central Intelligence Agency, a contractor of
				the Central Intelligence Agency, or another entity on behalf of the Central
				Intelligence Agency that process any information the unauthorized access, use,
				disclosure, disruption, modification, or destruction of which would have a
				debilitating impact on the mission of the Central Intelligence Agency.</text>
									</paragraph><paragraph id="ID79f5cf53c4d547078473ee664a33f885"><enum>(4)</enum><header>Office of the
				director of national intelligence</header><text>The systems described in this
				paragraph are systems that are operated by the Office of the Director of
				National Intelligence, a contractor of the Office of the Director of National
				Intelligence, or another entity on behalf of the Office of the Director of
				National Intelligence that process any information the unauthorized access,
				use, disclosure, disruption, modification, or destruction of which would have a
				debilitating impact on the mission of the Office of the Director of National
				Intelligence.</text>
									</paragraph><paragraph id="ID3bf1dee9411f472f89b8e70f5b42fcfd"><enum>(5)</enum><header>Integration of
				information</header><text>The Secretary of Defense, the Director of the Central
				Intelligence Agency, and the Director of National Intelligence shall carry out
				their responsibilities under this subsection in coordination with the Secretary
				and share relevant information in a timely manner with the Secretary relating
				to the security of agency information and information systems, including
				systems described in paragraphs (2), (3), and (4), to enable the Secretary to
				carry out the responsibilities set forth in this section and to maintain
				comprehensive situational awareness regarding information security incidents,
				threats, and vulnerabilities affecting agency information systems, consistent
				with standards and guidelines for national security systems, issued in
				accordance with law and as directed by the President.</text>
									</paragraph></subsection></section><section id="ID9fd9630e3c2242a3914854923dbbc7f9"><enum>3554.</enum><header>Agency
				responsibilities</header>
								<subsection id="IDfe14bef9a28e4a92889f0018b66ac917"><enum>(a)</enum><header>In
				general</header><text>The head of each agency shall—</text>
									<paragraph id="IDdc20acc3bb9d48bb9953a2b798cf2bb9"><enum>(1)</enum><text>be responsible
				for—</text>
										<subparagraph id="ID267e81c67f624b8c8a4ec003adfb23e4"><enum>(A)</enum><text>providing
				information security protections commensurate with the risk resulting from
				unauthorized access, use, disclosure, disruption, modification, or destruction
				of—</text>
											<clause id="ID4537d2a7db154dc9b9709526904eedbc"><enum>(i)</enum><text>information
				collected, created, processed, stored, disseminated, or otherwise used or
				maintained by or on behalf of the agency; or</text>
											</clause><clause id="IDdd11bfae4077468c86b2b704b973eee2"><enum>(ii)</enum><text>information
				systems used or operated by the agency or by a contractor of the agency or
				other organization, such as a State government entity, on behalf of the
				agency;</text>
											</clause></subparagraph><subparagraph id="IDe8db5b0845ad40afab3e44b94477daef"><enum>(B)</enum><text>complying with
				this subchapter, including—</text>
											<clause id="IDf8c2f1ac6729454d9976e6f39d7d79c9"><enum>(i)</enum><text>the policies and
				directives issued under section 3553, including any directions under section
				3553(e); and</text>
											</clause><clause id="ID728601a74cc14f50b6cd379a45958a84"><enum>(ii)</enum><text>information
				security policies, directives, standards, and guidelines for national security
				systems issued in accordance with law and as directed by the President;</text>
											</clause></subparagraph><subparagraph id="ID544461ea5a184a7a9a9903b65a63b48e"><enum>(C)</enum><text>complying with
				the requirements of the information security standards prescribed under section
				11331 of title 40, including any required security configuration checklists;
				and</text>
										</subparagraph><subparagraph id="ID4d0960b55d1b46f8b54d487f78adadf1"><enum>(D)</enum><text>ensuring that
				information security management processes are integrated with agency strategic
				and operational planning processes;</text>
										</subparagraph></paragraph><paragraph id="ID20c35813f93f48bc81cef632cd6626f2"><enum>(2)</enum><text>ensure that
				senior agency officials provide information security for the information and
				information systems that support the operations and assets under the control of
				the officials, including through—</text>
										<subparagraph id="IDf81fd21822e14bb39e3fbbd2ccc17596"><enum>(A)</enum><text>assessing, with a
				frequency commensurate with risk, the risk and impact that could result from
				the unauthorized access, use, disclosure, disruption, modification, or
				destruction of the information or information systems;</text>
										</subparagraph><subparagraph id="ID6018cfa1a56f4f64a9cb16978abb6e42"><enum>(B)</enum><text>determining the
				levels of information security appropriate to protect the information and
				information systems in accordance with the policies and directives issued under
				section 3553(b) and standards prescribed under section 11331 of title
				40;</text>
										</subparagraph><subparagraph id="IDf1cf04a3f9e24be0a5f88b4fed577a9c"><enum>(C)</enum><text>implementing
				policies, procedures, and capabilities to reduce risks to an acceptable level
				in a cost-effective manner;</text>
										</subparagraph><subparagraph id="ID7f18711f7cf44aac8bf320a63f28f281"><enum>(D)</enum><text>security testing
				and evaluation, including continuously monitoring the effective implementation
				of information security controls and techniques, threats, vulnerabilities,
				assets, and other aspects of information security as appropriate; and</text>
										</subparagraph><subparagraph id="IDd47945213bc74cc1b4370e8c66888fed"><enum>(E)</enum><text>reporting
				information about information security incidents, threats, and vulnerabilities
				in a timely manner as required under policies and procedures established under
				subsection (b)(7);</text>
										</subparagraph></paragraph><paragraph id="IDd88129c3766e4b5da0a69e26faa35d5d"><enum>(3)</enum><text>assess and
				maintain the resiliency of information systems critical to the mission and
				operations of the agency;</text>
									</paragraph><paragraph id="IDf5981885437e49cd92fe10a396df194b"><enum>(4)</enum><text>delegate to the
				chief information officer or equivalent official (or to a senior agency
				official who reports to the chief information officer or equivalent official)
				the authority to ensure and primary responsibility for ensuring compliance with
				this subchapter, including—</text>
										<subparagraph id="IDe46b3a65ec91474f83a741c792ff285b"><enum>(A)</enum><text>overseeing the
				establishment and maintenance of an agencywide security operations capability
				that on a continuous basis can—</text>
											<clause id="ID62d7f9a3950145399e4dccbd256e97b2"><enum>(i)</enum><text>detect, report,
				respond to, contain, and mitigate information security incidents that impair
				adequate security of the agency information and information systems in a timely
				manner and in accordance with the policies and directives issued under section
				3553(b); and</text>
											</clause><clause id="IDc8cf4a2a320a4dc9bb4c38c5616b340d"><enum>(ii)</enum><text>report any
				information security incident described under clause (i) to the entity
				designated under section 3553(b)(6);</text>
											</clause></subparagraph><subparagraph id="ID3f850bb86503409291981acc78ccf8ad"><enum>(B)</enum><text>developing,
				maintaining, and overseeing an agencywide information security program as
				required under subsection (b);</text>
										</subparagraph><subparagraph id="IDa4c9999f730946cc9961b217be333a1d"><enum>(C)</enum><text>developing,
				maintaining, and overseeing information security policies, procedures, and
				control techniques to address all applicable requirements, including those
				issued under section 3553 and section 11331 of title 40;</text>
										</subparagraph><subparagraph id="ID7dfe15bdef88451cac5f67b179a7986f"><enum>(D)</enum><text>training and
				overseeing employees and contractors of the agency with significant
				responsibilities for information security with respect to such
				responsibilities; and</text>
										</subparagraph><subparagraph id="IDe2db2430636d402297adc393ac824a9f"><enum>(E)</enum><text>assisting senior
				agency officials concerning their responsibilities under paragraph (2);</text>
										</subparagraph></paragraph><paragraph id="ID686e031f988c49afb431188446e051e1"><enum>(5)</enum><text>the agency has
				trained and obtained security clearances for an adequate number of employees to
				assist the agency in complying with this subchapter, including the policies and
				directives issued under section 3553(b);</text>
									</paragraph><paragraph id="IDee733f967b064205a43f2e9d53ce6e0f"><enum>(6)</enum><text>ensure that the
				chief information officer (or other senior agency official designated under
				paragraph (4)), in coordination with other senior agency officials, reports to
				the head of the agency on the effectiveness of the agency information security
				program, including the progress of remedial actions;</text>
									</paragraph><paragraph id="ID6da15634441f4fa7bf9f58e12c29ce2e"><enum>(7)</enum><text>ensure that the
				chief information officer (or other senior agency official designated under
				paragraph (4))—</text>
										<subparagraph id="ID34d1b1b3b6444b80ac205cd0ece25ea3"><enum>(A)</enum><text>possesses the
				necessary qualifications to administer the duties of the official under this
				subchapter; and</text>
										</subparagraph><subparagraph id="ID1598c68d6b5947b2bc37e2adea26d4a6"><enum>(B)</enum><text>has information
				security duties as a primary duty of the official; and</text>
										</subparagraph></paragraph><paragraph id="ID40059124c1df46a6b62f2c6b5f3570fb"><enum>(8)</enum><text>ensure that
				senior agency officials (including component chief information officers or
				equivalent officials) carry out responsibilities under this subchapter as
				directed by the official delegated authority under paragraph (4).</text>
									</paragraph></subsection><subsection id="ID3eb75d1775274194aedab79b5eea3214"><enum>(b)</enum><header>Agency
				program</header><text>The head of each agency shall develop, document, and
				implement an agencywide information security program, which shall be reviewed
				under section 3553(b)(2), to provide information security for the information
				and information systems that support the operations and assets of the agency,
				including those provided or managed by another agency, contractor, or other
				source, which shall include—</text>
									<paragraph id="ID7e599538b31447bbbc9d6df714773da9"><enum>(1)</enum><text>the development,
				execution, and maintenance of a risk management strategy for information
				security that—</text>
										<subparagraph id="IDf30427c0a5a747898622439560aaccad"><enum>(A)</enum><text>considers
				information security threats, vulnerabilities, and consequences;</text>
										</subparagraph><subparagraph id="ID7e6b8989e260451e8a2a4b6fdd6690c4"><enum>(B)</enum><text>includes periodic
				assessments and reporting of risk, with a frequency commensurate with risk and
				impact;</text>
										</subparagraph></paragraph><paragraph id="ID26363e1aba4b42ed8473bfa80986072d"><enum>(2)</enum><text>policies and
				procedures that—</text>
										<subparagraph id="ID4508c960624842ecb095be10d6a57680"><enum>(A)</enum><text>are based on the
				risk management strategy and assessment results required under paragraph
				(1);</text>
										</subparagraph><subparagraph id="ID8db067a3421f426093be28c0c5109a45"><enum>(B)</enum><text>reduce
				information security risks to an acceptable level in a cost-effective
				manner;</text>
										</subparagraph><subparagraph id="ID20f32bee4b114df3b21ef6dc2d14c587"><enum>(C)</enum><text>ensure that
				cost-effective and adequate information security is addressed throughout the
				life cycle of each agency information system; and</text>
										</subparagraph><subparagraph id="ID55e94b9d517d490b8433f0be4ec18285"><enum>(D)</enum><text>ensure compliance
				with—</text>
											<clause id="ID66352f4c584b44b3a08674819aa5d7e8"><enum>(i)</enum><text>this
				subchapter;</text>
											</clause><clause id="ID354f7595574548c4813ca9f65f36b541"><enum>(ii)</enum><text>the information
				security policies and directives issued under section 3553(b); and</text>
											</clause><clause id="IDe05905ca67cd4a2aae3666bd7328c77c"><enum>(iii)</enum><text>any other
				applicable requirements;</text>
											</clause></subparagraph></paragraph><paragraph id="ID5857aada140945e2999286b88f67a726"><enum>(3)</enum><text>subordinate plans
				for providing adequate information security for networks, facilities, and
				systems or groups of information systems;</text>
									</paragraph><paragraph id="IDc66c8da7e00f43508e915ea6b2b6a458"><enum>(4)</enum><text>security
				awareness training developed in accordance with the requirements issued under
				section 3553(b) to inform individuals with access to agency information
				systems, including information security employees, contractors, and other users
				of information systems that support the operations and assets of the agency,
				of—</text>
										<subparagraph id="ID3eb772db1f6f4714954d29c280ca8352"><enum>(A)</enum><text>information
				security risks associated with their activities;</text>
										</subparagraph><subparagraph id="ID6e45a67bc62849ac9da7c3f1540fa209"><enum>(B)</enum><text>their
				responsibilities in complying with agency policies and procedures designed to
				reduce those risks;</text>
										</subparagraph><subparagraph id="ID78f61d8ef9224c8ca68366b7083dbdc5"><enum>(C)</enum><text>requirements for
				fulfilling privacy, civil rights, civil liberties, and other information
				oversight responsibilities; and</text>
										</subparagraph><subparagraph id="idFC1FB663466B426D987703C11A392510"><enum>(D)</enum><text>methods for
				individuals to report risks and incidents to relevant Offices of Inspectors
				General and the Secretary under section 106 of the Cybersecurity Act of
				2012;</text>
										</subparagraph></paragraph><paragraph id="ID78d7aa7df0de4cf58389b46037154730"><enum>(5)</enum><text>security testing
				and evaluation commensurate with risk and impact that includes—</text>
										<subparagraph id="ID31db547c0dcf4733b2d1e5a19adc97e9"><enum>(A)</enum><text>risk-based
				continuous monitoring of the operational status and security of agency
				information systems to enable evaluation of the effectiveness of and compliance
				with information security policies, procedures, and practices, including a
				relevant and appropriate selection of management, operational, and technical
				controls of information systems identified in the inventory required under
				section 3505(c);</text>
										</subparagraph><subparagraph id="IDc455125c927e44398f756a60948a8472"><enum>(B)</enum><text>penetration
				testing exercises and operational evaluations in accordance with the
				requirements issued under section 3553(b) to evaluate whether the agency
				adequately protects against, detects, and responds to incidents;</text>
										</subparagraph><subparagraph id="IDc362b3c924e6430d936f14e32f828573"><enum>(C)</enum><text>vulnerability
				scanning, intrusion detection and prevention, and penetration testing, in
				accordance with the requirements issued under section 3553(b); and</text>
										</subparagraph><subparagraph id="IDe9081eff47004551ab3ca79f1b447ae7"><enum>(D)</enum><text>any other
				periodic testing and evaluation, in accordance with the requirements issued
				under section 3553(b);</text>
										</subparagraph></paragraph><paragraph id="IDf88d547bc5c74e5a93b6964347017dd0"><enum>(6)</enum><text>a process for
				ensuring that remedial actions are taken to mitigate information security
				vulnerabilities commensurate with risk and impact, and otherwise address any
				deficiencies in the information security policies, procedures, and practices of
				the agency;</text>
									</paragraph><paragraph id="ID2cf7b411ad5f4b9eb2c11ed0b62c91bf"><enum>(7)</enum><text>policies and
				procedures to ensure detection, mitigation, reporting, and responses to
				information security incidents, in accordance with the policies and directives
				issued under section 3553(b), including—</text>
										<subparagraph id="IDed316885281f4c95b3bf055ac1317a4a"><enum>(A)</enum><text>ensuring timely
				internal reporting of information security incidents;</text>
										</subparagraph><subparagraph id="ID279f5530318a42f899ebc8f5266f6eb0"><enum>(B)</enum><text>establishing and
				maintaining appropriate technical capabilities to detect and mitigate risks
				associated with information security incidents;</text>
										</subparagraph><subparagraph id="ID2af2c7d065f641af8b3b8dc5c7915d7b"><enum>(C)</enum><text>notifying and
				consulting with the entity designated by the Secretary under section
				3553(b)(6); and</text>
										</subparagraph><subparagraph id="IDca8146e0bbce4513810e16015a5dc8ff"><enum>(D)</enum><text>notifying and
				consulting with—</text>
											<clause id="IDf2e6cbd321de4b258d411c44a0e7b5d9"><enum>(i)</enum><text>law enforcement
				agencies and relevant Offices of Inspectors General;</text>
											</clause><clause id="id601A533AD81F455283F7C39BB57170FE"><enum>(ii)</enum><text>relevant
				committees of Congress, as appropriate; and</text>
											</clause><clause id="IDb1b746df3e5d4102b6883a5d9b18924f"><enum>(iii)</enum><text>any other
				entity, in accordance with law and as directed by the President; and</text>
											</clause></subparagraph></paragraph><paragraph id="ID07fefd66cf0b4179afbbdc6606130f9e"><enum>(8)</enum><text>plans and
				procedures to ensure continuity of operations for information systems that
				support the operations and assets of the agency.</text>
									</paragraph></subsection><subsection id="IDd70dfdb319af4c39aeb51a72169f56c7"><enum>(c)</enum><header>Annual agency
				reporting</header><text>The head of each agency shall—</text>
									<paragraph id="ID9b77b5f2e712485ca692ec1641238ae1"><enum>(1)</enum><text>report annually
				to the Committee on Government Reform and the Committee on Science, Space, and
				Technology of the House of Representatives, the Committee on Homeland Security
				and Governmental Affairs and the Committee on Commerce, Science, and
				Transportation of the Senate, any other appropriate committees of Congress, and
				the Secretary on the adequacy and effectiveness of information security
				policies, procedures, and practices, including—</text>
										<subparagraph id="id8d765bc267054fc9aab9cfe86adfc4e6"><enum>(A)</enum><text>a description of
				each major information security incident, or set of related incidents,
				resulting in significant compromise of information security, including a
				summary of—</text>
											<clause id="idaf33a0f8bac14549b189f025cee2ee12"><enum>(i)</enum><text>the threats,
				vulnerabilities, and impact of the incident;</text>
											</clause><clause id="id21fb3fe8925240cbbe8120b642009fb5"><enum>(ii)</enum><text>the system risk
				assessment conducted before the incident and required under section 3554(a)(2);
				and</text>
											</clause><clause id="id4ba04f595b72404c913887cb48d5b96b"><enum>(iii)</enum><text>the detection
				and response actions taken;</text>
											</clause></subparagraph><subparagraph id="idfef570207ca144869c4c84eb3b24afea"><enum>(B)</enum><text>the number of
				information security incidents within the agency resulting in significant
				compromise of information security, presented by system impact level, type of
				incident, and location;</text>
										</subparagraph><subparagraph id="idc84e285387884a64bd7abc8e27caadca"><enum>(C)</enum><text>the total number
				of information security incidents within the agency, presented by system impact
				level, type of incident, and location;</text>
										</subparagraph><subparagraph id="ID8e645121f77b4dceb220885a060d6693"><enum>(D)</enum><text>an identification
				and analysis of, including actions and plans to address, any significant
				deficiencies identified in such policies, procedures and practices;</text>
										</subparagraph><subparagraph id="ID29a2a5f511824b40a055c744e0846d72"><enum>(E)</enum><text>any information
				or evaluation required under the reporting requirements issued under section
				3553(b); and</text>
										</subparagraph></paragraph><paragraph id="IDdebbc78ef7c547b7b9cba9f07ba90e5c"><enum>(2)</enum><text>address the
				adequacy and effectiveness of the information security policies, procedures,
				and practices of the agency as required for management and budget plans and
				reports, as appropriate.</text>
									</paragraph></subsection><subsection id="ID4775675054c444e1a89dffe34c0a309a"><enum>(d)</enum><header>Communications
				and system traffic</header><text>Notwithstanding any other provision of law,
				the head of each agency is authorized to allow the Secretary, or a private
				entity providing assistance to the Secretary under section 3553, to acquire,
				intercept, retain, use, and disclose communications, system traffic, records,
				or other information transiting to or from or stored on an agency information
				system for the purpose of protecting agency information and information systems
				from information security threats or mitigating the threats in connection with
				the implementation of the information security capabilities authorized by
				paragraph (3) or (4) of section 3553(b).</text>
								</subsection></section><section id="ID53ad35265c5a4499a1e33cfe60cde922"><enum>3555.</enum><header>Annual
				assessments</header>
								<subsection id="ID6b526b3152b94e5c880b2baf3bd55096"><enum>(a)</enum><header>In
				general</header><text>Except as provided in subsection (c), the Secretary shall
				conduct periodic assessments of the information security programs and practices
				of agencies based on the annual agency reports required under section 3554(c),
				the annual independent evaluations required under section 3556, the results of
				any continuous monitoring, and other available information.</text>
								</subsection><subsection id="ID1ff4b643496a45f89d440f72b1b2e0b7"><enum>(b)</enum><header>Contents</header><text>Each
				assessment conducted under subsection (a) shall—</text>
									<paragraph id="IDf934402777e04b2697f066d8197910bb"><enum>(1)</enum><text>assess the
				effectiveness of agency information security policies, procedures, and
				practices;</text>
									</paragraph><paragraph id="IDd569919b7be24cdea06a78ea5572bd9b"><enum>(2)</enum><text>provide an
				assessment of the status of agency information system security for the Federal
				Government as a whole; and</text>
									</paragraph><paragraph id="ID2c37240188d4409ea21924f330a000c6"><enum>(3)</enum><text>include
				recommendations for improving information system security for an agency or the
				Federal Government as a whole.</text>
									</paragraph></subsection><subsection id="ID9c656c30cea8482292a5e8eed0593ea9"><enum>(c)</enum><header>Certain
				information systems</header>
									<paragraph id="IDf04f825400ec49de8bafc884d486bb7c"><enum>(1)</enum><header>National
				security systems</header><text>A periodic assessment conducted under subsection
				(a) relating to a national security system shall be prepared as directed by the
				President.</text>
									</paragraph><paragraph id="ID6f1c862f05ce455c8de9a9b3eee73080"><enum>(2)</enum><header>Specific
				agencies</header><text>Periodic assessments conducted under subsection (a)
				shall be prepared in accordance with governmentwide reporting requirements
				by—</text>
										<subparagraph id="ID70bb1d9d224d4c848df0da1eb3e25a02"><enum>(A)</enum><text>the Secretary of
				Defense for information systems under the control of the Department of
				Defense;</text>
										</subparagraph><subparagraph id="ID7af86be455534ba0864d21e622fe2fc0"><enum>(B)</enum><text>the Director of
				the Central Intelligence Agency for information systems under the control of
				the Central Intelligence Agency; and</text>
										</subparagraph><subparagraph id="IDd53de144e1b24837bf755c1e7880e7b0"><enum>(C)</enum><text>the Director of
				National Intelligence for information systems under the control of the Office
				of the Director of National Intelligence.</text>
										</subparagraph></paragraph></subsection><subsection id="IDc4975445bf9e413c99e64ceb8085f477"><enum>(d)</enum><header>Agency-specific
				assessments</header><text>Each assessment conducted under subsection (a) that
				relates, in whole or in part, to the information systems of an agency shall be
				made available to the head of the agency.</text>
								</subsection><subsection id="ID16ef3afe21654948bc45ebe4508095e4"><enum>(e)</enum><header>Protection of
				information</header><text>In conducting assessments under subsection (a), the
				Secretary shall take appropriate actions to ensure the protection of
				information which, if disclosed, may adversely affect information security.
				Such protections shall be commensurate with the risk and comply with all
				applicable laws and policies.</text>
								</subsection><subsection id="ID39656c0f57b94c6ea38edf1f1795b177"><enum>(f)</enum><header>Report to
				congress</header><text>The Secretary, in coordination with the Secretary of
				Defense, the Director of the Central Intelligence Agency, and the Director of
				National Intelligence, shall evaluate and submit to Congress an annual report
				on the adequacy and effectiveness of the information security programs and
				practices assessed under this section.</text>
								</subsection></section><section id="ID03d93c20de7c43a48ba87e09ec8aa5c2"><enum>3556.</enum><header>Independent
				evaluations</header>
								<subsection id="ID9471a957e4f1424dabb130797e416477"><enum>(a)</enum><header>In
				general</header><text>Not less than annually, an independent evaluation of the
				information security program and practices of each agency shall be performed to
				assess the effectiveness of the programs and practices.</text>
								</subsection><subsection id="ID2cc56bfc0d0e41acaed1444fa62e9849"><enum>(b)</enum><header>Contents</header><text>Each
				evaluation performed under subsection (a) shall include—</text>
									<paragraph id="ID3b298c4c76ce4882854b5513bbd6d58a"><enum>(1)</enum><text>testing of the
				effectiveness of information security policies, procedures, and practices of a
				representative subset of the information systems of the agency; and</text>
									</paragraph><paragraph id="ID94cc15589df0440897db9a9f05316614"><enum>(2)</enum><text>an assessment of
				the effectiveness of the information security policies, procedures, and
				practices of the agency.</text>
									</paragraph></subsection><subsection id="ID276d746845ea4a04b5a642ec5dd8396a"><enum>(c)</enum><header>Conduct of
				independent evaluations</header><text>Except as provided in subsection (f), an
				evaluation of an agency under subsection (a) shall be performed by—</text>
									<paragraph id="ID98aee25b47a74ddd8e1063dd63490cfe"><enum>(1)</enum><text>the Inspector
				General of the agency;</text>
									</paragraph><paragraph id="ID019699dfe974414585300e9d9f6eb6f6"><enum>(2)</enum><text>at the discretion
				of the Inspector General of the agency, an independent entity entering a
				contract with the Inspector General to perform the evaluation; or</text>
									</paragraph><paragraph id="ID6db210b63cd149949d632694f6d648f3"><enum>(3)</enum><text>if the agency
				does not have an Inspector General, an independent entity selected by the head
				of the agency, in consultation with the Secretary.</text>
									</paragraph></subsection><subsection id="ID1946f4397aba4b21b01ce7d1ae93d86c"><enum>(d)</enum><header>Previously
				conducted evaluations</header><text>The evaluation required by this section may
				be based in whole or in part on a previously conducted audit, evaluation, or
				report relating to programs or practices of the applicable agency.</text>
								</subsection><subsection id="ID8ffee42b26ef4052bad51de38954563e"><enum>(e)</enum><header>Reports</header><text>The
				official or entity performing an evaluation of an agency under subsection (a)
				shall submit to Congress, the agency, and the Comptroller General of the United
				States a report regarding the evaluation. The head of the agency shall provide
				to the Secretary a report received under this subsection.</text>
								</subsection><subsection id="ID348a290585e447b8a585b07c59c6f547"><enum>(f)</enum><header>National
				security systems</header><text>An evaluation under subsection (a) of a national
				security system shall be performed as directed by the President.</text>
								</subsection><subsection id="ID9019289093794ebfb2f19b058b8eec5c"><enum>(g)</enum><header>Comptroller
				general</header><text>The Comptroller General of the United States shall
				periodically evaluate and submit to Congress reports on—</text>
									<paragraph id="ID0b9bf035f63e4a40beebf9770df29fb4"><enum>(1)</enum><text>the adequacy and
				effectiveness of the information security policies and practices of agencies;
				and</text>
									</paragraph><paragraph id="ID61df3622c0b84964a31db6ea7e48b3d9"><enum>(2)</enum><text>implementation of
				this subchapter.</text>
									</paragraph></subsection></section><section id="IDd7071e79ec0447a492633a89459d1e80"><enum>3557.</enum><header>National
				security systems</header><text display-inline="no-display-inline">The head of
				each agency operating or exercising control of a national security system shall
				be responsible for ensuring that the agency—</text>
								<paragraph id="IDedc7f9b4fde849a69ae55d3ef1d10c91"><enum>(1)</enum><text>provides
				information security protections commensurate with the risk and magnitude of
				the harm resulting from the unauthorized use, disclosure, disruption,
				modification, or destruction of the information contained in the national
				security system;</text>
								</paragraph><paragraph id="ID96df8f86d4144de985a154e6ee2ee5b8"><enum>(2)</enum><text>implements
				information security policies and practices as required by standards and
				guidelines for national security systems issued in accordance with law and as
				directed by the President; and</text>
								</paragraph><paragraph id="ID136dec63aad2466e8fb106337b7c6206"><enum>(3)</enum><text>complies with
				this subchapter.</text>
								</paragraph></section><section id="IDe2af7888bdae402b91c105e5a6c32a69"><enum>3558.</enum><header>Effect on
				existing law</header><text display-inline="no-display-inline">Nothing in this
				subchapter shall be construed to alter or amend any law regarding the authority
				of any head of an agency over the
				agency.</text>
							</section></subchapter><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="ID05b2ea7ab5f041c0a327c6e48865f8d1"><enum>(b)</enum><header>Technical and
			 conforming amendment</header><text>The table of sections for chapter 35 of
			 title 44 is amended by striking the matter relating to subchapters II and III
			 and inserting the following:</text>
					<quoted-block id="id73b5657e-9226-4978-b784-a024729e9012" style="USC">
						<toc>
							<toc-entry idref="id860D576E970C4A0A84DF9DADD66F6212" level="subchapter">SUBCHAPTER II—Information security</toc-entry>
							<toc-entry idref="id3BB7B7410F744A88987C767B601D23F2" level="section">Sec. 3551. Purposes.</toc-entry>
							<toc-entry idref="ID18c656f7bdd64b6fbe88a4bff412793d" level="section">Sec. 3552. Definitions.</toc-entry>
							<toc-entry idref="ID7c9ab5fec0964a36b57f51932d5ca0ad" level="section">Sec. 3553. Federal information security authority and
				coordination.</toc-entry>
							<toc-entry idref="ID9fd9630e3c2242a3914854923dbbc7f9" level="section">Sec. 3554. Agency responsibilities.</toc-entry>
							<toc-entry idref="ID53ad35265c5a4499a1e33cfe60cde922" level="section">Sec. 3555. Annual assessments.</toc-entry>
							<toc-entry idref="ID03d93c20de7c43a48ba87e09ec8aa5c2" level="section">Sec. 3556. Independent evaluations.</toc-entry>
							<toc-entry idref="IDd7071e79ec0447a492633a89459d1e80" level="section">Sec. 3557. National security systems.</toc-entry>
							<toc-entry level="section">Sec. 3558. Effect on existing
				law.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section><section id="ID1f78ed935a9449098664d18aa30aabdc"><enum>202.</enum><header>Management of
			 information technology</header>
				<subsection id="ID4c90e2a581f84d5b82658fdc0adfe100"><enum>(a)</enum><header>In
			 general</header><text>Section 11331 of title 40, United States Code, is amended
			 to read as follows:</text>
					<quoted-block display-inline="no-display-inline" id="idE8E95DE20C7245A7BEB42F1AE9E7846C" style="USC">
						<section id="IDeb3e122ee783446cbdde566265acd246"><enum>11331.</enum><header>Responsibilities
				for Federal information systems standards</header>
							<subsection id="ID3f2b92796de14245bdc279231271514d"><enum>(a)</enum><header>Definitions</header><text>In
				this section:</text>
								<paragraph id="IDa0e1b606f8a047b28ff7424dceea767a"><enum>(1)</enum><header>Federal
				information system</header><text>The term <term>Federal information
				system</term> means an information system used or operated by an executive
				agency, by a contractor of an executive agency, or by another entity on behalf
				of an executive agency.</text>
								</paragraph><paragraph id="IDdf91955cd4b248289515c18d301339e8"><enum>(2)</enum><header>Information
				security</header><text>The term <term>information security</term> has the
				meaning given that term in section 3552 of title 44.</text>
								</paragraph><paragraph id="IDfe9e32530d234f5e8ddddcf86516a389"><enum>(3)</enum><header>National
				security system</header><text>The term <term>national security system</term>
				has the meaning given that term in section 3552 of title 44.</text>
								</paragraph></subsection><subsection id="ID3e9ff20d3c73408cb942e14073531a10"><enum>(b)</enum><header>Standards and
				guidelines</header>
								<paragraph id="ID0da5acc9d4df45408379df01728e918e"><enum>(1)</enum><header>Authority to
				prescribe</header><text>Except as provided under paragraph (2), and based on
				the standards and guidelines developed by the National Institute of Standards
				and Technology under paragraphs (2) and (3) of section 20(a) of the National
				Institute of Standards and Technology Act (15 U.S.C. 278g–3(a)), the Secretary
				of Commerce, in consultation with the Secretary of Homeland Security, shall
				prescribe standards and guidelines relating to Federal information
				systems.</text>
								</paragraph><paragraph id="ID64284af07583412eb0d010e8c458464a"><enum>(2)</enum><header>National
				security systems</header><text>Standards and guidelines for national security
				systems shall be developed, prescribed, enforced, and overseen as otherwise
				authorized by law and as directed by the President.</text>
								</paragraph></subsection><subsection id="IDfe0d38dc3f824ee795a47a536a1bbc1d"><enum>(c)</enum><header>Mandatory
				requirements</header>
								<paragraph id="ID93da7a998fab480b86854473c45749dd"><enum>(1)</enum><header>Authority to
				make mandatory</header><text>The Secretary of Commerce may require executive
				agencies to comply with the standards prescribed under subsection (b)(1) to the
				extent determined necessary by the Secretary of Commerce to improve the
				efficiency of operation or security of Federal information systems.</text>
								</paragraph><paragraph id="ID34cf57b395454210983f0f7f513ad633"><enum>(2)</enum><header>Required
				mandatory standards</header>
									<subparagraph id="IDa67406418edc4197ab7f310de8716134"><enum>(A)</enum><header>In
				general</header><text>The Secretary of Commerce shall require executive
				agencies to comply with the standards described in subparagraph (B).</text>
									</subparagraph><subparagraph id="ID496f1ae2635f4b438713af50af525d1e"><enum>(B)</enum><header>Contents</header><text>The
				standards described in this subparagraph are information security standards
				that—</text>
										<clause id="ID2bb9db0daae64974a2bf9005e13da6b9"><enum>(i)</enum><text>provide minimum
				information security requirements as determined under section 20(b) of the
				National Institute of Standards and Technology Act (15 U.S.C. 278g–3(b));
				and</text>
										</clause><clause id="IDaad90c4f794e46bb8230507cc9427f2b"><enum>(ii)</enum><text>are otherwise
				necessary to improve the security of Federal information and Federal
				information systems.</text>
										</clause></subparagraph></paragraph></subsection><subsection id="IDe7ababd5e3c64c2ba0384e6badc85f29"><enum>(d)</enum><header>Authority To
				disapprove or modify</header><text>The President may disapprove or modify the
				standards and guidelines prescribed under subsection (b)(1) if the President
				determines such action to be in the public interest. The authority of the
				President to disapprove or modify the standards and guidelines may be delegated
				to the Director of the Office of Management and Budget. Notice of a disapproval
				or modification under this subsection shall be published promptly in the
				Federal Register. Upon receiving notice of a disapproval or modification, the
				Secretary of Commerce shall immediately rescind or modify the standards or
				guidelines as directed by the President or the Director of the Office of
				Management and Budget.</text>
							</subsection><subsection id="ID24e51b9c372e42239272438ae32317fc"><enum>(e)</enum><header>Exercise of
				authority</header><text>To ensure fiscal and policy consistency, the Secretary
				of Commerce shall exercise the authority under this section subject to
				direction by the President and in coordination with the Director of the Office
				of Management and Budget.</text>
							</subsection><subsection id="IDfda8e14091084f2a9ac760faf2a858b4"><enum>(f)</enum><header>Application of
				more stringent standards</header><text>The head of an executive agency may
				employ standards for the cost-effective information security for Federal
				information systems of that agency that are more stringent than the standards
				prescribed by the Secretary of Commerce under subsection (b)(1) if the more
				stringent standards—</text>
								<paragraph id="ID681bad4457454bc08797f925450b4adf"><enum>(1)</enum><text>contain any
				standards with which the Secretary of Commerce has required the agency to
				comply; and</text>
								</paragraph><paragraph id="ID0a9a3e40e4f4451d84506d805d9ca941"><enum>(2)</enum><text>are otherwise
				consistent with the policies and directives issued under section 3553(b) of
				title 44.</text>
								</paragraph></subsection><subsection id="ID0d5d52686ed24435aba229e8afecd7d4"><enum>(g)</enum><header>Decisions on
				promulgation of standards</header><text>The decision by the Secretary of
				Commerce regarding the promulgation of any standard under this section shall
				occur not later than 6 months after the submission of the proposed standard to
				the Secretary of Commerce by the National Institute of Standards and
				Technology, as provided under section 20 of the National Institute of Standards
				and Technology Act (15 U.S.C.
				278g–3).</text>
							</subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="IDa85bf0bdfc82412f8d30138e5ed3b0f4"><enum>(b)</enum><header>Technical and
			 conforming amendments</header>
					<paragraph id="ID5c9d015d06c546c280849d0ebe891ea7"><enum>(1)</enum><text>Section 3502(8))
			 of title 44, United States Code, is amended by inserting
			 <quote>hosting,</quote> after <quote>collection,</quote>.</text>
					</paragraph><paragraph id="ID39816510303a45cf9a3d3788361907a0"><enum>(2)</enum><text>The National
			 Institute of Standards and Technology Act (15 U.S.C. 271 et seq.) is
			 amended—</text>
						<subparagraph id="ID97cf935d97ee4521a115303c17e6a3da"><enum>(A)</enum><text>in section
			 20(a)(2) (15 U.S.C. 278g–3(a)(2)), by striking <quote>section
			 3532(b)(2)</quote> and inserting <quote>section 3552(b)</quote>; and</text>
						</subparagraph><subparagraph id="IDec29e838c29f491fb895dd39d4ac1299"><enum>(B)</enum><text>in section 21(b)
			 (15 U.S.C. 278g–4(b))—</text>
							<clause id="ID5fa8af68d0c4407783673293d66d9863"><enum>(i)</enum><text>in
			 paragraph (2), by inserting <quote>, the Secretary of Homeland
			 Security,</quote> after <quote>the Institute</quote>; and</text>
							</clause><clause id="IDcf9c6a219944426785ed135564e9379f"><enum>(ii)</enum><text>in
			 paragraph (3), by inserting <quote>the Secretary of Homeland Security,</quote>
			 after <quote>the Secretary of Commerce,</quote>.</text>
							</clause></subparagraph></paragraph><paragraph id="ID5d124d9e609341a1b0461201b85f40ca"><enum>(3)</enum><text>Section
			 1001(c)(1)(A) of the Homeland Security Act of 2002 (6 U.S.C. 511(c)(1)(A)) is
			 amended by striking <quote>section 3532(3)</quote> and inserting <quote>section
			 3552(b)</quote>.</text>
					</paragraph><paragraph id="IDa2ab6e42fdd8419daf53a097056742c0"><enum>(4)</enum><text>Part IV of title
			 10, United States Code, is amended—</text>
						<subparagraph id="ID65e414186437425da46afaf9667d50b2"><enum>(A)</enum><text>in section
			 2222(j)(5), by striking <quote>section 3542(b)(2)</quote> and inserting
			 <quote>section 3552(b)</quote>;</text>
						</subparagraph><subparagraph id="ID239a3a3298ea468aab047916def38495"><enum>(B)</enum><text>in section
			 2223(c)(3), by striking <quote>section 3542(b)(2)</quote> and inserting
			 <quote>section 3552(b)</quote>; and</text>
						</subparagraph><subparagraph id="IDf2dd603eb1224889b1701c331804baf5"><enum>(C)</enum><text>in section 2315,
			 by striking <quote>section 3542(b)(2)</quote> and inserting <quote>section
			 3552(b)</quote>.</text>
						</subparagraph></paragraph><paragraph id="ID64201ae2e2074f9da38c4951266fa8f8"><enum>(5)</enum><text>Section 8(d)(1)
			 of the Cyber Security Research and Development Act (15 U.S.C. 7406(d)(1)) is
			 amended by striking <quote>section 3534(b)</quote> and inserting <quote>section
			 3554(b)</quote>.</text>
					</paragraph></subsection></section><section id="ID0878d5bdfa38404bae793bf89eb098e7"><enum>203.</enum><header>Savings
			 provisions</header>
				<subsection id="IDe25590120a8e4bc2bc71d7049806e1e1"><enum>(a)</enum><header>In
			 general</header><text>Policies and compliance guidance issued by the Director
			 of the Office of Management and Budget before the date of enactment of this Act
			 under section 3543(a)(1) of title 44 (as in effect on the day before the date
			 of enactment of this Act) shall continue in effect, according to their terms,
			 until modified, terminated, superseded, or repealed under section 3553(b)(1) of
			 title 44, as added by this Act.</text>
				</subsection><subsection commented="no" display-inline="no-display-inline" id="ID0b2e8a3dc00e42e386f56ee94ac856f2"><enum>(b)</enum><header>Other standards
			 and guidelines</header><text>Standards and guidelines issued by the Secretary
			 of Commerce or by the Director of the Office of Management and Budget before
			 the date of enactment of this Act under section 11331(b)(1) of title 40 (as in
			 effect on the day before the date of enactment of this Act) shall continue in
			 effect, according to their terms, until modified, terminated, superseded, or
			 repealed under section 11331(b)(1), as added by this Act.</text>
				</subsection></section><section id="ID3d57e7d77d5f46558b466ddec449d31c"><enum>204.</enum><header>Consolidation
			 of existing departmental cyber resources and authorities</header>
				<subsection id="idCE7C8EE8FB324F338D7CD4EA1302120F"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Title II of the
			 Homeland Security Act of 2002 (6 U.S.C. 121 et seq.) is amended by adding at
			 the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idBE10978979E1467E8313652F244E7ED5" style="OLC">
						<subtitle id="id5D00954CBF94409B93D467C1233E5508"><enum>E</enum><header>Cybersecurity</header>
							<section id="ID1bda65c3690248ffa8b0f77639df8253"><enum>241.</enum><header>Definitions</header><text display-inline="no-display-inline">In this subtitle:</text>
								<paragraph id="id02202901F3154FC0BF3184AA157A58F3"><enum>(1)</enum><header>Agency
				information infrastructure</header><text>The term <term>agency information
				infrastructure</term> means the Federal information infrastructure of a
				particular Federal agency.</text>
								</paragraph><paragraph id="idB468F954261844CFA6221A03BB1A1D04"><enum>(2)</enum><header>Center</header><text>The
				term <term>Center</term> means the National Center for Cybersecurity and
				Communications established under section 242.</text>
								</paragraph><paragraph id="ID7854f965bc104e7c8ffa4e12833fa965"><enum>(3)</enum><header>Damage</header><text>The
				term <term>damage</term> has the meaning given that term in section 1030(e) of
				title 18, United States Code.</text>
								</paragraph><paragraph id="id7D0F66635A0D4B3286108D5DDA143E3A"><enum>(4)</enum><header>Federal
				agency</header><text>The term <term>Federal agency</term> has the meaning given
				the term <term>agency</term> in section 3502 of title 44, United States
				Code.</text>
								</paragraph><paragraph id="id73654BB2B3304CD693D809C8415B6924"><enum>(5)</enum><header>Federal
				cybersecurity center</header><text>The term <term>Federal cybersecurity
				center</term> has the meaning given that term in section 708 of the
				<short-title>Cybersecurity Act of
				2012</short-title>.</text>
								</paragraph><paragraph id="id9CAA04393F75489C9DE4746DF3E1090E"><enum>(6)</enum><header>Federal
				entity</header><text>The term <term>Federal entity</term> has the meaning given
				that term in section 708 of the <short-title>Cybersecurity
				Act of 2012</short-title>.</text>
								</paragraph><paragraph id="idE82410B0D40A4305AA5175F3B32C250D"><enum>(7)</enum><header>Federal
				information infrastructure</header><text>The term <term>Federal information
				infrastructure</term>—</text>
									<subparagraph id="idB5AC58A66E314E4892034439DA6DED8C"><enum>(A)</enum><text>means information
				and information systems that are owned, operated, controlled, or licensed
				solely for use by, or on behalf of, any Federal agency, including information
				systems used or operated by another entity on behalf of a Federal agency;
				and</text>
									</subparagraph><subparagraph id="idB1A1E510D2C847099CD3B16926F5D521"><enum>(B)</enum><text>does not
				include—</text>
										<clause id="id7C78A01BB1704874BFADBC2EFBDF0F6C"><enum>(i)</enum><text>a
				national security system; or</text>
										</clause><clause id="id2A6554911D8F41D69F505672FD2981DD"><enum>(ii)</enum><text>information and
				information systems that are owned, operated, controlled, or licensed for use
				solely by, or on behalf of, the Department of Defense, a military department,
				or another element of the intelligence community.</text>
										</clause></subparagraph></paragraph><paragraph id="idDF37FDF960AE455FAAF01B5E3AB1D1AD"><enum>(8)</enum><header>Incident</header><text>The
				term <term>incident</term> has the meaning given that term in section 3552 of
				title 44, United States Code.</text>
								</paragraph><paragraph id="idF5422385BAE34332995297231CAAB870"><enum>(9)</enum><header>Information
				security</header><text>The term <term>information security</term> has the
				meaning given that term in section 3552 of title 44, United States Code.</text>
								</paragraph><paragraph id="id53280365756148A3863B97BC4133519D"><enum>(10)</enum><header>Information
				system</header><text>The term <term>information system</term> has the meaning
				given that term in section 3502 of title 44, United States Code.</text>
								</paragraph><paragraph id="id3608D0160AF94ED0A5FDE63A6D494B87"><enum>(11)</enum><header>Intelligence
				community</header><text>The term <term>intelligence community</term> has the
				meaning given that term in section 3(4) of the National Security Act of 1947
				(50 U.S.C. 401a(4)).</text>
								</paragraph><paragraph id="idDA60533E9A134757AD6238A0A609EAEB"><enum>(12)</enum><header>National
				security and emergency preparedness communications
				infrastructure</header><text>The term <term>national security and emergency
				preparedness communications infrastructure</term> means the systems supported
				or covered by the Office of Emergency Communications and the National
				Communications System on the date of enactment of the
				<short-title>Cybersecurity Act of 2012</short-title> or
				otherwise described in Executive Order 12472, or any successor thereto,
				relating to national security and emergency preparedness communications
				functions.</text>
								</paragraph><paragraph id="id914CDDC8FAA44BA496231F1E05C06DB7"><enum>(13)</enum><header>National
				information infrastructure</header><text>The term <term>national information
				infrastructure</term> means information and information systems—</text>
									<subparagraph id="idD9140685ACB94A74BFB809D60D10243A"><enum>(A)</enum><text>that are owned,
				operated, or controlled, in whole or in part, within or from the United States;
				and</text>
									</subparagraph><subparagraph id="id35AB443097134D07AC7AC4E804964BC1"><enum>(B)</enum><text>that are not
				owned, operated, controlled, or licensed for use by a Federal agency.</text>
									</subparagraph></paragraph><paragraph id="idC5ABA9A7E6F243BCA8AFF76BA588393B"><enum>(14)</enum><header>National
				security system</header><text>The term <term>national security system</term>
				has the meaning given that term in section 3552 of title 44, United States
				Code.</text>
								</paragraph><paragraph id="idA097E22E45994DBB9E5E2B40B9B2448F"><enum>(15)</enum><header>Non-Federal
				entity</header><text>The term <term>non-Federal entity</term> has the meaning
				given that term in section 708 of the <short-title>Cybersecurity Act of 2012</short-title>.</text>
								</paragraph></section><section id="idA2F947FA68CC42F6AE2E911520EF7FD6"><enum>242.</enum><header>Consolidation
				of existing resources</header>
								<subsection id="IDd24a2d9203314e438a6f8b4265c8f903"><enum>(a)</enum><header>Establishment</header><text>There
				is established within the Department a National Center for Cybersecurity and
				Communications.</text>
								</subsection><subsection id="idC2539E84D3FE42A697127DDB2673352A"><enum>(b)</enum><header>Transfer of
				functions</header><text>There are transferred to the Center the National Cyber
				Security Division, the Office of Emergency Communications, and the National
				Communications System, including all the functions, personnel, assets,
				authorities, and liabilities of the National Cyber Security Division, the
				Office of Emergency Communications, and the National Communications
				System.</text>
								</subsection><subsection id="IDb055cd267e424515bb0e03479ed1e82f"><enum>(c)</enum><header>Director</header><text>The
				Center shall be headed by a Director, who shall be appointed by the President,
				by and with the advice and consent of the Senate, and who shall report directly
				to the Secretary.</text>
								</subsection><subsection id="ID73f62147da414b1280ad9c0240a23072"><enum>(d)</enum><header>Duties</header><text>The
				Director of the Center shall—</text>
									<paragraph id="IDe6881c60ac464b82814d475d54720636"><enum>(1)</enum><text>manage Federal
				efforts to secure, protect, and ensure the resiliency of the Federal
				information infrastructure, national information infrastructure, and national
				security and emergency preparedness communications infrastructure of the United
				States, working cooperatively with appropriate government agencies and the
				private sector;</text>
									</paragraph><paragraph id="IDa74bd8cc0a12446b883ce1f44eafe66f"><enum>(2)</enum><text>support private
				sector efforts to secure, protect, and ensure the resiliency of the national
				information infrastructure;</text>
									</paragraph><paragraph id="IDff82e1ef522a4a6fab394be0fbda8082"><enum>(3)</enum><text>prioritize the
				efforts of the Center to address the most significant risks and incidents that
				have caused or are likely to cause damage to the Federal information
				infrastructure, the national information infrastructure, and national security
				and emergency preparedness communications infrastructure of the United
				States;</text>
									</paragraph><paragraph id="ID29c4433f6f6940c69b39d9df856bffd9"><enum>(4)</enum><text>ensure, in
				coordination with the privacy officer designated under subsection (j), the
				privacy officer appointed under section 222, and the Director of the Office of
				Civil Rights and Civil Liberties appointed under section 705, that the
				activities of the Center comply with all policies, regulations, and laws
				protecting the privacy and civil liberties of United States persons; and</text>
									</paragraph><paragraph id="ID103f223636204bc8991e4f10fea882e2"><enum>(5)</enum><text>perform such
				other duties as the Secretary may require relating to the security and
				resiliency of the Federal information infrastructure, national information
				infrastructure, and the national security and emergency preparedness
				communications infrastructure of the United States.</text>
									</paragraph></subsection><subsection id="ID3a5f38d98dc4433d9d813018caff4a67"><enum>(e)</enum><header>Authorities and
				responsibilities of Center</header><text>The Center shall—</text>
									<paragraph id="ID9d83ddb6374e4bc1a1bc2cd10bdbb78e"><enum>(1)</enum><text>engage in
				activities and otherwise coordinate Federal efforts to identify, protect
				against, remediate, and mitigate, respond to, and recover from cybersecurity
				threats, consequences, vulnerabilities and incidents impacting the Federal
				information infrastructure and the national information infrastructure,
				including by providing support to entities that own or operate national
				information infrastructure, at their request;</text>
									</paragraph><paragraph id="ID5d14bdc10e814caebeaf193046c1c259"><enum>(2)</enum><text>conduct
				risk-based assessments of the Federal information infrastructure, and risk
				assessments of critical infrastructure;</text>
									</paragraph><paragraph id="ID84cd52a5981144d298ca39f7e26c8468"><enum>(3)</enum><text>develop, oversee
				the implementation of, and enforce policies, principles, and guidelines on
				information security for the Federal information infrastructure, including
				exercise of the authorities under the Federal Information Security Management
				Act of 2002 (title III of Public Law 107–347; 116 Stat. 2946);</text>
									</paragraph><paragraph id="IDc2830bf003894e6a8a66a5a3ca7bef6f"><enum>(4)</enum><text>evaluate and
				facilitate the adoption of technologies designed to enhance the protection of
				information infrastructure, including making such technologies available to
				entities that own or operate national information infrastructure, with or
				without reimbursement, as necessary to accomplish the purposes of this
				section;</text>
									</paragraph><paragraph id="idc7fca3894ea54befa328d56fb237dcd6"><enum>(5)</enum><text>oversee the
				responsibilities related to national security and emergency preparedness
				communications infrastructure, including the functions of the Office of
				Emergency Communications and the National Communications System;</text>
									</paragraph><paragraph id="id984080a656a6459fa5e7358b23b9c21b"><enum>(6)</enum><subparagraph commented="no" display-inline="yes-display-inline" id="idA99FDD649C684AF0860D2B8C3610F994"><enum>(A)</enum><text>maintain comprehensive
				situational awareness of the security of the Federal information infrastructure
				and the national information infrastructure for the purpose of enabling and
				supporting activities under subparagraph (e)(1); and</text>
										</subparagraph><subparagraph id="id782e3ced85ba40849dd870c0e7fae70e" indent="up1"><enum>(B)</enum><text>receive and distribute classified and
				unclassified information from and to entities that own or operate national
				information infrastructure to support efforts by such entities to secure such
				infrastructure and for enhancing overall situational awareness;</text>
										</subparagraph></paragraph><paragraph id="idd6d0a8bd00174857a3e6b0c996970a42"><enum>(7)</enum><text>serve as the
				focal point for, and foster collaboration between, the Federal Government,
				State and local governments, and private entities on matters relating to the
				security of the national information infrastructure;</text>
									</paragraph><paragraph id="ide479bd29bc06413abc67a63cd13b64bf"><enum>(8)</enum><text>develop, in
				coordination with the Assistant Secretary for Infrastructure Protection, other
				Federal agencies, the private sector, and State and local governments a
				national incident response plan that details the roles of Federal agencies,
				State and local governments, and the private sector, and coordinate national
				cyber incident response efforts;</text>
									</paragraph><paragraph id="ID646a9f9f340a46b9a51eec1fe9729ddd"><enum>(9)</enum><text>consult, in
				coordination with the Secretary of State, with appropriate international
				partners to enhance the security of the Federal information infrastructure,
				national information infrastructure, and information infrastructure located
				outside the United States the disruption of which could result in national or
				regional catastrophic damage in the United States;</text>
									</paragraph><paragraph id="ID28db696a01a2462e854d166baa4c8907"><enum>(10)</enum><text>coordinate the
				activities undertaken by Federal agencies to—</text>
										<subparagraph id="idF5CA0C025FB642B0B956C9626C5F6FAB"><enum>(A)</enum><text>protect Federal
				information infrastructure and national information infrastructure; and</text>
										</subparagraph><subparagraph id="id9B6659B1D11046779F72A2F4EDDEBCFF"><enum>(B)</enum><text>prepare the
				Nation to respond to, recover from, and mitigate against risks of incidents
				involving such infrastructure; and</text>
										</subparagraph></paragraph><paragraph id="ID4aa98d1b01364be3b143539703379216"><enum>(11)</enum><text>perform such
				other duties as the Secretary may require relating to the security and
				resiliency of the Federal information infrastructure, national information
				infrastructure, and national security and emergency preparedness communications
				infrastructure of the United States.</text>
									</paragraph></subsection><subsection id="ID2dac4f54b3e34ff4b2b363943ae2c253"><enum>(f)</enum><header>Use of existing
				mechanisms for collaboration</header><text>To avoid unnecessary duplication or
				waste, in carrying out the authorities and responsibilities of the Center under
				this subtitle, to the maximum extent practicable, the Director of the Center
				shall make use of existing mechanisms for collaboration and information
				sharing, including mechanisms relating to the identification and communication
				of cybersecurity threats, vulnerabilities, and associated consequences,
				established by other components of the Department or other Federal agencies and
				the information sharing mechanisms established under title VII of the
				<short-title>Cybersecurity Act of
				2012</short-title>.</text>
								</subsection><subsection id="IDab0ef478b41d45048ab512ed62640761"><enum>(g)</enum><header>Deputy
				directors</header>
									<paragraph id="IDfba6ab460fa34f1ebfa2924a6eb88aeb"><enum>(1)</enum><header>In
				general</header><text>There shall be a Deputy Director appointed by the
				Secretary, who shall—</text>
										<subparagraph id="idEB72103A2610443AA6F8A82329495A6F"><enum>(A)</enum><text>have expertise in
				infrastructure protection; and</text>
										</subparagraph><subparagraph id="id4B05E388412A4E7F95710BBA3486D35A"><enum>(B)</enum><text>ensure that the
				operations of the Center and the Office of Infrastructure Protection avoid
				duplication and use, to the maximum extent practicable, joint mechanisms for
				information sharing and coordination with the private sector.</text>
										</subparagraph></paragraph><paragraph id="IDadde2986206e4bf9918e3555df3f7b64"><enum>(2)</enum><header>Intelligence
				community</header><text>The Director of National Intelligence, with the
				concurrence of the Secretary, shall identify an employee of an element of the
				intelligence community to serve as a Deputy Director of the Center. The
				employee shall be detailed to the Center on a reimbursable basis for such
				period as is agreed to by the Director of the Center and the Director of
				National Intelligence, and, while serving as Deputy Director, shall report
				directly to the Director of the Center.</text>
									</paragraph></subsection><subsection id="ID5910803aacfe4d9b8be2c1ef27fc2aa4"><enum>(h)</enum><header>Cybersecurity
				exercise program</header><text>The Director of the Center shall develop and
				implement a national cybersecurity exercise program with the participation of
				State and local governments, international partners of the United States, and
				the private sector.</text>
								</subsection><subsection id="ID9a3e95bbf1a1468ab56ccfbc95b31bb4"><enum>(i)</enum><header>Liaison
				officers</header>
									<paragraph id="ID0497af533e30473a942dda01b4b9757a"><enum>(1)</enum><header>Required detail
				of liaison officers</header><text>The Secretary of Defense, the Attorney
				General, the Secretary of Commerce, and the Director of National Intelligence
				shall assign personnel to the Center to act as full-time liaisons.</text>
									</paragraph><paragraph id="ID137b7bee374a45bba591a0a2681eaa7e"><enum>(2)</enum><header>Optional detail
				of liaison officers</header><text>The head of any Federal agency not described
				in paragraph (1), with the concurrence of the Director of the Center, may
				assign personnel to the Center to act as liaisons.</text>
									</paragraph><paragraph id="ID96ea22d4b441496087c000eb7cc88e34"><enum>(3)</enum><header>Private sector
				liaison</header><text>The Director of the Center shall designate not less than
				1 employee of the Center to serve as a liaison with the private sector.</text>
									</paragraph></subsection><subsection id="ID72415d2f62e64ec6847848e061e7ee2f"><enum>(j)</enum><header>Privacy
				officer</header><text>The Director of the Center, in consultation with the
				Secretary, shall designate a full-time privacy officer.</text>
								</subsection><subsection id="ID30f3835fc3a5453a849d7d27be16c899"><enum>(k)</enum><header>Sufficiency of
				resources plan</header>
									<paragraph id="ID46cd8eb686ba4282b3c442edb2ad1693"><enum>(1)</enum><header>Report</header><text>Not
				later than 120 days after the date of enactment of the
				<short-title>Cybersecurity Act of 2012</short-title>, the
				Director of the Office of Management and Budget shall submit to the appropriate
				committees of Congress and the Comptroller General of the United States a
				report on the resources and staff necessary to carry out fully the
				responsibilities under this subtitle, including the availability of existing
				resources and staff.</text>
									</paragraph><paragraph id="ID9923811ba740441dbf36663bc499eedd"><enum>(2)</enum><header>Comptroller
				general review</header><text>The Comptroller General of the United States shall
				evaluate the reasonableness and adequacy of the report submitted by the
				Director of the Office of Management and Budget under paragraph (1) and submit
				to the appropriate committees of Congress a report regarding the same.</text>
									</paragraph></subsection><subsection id="id4019B24D17D94879B769F1E197DC2038"><enum>(l)</enum><header>No right or
				benefit</header><text>The provision of assistance or information under this
				section to governmental or private entities that own or operate critical
				infrastructure shall be at the discretion of the Secretary. The provision of
				certain assistance or information to a governmental or private entity pursuant
				to this section shall not create a right or benefit, substantive or procedural,
				to similar assistance or information for any other governmental or private
				entity.</text>
								</subsection></section><section commented="no" id="ID75908c8914a845419cc2235c95d290a6"><enum>243.</enum><header>Department of
				Homeland Security information sharing</header>
								<subsection id="IDfbca5de454a14909853ebadbd9813c2b"><enum>(a)</enum><header>Information
				sharing</header><text>The Director of the Center shall establish procedures
				to—</text>
									<paragraph id="id85AA29F9547A4B1A8EACE3BD7BF501CA"><enum>(1)</enum><text>ensure the
				appropriate, regular, and timely sharing of classified and unclassified
				cybersecurity information, including information relating to threats,
				vulnerabilities, traffic, trends, incidents, and other anomalous activities
				that affect the Federal information infrastructure, national information
				infrastructure, or information systems between and among appropriate Federal
				and non-Federal entities, including Federal cybersecurity centers, Federal and
				non-Federal network and security operations centers, cybersecurity exchanges,
				and non-Federal entities responsible for such information systems;</text>
									</paragraph><paragraph id="idCF738A59D70F4F1E845DD4BB7FA2EE4F"><enum>(2)</enum><text>expand and
				enhance the sharing of timely and actionable cybersecurity threat and
				vulnerability information by the Federal Government with owners and operators
				of the national information infrastructure;</text>
									</paragraph><paragraph id="idFCBEE6CB0B78483CA2363829203B502E"><enum>(3)</enum><text>establish a
				method of accessing classified or unclassified information, as appropriate and
				in accordance with applicable laws protecting trade secrets, that will provide
				situational awareness of the security of the Federal information infrastructure
				and the national information infrastructure relating to cybersecurity threats,
				and vulnerabilities, including traffic, trends, incidents, damage, and other
				anomalous activities affecting the Federal information infrastructure or the
				national information infrastructure;</text>
									</paragraph><paragraph id="idd80fc46e87434194b7d462d656acf60b"><enum>(4)</enum><text>develop, in
				consultation with the Attorney General, the Director of National Intelligence,
				and the privacy officer established under section 242(j), guidelines to protect
				the privacy and civil liberties of United States persons and intelligence
				sources and methods, while carrying out this subsection; and</text>
									</paragraph><paragraph id="id6d16e0c20e514e08b69d85e1f788a73b"><enum>(5)</enum><text>ensure, to the
				extent necessary, that any information sharing under this section is consistent
				with title VII of the Cybersecurity Act of 2012.</text>
									</paragraph></subsection><subsection id="idD29A4E9EBC4B4DE2970D078A5498CDA9"><enum>(b)</enum><header>Voluntarily
				shared information</header>
									<paragraph id="id94ef2d8b3ec7410998902146bd711a1f"><enum>(1)</enum><header>In
				general</header><text>The Director of the Center shall ensure that information
				submitted in accordance with this section by States and units of local
				governments, private entities, and international partners of the United States
				regarding threats, vulnerabilities, incidents, and anomalous activities
				affecting the national information infrastructure, Federal information
				infrastructure, or information infrastructure that is owned, operated,
				controlled, or licensed solely for use by, or on behalf of, the Department of
				Defense, a military department, or another element of the intelligence
				community is treated as voluntarily shared critical infrastructure information
				under section 214 as requested by submitting entities.</text>
									</paragraph><paragraph id="id0F50A255BA054FA9A36C0C611132FE70"><enum>(2)</enum><header>Limitation</header><text>Paragraph
				(1) shall not apply to information that is submitted to—</text>
										<subparagraph id="idA0E105970B5844908DD01E63239F9CC7"><enum>(A)</enum><text>conceal
				violations of law, inefficiency, or administrative error;</text>
										</subparagraph><subparagraph id="idb968bd52e914424e9f1d58331b9408c0"><enum>(B)</enum><text>prevent
				embarrassment to a person, organization, or agency; or</text>
										</subparagraph><subparagraph id="idab47c3166eee4876b50be3074e1125eb"><enum>(C)</enum><text>interfere with
				competition in the private sector.</text>
										</subparagraph></paragraph></subsection><subsection id="id2B84B471789D451B96221A3E45A2D97A"><enum>(c)</enum><header>Limitation on
				use of voluntarily submitted information for regulatory enforcement
				actions</header><text>A Federal entity may not use information submitted under
				this subtitle as evidence in a regulatory enforcement action against the
				individual or entity that lawfully submitted the information.</text>
								</subsection><subsection id="IDd5e28ee3c9f54ed4b28b1494740712b6"><enum>(d)</enum><header>Federal
				agencies</header>
									<paragraph id="ID615ef4b5c927443991a03655ec2ca879"><enum>(1)</enum><header>Information
				sharing program</header><text>The Director of the Center, in consultation with
				the members of the Chief Information Officers Council established under section
				3603 of title 44, United States Code, shall establish a program for sharing
				information with and between the Center and other Federal agencies that
				includes processes and procedures—</text>
										<subparagraph id="IDa0f9ebb146184fad8d517feef4b1bb07"><enum>(A)</enum><text>under which the
				Director of the Center regularly shares with each Federal agency analyses and
				reports regarding the security of such agency information infrastructure and on
				the overall security of the Federal information infrastructure and information
				infrastructure that is owned, operated, controlled, or licensed for use by, or
				on behalf of, the Department of Defense, a military department, or another
				element of the intelligence community, which shall include means and methods of
				preventing, responding to, mitigating, and remediating cybersecurity threats
				and vulnerabilities; and</text>
										</subparagraph><subparagraph id="ID207d0b1580ea44a1bacd34fc60c3ae82"><enum>(B)</enum><text>under which
				Federal agencies provide the Director of the Center, upon request, with
				information concerning the security of the Federal information infrastructure,
				information infrastructure that is owned, operated, controlled, or licensed for
				use by, or on behalf of, the Department of Defense, a military department, or
				another element of the intelligence community, or the national information
				infrastructure necessary to carry out the duties of the Director of the Center
				under this subtitle or any other provision of law.</text>
										</subparagraph></paragraph><paragraph id="ID0e003529f8064bd4a3827be9e9b41d76"><enum>(2)</enum><header>Access to
				information</header>
										<subparagraph id="id4EEACF033B07469991A5694D329ECE91"><enum>(A)</enum><header>In
				general</header><text>The Director of the Center shall ensure—</text>
											<clause id="id332322D3D61D4A5A827613E504F74AFB"><enum>(i)</enum><text>that the head of
				each Federal agency has timely access to data, including appropriate raw and
				processed data, regarding the information infrastructure of the Federal agency;
				and</text>
											</clause><clause id="idF8AF96F4F89147FA97E50DDECF8B7BF4"><enum>(ii)</enum><text>to the greatest
				extent possible, that the head of each Federal agency is kept apprised of
				common trends in security compliance as well as the likelihood that a
				significant cybersecurity risk or incident could cause damage to the agency
				information infrastructure.</text>
											</clause></subparagraph><subparagraph id="ID1609b74f2b644bb09331c6216c1ba35a"><enum>(B)</enum><header>Compliance</header><text>The
				head of a Federal agency shall comply with all processes and procedures
				established under this subsection regarding notification to the Director of the
				Center relating to incidents.</text>
										</subparagraph><subparagraph id="IDbde08cae6170453691eefba845e24c4f"><enum>(C)</enum><header>Immediate
				notification required</header><text>Unless otherwise directed by the President,
				any Federal agency with a national security system shall, consistent with the
				level of the risk, immediately notify the Director of the Center regarding any
				incident affecting the security of a national security system.</text>
										</subparagraph></paragraph></subsection></section><section id="ID5c0cf4ce3d51475281b45d9b441cea20"><enum>244.</enum><header>Prohibited
				conduct</header><text display-inline="no-display-inline">None of the
				authorities provided under this subtitle shall authorize the Director of the
				Center, the Center, the Department, or any other Federal entity to—</text>
								<paragraph id="IDc38632db32654daebc84cb794e6b4804"><enum>(1)</enum><text>compel the
				disclosure of information from a private entity relating to an incident unless
				otherwise authorized by law; or</text>
								</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDd582dae0099748a499034e44af2206c1"><enum>(2)</enum><text>intercept a wire,
				oral, or electronic communication (as those terms are defined in section 2510
				of title 18, United States Code), access a stored electronic or wire
				communication, install or use a pen register or trap and trace device, or
				conduct electronic surveillance (as defined in section 101 of the Foreign
				Intelligence Surveillance Act of 1978 (50 U.S.C.1801)) relating to an incident
				unless otherwise authorized under chapter 119, chapter 121, or chapter 206 of
				title 18, United States Code, or the Foreign Intelligence Surveillance Act of
				1978 (50 U.S.C. 1801 et
				seq.).</text>
								</paragraph></section></subtitle><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="id0A024693C1634757A124899203CC552A"><enum>(b)</enum><header>Technical and
			 conforming amendment</header><text>The table of contents in section 1(b) of the
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended by inserting
			 after the item relating to section 237 the following:</text>
					<quoted-block id="idd401f40a-3f5c-4f7f-83f6-a8630a37b9be" style="OLC">
						<toc>
							<toc-entry idref="id5D00954CBF94409B93D467C1233E5508" level="subtitle">Subtitle E—Cybersecurity</toc-entry>
							<toc-entry idref="ID1bda65c3690248ffa8b0f77639df8253" level="section">Sec. 241. Definitions.</toc-entry>
							<toc-entry idref="idA2F947FA68CC42F6AE2E911520EF7FD6" level="section">Sec. 242. Consolidation of existing resources.</toc-entry>
							<toc-entry idref="ID75908c8914a845419cc2235c95d290a6" level="section">Sec. 243. Department of Homeland Security information
				sharing.</toc-entry>
							<toc-entry idref="ID5c0cf4ce3d51475281b45d9b441cea20" level="section">Sec. 244. Prohibited
				conduct.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section></title><title id="id2487DB755B2240DA9CB1C2F2F611FC0D"><enum>III</enum><header>Research and
			 development</header>
			<section id="idEEC57A3DCAF148769074670062EBE0B9"><enum>301.</enum><header>Federal
			 cybersecurity research and development</header>
				<subsection id="id8E726D8005E34FB1A59C9F6320DD1FAE"><enum>(a)</enum><header>Fundamental
			 cybersecurity research</header><text>The Director of the Office of Science and
			 Technology Policy (referred to in this section as the <term>Director</term>),
			 in coordination with the Secretary and the head of any relevant Federal agency,
			 shall build upon programs and plans in effect as of the date of enactment of
			 this Act to develop a national cybersecurity research and development plan,
			 which shall be updated biennially.</text>
				</subsection><subsection id="id6F6D304833C844F9910129B4B67EC392"><enum>(b)</enum><header>Requirements</header><text>The
			 plan required to be developed under subsection (a) shall encourage computer and
			 information science and engineering research to meet challenges in
			 cybersecurity, including—</text>
					<paragraph id="ID843ab44af9de4c5fb9e7e0187a75ab76"><enum>(1)</enum><text>how to design and
			 build complex software-intensive systems that are secure and reliable when
			 first deployed;</text>
					</paragraph><paragraph id="ID5f9e5f09980d42d892bf42377858bd42"><enum>(2)</enum><text>how to test and
			 verify that software, whether developed locally or obtained from a third party,
			 is free of significant known security flaws;</text>
					</paragraph><paragraph id="ID4915495f8d30404b99cbd4e82b9831f4"><enum>(3)</enum><text>how to test and
			 verify that software obtained from a third party correctly implements stated
			 functionality, and only that functionality;</text>
					</paragraph><paragraph id="ID78135b5875ad4f3b90a11ddccb35a54b"><enum>(4)</enum><text>how to guarantee
			 the privacy of the identity, information, or lawful transactions of an
			 individual when stored in distributed systems or transmitted over
			 networks;</text>
					</paragraph><paragraph id="ID64b95672d7b44c29a822b5d2ad3e80e9"><enum>(5)</enum><text>how to build new
			 protocols to enable the Internet to have robust security as one of the key
			 capabilities of the Internet;</text>
					</paragraph><paragraph id="ID05a3bb88e94f4d948d0d2c39bc53f540"><enum>(6)</enum><text>how to determine
			 the origin of a message transmitted over the Internet;</text>
					</paragraph><paragraph id="IDb578e3fad7944fc9b067148562fc9743"><enum>(7)</enum><text>how to support
			 privacy in conjunction with improved security;</text>
					</paragraph><paragraph id="ID59512de672f84d1491d59a068d03ad3f"><enum>(8)</enum><text>how to address
			 the growing problem of insider threat;</text>
					</paragraph><paragraph id="IDce5b53be6f5c4c0a99ff12612e927bcd"><enum>(9)</enum><text>how improved
			 consumer education and digital literacy initiatives can address human factors
			 that contribute to cybersecurity;</text>
					</paragraph><paragraph id="id5CC377B731364F5BB5398D6E0A308ABA"><enum>(10)</enum><text>how to protect
			 information stored through cloud computing or transmitted through wireless
			 services;</text>
					</paragraph><paragraph id="idD6C0E9ADC284488DBB0CC7EB15A46DB1"><enum>(11)</enum><text>conducting
			 research in the areas described in section 4(a)(1) of the Cyber Security
			 Research and Development Act (15 U.S.C. 7403(a)(1)), as amended by subsection
			 (f); and</text>
					</paragraph><paragraph id="idDD534D892AAF4FA59DEA0B53B863EAAA"><enum>(12)</enum><text>any additional
			 objectives the Director or Secretary determines appropriate.</text>
					</paragraph></subsection><subsection id="ID3b790cf724fc490995f4bb4d2830b671"><enum>(c)</enum><header>Cybersecurity
			 practices research</header><text>The Director of the National Science
			 Foundation shall support research—</text>
					<paragraph id="id9611C458828F4081B1BA97E83C6AE700"><enum>(1)</enum><text>that develops,
			 evaluates, disseminates, and integrates new cybersecurity practices and
			 concepts into the core curriculum of computer science programs and of other
			 programs where graduates of such programs have a substantial probability of
			 developing software after graduation, including new practices and concepts
			 relating to secure coding education and improvement programs; and</text>
					</paragraph><paragraph id="id494E132E3C744293893384999D63F014"><enum>(2)</enum><text>that develops new
			 models for professional development of faculty in cybersecurity education,
			 including secure coding development.</text>
					</paragraph></subsection><subsection id="ID111014632884401b90b27262b4f217f4"><enum>(d)</enum><header>Cybersecurity
			 modeling and test beds</header>
					<paragraph id="idF16463A906D745F5A4771FECB1AFD341"><enum>(1)</enum><header>Review</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Director shall
			 conduct a review of cybersecurity test beds in existence on the date of
			 enactment of this Act to inform the program established under paragraph
			 (2).</text>
					</paragraph><paragraph id="id87C9A62267A7440CAEBBDC0FA14A5541"><enum>(2)</enum><header>Establishment
			 of program</header>
						<subparagraph id="idd5dde573eda749af9620c7092a431d4c"><enum>(A)</enum><header>In
			 general</header><text>The Director of the National Science Foundation, the
			 Secretary, and the Secretary of Commerce shall establish a program for the
			 appropriate Federal agencies to award grants to institutions of higher
			 education or research and development non-profit institutions to establish
			 cybersecurity test beds capable of realistic modeling of real-time cyber
			 attacks and defenses.</text>
						</subparagraph><subparagraph id="idBC0DBA45C5464C19980C15797FB502E7"><enum>(B)</enum><header>Requirement</header><text>The
			 test beds established under subparagraph (A) shall be sufficiently large in
			 order to model the scale and complexity of real world networks and
			 environments.</text>
						</subparagraph></paragraph><paragraph id="id9F535A40932A4F72A9ECC2F8CA99F71F"><enum>(3)</enum><header>Purpose</header><text>The
			 purpose of the program established under paragraph (2) shall be to support the
			 rapid development of new cybersecurity defenses, techniques, and processes by
			 improving understanding and assessing the latest technologies in a real-world
			 environment.</text>
					</paragraph></subsection><subsection id="ID2a252ee596b241d28da1fc448b50d100"><enum>(e)</enum><header>Coordination
			 with other research initiatives</header><text>The Director shall to the extent
			 practicable, coordinate research and development activities under this section
			 with other ongoing research and development security-related initiatives,
			 including research being conducted by—</text>
					<paragraph id="ID89363ac10de847e88cd2a13b2e81f9d8"><enum>(1)</enum><text>the National
			 Institute of Standards and Technology;</text>
					</paragraph><paragraph id="id066A6E95A4044753956254B9E8A02D37"><enum>(2)</enum><text>the
			 Department;</text>
					</paragraph><paragraph id="IDb63fe4e1bbbb4de48cb80017ae41c72b"><enum>(3)</enum><text>other Federal
			 agencies;</text>
					</paragraph><paragraph id="ID135321f5529d4d418236dbbd1066b803"><enum>(4)</enum><text>other Federal and
			 private research laboratories, research entities, and universities and
			 institutions of higher education, and relevant nonprofit organizations;
			 and</text>
					</paragraph><paragraph id="ID646ca2fce56e40aea7035850a72a9409"><enum>(5)</enum><text>international
			 partners of the United States.</text>
					</paragraph></subsection><subsection id="ID21471d798bf44173833d85f48ae07834"><enum>(f)</enum><header>NSF computer
			 and network security research grant areas</header><text>Section 4(a)(1) of the
			 Cyber Security Research and Development Act (15 U.S.C. 7403(a)(1)) is
			 amended—</text>
					<paragraph id="IDc6fd9817701f4c1f9d51727cfb8053ca"><enum>(1)</enum><text>in subparagraph
			 (H), by striking <quote>and</quote> at the end;</text>
					</paragraph><paragraph id="ID985bd282064748d7a3c5cdf66258eee7"><enum>(2)</enum><text>in subparagraph
			 (I), by striking the period at the end and inserting a semicolon; and</text>
					</paragraph><paragraph id="ID89b226f5f32d40138afe9aa5745e2d7a"><enum>(3)</enum><text>by adding at the
			 end the following:</text>
						<quoted-block display-inline="no-display-inline" id="id9C20512255B9457595CB3CD45EAAC8CE" style="OLC">
							<subparagraph id="IDa2e059fb527c486eb9b9dae7a1a90eaf"><enum>(J)</enum><text>secure
				fundamental protocols that are at the heart of inter-network communications and
				data exchange;</text>
							</subparagraph><subparagraph id="IDf82b8e4d3ba841559f73aa2a2246d5d0"><enum>(K)</enum><text>secure software
				engineering and software assurance, including—</text>
								<clause id="IDec3d95622afb4c20880522ee5fa1ad2f"><enum>(i)</enum><text>programming
				languages and systems that include fundamental security features;</text>
								</clause><clause id="IDcb64a00630ab4eb5aad3fc2e32166791"><enum>(ii)</enum><text>portable or
				reusable code that remains secure when deployed in various environments;</text>
								</clause><clause id="ID860ad74b696940a182a32e391839c9fb"><enum>(iii)</enum><text>verification
				and validation technologies to ensure that requirements and specifications have
				been implemented; and</text>
								</clause><clause id="IDef348faa010241ca9a6f5c0c14e51bc5"><enum>(iv)</enum><text>models for
				comparison and metrics to assure that required standards have been met;</text>
								</clause></subparagraph><subparagraph id="IDae628e651a3748a3aa0dcd1686b7034e"><enum>(L)</enum><text>holistic system
				security that—</text>
								<clause id="ID43ac629532354dc0a57e6eb86f555468"><enum>(i)</enum><text>addresses the
				building of secure systems from trusted and untrusted components;</text>
								</clause><clause id="IDb2d2b9c5af32485287ff87f7a6ce7865"><enum>(ii)</enum><text>proactively
				reduces vulnerabilities;</text>
								</clause><clause id="IDcb20818837364e9c83828535d9d864dd"><enum>(iii)</enum><text>addresses
				insider threats; and</text>
								</clause><clause id="IDed6db707368946a0946ab39d626f9467"><enum>(iv)</enum><text>supports privacy
				in conjunction with improved security;</text>
								</clause></subparagraph><subparagraph id="ID0b7f68da7d094c8b9c50dba29869ed7a"><enum>(M)</enum><text>monitoring and
				detection;</text>
							</subparagraph><subparagraph id="ID06ab930278ca4cb4ba0af4c04d6c746e"><enum>(N)</enum><text>mitigation and
				rapid recovery methods;</text>
							</subparagraph><subparagraph id="id9DB10382D9F94DCF8DFC91A31CC91A2D"><enum>(O)</enum><text>security of
				wireless networks and mobile devices; and</text>
							</subparagraph><subparagraph id="id2FC160104746426D9ED5C65004A5626F"><enum>(P)</enum><text>security of cloud
				infrastructure and
				services.</text>
							</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection><subsection id="ID6b7af1138eb74e479a645d761a43ea0b"><enum>(g)</enum><header>Cybersecurity
			 faculty development traineeship program</header><text>Section 5(e)(9) of the
			 Cyber Security Research and Development Act (15 U.S.C. 7404(e)(9)) is amended
			 by striking <quote>2003 through 2007</quote> and inserting <quote>2012 through
			 2014</quote>.</text>
				</subsection><subsection id="ID6557a9a487f74628b219d328d408074a"><enum>(h)</enum><header>Networking and
			 information technology research and development program</header><text>Section
			 204(a)(1) of the High-Performance Computing Act of 1991 (15 U.S.C. 5524(a)(1))
			 is amended—</text>
					<paragraph id="IDec37c3d7065e4d1e8a1a5ddedf958bb6"><enum>(1)</enum><text>in subparagraph
			 (B), by striking <quote>and</quote> at the end; and</text>
					</paragraph><paragraph id="ID59129442e3584e68902d392578950de2"><enum>(2)</enum><text>by adding at the
			 end the following:</text>
						<quoted-block display-inline="no-display-inline" id="idC9B74A3E005B42BE83322261D8438826" style="OLC">
							<subparagraph id="ID198979cd7156497fa498c1f37cf048e9"><enum>(D)</enum><text>develop and
				propose standards and guidelines, and develop measurement techniques and test
				methods, for enhanced cybersecurity for computer networks and common user
				interfaces to systems;
				and</text>
							</subparagraph><after-quoted-block>.</after-quoted-block></quoted-block>
					</paragraph></subsection></section><section id="id21267FF88F3F4BCA90A5249056D20D28"><enum>302.</enum><header>Homeland
			 security cybersecurity research and development</header>
				<subsection id="id1D6E090DD143463693414DCCC60A4423"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Subtitle D of title
			 II of the Homeland Security Act of 2002 (6 U.S.C. 161 et seq.) is amended by
			 adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="idA55877285EEB491E9D3211097BC4795D" style="OLC">
						<section id="id1905FC111CFA48C8A070E2B51D950C1C"><enum>238.</enum><header>Cybersecurity
				research and development</header>
							<subsection id="idF3F1334581ED48E7881EDCD06B9866C2"><enum>(a)</enum><header>Establishment
				of research and development program</header><text>The Under Secretary for
				Science and Technology, in coordination with the Director of the National
				Center for Cybersecurity and Communications, shall carry out a research and
				development program for the purpose of improving the security of information
				infrastructure.</text>
							</subsection><subsection id="idE16D5EBA2E184A7C93B5B1680604E7C6"><enum>(b)</enum><header>Eligible
				projects</header><text>The research and development program carried out under
				subsection (a) may include projects to—</text>
								<paragraph id="id6704C1BFAC3246358C18213A7591AB79"><enum>(1)</enum><text>advance the
				development and accelerate the deployment of more secure versions of
				fundamental Internet protocols and architectures, including for the secure
				domain name addressing system and routing security;</text>
								</paragraph><paragraph id="id7D4D08B7C322422DB7A50875EAB73431"><enum>(2)</enum><text>improve and
				create technologies for detecting and analyzing attacks or intrusions,
				including analysis of malicious software;</text>
								</paragraph><paragraph id="idB4699976BCD34BE494838DDB38A4D291"><enum>(3)</enum><text>improve and
				create mitigation and recovery methodologies, including techniques for
				containment of attacks and development of resilient networks and
				systems;</text>
								</paragraph><paragraph id="id1094A899ED2E4A0496BFFBF9362BD355"><enum>(4)</enum><text>develop and
				support infrastructure and tools to support cybersecurity research and
				development efforts, including modeling, test beds, and data sets for
				assessment of new cybersecurity technologies;</text>
								</paragraph><paragraph id="id88853C9E2C9040E7AFB537441B43B310"><enum>(5)</enum><text>assist the
				development and support of technologies to reduce vulnerabilities in process
				control systems;</text>
								</paragraph><paragraph id="id12DD0389FB3C41EB8EA6E195E797A17F"><enum>(6)</enum><text>understand human
				behavioral factors that can affect cybersecurity technology and
				practices;</text>
								</paragraph><paragraph id="id5244F74861ED4D15B2829DE132CB0EC8"><enum>(7)</enum><text>test, evaluate,
				and facilitate, with appropriate protections for any proprietary information
				concerning the technologies, the transfer of technologies associated with the
				engineering of less vulnerable software and securing the information technology
				software development lifecycle;</text>
								</paragraph><paragraph id="id77BEC247B513448E8DE1AC71CCDD1DC9"><enum>(8)</enum><text>assist the
				development of identity management and attribution technologies;</text>
								</paragraph><paragraph id="id16D0337FAC6F4C9BBC296AD426B25DDD"><enum>(9)</enum><text>assist the
				development of technologies designed to increase the security and resiliency of
				telecommunications networks;</text>
								</paragraph><paragraph id="idE262A7F1DEAF433BA8321EAF805CB315"><enum>(10)</enum><text>advance the
				protection of privacy and civil liberties in cybersecurity technology and
				practices; and</text>
								</paragraph><paragraph id="idC7C9FDB9692E4C1FAFDC5A5BBD3D8782"><enum>(11)</enum><text>address other
				risks identified by the Director of the National Center for Cybersecurity and
				Communications.</text>
								</paragraph></subsection><subsection id="idDF3FDD1C8F7A40669425C9129AE304C1"><enum>(c)</enum><header>Coordination
				with other research initiatives</header><text>The Under Secretary for Science
				and Technology—</text>
								<paragraph id="idD4FD380D46AF428C8709F8AE830102D7"><enum>(1)</enum><text>shall ensure that
				the research and development program carried out under subsection (a) is
				consistent with any strategy to increase the security and resilience of
				cyberspace;</text>
								</paragraph><paragraph id="id0AABBA38ADEB47C4A568A58B983C6A40"><enum>(2)</enum><text>shall, to the
				extent practicable, coordinate the research and development activities of the
				Department with other ongoing research and development security-related
				initiatives, including research being conducted by—</text>
									<subparagraph id="id82FEC5CA6340474A927F19EDAAD96DEE"><enum>(A)</enum><text>the National
				Institute of Standards and Technology;</text>
									</subparagraph><subparagraph id="id0E18F599BFFD449AA1CAD57997B4A992"><enum>(B)</enum><text>the National
				Science Foundation;</text>
									</subparagraph><subparagraph id="idB4511D2231364990A320D100137C3253"><enum>(C)</enum><text>the National
				Academy of Sciences;</text>
									</subparagraph><subparagraph id="id9848CD1A7B644716A25BA92556AC2313"><enum>(D)</enum><text>other Federal
				agencies;</text>
									</subparagraph><subparagraph id="id3326ED43FBF441AF8395135D648AB352"><enum>(E)</enum><text>other Federal and
				private research laboratories, research entities, and universities and
				institutions of higher education, and relevant nonprofit organizations;
				and</text>
									</subparagraph><subparagraph id="idAD0F3652E5D84F9C99BA5D477E23991B"><enum>(F)</enum><text>international
				partners of the United States;</text>
									</subparagraph></paragraph><paragraph id="id72A6243C845C4C98A7D2FD15F45FDF87"><enum>(3)</enum><text>shall carry out
				any research and development project under subsection (a) through a
				reimbursable agreement with an appropriate Federal agency, if the Federal
				agency—</text>
									<subparagraph id="id3D0529DFC1164605B2BF4B40E4B71D3D"><enum>(A)</enum><text>is sponsoring a
				research and development project in a similar area; or</text>
									</subparagraph><subparagraph id="id8F7DD5959AAD4BD7834D25F2A034E651"><enum>(B)</enum><text>has a unique
				facility or capability that would be useful in carrying out the project;</text>
									</subparagraph></paragraph><paragraph id="idE8E059D310CD4ADFA0781EFD0DA5FACE"><enum>(4)</enum><text>may make grants
				to, or enter into cooperative agreements, contracts, other transactions, or
				reimbursable agreements with, the entities described in paragraph (2);
				and</text>
								</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idA5D50CA40A9048669202E58E375D9547"><enum>(5)</enum><text>shall submit a
				report to the appropriate committees of Congress on a review of the
				cybersecurity activities, and the capacity, of the national laboratories and
				other research entities available to the Department to determine if the
				establishment of a national laboratory dedicated to cybersecurity research and
				development is
				necessary.</text>
								</paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="idDAFF1CC444F446EEB4C3D3AF33897783"><enum>(b)</enum><header>Technical and
			 conforming amendment</header><text>The table of contents in section 1(b) of the
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq.), as amended by section
			 204, is amended by inserting after the item relating to section 237 the
			 following:</text>
					<quoted-block display-inline="no-display-inline" id="idF2AE3C6B3A4B44D5975072466342F6E5" style="OLC">
						<toc>
							<toc-entry bold="off" level="section">Sec. 238. Cybersecurity
				research and
				development.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section><section id="id1af83532462c432f9cf9b9b9ba9e9ef1"><enum>303.</enum><header>Research
			 centers for cybersecurity</header>
				<subsection id="id5103224397d942059d372ede7c94b210"><enum>(a)</enum><header>Establishment</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Director of the
			 National Science Foundation, in coordination with the Secretary, shall
			 establish cybersecurity research centers based at institutions of higher
			 education and other entities that meet the criteria described in subsection (b)
			 to develop solutions and strategies that support the efforts of the Federal
			 government under this Act in—</text>
					<paragraph id="idD30C527057C449C3BEE7BEED8B4D1899"><enum>(1)</enum><text>improving the
			 security and resilience of information infrastructure;</text>
					</paragraph><paragraph id="id2175BF2D495F4A90AD7C49551E5BA72F"><enum>(2)</enum><text>reducing cyber
			 vulnerabilities; and</text>
					</paragraph><paragraph id="idCE8887C399874938AFC537E5580FA1F8"><enum>(3)</enum><text>mitigating the
			 consequences of cyber attacks on critical infrastructure.</text>
					</paragraph></subsection><subsection id="id76daa4e067684b07ab303cb26304ed58"><enum>(b)</enum><header>Criteria for
			 selection</header><text>In selecting an institution of higher education or
			 other entity to serve as a Research Center for Cybersecurity, the Director of
			 the National Science Foundation shall consider—</text>
					<paragraph id="id700f00137bfe42f1b79a8af85c22b878"><enum>(1)</enum><text>demonstrated
			 expertise in systems security, wireless security, networking and protocols,
			 formal methods and high-performance computing, nanotechnology, and industrial
			 control systems;</text>
					</paragraph><paragraph id="id3ff75282ec51420a8bb17915fd6ba624"><enum>(2)</enum><text>demonstrated
			 capability to conduct high performance computation integral to complex
			 cybersecurity research, whether through on-site or off-site computing;</text>
					</paragraph><paragraph id="id28097e3cc89045c2bae3f9f37c6cb0c6"><enum>(3)</enum><text>demonstrated
			 expertise in interdisciplinary cybersecurity research;</text>
					</paragraph><paragraph id="id1416dba173f240f69a3083ae991048d6"><enum>(4)</enum><text>affiliation with
			 private sector entities involved with industrial research described in
			 paragraph (1) and ready access to testable commercial data;</text>
					</paragraph><paragraph id="id7f7c694f7d5e4fc3bc84bcef8e40178c"><enum>(5)</enum><text>prior formal
			 research collaboration arrangements with institutions of higher education and
			 Federal research laboratories;</text>
					</paragraph><paragraph id="id30e37d2962ca488ba7e8823ee283b61e"><enum>(6)</enum><text>capability to
			 conduct research in a secure environment; and</text>
					</paragraph><paragraph id="idd45c5fbb3b414c568e56df4d2e37dd18"><enum>(7)</enum><text>affiliation with
			 existing research programs of the Federal Government.</text>
					</paragraph></subsection></section><section id="id7321EF5586294BC592054FED78C4F7DC"><enum>304.</enum><header>Centers of
			 excellence</header><text display-inline="no-display-inline">The Secretary and
			 the Secretary of Defense may jointly establish academic and professional
			 Centers of Excellence in cybersecurity for the protection of critical
			 infrastructure in conjunction with international academic and professional
			 partners from countries that may include allies of the United States, as
			 determined to be appropriate under title XIX of the Implementing
			 Recommendations of the 9/11 Commission Act of 2007 (Public Law 110–53; 121
			 Stat. 505) in order to research and develop technologies, best practices, and
			 other means to defend critical infrastructure.</text>
			</section></title><title id="id9e0069282f494ca08395913d6d91ef59"><enum>IV</enum><header>Education,
			 workforce, and awareness</header>
			<section id="idd17e422beb2346b2a39fab74e4ec2a77"><enum>401.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="idb771db04596b4c7f8edcb531f316f94b"><enum>(1)</enum><header>Cybersecurity
			 mission</header><text>The term <term>cybersecurity mission</term> means
			 activities that encompass the full range of threat reduction, vulnerability
			 reduction, deterrence, international engagement, incident response, resiliency,
			 and recovery policies and activities, including computer network operations,
			 information assurance, law enforcement, diplomacy, military, and intelligence
			 missions as such activities relate to the security and stability of
			 cyberspace.</text>
				</paragraph><paragraph id="id0b42703f7bf94d77af1417bb05ddf00a"><enum>(2)</enum><header>Cybersecurity
			 mission of a federal agency</header><text>The term <term>cybersecurity mission
			 of a Federal agency</term> means the portion of a cybersecurity mission that is
			 the responsibility of a Federal agency.</text>
				</paragraph></section><section id="idA2C088BFDFDE409C9539B8D7328255EE"><enum>402.</enum><header>Education and
			 awareness</header>
				<subsection id="id01FB89E38E4F4572A59BBAC3EDDB83BC"><enum>(a)</enum><header>Assessment of
			 cybersecurity education in colleges and universities</header>
					<paragraph id="id656DBAC0CEBB44E6A3B1B3BAD235A50E"><enum>(1)</enum><header>Report</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Director of the
			 National Science Foundation shall submit to the Committee on Commerce, Science,
			 and Transportation of the Senate and the Committee on Science, Space, and
			 Technology of the House of Representatives a report on the state of
			 cybersecurity education in institutions of higher education in the United
			 States.</text>
					</paragraph><paragraph id="idA17ECE9D286A4FD7A7C661953055A986"><enum>(2)</enum><header>Contents of
			 report</header><text>The report required under paragraph (1) shall include
			 baseline data on—</text>
						<subparagraph id="id731C814565A34F67AE6F90F9B18392FC"><enum>(A)</enum><text>the state of
			 cybersecurity education in the United States;</text>
						</subparagraph><subparagraph id="id831E811D740146DCA380FFF60EB62674"><enum>(B)</enum><text>the extent of
			 professional development opportunities for faculty in cybersecurity principles
			 and practices;</text>
						</subparagraph><subparagraph id="id31B1C1F9DC0B4B51A20FC48BC3BA42BE"><enum>(C)</enum><text>descriptions of
			 the content of cybersecurity courses in undergraduate computer science
			 curriculum;</text>
						</subparagraph><subparagraph id="idF4EEFEE07B304166BE83A110F4582500"><enum>(D)</enum><text>the extent of the
			 partnerships and collaborative cybersecurity curriculum development activities
			 that leverage industry and government needs, resources, and tools; and</text>
						</subparagraph><subparagraph id="id6C87BE69061944DBBC0035577C28A1ED"><enum>(E)</enum><text>proposed metrics
			 to assess progress toward improving cybersecurity education.</text>
						</subparagraph></paragraph></subsection><subsection id="id68746260E96D49B2B65DA31D059DE35C"><enum>(b)</enum><header>Enrichment
			 programs</header><text>The Director of the National Science Foundation
			 shall—</text>
					<paragraph id="ida018876867ec4a0fa8d46883f9fef8e0"><enum>(1)</enum><text>encourage and
			 support programming, including summer enrichment programs, to be provided by
			 nonprofit organizations, in math, computer programming, science, technology,
			 and engineering, with a goal of increasing cybersecurity skills in students
			 enrolled in kindergarten through grade 12; and</text>
					</paragraph><paragraph id="id7fd2c00f5c1e4c02bbf48d5cdb7174d2"><enum>(2)</enum><text>when appropriate,
			 provide opportunities for top-achieving students to participate in the programs
			 described in paragraph (1) at no cost.</text>
					</paragraph></subsection><subsection id="IDfb4659a308374b9d868dfc85399a75f8"><enum>(c)</enum><header>National
			 education and awareness campaign</header><text>The Secretary, in consultation
			 with appropriate Federal agencies shall develop and implement outreach and
			 awareness programs on cybersecurity, including—</text>
					<paragraph id="ID7b2203cce7014f0ea42018912d377591"><enum>(1)</enum><text>in consultation
			 with the Director of the National Institute of Standards and Technology—</text>
						<subparagraph id="id6C71CC9900B34493B2EC7199096096FD"><enum>(A)</enum><text>a public
			 education campaign to increase the awareness of cybersecurity, cyber safety,
			 and cyber ethics, which shall include the use of the Internet, social media,
			 entertainment, and other media to reach the public; and</text>
						</subparagraph><subparagraph id="ID2f25234f03f24443b48b671f849002a2"><enum>(B)</enum><text>an education
			 campaign to increase the understanding of State and local governments and
			 private sector entities of the benefits of ensuring effective risk management
			 of the information infrastructure versus the costs of failure to do so and
			 methods to mitigate and remediate vulnerabilities;</text>
						</subparagraph></paragraph><paragraph id="ID47ed1e44d38847009204c7275346db75"><enum>(2)</enum><text>in coordination
			 with the Secretary of Commerce, development of a program to publicly recognize
			 or identify products, services, and companies, including owners and operators,
			 that meet the highest standards of cybersecurity; and</text>
					</paragraph><paragraph id="idfc467e2acc714c6894fb526f159a2bf9"><enum>(3)</enum><text>in accordance
			 with subsection (d), a program for carrying out collaborative education and
			 training activities for cybersecurity through a consortium or other appropriate
			 entity.</text>
					</paragraph></subsection><subsection commented="no" id="ide2b3e33f663646d38c94b8b9aa8334f3"><enum>(d)</enum><header>Collaborative
			 education and training</header>
					<paragraph commented="no" id="idA4FE71E3C9BC425E94AA45BB3A295384"><enum>(1)</enum><header>In
			 general</header><text>The consortium or other entity established under
			 subsection (c)(3) shall—</text>
						<subparagraph commented="no" id="id145660c4824c427f91a0b14335424e74"><enum>(A)</enum><text>provide training
			 to State and local first responders and officials specifically for preparing
			 and responding to cyber attacks;</text>
						</subparagraph><subparagraph commented="no" id="idf580de15b48b45b4ab2483f3b5aa23b7"><enum>(B)</enum><text>develop and
			 update a curriculum and training models for State and local first responders
			 and officials;</text>
						</subparagraph><subparagraph commented="no" id="id75c166ae0deb4ca38928e439f9fdedfd"><enum>(C)</enum><text>provide technical
			 assistance services to build and sustain capabilities in support of
			 cybersecurity preparedness and response; and</text>
						</subparagraph><subparagraph commented="no" id="id8d7c934428d846fe935175772fedd24b"><enum>(D)</enum><text>conduct
			 cybersecurity training and simulation exercises to defend from and respond to
			 cyber attacks.</text>
						</subparagraph></paragraph><paragraph commented="no" id="ide90b52867ce145e2ab9e797a011b380a"><enum>(2)</enum><header>Members</header><text>The
			 Consortium or other entity established under subsection (c)(3) shall consist of
			 academic, nonprofit, Federal Government, and State and local government
			 partners that develop, update, and deliver cybersecurity training in support of
			 homeland security.</text>
					</paragraph></subsection><subsection id="id8A8D0CD712754A30AB516E9965F6E61C"><enum>(e)</enum><header>Considerations</header><text>In
			 carrying out the authority described in subsection (c), the Secretary of
			 Commerce, the Secretary, and the Director of the National Institute of
			 Standards and Technology shall leverage existing programs designed to inform
			 the public of safety and security of products or services, including
			 self-certifications and independently-verified assessments regarding the
			 quantification and valuation of information security risk.</text>
				</subsection></section><section id="IDbf31f9a8885d4e57b1622cc760aba677"><enum>403.</enum><header>National
			 cybersecurity competition and challenge</header>
				<subsection id="IDc57fc2b1afde4ff68a1086d406235fd4"><enum>(a)</enum><header>Talent
			 competition and challenge</header>
					<paragraph id="IDfec912b1ea3149c3a1e91841e9853d9e"><enum>(1)</enum><header>In
			 general</header><text>The Secretary and the Secretary of Commerce shall
			 establish a program to conduct competitions and challenges and ensure the
			 effective operation of national and statewide competitions and challenges that
			 seek to identify, develop, and recruit talented individuals to work in Federal
			 agencies, State and local government agencies, and the private sector to
			 perform duties relating to the security of the Federal information
			 infrastructure or the national information infrastructure.</text>
					</paragraph><paragraph id="ID53579cf83abc4424b48b4b46209ae06e"><enum>(2)</enum><header>Participation</header><text>Participants
			 in the competitions and challenges of the program established under paragraph
			 (1) shall include—</text>
						<subparagraph id="ID826ae6e4424d489f8aaf4c3a86938c70"><enum>(A)</enum><text>students enrolled
			 in grades 9 through 12;</text>
						</subparagraph><subparagraph id="ID012dd95daab64a92a38a37c8e1d28ae3"><enum>(B)</enum><text>students enrolled
			 in a postsecondary program of study leading to a baccalaureate degree at an
			 institution of higher education;</text>
						</subparagraph><subparagraph id="ID48f5d04b05e0498c8f3400b6f06c2ebf"><enum>(C)</enum><text>students enrolled
			 in a postbaccalaureate program of study at an institution of higher
			 education;</text>
						</subparagraph><subparagraph id="ID164f128c21b14bbfa606013a16f341f7"><enum>(D)</enum><text>institutions of
			 higher education and research institutions;</text>
						</subparagraph><subparagraph id="ID3a554405a57548428bb5f14a361a5c4b"><enum>(E)</enum><text>veterans;
			 and</text>
						</subparagraph><subparagraph id="ID6233720abdb94d4cb6ad98b82ff50b0b"><enum>(F)</enum><text>other groups or
			 individuals as the Secretary and the Secretary of Commerce determine
			 appropriate.</text>
						</subparagraph></paragraph><paragraph id="ID7c7e997877bf48888a9f2f5fe4acd619"><enum>(3)</enum><header>Support of
			 other competitions and challenges</header><text>The program established under
			 paragraph (1) may support other competitions and challenges not established
			 under this subsection through affiliation and cooperative agreements
			 with—</text>
						<subparagraph id="ID2c5c873844de45c7b71f631457044f22"><enum>(A)</enum><text>Federal
			 agencies;</text>
						</subparagraph><subparagraph id="ID0846b6f627134e17ba7ed8650d194db8"><enum>(B)</enum><text>regional, State,
			 or school programs supporting the development of cyber professionals;</text>
						</subparagraph><subparagraph id="IDa1178ab2ecd840c581d7dd0f3d82a587"><enum>(C)</enum><text>State, local, and
			 tribal governments; or</text>
						</subparagraph><subparagraph id="ID1a8401a077bf4a58aa3acf6b5241571b"><enum>(D)</enum><text>other private
			 sector organizations.</text>
						</subparagraph></paragraph><paragraph id="ID17a8e2d572ca4e8ca6105b379ae189d8"><enum>(4)</enum><header>Areas of
			 talent</header><text>The program established under paragraph (1) shall seek to
			 identify, develop, and recruit exceptional talent relating to—</text>
						<subparagraph id="ID853dabbdf03f49fe86b18230af104bad"><enum>(A)</enum><text>ethical
			 hacking;</text>
						</subparagraph><subparagraph id="ID39befb93ab074e9a8c16536704f46900"><enum>(B)</enum><text>penetration
			 testing;</text>
						</subparagraph><subparagraph id="IDe09441ec097745479ac422d74d4da085"><enum>(C)</enum><text>vulnerability
			 assessment;</text>
						</subparagraph><subparagraph id="ID146ec76a7b05427eafda1ed4cc2bc331"><enum>(D)</enum><text>continuity of
			 system operations;</text>
						</subparagraph><subparagraph id="ID85d906cbd8d24c09b11ea6c7211bca94"><enum>(E)</enum><text>cyber
			 forensics;</text>
						</subparagraph><subparagraph id="ID4d8a38ead4e54198babcc6ce9368d2e5"><enum>(F)</enum><text>offensive and
			 defensive cyber operations; and</text>
						</subparagraph><subparagraph id="IDc87a764db2c7433e91ee3dabeaef50a0"><enum>(G)</enum><text>other areas to
			 fulfill the cybersecurity mission as the Secretary determines
			 appropriate.</text>
						</subparagraph></paragraph><paragraph id="IDdf4178acad9944e7ad1c25b5c7666b36"><enum>(5)</enum><header>Internships</header><text>The
			 Director of the Office of Personnel Management shall establish, in coordination
			 with the Director of the National Center for Cybersecurity and Communications,
			 a program to provide, where appropriate, internships or other work experience
			 in the Federal government to the winners of the competitions and
			 challenges.</text>
					</paragraph></subsection><subsection id="IDc760bfdb9bbd433bb2574ba04466d5e6"><enum>(b)</enum><header>National
			 research and development competition and challenge</header>
					<paragraph id="IDaa5de590cb444083a21f4f40e1149f14"><enum>(1)</enum><header>In
			 general</header><text>The Director of the National Science Foundation, in
			 consultation with appropriate Federal agencies, shall establish a program of
			 cybersecurity competitions and challenges to stimulate innovation in basic and
			 applied cybersecurity research, technology development, and prototype
			 demonstration that has the potential for application to the information
			 technology activities of the Federal Government.</text>
					</paragraph><paragraph id="id08F60C3C523B418CB0A1E9A2F6E8BC72"><enum>(2)</enum><header>Participation</header><text>Participants
			 in the competitions and challenges of the program established under paragraph
			 (1) shall include—</text>
						<subparagraph id="idF5AE95D47E444D2597A946662E7675F2"><enum>(A)</enum><text>students enrolled
			 in grades 9 through 12;</text>
						</subparagraph><subparagraph id="idE1F6CA52182E4F3B846F2E1D57C65C5B"><enum>(B)</enum><text>students enrolled
			 in a postsecondary program of study leading to a baccalaureate degree at an
			 institution of higher education;</text>
						</subparagraph><subparagraph id="id9B080AB9E67245388BAC18978D30387C"><enum>(C)</enum><text>students enrolled
			 in a postbaccalaureate program of study at an institution of higher
			 education;</text>
						</subparagraph><subparagraph id="id3F6012E0924248DCB5DAF9634C46F991"><enum>(D)</enum><text>institutions of
			 higher education and research institutions;</text>
						</subparagraph><subparagraph id="idD801B8B66EE34180942A9936AD03CDDE"><enum>(E)</enum><text>veterans;
			 and</text>
						</subparagraph><subparagraph id="id9E36101B1C514BB19FA12ABBA78B94CC"><enum>(F)</enum><text>other groups or
			 individuals as the Director of the National Science Foundation determines
			 appropriate.</text>
						</subparagraph></paragraph><paragraph id="IDdb8b8544f5b14d57b26f3dca1b7956bd"><enum>(3)</enum><header>Topics</header><text>In
			 selecting topics for competitions and challenges held as part of the program
			 established under paragraph (1), the Director—</text>
						<subparagraph id="idB4250E35AA564FEFA72C6B4F39C178DE"><enum>(A)</enum><text>shall consult
			 widely both within and outside the Federal Government; and</text>
						</subparagraph><subparagraph id="idBBF1B32E971E4C8EA0CA3CF3EC28A39E"><enum>(B)</enum><text>may empanel
			 advisory committees.</text>
						</subparagraph></paragraph><paragraph id="ID1e15db9f9d454d73a5a021543eb7596c"><enum>(4)</enum><header>Internships</header><text>The
			 Director of the Office of Personnel Management shall establish, in coordination
			 with the Director of the National Science Foundation, a program to provide,
			 where appropriate, internships or other work experience in the Federal
			 government to the winners of the competitions and challenges held as part of
			 the program established under paragraph (1).</text>
					</paragraph></subsection></section><section id="ID8843459fc57a44ceba9b4e24983fa9e0"><enum>404.</enum><header>Federal Cyber
			 Scholarship-for-Service program</header>
				<subsection id="ID2cf51a6a0590402ba466c5bade151969"><enum>(a)</enum><header>In
			 general</header><text>The Director of the National Science Foundation, in
			 coordination with the Secretary, shall establish a Federal Cyber
			 Scholarship-for-Service program to recruit and train the next generation of
			 information technology professionals, industrial control system security
			 professionals, and security managers to meet the needs of the cybersecurity
			 mission for the Federal Government and State, local, and tribal
			 governments.</text>
				</subsection><subsection id="ID96be30c9159c421a835251fdeb0a1932"><enum>(b)</enum><header>Program
			 description and components</header><text>The program established under
			 subsection (a) shall—</text>
					<paragraph id="ID8a15b1748aee4456b389c2d33ec0bbc1"><enum>(1)</enum><text>incorporate
			 findings from the assessment and development of the strategy under section
			 405;</text>
					</paragraph><paragraph id="ID22346ebac3a44b6cb953eb3a3b6d196f"><enum>(2)</enum><text>provide not more
			 than 1,000 scholarships per year, to students who are enrolled in a program of
			 study at an institution of higher education leading to a degree or specialized
			 program certification in the cybersecurity field, in an amount that covers each
			 student's tuition and fees at the institution and provides the student with an
			 additional stipend;</text>
					</paragraph><paragraph id="ID2eb9e443013d47b7ad76540c19062577"><enum>(3)</enum><text>require each
			 scholarship recipient, as a condition of receiving a scholarship under the
			 program, to enter into an agreement under which the recipient agrees to work in
			 the cybersecurity mission of a Federal, State, local, or tribal agency for a
			 period equal to the length of the scholarship following receipt of the
			 student's degree if offered employment in that field by a Federal, State,
			 local, or tribal agency;</text>
					</paragraph><paragraph id="IDa242417ac2794232b6e895851d52ca7a"><enum>(4)</enum><text>provide a
			 procedure by which the National Science Foundation or a Federal agency may,
			 consistent with regulations of the Office of Personnel Management, request and
			 fund security clearances for scholarship recipients, including providing for
			 clearances during summer internships and after the recipient receives the
			 degree; and</text>
					</paragraph><paragraph id="ID73266856659e482e9201d45a0150da5a"><enum>(5)</enum><text>provide
			 opportunities for students to receive temporary appointments for meaningful
			 employment in the cybersecurity mission of a Federal agency during school
			 vacation periods and for internships.</text>
					</paragraph></subsection><subsection id="IDadba0c5765094a83901d801396ed02b3"><enum>(c)</enum><header>Hiring
			 authority</header>
					<paragraph id="id6EDE2E46E43547D8906D360D609BD206"><enum>(1)</enum><header>In
			 general</header><text>For purposes of any law or regulation governing the
			 appointment of individuals in the Federal civil service, upon receiving a
			 degree for which an individual received a scholarship under this section, the
			 individual shall be—</text>
						<subparagraph id="id3BCB14C907E8468FA39A3A5A93E338F4"><enum>(A)</enum><text>hired under the
			 authority provided for in section 213.3102(r) of title 5, Code of Federal
			 Regulations; and</text>
						</subparagraph><subparagraph id="id53FC59061C8347F1B003313F9F83A4E3"><enum>(B)</enum><text>exempt from
			 competitive service.</text>
						</subparagraph></paragraph><paragraph id="idAEC7CB4903D2464486500C6F7981FB43"><enum>(2)</enum><header>Competitive
			 service position</header><text>Upon satisfactory fulfillment of the service
			 term of an individual hired under paragraph (1), the individual may be
			 converted to a competitive service position without competition if the
			 individual meets the requirements for that position.</text>
					</paragraph></subsection><subsection id="IDba3b62081b134affb2d6760a0138634d"><enum>(d)</enum><header>Eligibility</header><text>To
			 be eligible to receive a scholarship under this section, an individual
			 shall—</text>
					<paragraph id="IDcad799fa0be3462396a5c4e60147780b"><enum>(1)</enum><text>be a citizen or
			 lawful permanent resident of the United States;</text>
					</paragraph><paragraph id="IDe221614c5f604b82904589cb93e72284"><enum>(2)</enum><text>demonstrate a
			 commitment to a career in improving the security of information infrastructure;
			 and</text>
					</paragraph><paragraph id="ID20fd0ce2cfff4ee59de69fce094513fd"><enum>(3)</enum><text>have demonstrated
			 a high level of proficiency in mathematics, engineering, or computer
			 sciences.</text>
					</paragraph></subsection><subsection commented="no" id="id0DD15613169B4D6EB9FCB68F858ED05B"><enum>(e)</enum><header>Repayment</header><text>If
			 a recipient of a scholarship under this section does not meet the terms of the
			 scholarship program, the recipient shall refund the scholarship payments in
			 accordance with rules established by the Director of the National Science
			 Foundation, in coordination with the Secretary.</text>
				</subsection><subsection id="ID7ed57dd598ce4d658192e2172c621b62"><enum>(f)</enum><header>Evaluation and
			 report</header><text>The Director of the National Science Foundation shall
			 evaluate and report periodically to Congress on the success of recruiting
			 individuals for the scholarships and on hiring and retaining those individuals
			 in the public sector workforce.</text>
				</subsection></section><section id="ID39f44a12e75e48818bb922681689b254"><enum>405.</enum><header>Assessment of
			 cybersecurity Federal workforce</header>
				<subsection id="ID2ef51f40a82741c6b64b06838eae1b6e"><enum>(a)</enum><header>In
			 general</header><text>The Director of the Office of Personnel Management and
			 the Secretary, in coordination with the Director of National Intelligence, the
			 Secretary of Defense, and the Chief Information Officers Council established
			 under section 3603 of title 44, United States Code, shall assess the readiness
			 and capacity of the Federal workforce to meet the needs of the cybersecurity
			 mission of the Federal Government.</text>
				</subsection><subsection id="ID5bcf77d962d54c84b83343a22041bd22"><enum>(b)</enum><header>Strategy</header>
					<paragraph id="ID5d6738e6c32340a59816bf6130d5a158"><enum>(1)</enum><header>In
			 general</header><text>Not later than 180 days after the date of enactment of
			 this Act, the Director of the Office of Personnel Management, in consultation
			 with the Director of the National Center for Cybersecurity and Communications
			 and the Director of the Office of Management and Budget, shall develop a
			 comprehensive workforce strategy that enhances the readiness, capacity,
			 training, and recruitment and retention of cybersecurity personnel of the
			 Federal Government.</text>
					</paragraph><paragraph id="IDb74869beb4ec49b4af6712550ca08de2"><enum>(2)</enum><header>Contents</header><text>The
			 strategy developed under paragraph (1) shall include—</text>
						<subparagraph id="IDbb92e1327a594c8f86dcadd1297bbd75"><enum>(A)</enum><text>a 5-year plan on
			 recruitment of personnel for the Federal workforce; and</text>
						</subparagraph><subparagraph id="ID5f22185a8a9b4c62ba70eaca50ecb7ac"><enum>(B)</enum><text>a 10-year
			 projections of Federal workforce needs.</text>
						</subparagraph></paragraph></subsection><subsection id="ID4ef37a5201ce43d48d42830a3e8fdaea"><enum>(c)</enum><header>Updates</header><text>The
			 Director of the Office of Personnel Management, in consultation with the
			 Director of the National Center for Cybersecurity and Communications and the
			 Director of the Office of Management and Budget, shall update the strategy
			 developed under subsection (b) as needed.</text>
				</subsection></section><section id="ID9331158723ab46b3a429bd52095920d4"><enum>406.</enum><header>Federal
			 cybersecurity occupation classifications</header>
				<subsection id="ID5d8d8edfb6a14f38b01a3e6bfb6331b9"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Director of the Office of Personnel Management, in coordination with
			 the Director of the National Center for Cybersecurity and Communications, shall
			 develop and issue comprehensive occupation classifications for Federal
			 employees engaged in cybersecurity missions.</text>
				</subsection><subsection id="ID7fd00451991344dd90918efc7f26a54e"><enum>(b)</enum><header>Applicability
			 of classifications</header><text>The Director of the Office of Personnel
			 Management shall ensure that the comprehensive occupation classifications
			 issued under subsection (a) may be used throughout the Federal
			 Government.</text>
				</subsection></section><section id="ID1d3b542c748c4c3e988d293e2aba0f61"><enum>407.</enum><header>Training and
			 education of Federal employees</header>
				<subsection id="ID8f5cde339dfb4aa8bad100dffb7f89d7"><enum>(a)</enum><header>Definition</header><text>In
			 this section, the term <term>agency information infrastructure</term> means the
			 Federal information infrastructure of a Federal agency.</text>
				</subsection><subsection id="idC9A4A90B586649B9908C03D02D5B4FB4"><enum>(b)</enum><header>Training</header>
					<paragraph id="ID1dbc65e17ecb474b949619d5cbda0fd7"><enum>(1)</enum><header>Federal
			 government employees and federal contractors</header><text>The Director of the
			 Office of Personnel Management, in coordination with the Secretary, the
			 Director of National Intelligence, the Secretary of Defense, and the Chief
			 Information Officers Council established under section 3603 of title 44, United
			 States Code, shall establish a cybersecurity awareness and education curriculum
			 that shall be required for all Federal employees and contractors engaged in the
			 design, development, or operation of an agency information infrastructure or
			 the Federal information infrastructure.</text>
					</paragraph><paragraph id="ID39b23111861142a284f2062f9249f2ec"><enum>(2)</enum><header>Contents</header><text>The
			 curriculum established under paragraph (1) shall include, at a minimum—</text>
						<subparagraph id="ID2abddb265d6e44f49f05a2652d944fc9"><enum>(A)</enum><text>role-based
			 security awareness training;</text>
						</subparagraph><subparagraph id="IDe6647bdcc2fa48cebfb3c9c3dd475c63"><enum>(B)</enum><text>recommended
			 cybersecurity practices;</text>
						</subparagraph><subparagraph id="ID445d6e0495584a648542ac65dd45cd1b"><enum>(C)</enum><text>cybersecurity
			 recommendations for traveling abroad;</text>
						</subparagraph><subparagraph id="ID0f5048a4ce724c2d85c7e9619bcfd2f9"><enum>(D)</enum><text>unclassified
			 counterintelligence information;</text>
						</subparagraph><subparagraph id="IDf6a2b2d5182e4bc3bb09915c168a90c8"><enum>(E)</enum><text>information
			 regarding industrial espionage;</text>
						</subparagraph><subparagraph id="ID979ce1c4ac0f4147a8298bff9f68cc4d"><enum>(F)</enum><text>information
			 regarding malicious activity online;</text>
						</subparagraph><subparagraph id="ID9b675ab3dab844feaf3b305338f342d7"><enum>(G)</enum><text>information
			 regarding cybersecurity and law enforcement;</text>
						</subparagraph><subparagraph id="ID7f24940890284c16a0af38d7e71c66fe"><enum>(H)</enum><text>identity
			 management information;</text>
						</subparagraph><subparagraph id="ID4e44280d1b8c4634a0d85b6e915886ea"><enum>(I)</enum><text>information
			 regarding supply chain security;</text>
						</subparagraph><subparagraph id="IDdaf8add576ae46fcbb15efb87cdf55ac"><enum>(J)</enum><text>information
			 security risks associated with the activities of Federal employees and
			 contractors; and</text>
						</subparagraph><subparagraph id="ID89d22cb948c54db5a90d868d25929285"><enum>(K)</enum><text>the
			 responsibilities of Federal employees and contractors in complying with
			 policies and procedures designed to reduce information security risks
			 identified under subparagraph (J).</text>
						</subparagraph></paragraph><paragraph id="ID7d95ea6212f040b69f7b2ffd0f7e72cd"><enum>(3)</enum><header>Federal
			 cybersecurity professionals</header><text>The Director of the Office of
			 Personnel Management in conjunction with the Secretary, the Director of
			 National Intelligence, the Secretary of Defense, the Director of the Office of
			 Management and Budget, and, as appropriate, colleges, universities, and
			 nonprofit organizations with cybersecurity training expertise, shall develop a
			 program to provide training to improve and enhance the skills and capabilities
			 of Federal employees engaged in the cybersecurity mission, including training
			 specific to the acquisition workforce.</text>
					</paragraph><paragraph id="ID56b508f56bec4306a509621230dcb40d"><enum>(4)</enum><header>Heads of
			 Federal agencies</header><text>Not later than 30 days after the date on which
			 an individual is appointed to a position at level I or II of the Executive
			 Schedule, the Secretary and the Director of National Intelligence shall provide
			 that individual with a cybersecurity threat briefing.</text>
					</paragraph><paragraph id="ID5e33edefb9b54c66b774bf6a681e943b"><enum>(5)</enum><header>Certification</header><text>The
			 head of each Federal agency shall include in the annual report required under
			 section 3554(c) of title 44, United States Code, as amended by this Act, a
			 certification regarding whether all employees and contractors of the Federal
			 agency have completed the training required under this subsection.</text>
					</paragraph></subsection><subsection id="IDae9c4f85483c4bebb55a133634bc72c2"><enum>(c)</enum><header>Recruitment</header><text>The
			 Director of the Office of Personnel Management, in coordination with the
			 Director of the National Center for Cybersecurity and Communications, shall
			 develop strategies and programs to recruit students enrolled in institutions of
			 higher education and students enrolled in career and technical institutions in
			 the United States to serve as Federal employees engaged in cybersecurity
			 missions.</text>
				</subsection><subsection id="idDB11DD8BB00D4FB7BAFC205892FB029B"><enum>(d)</enum><header>Leadership in
			 cybersecurity</header><text>The head of each Federal agency shall adopt best
			 practices, developed by the Office of Personnel Management, regarding effective
			 ways to educate and motivate employees of the Federal Government to demonstrate
			 leadership in cybersecurity, including—</text>
					<paragraph id="id9E5A58ADCF7F499EAFA60CAD773FC5B1"><enum>(1)</enum><text>promotions and
			 other nonmonetary awards; and</text>
					</paragraph><paragraph id="id87DDCF4A8C494F19AC1F03CCCCA5654F"><enum>(2)</enum><text>publicizing
			 information sharing accomplishments by individual employees and, if
			 appropriate, the tangible benefits that resulted.</text>
					</paragraph></subsection></section><section id="idb4c7cc289a1b4bf4899fa8696040df39"><enum>408.</enum><header>National
			 Center for Cybersecurity and Communications acquisition authorities</header>
				<subsection id="idF9CDB6148EE44620B761150BCF3EB6FE"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Subtitle E of title
			 II of the Homeland Security Act of 2002, as added by section 204, is amended by
			 adding at the end the following:</text>
					<quoted-block display-inline="no-display-inline" id="id96ca88d50587482abe8f850ebcd271f8" style="OLC">
						<section id="id6ed3f8952cad43aba6ebaa163de51e4a"><enum>245.</enum><header>National
				Center for Cybersecurity and Communications acquisition authorities</header>
							<subsection id="id03beb4616e09402bb2bfcfc7b0d89ef1"><enum>(a)</enum><header>In
				general</header><text>The National Center for Cybersecurity and Communications
				is authorized to use the authorities under subsections (c)(1) and (d)(1)(B) of
				section 2304 of title 10, United States Code, instead of the authorities under
				subsections (a)(1) and (b)(2) of section 3304 of title 41, United States Code,
				subject to all other requirements of sections 3301 and 3304 of title 41, United
				States Code.</text>
							</subsection><subsection id="id2ac8fe33be854db6a15eeeb655f0d4bf"><enum>(b)</enum><header>Guidelines</header><text>Not
				later than 90 days after the date of enactment of the
				<short-title>Cybersecurity Act of 2012</short-title>, the
				chief procurement officer of the Department shall issue guidelines for use of
				the authority under subsection (a).</text>
							</subsection><subsection id="id1d80a11a4dcf4349842ec87e40a1fbad"><enum>(c)</enum><header>Termination</header><text>The
				National Center for Cybersecurity and Communications may not use the authority
				under subsection (a) on and after the date that is 3 years after the date of
				enactment of this Act.</text>
							</subsection><subsection id="id3d22aca33e0b45fab5cad86f7caf1cdf"><enum>(d)</enum><header>Reporting</header>
								<paragraph id="id2465a4d1377e4ed99689b433ac82941b"><enum>(1)</enum><header>In
				general</header><text>On a semiannual basis, the Director of the Center shall
				submit a report on use of the authority granted by subsection (a) to—</text>
									<subparagraph id="ida4822b496e85464f9249795bd65d7a5c"><enum>(A)</enum><text>the Committee on
				Homeland Security and Governmental Affairs of the Senate; and</text>
									</subparagraph><subparagraph id="iddc63bb029aec4929aef2e93533e6bf0e"><enum>(B)</enum><text>the Committee on
				Homeland Security of the House of Representatives.</text>
									</subparagraph></paragraph><paragraph id="id3d2c7cafe8d945cd85b1865ac1c92dd3"><enum>(2)</enum><header>Contents</header><text>Each
				report submitted under paragraph (1) shall include, at a minimum—</text>
									<subparagraph id="idde84a2c78ef443d5a37b87b78d563a85"><enum>(A)</enum><text>the number of
				contract actions taken under the authority under subsection (a) during the
				period covered by the report; and</text>
									</subparagraph><subparagraph id="id1e4900d5032044c68cfdc1f059d85873"><enum>(B)</enum><text>for each contract
				action described in subparagraph (A)—</text>
										<clause id="idfe434658e01442a08db7a3246d2eede4"><enum>(i)</enum><text>the total dollar
				value of the contract action;</text>
										</clause><clause id="ide8e6ffc5c5fd457b809878569767e8a6"><enum>(ii)</enum><text>a summary of the
				market research conducted by the National Center for Cybersecurity and
				Communications, including a list of all offerors who were considered and those
				who actually submitted bids, in order to determine that use of the authority
				was appropriate; and</text>
										</clause><clause id="id9b76ea05bd884c55a2561bfd2ad530e5"><enum>(iii)</enum><text>a copy of the
				justification and approval documents required by section 3304(e) of title 41,
				United States Code.</text>
										</clause></subparagraph></paragraph><paragraph id="id85bf61f76b1b403f95f59b600b205f90"><enum>(3)</enum><header>Classified
				annex</header><text>A report submitted under this subsection shall be submitted
				in an unclassified form, but may include a classified annex, if
				necessary.</text>
								</paragraph></subsection></section><section id="idfb0e8e7ebce8454ca0875b08743e1de2"><enum>246.</enum><header>Recruitment
				and retention program for the national center for cybersecurity and
				communications</header>
							<subsection id="idec4d4beec173491ea2d20d94e14c8119"><enum>(a)</enum><header>Definitions</header><text>In
				this section:</text>
								<paragraph id="ide62ed607564741b7b95865426bcc290e"><enum>(1)</enum><header>Collective
				bargaining agreement</header><text>The term <term>collective bargaining
				agreement</term> has the meaning given that term in section 7103(a)(8) of title
				5, United States Code.</text>
								</paragraph><paragraph id="id97f094f5e5174d518d6ef856707e9fad"><enum>(2)</enum><header>Qualified
				employee</header><text>The term <term>qualified employee</term> means an
				employee who performs functions relating to the security of Federal systems and
				critical information infrastructure.</text>
								</paragraph></subsection><subsection id="id22b6c47a33ca41eda89f44ce8cc94a84"><enum>(b)</enum><header>General
				authority</header>
								<paragraph id="id1e18db3f13414430a0495fb745dbb03e"><enum>(1)</enum><header>Establish
				positions, appoint personnel, and fix rates of pay</header><text>The Secretary
				may exercise with respect to qualified employees of the Department the same
				authority of that the Secretary of Defense has with respect to civilian
				intelligence personnel under sections 1601, 1602, and 1603 of title 10, United
				States Code, to establish as positions in the excepted service, to appoint
				individuals to those positions, and fix pay. Such authority shall be exercised
				subject to the same conditions and limitations applicable to the Secretary of
				Defense with respect to civilian intelligence personnel of the Department of
				Defense.</text>
								</paragraph><paragraph id="id3492430067584b1ca3549fd1850ea18a"><enum>(2)</enum><header>Scholarship
				program</header><text>The Secretary may exercise with respect to qualified
				employees of the Department the same authority of the Secretary of Defense has
				with respect to civilian personnel under section 2200a of title 10, United
				States Code, to the same extent, and subject to the same conditions and
				limitations, that the Secretary of Defense may exercise such authority with
				respect to civilian personnel of the Department of Defense.</text>
								</paragraph><paragraph id="id6783e65207b14210b48a122187103565"><enum>(3)</enum><header>Plan for
				execution of authorities</header><text>Not later than 120 days after the date
				of enactment of this subtitle, the Secretary shall submit a report to the
				appropriate committees of Congress with a plan for the use of the authorities
				provided under this subsection.</text>
								</paragraph><paragraph id="ided6ddcedc17247d99c948c0d055c93fc"><enum>(4)</enum><header>Collective
				bargaining agreements</header><text>Nothing in paragraph (1) may be construed
				to impair the continued effectiveness of a collective bargaining agreement with
				respect to an office, component, subcomponent, or equivalent of the Department
				that is a successor to an office, component, subcomponent, or equivalent of the
				Department covered by the agreement before the succession.</text>
								</paragraph><paragraph id="id050ea4ac2ea44daf99e7717cd4504714"><enum>(5)</enum><header>Required
				regulations</header><text>The Secretary, in coordination with the Director of
				the Center and the Director of the Office of Personnel Management, shall
				prescribe regulations for the administration of this section.</text>
								</paragraph></subsection><subsection id="idc30f414577314bb5a29f84c7912b2b95"><enum>(c)</enum><header>Merit system
				principles and civil service protections: applicability</header>
								<paragraph id="idaba02ad5151a4646998fb0ed1d6afd19"><enum>(1)</enum><header>Applicability
				of merit system principles</header><text>The Secretary shall exercise the
				authority under subsection (b) in a manner consistent with the merit system
				principles set forth in section 2301 of title 5, United States Code.</text>
								</paragraph><paragraph id="id9ef8967f9b1f4f51979c845c1b66cfdd"><enum>(2)</enum><header>Civil service
				protections</header><text>Section 1221, section 2302, and chapter 75 of title
				5, United States Code, shall apply to the positions established under
				subsection (b)(1).</text>
								</paragraph></subsection><subsection id="idfba8b9aa5f724868a0dfe94d430285b3"><enum>(d)</enum><header>Requirements</header><text>Before
				the initial exercise of any authority authorized under subsection (b)(1) the
				Secretary shall—</text>
								<paragraph id="id0c2ddb3f860e442b9a10e25be28b18ec"><enum>(1)</enum><text>seek input from
				affected employees, and the union representatives of affected employees as
				applicable, and Federal manager and professional associations into the design
				and implementation of a fair, credible, and transparent system for exercising
				any authority under subsection (b)(1);</text>
								</paragraph><paragraph id="id416a8ed8ba9841c5962433dd45192c06"><enum>(2)</enum><text>make a good faith
				attempt to resolve any employee concerns regarding proposed changes in
				conditions of employment through discussions with the groups described in
				paragraph (1);</text>
								</paragraph><paragraph id="id03b6d457493d4458a103e2b6b15d2f22"><enum>(3)</enum><text>develop a program
				to provide training to supervisors of cybersecurity employees at the Department
				on the use of the new authorities, including actions, options, and strategies a
				supervisor may use in—</text>
									<subparagraph id="id5b43b0ccf8ec49de9858fa0f627708e3"><enum>(A)</enum><text>developing and
				discussing relevant goals and objectives with the employee, communicating and
				discussing progress relative to performance goals and objectives, and
				conducting performance appraisals;</text>
									</subparagraph><subparagraph id="ida6cc60d1457c437aafcfc8e677693ac2"><enum>(B)</enum><text>mentoring and
				motivating employees, and improving employee performance and
				productivity;</text>
									</subparagraph><subparagraph id="id8d301a8d00e949a6b86bf98b16f880fd"><enum>(C)</enum><text>fostering a work
				environment characterized by fairness, respect, equal opportunity, and
				attention to the quality of work of the employees;</text>
									</subparagraph><subparagraph id="idca54e6e14c814282b900e60d2e0e683f"><enum>(D)</enum><text>effectively
				managing employees with unacceptable performance;</text>
									</subparagraph><subparagraph id="idd9c4d329f7304b6b800ea0d5078002a3"><enum>(E)</enum><text>addressing
				reports of a hostile work environment, reprisal, or harassment of or by another
				supervisor or employee; and</text>
									</subparagraph><subparagraph id="idf752a9ff17524142bff3283a5b705bfc"><enum>(F)</enum><text>otherwise
				carrying out the duties and responsibilities of a supervisor;</text>
									</subparagraph></paragraph><paragraph id="id8580c17364b64eb694dd8ada2fef2958"><enum>(4)</enum><text>develop a program
				to provide training to supervisors of cybersecurity employees at the Department
				on the prohibited personnel practices under section 2302 of title 5, United
				States Code, (particularly with respect to the practices described in
				paragraphs (1) and (8) of section 2302(b) of title 5, United States Code),
				employee collective bargaining and union participation rights, and the
				procedures and processes used to enforce employee rights; and</text>
								</paragraph><paragraph id="id0bc493cd26394567a5545b44fb4635a8"><enum>(5)</enum><text>develop a program
				under which experienced supervisors mentor new supervisors by—</text>
									<subparagraph id="id05a632b9e67542248afb9fb944f6823b"><enum>(A)</enum><text>sharing knowledge
				and advice in areas such as communication, critical thinking, responsibility,
				flexibility, motivating employees, teamwork, leadership, and professional
				development; and</text>
									</subparagraph><subparagraph id="idbf4b536ef61d49739ede69abe8ae1260"><enum>(B)</enum><text>pointing out
				strengths and areas for development.</text>
									</subparagraph></paragraph></subsection><subsection id="idb2ddad94601a4a60a09dcdbed79803e2"><enum>(e)</enum><header>Supervisor
				requirement</header>
								<paragraph id="id3436279e555d4542921e5087a03ece1c"><enum>(1)</enum><header>In
				general</header><text>Except as provided in paragraph (2), not later than 1
				year after the date of enactment of the <short-title>Cybersecurity Act of 2012</short-title> and every 3 years
				thereafter, every supervisor of cybersecurity employees at the Department shall
				complete the programs established under paragraphs (3) and (4) of subsection
				(d).</text>
								</paragraph><paragraph id="idcb45792323724e5e8f7a49883433656d"><enum>(2)</enum><header>Exception</header><text>A
				supervisor of cybersecurity employees at the Department who is appointed after
				the date of enactment of the <short-title>Cybersecurity
				Act of 2012</short-title> shall complete the programs established under
				paragraphs (3) and (4) of subsection (d) not later than 1 year after the date
				on which the supervisor is appointed to the position, and every 3 years
				thereafter.</text>
								</paragraph><paragraph id="idb439fdc5a13b49e5bd8c9f9b621046eb"><enum>(3)</enum><header>Ongoing
				participation</header><text>Participation by supervisors of cybersecurity
				employees at the Department in the program established under subsection (d)(5)
				shall be ongoing.</text>
								</paragraph></subsection><subsection id="idd92cf49a03de4cd79834a3ee46fe1abc"><enum>(f)</enum><header>Conversion to
				competitive service</header><text>In consultation with the Director of the
				Center, the Secretary may grant competitive civil service status to a qualified
				employee appointed to the excepted service under subsection (b) if that
				employee is employed in the Center or is transferring to the Center.</text>
							</subsection><subsection id="id9da32285f9184f8aa535075aed78a23d"><enum>(g)</enum><header>Annual
				report</header><text>Not later than 1 year after the date of enactment of this
				subtitle, and every year thereafter for 4 years, the Secretary shall submit to
				the appropriate committees of Congress a detailed report that—</text>
								<paragraph id="id03fc9e82868340148bc40c81b68f3f61"><enum>(1)</enum><text>discusses the
				process used by the Secretary in accepting applications, assessing candidates,
				ensuring adherence to veterans’ preference, and selecting applicants for
				vacancies to be filled by a qualified employee;</text>
								</paragraph><paragraph id="id2ec12fd4a15147749fd7fc4908777acf"><enum>(2)</enum><text>describes—</text>
									<subparagraph id="id6936923d2b0242e2a434dc07510a609b"><enum>(A)</enum><text>how the Secretary
				plans to fulfill the critical need of the Department to recruit and retain
				qualified employees;</text>
									</subparagraph><subparagraph id="id174102146a444dce9d8b88e1920e8df4"><enum>(B)</enum><text>the measures that
				will be used to measure progress; and</text>
									</subparagraph><subparagraph id="idb56ad7888a794599b2072adafcb15002"><enum>(C)</enum><text>any actions taken
				during the reporting period to fulfill such critical need;</text>
									</subparagraph></paragraph><paragraph id="id9b89511673a14f9b84cb1224420f0019"><enum>(3)</enum><text>discusses how the
				planning and actions taken under paragraph (2) are integrated into the
				strategic workforce planning of the Department;</text>
								</paragraph><paragraph id="id7873ef883bba4c919fb9e0e737267df9"><enum>(4)</enum><text>provides metrics
				on actions occurring during the reporting period, including—</text>
									<subparagraph id="id0ea93284b6934966af54afea7cc943a7"><enum>(A)</enum><text>the number of
				qualified employees hired by occupation and grade and level or pay band;</text>
									</subparagraph><subparagraph id="idc6bb236af8d84efda31879491eaef5af"><enum>(B)</enum><text>the total number
				of veterans hired;</text>
									</subparagraph><subparagraph id="id5c009832f2a544e4ba2196bde7804ff9"><enum>(C)</enum><text>the number of
				separations of qualified employees by occupation and grade and level or pay
				band;</text>
									</subparagraph><subparagraph id="idbc93794c89cf4b41b3657d0ab2adfd14"><enum>(D)</enum><text>the number of
				retirements of qualified employees by occupation and grade and level or pay
				band; and</text>
									</subparagraph><subparagraph id="idbf5e48c617724568b1888c1f3522bd2e"><enum>(E)</enum><text>the number and
				amounts of recruitment, relocation, and retention incentives paid to qualified
				employees by occupation and grade and level or pay
				band.</text>
									</subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection><subsection id="id5D4D78C6334F45F9A2561AD3E24AACA0"><enum>(b)</enum><header>Technical and
			 conforming amendment</header><text>The table of contents in section 1(b) of the
			 Homeland Security Act of 2002 (6 U.S.C. 101 et seq.), as amended by section
			 204, is amended by inserting after the item relating to section 244 the
			 following:</text>
					<quoted-block id="idf55857fb-3166-49da-92dc-da099f28b518" style="OLC">
						<toc>
							<toc-entry idref="id6ed3f8952cad43aba6ebaa163de51e4a" level="section">Sec. 245. National Center for Cybersecurity and Communications
				acquisition authorities.</toc-entry>
							<toc-entry idref="idfb0e8e7ebce8454ca0875b08743e1de2" level="section">Sec. 246. Recruitment and retention program for the national
				center for cybersecurity and
				communications.</toc-entry>
						</toc>
						<after-quoted-block>.</after-quoted-block></quoted-block>
				</subsection></section><section id="id1DFB1422EDC8475EB1A76115940EBFE0"><enum>409.</enum><header>Reports on
			 cyber incidents against Government networks</header>
				<subsection id="idC3125B2F8AD94E638914F1EC15EB502C"><enum>(a)</enum><header>Department of
			 Homeland Security</header><text>Not later than 180 days after the date of
			 enactment of this Act, and annually thereafter, the Secretary shall submit to
			 Congress a report that—</text>
					<paragraph id="id7D24CB6F40AD4970BE82227BF0CE5DAC"><enum>(1)</enum><text>summarizes major
			 cyber incidents involving networks of Executive agencies (as defined in section
			 105 of title 5, United States Code), except for the Department of
			 Defense;</text>
					</paragraph><paragraph id="idFC49F36878CE4E33B4C806DEDAE48813"><enum>(2)</enum><text>provides
			 aggregate statistics on the number of breaches of networks of Executive
			 agencies, the volume of data exfiltrated, and the estimated cost of remedying
			 the breaches; and</text>
					</paragraph><paragraph id="IDc360fd504e6a4bef91c12f1483872f05"><enum>(3)</enum><text>discusses the
			 risk of cyber sabotage.</text>
					</paragraph></subsection><subsection id="id4B4E2B67640442C882AC4B1795679046"><enum>(b)</enum><header>Department of
			 Defense</header><text>Not later than 180 days after the date of enactment of
			 this Act, and annually thereafter, the Secretary of Defense shall submit to
			 Congress a report that—</text>
					<paragraph id="IDea267cbd08374b428fbb184e8eb3a79c"><enum>(1)</enum><text>summarizes major
			 cyber incidents against networks of the Department of Defense and the military
			 departments;</text>
					</paragraph><paragraph id="ID710a25d198a748978bf860c62556c3af"><enum>(2)</enum><text>provides
			 aggregate statistics on the number of breaches against networks of the
			 Department of Defense and the military departments, the volume of data
			 exfiltrated, and the estimated cost of remedying the breaches; and</text>
					</paragraph><paragraph id="ID9aa00fe667b34ac3899cab5fb5d7ca98"><enum>(3)</enum><text>discusses the
			 risk of cyber sabotage.</text>
					</paragraph></subsection><subsection id="id8F618495E3F44733B6D4D758EA4E1658"><enum>(c)</enum><header>Form of
			 reports</header><text>Each report submitted under this section shall be in
			 unclassified form, but may include a classified annex as necessary to protect
			 sources, methods, and national security.</text>
				</subsection><subsection id="idd88a919d7d0149e29a79671ea5b1a252"><enum>(d)</enum><header>Contents of
			 reports</header><text>Each report submitted under this section may be based in
			 whole or in part on the reporting requirements under section 3553 of chapter 35
			 of title 44, United States Code, as amended by this Act.</text>
				</subsection></section><section id="id9DD9775D1FD24DF3933B951C3DDD0A4C"><enum>410.</enum><header>Reports on
			 prosecution for cybercrime</header>
				<subsection id="id6A2E58BBBF4D47A8886D23CBEE9337FF"><enum>(a)</enum><header>In
			 general</header><text>Not later than 180 days after the date of enactment of
			 this Act, the Attorney General and the Directors of the Federal Bureau of
			 Investigation and the United States Secret Service shall submit to Congress
			 reports—</text>
					<paragraph id="ID7104228c72d74b93a2c10f3ead49c383"><enum>(1)</enum><text>describing
			 investigations and prosecutions relating to cyber intrusions or other
			 cybercrimes the preceding year, including—</text>
						<subparagraph id="ID150bddfb6eca4936bf1ef18a8ae4055a"><enum>(A)</enum><text>the number of
			 investigations initiated relating to such crimes;</text>
						</subparagraph><subparagraph id="ID325a16d3b64e4079aa20adebe327432a"><enum>(B)</enum><text>the number of
			 arrests relating to such crimes;</text>
						</subparagraph><subparagraph id="IDef31994656c64b288ce901c4a1d21c68"><enum>(C)</enum><text>the number and
			 description of instances in which investigations or prosecutions relating to
			 such crimes have been delayed or prevented because of an inability to extradite
			 a criminal defendant in a timely manner; and</text>
						</subparagraph><subparagraph id="ID31488c80d4334412a54ce4297cfff8c3"><enum>(D)</enum><text>the number of
			 prosecutions for such crimes, including—</text>
							<clause id="ID066e7fc285ef4d57b189ac7abc265829"><enum>(i)</enum><text>the
			 number of defendants prosecuted;</text>
							</clause><clause id="IDd08535ed6ef4480ab247c17dbbcace6a"><enum>(ii)</enum><text>whether the
			 prosecutions resulted in a conviction;</text>
							</clause><clause id="ID78a855ffc8c64d968e0778b00a571821"><enum>(iii)</enum><text>the sentence
			 imposed and the statutory maximum for each such crime for which a defendant was
			 convicted; and</text>
							</clause><clause id="IDcf76802edfbc452cbcb5c68b2f9b4b21"><enum>(iv)</enum><text>the average
			 sentence imposed for a conviction of such crimes;</text>
							</clause></subparagraph></paragraph><paragraph id="IDcc70b594f5314d40a91cac28ef8f7d72"><enum>(2)</enum><text>identifying the
			 number of employees, financial resources, and other resources (such as
			 technology and training) devoted to the enforcement, investigation, and
			 prosecution of cyber intrusions or other cybercrimes, including the number of
			 investigators, prosecutors, and forensic specialists dedicated to investigating
			 and prosecuting cyber intrusions or other cybercrimes; and</text>
					</paragraph><paragraph id="IDbb2b7a5c5fc3425282107691010ddf9e"><enum>(3)</enum><text>discussing any
			 impediments under the laws of the United States or international law to
			 prosecutions for cyber intrusions or other cybercrimes.</text>
					</paragraph></subsection><subsection id="ID3f0bf460455745be8f83ac9dcc6d60ec"><enum>(b)</enum><header>Updates</header><text>The
			 Attorney General and the Directors of the Federal Bureau of Investigation and
			 the United States Secret Service shall annually submit to Congress reports
			 updating the reports submitted under subsection (a) at the same time the
			 Attorney General and the Directors submit annual reports under section 404 of
			 the Prioritizing Resources and Organization for Intellectual Property Act of
			 2008 (42 U.S.C. 3713d).</text>
				</subsection></section><section id="IDec6b15807a434a079aadc4ba2fec9c12"><enum>411.</enum><header>Report on
			 research relating to secure domain</header>
				<subsection id="id8A320A52F74F41808C1AE08BC14381B4"><enum>(a)</enum><header>In
			 general</header><text>The Secretary shall enter into a contract with the
			 National Research Council, or another federally funded research and development
			 corporation, under which the Council or corporation shall submit to Congress
			 reports on available technical options, consistent with constitutional and
			 statutory privacy rights, for enhancing the security of the information
			 networks of entities that own or manage critical infrastructure through—</text>
					<paragraph id="ID3c00c6b405f84461822215f1d8c94c6f"><enum>(1)</enum><text>technical
			 improvements, including developing a secure domain; or</text>
					</paragraph><paragraph id="ID01840b8e42e048dc98e79ccd9fcbc100"><enum>(2)</enum><text>increased notice
			 of and consent to the use of technologies to scan for, detect, and defeat cyber
			 security threats, such as technologies used in a secure domain.</text>
					</paragraph></subsection><subsection id="IDa233691f672843f085f4dba945168621"><enum>(b)</enum><header>Timing</header><text>The
			 contract entered into under subsection (a) shall require that the report
			 described in subsection (a) be submitted—</text>
					<paragraph id="ID7ed54efb81b5437d8c77b56f40b21a25"><enum>(1)</enum><text>not later than
			 180 days after the date of enactment of this Act;</text>
					</paragraph><paragraph id="IDc5e811611b554e61bbaa4acb8d3543be"><enum>(2)</enum><text>annually, after
			 the first report submitted under subsection (a), for 3 years; and</text>
					</paragraph><paragraph id="IDcb95b3aeaa0c4f61a819f475e8821d9f"><enum>(3)</enum><text>more frequently,
			 as determined appropriate by the Secretary in response to new risks or
			 technologies that emerge.</text>
					</paragraph></subsection></section><section id="id816DAE20CBF14533927D138F96B9DFB2"><enum>412.</enum><header>Report on
			 preparedness of Federal courts to promote cybersecurity</header><text display-inline="no-display-inline">Not later than 180 days after the date of
			 enactment of this Act, the Attorney General, in coordination with the
			 Administrative Office of the United States Courts, shall submit to Congress a
			 report—</text>
				<paragraph id="ID01c82e59322b4e889b928013dd398705"><enum>(1)</enum><text>on whether
			 Federal courts have granted timely relief in matters relating to botnets and
			 other cybercrime and cyber security threats; and</text>
				</paragraph><paragraph id="IDb132241eb9cd4ed59f518dfafdaf130d"><enum>(2)</enum><text>that includes, as
			 appropriate, recommendations on changes or improvements to—</text>
					<subparagraph id="IDd8344460c1a749688365f89cd92eef32"><enum>(A)</enum><text>the Federal Rules
			 of Civil Procedure or the Federal Rules of Criminal Procedure;</text>
					</subparagraph><subparagraph id="ID4edcc91c637b4cde9d2c0b0d593cddab"><enum>(B)</enum><text>the training and
			 other resources available to support the Federal judiciary;</text>
					</subparagraph><subparagraph id="ID23b26843c19a4d04a68d28adde7959bb"><enum>(C)</enum><text>the capabilities
			 and specialization of courts to which such cases may be assigned; and</text>
					</subparagraph><subparagraph id="ID85cc2ca510b147629451bbf1355be17e"><enum>(D)</enum><text>Federal civil and
			 criminal laws.</text>
					</subparagraph></paragraph></section><section id="id92FC6DCE76264D6EACED8FD07B5549F0"><enum>413.</enum><header>Report on
			 impediments to public awareness</header><text display-inline="no-display-inline">Not later than 180 days after the date of
			 enactment of this Act, and annually thereafter for 3 years (or more frequently
			 if determined appropriate by the Secretary) the Secretary shall submit to
			 Congress a report on—</text>
				<paragraph id="IDd794e0f47dab434aae53c9edc37baf19"><enum>(1)</enum><text>legal or other
			 impediments to appropriate public awareness of—</text>
					<subparagraph id="ID4b6cd7288af84603bf417c06ab3d8b91"><enum>(A)</enum><text>the nature of,
			 methods of propagation of, and damage caused by common cyber security threats
			 such as computer viruses, phishing techniques, and malware;</text>
					</subparagraph><subparagraph id="ID77f1bb1e1ae94a9c819551f961d7e6c6"><enum>(B)</enum><text>the minimal
			 standards of computer security necessary for responsible Internet use;
			 and</text>
					</subparagraph><subparagraph id="IDd66e75a39d954ff18c37cc97cd37baba"><enum>(C)</enum><text>the availability
			 of commercial off the shelf technology that allows consumers to meet such
			 levels of computer security;</text>
					</subparagraph></paragraph><paragraph id="IDcdbcce7df0d44a74bd602db913835457"><enum>(2)</enum><text>a summary of the
			 plans of the Secretary to enhance public awareness of common cyber security
			 threats, including a description of the metrics used by the Department for
			 evaluating the efficacy of public awareness campaigns; and</text>
				</paragraph><paragraph id="ID2b59a83021f44f4c8642b7832591299c"><enum>(3)</enum><text>recommendations
			 for congressional actions to address these impediments to appropriate public
			 awareness of common cyber security threats.</text>
				</paragraph></section><section commented="no" display-inline="no-display-inline" id="idB800AA73B89A4703842A6653E02578C8" section-type="subsequent-section"><enum>414.</enum><header>Report on protecting
			 the electrical grid of the United States</header><text display-inline="no-display-inline">Not later than 180 days after the date of
			 enactment of this Act, the Secretary, in consultation with the Secretary of
			 Defense and the Director of National Intelligence, shall submit to Congress a
			 report on—</text>
				<paragraph id="ID516197ba03e34b5f9a242510c9f1b858"><enum>(1)</enum><text>the threat of a
			 cyber attack disrupting the electrical grid of the United States;</text>
				</paragraph><paragraph id="IDb426153aa60b42f8aa85cb4edafd7c1e"><enum>(2)</enum><text>the implications
			 for the national security of the United States if the electrical grid is
			 disrupted;</text>
				</paragraph><paragraph id="ID6b7ebd60eeeb4eaaaf5ba1bd4eb41e18"><enum>(3)</enum><text>the options
			 available to the United States and private sector entities to quickly
			 reconstitute electrical service to provide for the national security of the
			 United States, and, within a reasonable time frame, the reconstitution of all
			 electrical service within the United States; and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID18c26082a8d846b4b8a5c0b3e1f700a1"><enum>(4)</enum><text>a plan to prevent
			 disruption of the electric grid of the United States caused by a cyber
			 attack.</text>
				</paragraph></section><section commented="no" display-inline="no-display-inline" id="idFF7EC7032D444175B5EE17FA72A8DC36"><enum>415.</enum><header>Marketplace
			 information</header>
				<subsection commented="no" display-inline="no-display-inline" id="id5EB63571F7524108BB35356A54EFC2CE"><enum>(a)</enum><header>Sense of
			 Congress</header><text>It is the sense of Congress that—</text>
					<paragraph commented="no" display-inline="no-display-inline" id="idA973020728DF4BE5B5B34D08A0F1F2DD"><enum>(1)</enum><text>registrants that
			 file reports with the Securities and Exchange Commission have an obligation to
			 disclose material risks to investors; and</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id1FE742A82B7947EBAC4D5FABACA09642"><enum>(2)</enum><text>as with
			 longstanding rules regarding other material risks, information security risks
			 and related events that are material to investors should be disclosed on a
			 regular basis to provide quality information to the marketplace and enable
			 informed investor decisions.</text>
					</paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id9868C5B65C654D0087E88BBB434FA03D"><enum>(b)</enum><header>Definition of
			 information security risk</header><text>In this section, the term
			 <term>information security risk and related events</term> means the risk to a
			 registrant’s business operations, assets, financial condition, strategy,
			 competitive positioning, and reputation, due to the potential for unauthorized
			 access, use, disclosure, disruption, modification, or destruction of registrant
			 information, information of third parties collected by the registrant, or
			 information systems of the registrant.</text>
				</subsection><subsection id="id005e80c7353e45a5a7e7316978cb583f"><enum>(c)</enum><header>Guidance</header><text>Not
			 later than 1 year after the date of enactment of this Act, the Securities and
			 Exchange Commission (referred to in this section as the
			 <quote>Commission</quote>) shall evaluate existing guidance to registrants
			 related to disclosures by registrants of information security risks and related
			 events (including Securities and Exchange Commission Division of Corporation
			 Finance, CF Disclosure Guidance: Topic No. 2, Cybersecurity) to determine
			 whether such guidance, in light of the evaluation, should be—</text>
					<paragraph id="id7c27f68f153a42f4b67f6528aa8ececa"><enum>(1)</enum><text>updated by the
			 Division of Corporation Finance; or</text>
					</paragraph><paragraph id="id8e59b71e61c042db8306f22581c90965"><enum>(2)</enum><text>issued as
			 Commission interpretive guidance.</text>
					</paragraph></subsection><subsection id="id291ec056c6a14a60ab02cbe558761058"><enum>(d)</enum><header>Annual
			 reports</header><text>For 5 years following the evaluation under subsection
			 (b), the Commission shall submit to Congress, on an annual basis, a report that
			 reviews—</text>
					<paragraph id="idade4104636974a0093f874d5c49a1c49"><enum>(1)</enum><text>the types of
			 information security risks and related events that registrants disclosed in the
			 previous year;</text>
					</paragraph><paragraph id="id6acc808768f341cf9c737c30e5448441"><enum>(2)</enum><text>whether the staff
			 of the Commission has requested registrants to provide additional information
			 on the disclosures under paragraph (1);</text>
					</paragraph><paragraph id="id9e3f3231258e4fce885fb5933a9dcae1"><enum>(3)</enum><text>any awareness or
			 education activities for registrants or investors, on the subject of
			 information security risks and related events disclosure requirements,
			 sponsored by the Commission or attended by a Commissioner or staff of the
			 Commission; and</text>
					</paragraph><paragraph id="id8e2fa48c9056487aa42ddf3e669f6490"><enum>(4)</enum><text>any public
			 actions commenced by the Commission relating to the enforcement of disclosure
			 requirements pertaining to the information security risks and related
			 events.</text>
					</paragraph></subsection></section></title><title id="id7694758327444028A1C1A12404E619ED"><enum>V</enum><header>Federal
			 acquisition risk management strategy</header>
			<section id="IDa6fe930650cb41c7a95bfae9aae079a0"><enum>501.</enum><header>Federal
			 acquisition risk management strategy</header>
				<subsection id="IDbb6fe11a07954b81962dcaae0cf6c41e"><enum>(a)</enum><header>In
			 general</header><text>The Secretary, in coordination with relevant private
			 sector and academic experts and each Federal entity described in paragraphs (1)
			 through (9) of subsection (b), shall develop and periodically update an
			 acquisition risk management strategy designed to ensure, based on mission
			 criticality and cost effectiveness, the security of the Federal information
			 infrastructure.</text>
				</subsection><subsection id="IDd522db4f0eb0403fb73f41a33cc25a24"><enum>(b)</enum><header>Coordination</header><text>In
			 developing the acquisition risk management strategy required under subsection
			 (a), the Secretary shall coordinate with—</text>
					<paragraph id="id32ED2161741246E083418C8615EF938B"><enum>(1)</enum><text>the Secretary of
			 Defense;</text>
					</paragraph><paragraph id="idCCE057E3268941059299C50C23763EF6"><enum>(2)</enum><text>the Secretary of
			 Commerce;</text>
					</paragraph><paragraph id="idB169F25D006344E286104478DE8F3F18"><enum>(3)</enum><text>the Secretary of
			 State;</text>
					</paragraph><paragraph id="idA92232FD1DB847288D56CF038E0B4F0F"><enum>(4)</enum><text>the Director of
			 National Intelligence;</text>
					</paragraph><paragraph id="idC3FDCDC8D28942A98BD74B2FFC85D80C"><enum>(5)</enum><text>the Administrator
			 of General Services;</text>
					</paragraph><paragraph id="idB88906C17D8642FDA42663DFCD9E8D1D"><enum>(6)</enum><text>the Administrator
			 for Federal Procurement Policy;</text>
					</paragraph><paragraph id="id1518E37DC8434AA481E037D86784337C"><enum>(7)</enum><text>the members of
			 the Chief Information Officers Council established under section 3603 of title
			 44, United States Code;</text>
					</paragraph><paragraph id="id703840DB62EB4F53B96887246DD3CCC7"><enum>(8)</enum><text>the Chief
			 Acquisition Officers Council established under section 1311 of title 41, United
			 States Code; and</text>
					</paragraph><paragraph id="id48A3895E0E2F44C1999991A73EBD4836"><enum>(9)</enum><text>the Chief
			 Financial Officers Council established under section 302 of the Chief Financial
			 Officers Act of 1990 (31 U.S.C. 901 note).</text>
					</paragraph></subsection><subsection id="IDcc0c8d21d1a5487698492e16b309a9b1"><enum>(c)</enum><header>Elements</header><text>The
			 risk management strategy developed under subsection (a) shall—</text>
					<paragraph id="idF7A97705DD984CBC9B3ADCD6745029D6"><enum>(1)</enum><text>address risks in
			 the acquisition of any part of the Federal information infrastructure;
			 and</text>
					</paragraph><paragraph id="id407D1060252B4B63B1A5B60204C1F3E3"><enum>(2)</enum><text>include
			 developing processes that—</text>
						<subparagraph id="ID6efed1c652c74bfc826fb4a9f420824e"><enum>(A)</enum><text>incorporate
			 all-source intelligence analysis into assessments of the integrity of the
			 supply chain for the Federal information infrastructure;</text>
						</subparagraph><subparagraph id="ID6eac3d96ed0a49419021bf793b6e5702"><enum>(B)</enum><text>incorporate
			 internationally recognized standards, guidelines, and best practices, including
			 those developed by the private sector, for supply chain integrity;</text>
						</subparagraph><subparagraph id="ID7817d53df5a14540ae966b335230f7a7"><enum>(C)</enum><text>enhance
			 capabilities to test and evaluate software and hardware within or for use in
			 the Federal information infrastructure, and, where appropriate, make the
			 capabilities available for use by the private sector;</text>
						</subparagraph><subparagraph id="IDf50a5441c24947e29be6909e3293730b"><enum>(D)</enum><text>protect the
			 intellectual property and trade secrets of suppliers of information and
			 communications technology products and services;</text>
						</subparagraph><subparagraph id="ID5ce6f7483d4b462ebaa904ddfa8fcff1"><enum>(E)</enum><text>share with the
			 private sector, to the fullest extent possible, the risks identified in the
			 supply chain and working with the private sector to mitigate those threats as
			 identified;</text>
						</subparagraph><subparagraph id="IDdd0eb69ae1b14c39b2162cb2a89dfab5"><enum>(F)</enum><text>identify specific
			 acquisition practices of Federal agencies that increase risks to the supply
			 chain and develop a process to provide recommendations for revisions to those
			 processes; and</text>
						</subparagraph><subparagraph id="ID5c36209747af4b2aa434c92df53e8c31"><enum>(G)</enum><text>to the maximum
			 extent practicable, promote the ability of Federal agencies to procure
			 authentic commercial off-the-shelf information and communications technology
			 products and services from a diverse pool of suppliers, consistent with the
			 preferences for the acquisition of commercial items under section 2377 of title
			 10, United States Code, and section 3307 of title 41, United States
			 Code.</text>
						</subparagraph></paragraph></subsection></section><section id="ID2174a7c4b179421490defd3b4352ce5b"><enum>502.</enum><header>Amendments to
			 Clinger-Cohen provisions to enhance agency planning for information security
			 needs</header><text display-inline="no-display-inline">Chapter 113 of title 40,
			 United States Code, is amended—</text>
				<paragraph id="ID66eb54361c2e4fe18b6cf175542fe08c"><enum>(1)</enum><text>in section
			 11302—</text>
					<subparagraph id="id2D5AE9569A9F44C8A9507BE3FDA21C3B"><enum>(A)</enum><text>in subsection
			 (f), by striking <quote>technology.</quote> and inserting <quote>technology,
			 including information technology or network information security
			 requirements.</quote>;</text>
					</subparagraph><subparagraph id="ID2da6711797594b15958e5bbac9b94f89"><enum>(B)</enum><text>in subsection
			 (i)—</text>
						<clause id="id891D3023C5ED41EBAE22313988DECC18"><enum>(i)</enum><text>by
			 inserting <quote>, including information security requirements,</quote> after
			 <quote>information resources management</quote>; and</text>
						</clause><clause id="id067B1F4833914DD697A0417EC177768E"><enum>(ii)</enum><text>by
			 adding at the end the following: <quote>The Administrator for Federal
			 Procurement Policy, in coordination with the Chief Information Officers Council
			 and the Federal Acquisition Institute, shall ensure that contracting officers
			 and the individuals preparing descriptions of the Government requirements and
			 statements of work have adequate training in information security requirements,
			 including in information technology security contracts.</quote>;</text>
						</clause></subparagraph><subparagraph commented="no" id="id23675DAE563646169654313FF147D938"><enum>(C)</enum><text>in subsection
			 (j), by adding at the end the following: <quote>The Director shall review and
			 report on possible impediments in the acquisition process or elsewhere that are
			 acting to slow agency uptake of the newest, most secure technologies.</quote>;
			 and</text>
					</subparagraph><subparagraph commented="no" id="idFE3865D63DAD48568AF130BA052097F7"><enum>(D)</enum><text>by adding at the
			 end the following:</text>
						<quoted-block display-inline="no-display-inline" id="id93C9A5DA07BB418E9FD02BDF3761A597" style="OLC">
							<subsection id="ID25d8901d6fba4b089161aa3a2891d8cc"><enum>(l)</enum><header>Multiple award
				schedule for information security</header><text>The Administrator of General
				Services shall develop a special item number under Schedule 70 for information
				security products and services and consolidate those products and services
				under that special item number to promote acquisition.</text>
							</subsection><subsection id="ID15ef654932e7467284882782f502711b"><enum>(m)</enum><header>Reducing the
				use of counterfeit products</header><text>Not later than 180 days after the
				date of enactment of the <short-title>Cybersecurity Act of
				2012</short-title>, the Director shall issue guidance requiring, to the extent
				practicable, Federal agencies to purchase information technology products only
				through the authorized channels or distributors of a
				supplier.</text>
							</subsection><after-quoted-block>;
				and</after-quoted-block></quoted-block>
					</subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ID7bd28bb4a9014e45be5265056c286052"><enum>(2)</enum><text>in section
			 11312(b)(3), by inserting <quote>, information security improvement,</quote>
			 after <quote>risk-adjusted return on investment</quote>.</text>
				</paragraph></section></title><title id="id1969E5C2828D4F5D93287BE784A4E085"><enum>VI</enum><header>International
			 cooperation</header>
			<section id="id688CC43888544A3FAB7B7DFAA329DFED"><enum>601.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="ID41f3175a64e741f38151519ee99aec17"><enum>(1)</enum><header>Computer
			 system; computer data</header><text>The terms <quote>computer system</quote>
			 and <quote>computer data</quote> have the meanings given those terms in chapter
			 I of the Convention on Cybercrime.</text>
				</paragraph><paragraph id="IDd2e3748f39da4d499681fddc01cedef1"><enum>(2)</enum><header>Convention on
			 Cybercrime</header><text>The term <quote>Convention on Cybercrime</quote> means
			 the Council of Europe’s Convention on Cybercrime, done at Budapest November 23,
			 2001 as ratified by the United States Senate on August 3, 2006 (Treaty 108–11)
			 with any relevant reservations of declarations.</text>
				</paragraph><paragraph id="IDf1da690785684aeebb04fcbc74bbe09c"><enum>(3)</enum><header>Cyber
			 issues</header><text>The term <term>cyber issues</term> means the full range of
			 international policies designed to ensure an open, interoperable, secure, and
			 reliable global information and communications infrastructure.</text>
				</paragraph><paragraph id="ID8ef61f58e5ce4720ba150a168d1eeab3"><enum>(4)</enum><header>Cybercrime</header><text>The
			 term <quote>cybercrime</quote> refers to criminal offenses relating to computer
			 systems of computer data described in the Convention of Cybercrime.</text>
				</paragraph><paragraph id="IDb471fe89b90742378935e9ba7f1bc122"><enum>(5)</enum><header>Relevant
			 Federal agencies</header><text>The term <quote>relevant Federal
			 agencies</quote> means any Federal agency that has responsibility for combating
			 cybercrime globally, including the Department of Commerce, the Department of
			 Homeland Security, the Department of Justice, the Department of State, the
			 Department of the Treasury, and the Office of the United States Trade
			 Representative.</text>
				</paragraph></section><section id="idAF0CC11AC02742A5A2EBFFF09E085AB1"><enum>602.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
				<paragraph id="IDcd8b990edd964769b5b045900ae2c095"><enum>(1)</enum><text>On February 2,
			 2010, Admiral Dennis C. Blair, the Director of National Intelligence, testified
			 before the Select Committee on Intelligence of the Senate regarding the Annual
			 Threat Assessment of the U.S. Intelligence Community, stating <quote>The
			 national security of the United States, our economic prosperity, and the daily
			 functioning of our government are dependent on a dynamic public and private
			 information infrastructure, which includes tele-communications, computer
			 networks and systems, and the information residing within. This critical
			 infrastructure is severely threatened. . . . We cannot protect cyberspace
			 without a coordinated and collaborative effort that incorporates both the US
			 private sector and our international partners.</quote></text>
				</paragraph><paragraph id="ID9989c6c194974ee2905dd8855a4cf93b"><enum>(2)</enum><text>In a January 2010
			 speech on Internet freedom, Secretary of State Hillary Clinton stated:
			 <quote>Those who disrupt the free flow of information in our society, or any
			 other, pose a threat to our economy, our government, and our civil society.
			 Countries or individuals that engage in cyber attacks should face consequences
			 and international condemnation. In an Internet-connected world, an attack on
			 one nation’s networks can be an attack on all. And by reinforcing that message,
			 we can create norms of behavior among states and encourage respect for the
			 global networked commons.</quote></text>
				</paragraph><paragraph id="ID6116496704e8479bb18443f5eca7b863"><enum>(3)</enum><text>November 2011
			 marked the tenth anniversary of the Convention on Cybercrime, the only
			 multilateral agreement on cybercrime, to which the Senate provided advice and
			 consent on August 3, 2006, and is currently ratified by over 30
			 countries.</text>
				</paragraph><paragraph id="IDf4fd04fa1e0340f7a835d366e68ce33e"><enum>(4)</enum><text>The May 2009
			 White House Cyberspace Policy Review asserts <quote>[t]he Nation also needs a
			 strategy for cybersecurity designed to shape the international environment and
			 bring like-minded nations together on a host of issues, such as technical
			 standards and acceptable legal norms regarding territorial jurisdiction,
			 sovereign responsibility, and use of force. International norms are critical to
			 establishing a secure and thriving digital infrastructure.</quote></text>
				</paragraph></section><section id="idEBD16752E8F446E9B457FBC3362383AF"><enum>603.</enum><header>Sense of
			 Congress</header><text display-inline="no-display-inline">It is the sense of
			 Congress that—</text>
				<paragraph id="ID0fdf15ef5efa4b17862f708430272322"><enum>(1)</enum><text>engagement with
			 other countries to advance the cyberspace objectives of the United States
			 should be an integral part of the conduct of United States foreign relations
			 and diplomacy;</text>
				</paragraph><paragraph id="ID162cfbda15304a60aaadc6030e4305df"><enum>(2)</enum><text>the cyberspace
			 objectives of the United States include the full range of cyber issues,
			 including issues related to governance, standards, cybersecurity, cybercrime,
			 international security, human rights, and the free flow of information;</text>
				</paragraph><paragraph id="ID6afe8b9c94bc497e84e6fbd7079b7adf"><enum>(3)</enum><text>it is in the
			 interest of the United States to work with other countries to build consensus
			 on principles and standards of conduct that protect computer systems and users
			 that rely on them, prevent and punish acts of cybercrime, and promote the free
			 flow of information;</text>
				</paragraph><paragraph id="ID89e8815523ec41f785d29c169423eec3"><enum>(4)</enum><text>a comprehensive
			 national cyberspace strategy must include tools for addressing threats to
			 computer systems and acts of cybercrime from sources and by persons outside the
			 United States;</text>
				</paragraph><paragraph id="IDbc788f8addcc40e9938a6c4d32854b30"><enum>(5)</enum><text>developing
			 effective solutions to international cyberspace threats requires engagement
			 with foreign countries on a bilateral basis and through relevant regional and
			 multilateral fora;</text>
				</paragraph><paragraph id="ID216dacbad047465fae5e16f5487d7216"><enum>(6)</enum><text>it is in the
			 interest of the United States to encourage the development of effective
			 frameworks for international cooperation to combat cyberthreats, and the
			 development of foreign government capabilities to combat cyberthreats;
			 and</text>
				</paragraph><paragraph id="ID176a301b4d71432d96f8c75c948682af"><enum>(7)</enum><text>the Secretary of
			 State, in consultation with other relevant Federal agencies, should develop and
			 lead Federal Government efforts to engage with other countries to advance the
			 cyberspace objectives of the United States, including efforts to bolster an
			 international framework of cyber norms, governance and deterrence.</text>
				</paragraph></section><section id="id4793D0AB051E4C1DA85AA8168938AC34"><enum>604.</enum><header>Coordination
			 of international cyber issues within the United States Government</header><text display-inline="no-display-inline">The Secretary of State is authorized to
			 designate a senior level official at the Department of State, to carry out the
			 Secretary’s responsibilities to—</text>
				<paragraph id="IDf600982b379f4ee7bcbaf9ebf4f4537b"><enum>(1)</enum><text>coordinate the
			 United States global diplomatic engagement on the full range of international
			 cyber issues, including building multilateral cooperation and developing
			 international norms, common policies, and responses to secure the integrity of
			 cyberspace;</text>
				</paragraph><paragraph id="IDfeee435a507849a7bb79ec82b9ab2ad0"><enum>(2)</enum><text>provide strategic
			 direction and coordination for United States Government policy and programs
			 aimed at addressing and responding to cyber issues overseas, especially in
			 relation to issues that affect United States foreign policy and related
			 national security concerns;</text>
				</paragraph><paragraph id="ID8f537d8548574abd8a00c272b246bdf1"><enum>(3)</enum><text>coordinate with
			 relevant Federal agencies, including the Department, the Department of Defense,
			 the Department of the Treasury, the Department of Justice, the Department of
			 Commerce, and the intelligence community to develop interagency plans regarding
			 international cyberspace, cybersecurity, and cybercrime issues; and</text>
				</paragraph><paragraph id="ID51780e3aa494448085145a1474daff09"><enum>(4)</enum><text>ensure that cyber
			 issues, including cybersecurity and cybercrime, are included in the
			 responsibilities of overseas Embassies and consulates of the United States, as
			 appropriate.</text>
				</paragraph></section><section id="IDbcf1e8b7f0244650b2fa209f60e39942"><enum>605.</enum><header>Consideration
			 of cybercrime in foreign policy and foreign assistance programs</header>
				<subsection id="IDc4c234dcb746460e8a852b974822868a"><enum>(a)</enum><header>Briefing</header>
					<paragraph id="IDd018ac8bf5b4490a81e6de71ba4001b8"><enum>(1)</enum><header>In
			 general</header><text>Not later than 1 year after the date of enactment of this
			 Act, the Secretary of State, after consultation with the heads of the relevant
			 Federal agencies, shall provide a comprehensive briefing to relevant
			 congressional committees—</text>
						<subparagraph id="ID4d8f051bf9244d41b2b91917cb1ff4a0"><enum>(A)</enum><text>assessing global
			 issues, trends, and actors considered to be significant with respect to
			 cybercrime;</text>
						</subparagraph><subparagraph id="IDa544c7e93144456f811bee748f4a7c71"><enum>(B)</enum><text>assessing, after
			 consultation with private industry groups, civil society organizations, and
			 other relevant domestic or multilateral organizations, which shall be selected
			 by the President based on an interest in combating cybercrime, means of
			 enhancing multilateral or bilateral efforts in areas of significance—</text>
							<clause id="ID3d0a7f8b161e40de8b07f2149485df69"><enum>(i)</enum><text>to
			 prevent and investigate cybercrime;</text>
							</clause><clause id="ID4bc358f81b2b4af2a4dd0dc2fa723594"><enum>(ii)</enum><text>to
			 develop and share best practices with respect to directly or indirectly
			 combating cybercrime; and</text>
							</clause><clause id="ID5abb1a93bad54455b54f7691e64e8af9"><enum>(iii)</enum><text>to cooperate
			 and take action with respect to the prevention, investigation, and prosecution
			 of cybercrime; and</text>
							</clause></subparagraph><subparagraph id="ID288a2e1094e04811baf4bafed9b51ebc"><enum>(C)</enum><text>describing the
			 steps taken by the United States to promote the multilateral or bilateral
			 efforts described in subparagraph (B).</text>
						</subparagraph></paragraph><paragraph id="IDdd0f80b4d12e4f65ac9beed6c0f9439c"><enum>(2)</enum><header>Contributions
			 from relevant Federal agencies</header><text>Not later than 30 days before the
			 date on which the briefing is to be provided under paragraph (1), the head of
			 each relevant Federal agency shall consult with and provide to the Secretary of
			 State relevant information appropriate for the briefing.</text>
					</paragraph></subsection><subsection id="IDfd00a8abab27468f8a88262b103a896e"><enum>(b)</enum><header>Periodic
			 updates</header><text>The Secretary of State shall provide updated information
			 highlighting significant developments relating to the issues described in
			 subsection (a), through periodic briefings to Congress.</text>
				</subsection><subsection id="ID80ce3ef7ddcf41c39da36394a182cb19"><enum>(c)</enum><header>Use of foreign
			 assistance programs</header>
					<paragraph id="ID65326d4ef36449e7869a233e653b1afb"><enum>(1)</enum><header>Foreign
			 assistance programs to combat cybercrime</header><text>The Secretary of State
			 is authorized to accord priority in foreign assistance to programs designed to
			 combat cybercrime in a region or program of significance in order to better
			 combat cybercrime by, among other things, improving the effectiveness and
			 capacity of the legal and judicial systems and the capabilities of law
			 enforcement agencies with respect to cybercrime.</text>
					</paragraph><paragraph commented="no" display-inline="no-display-inline" id="IDbcc926f74c2f4e88a05717940e9ad93d"><enum>(2)</enum><header>Sense of the
			 Congress with respect to bilateral and multilateral assistance</header><text>It
			 is the sense of Congress that the Secretary of State should include programs
			 designed to combat cybercrime in relevant bilateral or multilateral assistance
			 programs administered or supported by the United States Government.</text>
					</paragraph></subsection></section></title><title id="id3D53211210E34701AA5FA4526FE76BE0"><enum>VII</enum><header>Information
			 sharing</header>
			<section id="id6788880658D441D1B43DC27ADF206724"><enum>701.</enum><header>Affirmative
			 authority to monitor and defend against cybersecurity threats</header>
				<subsection id="idd55bd21e9dd9462eb49f6cb4ed5ad0d1"><enum>(a)</enum><header>In
			 general</header><text>Notwithstanding chapter 119, 121, or 206 of title 18,
			 United States Code, the Foreign Intelligence Surveillance Act of 1978 (50
			 U.S.C. 1801 et seq.), and sections 222 and 705 of the Communications Act of
			 1934 (47 U.S.C. 222 and 605), any private entity may—</text>
					<paragraph id="idd34d389f8c934d4a8103c079bc73a5c4"><enum>(1)</enum><text>monitor its
			 information systems and information that is stored on, processed by, or
			 transiting such information systems for—</text>
						<subparagraph id="idd1e9ce606c99442c930262d434f56d02"><enum>(A)</enum><text>malicious
			 reconnaissance;</text>
						</subparagraph><subparagraph id="id7f94521d82054e44bbc35cb02e13ec48"><enum>(B)</enum><text>efforts to defeat
			 a technical control or an operational control;</text>
						</subparagraph><subparagraph id="id27a06850447849fbabdbee7e5d40e3dc"><enum>(C)</enum><text>technical
			 vulnerabilities;</text>
						</subparagraph><subparagraph id="ided409d8d9ef746a8b55f83c37284789d"><enum>(D)</enum><text>efforts to cause
			 a user with legitimate access to an information system or information that is
			 stored on, processed by, or transiting an information system to unwittingly
			 enable the defeat of a technical control or an operational control;</text>
						</subparagraph><subparagraph id="id61689b661d254725a5ff7ad9cb8e015d"><enum>(E)</enum><text>malicious cyber
			 command and control;</text>
						</subparagraph><subparagraph id="id905dcec0eb244cbd885743950f8f5d8e"><enum>(F)</enum><text>information
			 exfiltrated as a result of defeating a technical control or an operational
			 control;</text>
						</subparagraph><subparagraph id="idea43b1f68da244aca248b4e29db3ae03"><enum>(G)</enum><text>any other
			 attribute of a cybersecurity threat, if monitoring for such attribute is not
			 otherwise prohibited by law; or</text>
						</subparagraph><subparagraph id="idfd4885c80d774e30ac78bddba3cebed4"><enum>(H)</enum><text>any combination
			 of subparagraphs (A) through (G);</text>
						</subparagraph></paragraph><paragraph id="id4ef58a807d214de2a12d056035094a5a"><enum>(2)</enum><text>operate
			 countermeasures on its information systems to protect its rights or property
			 from cybersecurity threats;</text>
					</paragraph><paragraph id="idfd7d796e77ec4caf96f7e12f1d5ab274"><enum>(3)</enum><text>consent to
			 another private entity monitoring or operating countermeasures on its
			 information systems and information that is stored on, processed by, or
			 transiting such information systems in accordance with this section;</text>
					</paragraph><paragraph id="id01cbf470a7594622acf27c6f08dfd036"><enum>(4)</enum><text>monitor a third
			 party’s information systems and information that is stored on, processed by, or
			 transiting such information systems for the information listed in subparagraphs
			 (A) through (H) of paragraph (1), if—</text>
						<subparagraph id="id9310d663c8644605bb07092287104c76"><enum>(A)</enum><text>the third party
			 provides express prior consent to such monitoring; and</text>
						</subparagraph><subparagraph id="idaa8e8e1e883944e4a9fecc02ebd937fb"><enum>(B)</enum><text>such monitoring
			 would be lawful under paragraph (1) or under any other provision of law if the
			 third party were to perform such monitoring of its own networks; and</text>
						</subparagraph></paragraph><paragraph id="id08eba326898440cca4f5ec13e8d2fc2a"><enum>(5)</enum><text>operate
			 countermeasures on a third party’s information systems to protect the third
			 party’s rights or property from cybersecurity threats, if—</text>
						<subparagraph id="idbd2d8fa1877e4804a2b95212e08a8696"><enum>(A)</enum><text>the third party
			 provides express prior consent to such countermeasures; and</text>
						</subparagraph><subparagraph id="id4e854e7da45f4a36a0195a5a02a4b2ef"><enum>(B)</enum><text>operating such
			 countermeasures would be lawful under paragraph (2) or under any other
			 provision of law if the third party were to operate such countermeasures on its
			 own information systems to protect its own rights or property.</text>
						</subparagraph></paragraph></subsection><subsection id="id6050d34d1203440587d8ed75faf1bb19"><enum>(b)</enum><header>Use and
			 protection of information</header><text>A private entity performing monitoring
			 or operating countermeasures under subsection (a)—</text>
					<paragraph id="id2b47cf57c08a4061ad9a362001c0d20a"><enum>(1)</enum><text>may use
			 cybersecurity threat indicators acquired under this title, provided such use is
			 solely for the purpose of protecting an information system or information that
			 is stored on, processed by, or transiting an information system from
			 cybersecurity threats or mitigating such threats;</text>
					</paragraph><paragraph id="id2c3b0805e4c14eadbcc87bd637874d9d"><enum>(2)</enum><text>shall make
			 reasonable efforts to safeguard communications, records, system traffic, or
			 other information that may be used to identify specific persons acquired in the
			 course of such monitoring from unauthorized access or acquisition;</text>
					</paragraph><paragraph id="id146dab438e6d4de38d768012db949d95"><enum>(3)</enum><text>shall comply with
			 any lawful restrictions placed on the use of cybersecurity threat indicators,
			 including, if requested, the removal or destruction of information that can be
			 used to identify specific persons from such indicators;</text>
					</paragraph><paragraph id="id2237850641654e5e835a61b3992942fa"><enum>(4)</enum><text>may not use
			 cybersecurity threat indicators to gain an unfair competitive advantage to the
			 detriment of the entity that authorized such monitoring or operation of
			 countermeasures; and</text>
					</paragraph><paragraph id="id603fec73717246dfb9481f147a69a54b"><enum>(5)</enum><text>may use
			 information obtained under any other provision of law.</text>
					</paragraph></subsection></section><section id="id3d58c2a6ca1a495bad35c9d044c67e94"><enum>702.</enum><header>Voluntary
			 disclosure of cybersecurity threat indicators among private entities</header>
				<subsection id="id716b3b693b0f44c5a9b8ecc67b4ef51e"><enum>(a)</enum><header>Authority to
			 disclose</header><text>Notwithstanding any other provision of law, any private
			 entity may disclose lawfully obtained cybersecurity threat indicators to any
			 other private entity in accordance with this section.</text>
				</subsection><subsection id="idfd2eacbbe72e468388fbff05dad9d6aa"><enum>(b)</enum><header>Use and
			 protection of information</header><text>A private entity disclosing or
			 receiving cybersecurity threat indicators pursuant to subsection (a)—</text>
					<paragraph id="idf2c1fd2771674991b3c347a70a196977"><enum>(1)</enum><text>may use, retain,
			 or further disclose such cybersecurity threat indicators solely for the purpose
			 of protecting an information system or information that is stored on, processed
			 by, or transiting an information system from cybersecurity threats or
			 mitigating such threats;</text>
					</paragraph><paragraph id="idf9bda58ed2d840758a5954a6a679d71e"><enum>(2)</enum><text>shall make
			 reasonable efforts to safeguard communications, records, system traffic, or
			 other information that can be used to identify specific persons from
			 unauthorized access or acquisition;</text>
					</paragraph><paragraph id="ida8a4b5e6c9a343b5968814ff98faadc2"><enum>(3)</enum><text>shall comply with
			 any lawful restrictions placed on the disclosure or use of cybersecurity threat
			 indicators, including, if requested, the removal of information that may be
			 used to identify specific persons from such indicators; and</text>
					</paragraph><paragraph id="id535689f54ab047909bf2cf2678500d5d"><enum>(4)</enum><text>may not use the
			 cybersecurity threat indicators to gain an unfair competitive advantage to the
			 detriment of the entity that authorized such sharing.</text>
					</paragraph></subsection><subsection id="ida399d7ffd9eb43d198028f42625dcb0e"><enum>(c)</enum><header>Transfers to
			 unreliable private entities prohibited</header><text>A private entity may not
			 disclose cybersecurity threat indicators to another private entity that the
			 disclosing entity knows—</text>
					<paragraph id="id5a60966b40564409bffb6f06f01875f4"><enum>(1)</enum><text>has intentionally
			 or willfully violated the requirements of subsection (b); and</text>
					</paragraph><paragraph id="ida279a2045d2943e287c9c80127ddd584"><enum>(2)</enum><text>is reasonably
			 likely to violate such requirements.</text>
					</paragraph></subsection></section><section id="idbd74bf64d78342edbd226eacb886bfce"><enum>703.</enum><header>Cybersecurity
			 exchanges</header>
				<subsection id="ide4896f9636aa4b74a0ad89d329041413"><enum>(a)</enum><header>Designation of
			 cybersecurity exchanges</header><text>The Secretary of Homeland Security, in
			 consultation with the Director of National Intelligence, the Attorney General,
			 and the Secretary of Defense, shall establish—</text>
					<paragraph id="id6c1e0b1a6258458ca15d03965263dd4f"><enum>(1)</enum><text>a process for
			 designating one or more appropriate civilian Federal entities or non-Federal
			 entities to serve as cybersecurity exchanges to receive and distribute
			 cybersecurity threat indicators;</text>
					</paragraph><paragraph id="idf76b3eb0128d48baacc3abfaf4c4182d"><enum>(2)</enum><text>procedures to
			 facilitate and ensure the sharing of classified and unclassified cybersecurity
			 threat indicators in as close to real time as possible with appropriate Federal
			 entities and non-Federal entities in accordance with this title; and</text>
					</paragraph><paragraph id="id47fe82a4ff3a4decbdfd663044011bb5"><enum>(3)</enum><text>a process for
			 identifying certified entities to receive classified cybersecurity threat
			 indicators in accordance with paragraph (2).</text>
					</paragraph></subsection><subsection id="id65f7293a84c844158581769ee58023b8"><enum>(b)</enum><header>Purpose</header><text>The
			 purpose of a cybersecurity exchange is to receive and distribute, in as close
			 to real time as possible, cybersecurity threat indicators, and to thereby avoid
			 unnecessary and duplicative Federal bureaucracy for information sharing as
			 provided in this title.</text>
				</subsection><subsection id="id87fb9eb1f552449c9bd7338eefc436f8"><enum>(c)</enum><header>Requirement for
			 a lead Federal civilian cybersecurity exchange</header>
					<paragraph id="id3fb41ab08f274334805e39cbb2107834"><enum>(1)</enum><header>In
			 general</header><text>The Secretary, in consultation with the Director of
			 National Intelligence, the Attorney General, and the Secretary of Defense,
			 shall designate a civilian Federal entity as the lead cybersecurity exchange to
			 serve as a focal point within the Federal Government for cybersecurity
			 information sharing among Federal entities and with non-Federal
			 entities.</text>
					</paragraph><paragraph id="id31ed575ff71b41cdaeeb7285f18830d6"><enum>(2)</enum><header>Responsibilities</header><text>The
			 lead Federal civilian cybersecurity exchange designated under paragraph (1)
			 shall—</text>
						<subparagraph id="id5c4b162459a74b3c9cdabe4819fc8d77"><enum>(A)</enum><text>receive and
			 distribute, in as close to real time as possible, cybersecurity threat
			 indicators in accordance with this title;</text>
						</subparagraph><subparagraph id="idcb29b54e8d2d411ea736f9cff6c768e6"><enum>(B)</enum><text>facilitate
			 information sharing, interaction, and collaboration among and between—</text>
							<clause id="id0769e4406c4941f1ae83fefbdcb23649"><enum>(i)</enum><text>Federal
			 entities;</text>
							</clause><clause id="id232e6a7473264fc583cda64423aa5b90"><enum>(ii)</enum><text>State, local,
			 tribal, and territorial governments;</text>
							</clause><clause id="id2406db7d2c23496d93a538a6ce1b5916"><enum>(iii)</enum><text>private
			 entities;</text>
							</clause><clause id="id1ec4fd51d2c14327b780ee30c9ca7101"><enum>(iv)</enum><text>academia;</text>
							</clause><clause id="idf8e0407a2e984195a5f43b4cfd1f68bd"><enum>(v)</enum><text>international
			 partners, in consultation with the Secretary of State; and</text>
							</clause><clause id="ida855a164ef754718935cf057eab2a64d"><enum>(vi)</enum><text>other
			 cybersecurity exchanges;</text>
							</clause></subparagraph><subparagraph id="id98e0206e2025418189dabcd5e7b052fb"><enum>(C)</enum><text>disseminate
			 timely and actionable cybersecurity threat, vulnerability, mitigation, and
			 warning information lawfully obtained from any source, including alerts,
			 advisories, indicators, signatures, and mitigation and response measures, to
			 appropriate Federal and non-Federal entities in as close to real time as
			 possible, to improve the security and protection of information systems;</text>
						</subparagraph><subparagraph id="id881fdb4602de478fb9c28c42081934b5"><enum>(D)</enum><text>coordinate with
			 other Federal and non-Federal entities, as appropriate, to integrate
			 information from Federal and non-Federal entities, including Federal
			 cybersecurity centers, non-Federal network or security operation centers, other
			 cybersecurity exchanges, and non-Federal entities that disclose cybersecurity
			 threat indicators under section 704(a), in as close to real time as possible,
			 to provide situational awareness of the United States information security
			 posture and foster information security collaboration among information system
			 owners and operators;</text>
						</subparagraph><subparagraph id="id56a1f48c442d47899688ba054e100db4"><enum>(E)</enum><text>conduct, in
			 consultation with private entities and relevant Federal and other governmental
			 entities, regular assessments of existing and proposed information sharing
			 models to eliminate bureaucratic obstacles to information sharing and identify
			 best practices for such sharing; and</text>
						</subparagraph><subparagraph id="idd46ae7714e4f46eda470a668dc31d61c"><enum>(F)</enum><text>coordinate with
			 other Federal entities, as appropriate, to compile and analyze information
			 about risks and incidents that threaten information systems, including
			 information voluntarily submitted in accordance with section 704(a) or
			 otherwise in accordance with applicable laws.</text>
						</subparagraph></paragraph><paragraph id="id2e74627e51e64b6ca1cda7c664ace550"><enum>(3)</enum><header>Schedule for
			 designation</header><text>The designation of a lead Federal civilian
			 cybersecurity exchange under paragraph (1) shall be made concurrently with the
			 issuance of the interim policies and procedures under section
			 704(g)(3)(D).</text>
					</paragraph></subsection><subsection id="id5420d180738f4f04b26d931a7b44e4ef"><enum>(d)</enum><header>Additional
			 civilian Federal cybersecurity exchanges</header><text>In accordance with the
			 process and procedures established in subsection (a), the Secretary, in
			 consultation with the Director of National Intelligence, the Attorney General,
			 and the Secretary of Defense, may designate additional civilian Federal
			 entities to receive and distribute cybersecurity threat indicators, if such
			 entities are subject to the requirements for use, retention, and disclosure of
			 information by a cybersecurity exchange under section 704(b) and the special
			 requirements for Federal entities under section 704(g).</text>
				</subsection><subsection id="id5fb45a41664949878aee04ce780d2aa1"><enum>(e)</enum><header>Requirements
			 for non-Federal cybersecurity exchanges</header>
					<paragraph id="idd3c465ee2ad247cea599681fc0f80e17"><enum>(1)</enum><header>In
			 general</header><text>In considering whether to designate a private entity or
			 any other non-Federal entity as a cybersecurity exchange to receive and
			 distribute cybersecurity threat indicators under section 704, and what entity
			 to designate, the Secretary shall consider the following factors:</text>
						<subparagraph id="id95fe1fd8f3ea4ffc94636d7f9a10ff6c"><enum>(A)</enum><text>The net effect
			 that such designation would have on the overall cybersecurity of the United
			 States.</text>
						</subparagraph><subparagraph id="id630b9711e390478c8871e7eb5b4aa8bd"><enum>(B)</enum><text>Whether such
			 designation could substantially improve such overall cybersecurity by serving
			 as a hub for receiving and sharing cybersecurity threat indicators in as close
			 to real time as possible, including the capacity of the non-Federal entity for
			 performing those functions.</text>
						</subparagraph><subparagraph id="id8f7ad8a9bab145a6bf34405470ba5917"><enum>(C)</enum><text>The capacity of
			 such non-Federal entity to safeguard cybersecurity threat indicators from
			 unauthorized disclosure and use.</text>
						</subparagraph><subparagraph id="id01486163325a4140a1583ad6cd9626f4"><enum>(D)</enum><text>The adequacy of
			 the policies and procedures of such non-Federal entity to protect personally
			 identifiable information from unauthorized disclosure and use.</text>
						</subparagraph><subparagraph id="idab9d43991ea147f6bd087a5223203b64"><enum>(E)</enum><text>The ability of
			 the non-Federal entity to sustain operations using entirely non-Federal sources
			 of funding.</text>
						</subparagraph></paragraph><paragraph id="id1baf51329edd46bf877eb1f7e47712bb"><enum>(2)</enum><header>Regulations</header><text>The
			 Secretary may promulgate regulations as may be necessary to carry out this
			 subsection.</text>
					</paragraph></subsection><subsection id="id209a602ff6394b9aba5d5a017036999f"><enum>(f)</enum><header>Construction
			 with other authorities</header><text>Nothing in this section may be construed
			 to alter the authorities of a Federal cybersecurity center, unless such
			 cybersecurity center is acting in its capacity as a designated cybersecurity
			 exchange.</text>
				</subsection><subsection id="idd9401e558d8d46a1a12832cb96b52086"><enum>(g)</enum><header>Congressional
			 notification of designation of cybersecurity exchanges</header>
					<paragraph id="id38885493A5A84BA78202A0ACDFB2F17F"><enum>(1)</enum><header>In
			 general</header><text>The Secretary, in coordination with the Director of
			 National Intelligence, the Attorney General, and the Secretary of Defense,
			 shall promptly notify Congress, in writing, of any designation of a
			 cybersecurity exchange under this title.</text>
					</paragraph><paragraph id="id4ED59465B59E44A1A4EB7FE7DD31E4EC"><enum>(2)</enum><header>Requirement</header><text>Written
			 notification under paragraph (1) shall include a description of the criteria
			 and processes used to make the designation.</text>
					</paragraph></subsection></section><section id="idfb0d269052c849599d761ac9a9d70297"><enum>704.</enum><header>Voluntary
			 disclosure of cybersecurity threat indicators to a cybersecurity
			 exchange</header>
				<subsection id="id92cb163bcde14137b46d47492c5cdd35"><enum>(a)</enum><header>Authority to
			 disclose</header><text>Notwithstanding any other provision of law, a
			 non-Federal entity may disclose lawfully obtained cybersecurity threat
			 indicators to a cybersecurity exchange in accordance with this section.</text>
				</subsection><subsection id="id4468053969784af8be020753b055631f"><enum>(b)</enum><header>Use, retention,
			 and disclosure of information by a cybersecurity exchange</header><text>A
			 cybersecurity exchange may only use, retain, or further disclose information
			 provided pursuant to subsection (a)—</text>
					<paragraph id="ideb6b40ad8f3c46eab03c65a6a3cc7762"><enum>(1)</enum><text>in order to
			 protect information systems from cybersecurity threats and to mitigate
			 cybersecurity threats; or</text>
					</paragraph><paragraph id="id1d87327be4d047ef8d2f001b55c881c3"><enum>(2)</enum><text>to law
			 enforcement pursuant to subsection (g)(2).</text>
					</paragraph></subsection><subsection id="id03840273d535449caee1794f0bd69d7d"><enum>(c)</enum><header>Use and
			 protection of information received from a cybersecurity
			 exchange</header><text>A non-Federal entity receiving cybersecurity threat
			 indicators from a cybersecurity exchange—</text>
					<paragraph id="id3a60669bf9274cd0847ba37312c781e2"><enum>(1)</enum><text>may use, retain,
			 or further disclose such cybersecurity threat indicators solely for the purpose
			 of protecting an information system or information that is stored on, processed
			 by, or transiting an information system from cybersecurity threats or
			 mitigating such threats;</text>
					</paragraph><paragraph id="id4519E545E3A340F19C1FEE278384734B"><enum>(2)</enum><text>shall make
			 reasonable efforts to safeguard communications, records, system traffic, or
			 other information that can be used to identify specific persons from
			 unauthorized access or acquisition;</text>
					</paragraph><paragraph id="id2cc0b2ac1ee347709f3f6ab29859ca1f"><enum>(3)</enum><text>shall comply with
			 any lawful restrictions placed on the disclosure or use of cybersecurity threat
			 indicators by the cybersecurity exchange or a third party, if the cybersecurity
			 exchange received such information from the third party, including, if
			 requested, the removal of information that can be used to identify specific
			 persons from such indicators; and</text>
					</paragraph><paragraph id="idc2f2ce85f0e14d09a9bb4da223d3eb18"><enum>(4)</enum><text>may not use the
			 cybersecurity threat indicators to gain an unfair competitive advantage to the
			 detriment of the third party that authorized such sharing.</text>
					</paragraph></subsection><subsection id="id125523dd180a4a03ad353b715a62eae7"><enum>(d)</enum><header>Exemption from
			 public disclosure</header><text>Any cybersecurity threat indicator disclosed by
			 a non-Federal entity to a cybersecurity exchange pursuant to subsection (a)
			 shall be—</text>
					<paragraph id="id43d453cde41f4f2da1106856cae53962"><enum>(1)</enum><text>exempt from
			 disclosure under section 552(b)(3) of title 5, United States Code, or any
			 comparable State law; and</text>
					</paragraph><paragraph id="idfa3664d63a7d453594d487c80d913cfb"><enum>(2)</enum><text>treated as
			 voluntarily shared information under section 552 of title 5, United States
			 Code, or any comparable State law.</text>
					</paragraph></subsection><subsection id="id9d74785656a047dfb10fc516e8d4dd03"><enum>(e)</enum><header>Exemption from
			 ex parte limitations</header><text>Any cybersecurity threat indicator disclosed
			 by a non-Federal entity to a cybersecurity exchange pursuant to subsection (a)
			 shall not be subject to the rules of any governmental entity or judicial
			 doctrine regarding ex parte communications with a decision making
			 official.</text>
				</subsection><subsection id="id06de7675895e401cbc5332166b42a56c"><enum>(f)</enum><header>Exemption from
			 waiver of privilege</header><text>Any cybersecurity threat indicator disclosed
			 by a non-Federal entity to a cybersecurity exchange pursuant to subsection (a)
			 may not be construed to be a waiver of any applicable privilege or protection
			 provided under Federal, State, tribal, or territorial law, including any trade
			 secret protection.</text>
				</subsection><subsection id="id30cb8812120e446ba72bcb5bdd5c92da"><enum>(g)</enum><header>Special
			 requirements for Federal and law enforcement entities</header>
					<paragraph id="idc17f5b16a30f4999be54b2398ee4a4ac"><enum>(1)</enum><header>Receipt,
			 disclosure and use of cybersecurity threat indicators by a Federal
			 entity</header>
						<subparagraph id="idae8f33a25b974c86b0b3f3acb73c79ff"><enum>(A)</enum><header>Authority to
			 receive and use cybersecurity threat indicators</header><text>A Federal entity
			 that is not a cybersecurity exchange may receive, retain, and use cybersecurity
			 threat indicators from a cybersecurity exchange in order—</text>
							<clause id="id0600ba320044470f9ed9f582da7a5065"><enum>(i)</enum><text>to
			 protect information systems from cybersecurity threats and to mitigate
			 cybersecurity threats; and</text>
							</clause><clause id="idc533bbc10ae64f5b8e6c8fbfb65f3a05"><enum>(ii)</enum><text>to
			 disclose such cybersecurity threat indicators to law enforcement in accordance
			 with paragraph (2).</text>
							</clause></subparagraph><subparagraph id="id50d9d4ae05114992a22badfa1eadee84"><enum>(B)</enum><header>Authority to
			 disclose cybersecurity threat indicators</header><text>A Federal entity that is
			 not a cybersecurity exchange shall ensure that if disclosing cybersecurity
			 threat indicators to a non-Federal entity under this section, such non-Federal
			 entity shall use or retain such cybersecurity threat indicators in a manner
			 that is consistent with the requirements in—</text>
							<clause id="id319867b9667c4cf79e73856c430b610a"><enum>(i)</enum><text>subsection (b) on
			 the use and protection of information; and</text>
							</clause><clause id="ide431950419cc4912a03fb8620813b317"><enum>(ii)</enum><text>paragraph
			 (2).</text>
							</clause></subparagraph></paragraph><paragraph id="id842ee0c6668e4cf58a23c71ab1be2579"><enum>(2)</enum><header>Law enforcement
			 access and use of cybersecurity threat indicators</header>
						<subparagraph id="id4f8d7c5f5db84ab19365f410a0cf80ef"><enum>(A)</enum><header>Disclosure to
			 law enforcement</header><text>A Federal entity may disclose cybersecurity
			 threat indicators received under this title to a law enforcement entity
			 if—</text>
							<clause id="id2a30e1a261514ee496895d8da2334e80"><enum>(i)</enum><text>the
			 disclosure is permitted under the procedures developed by the Secretary and
			 approved by the Attorney General under paragraph (3); and</text>
							</clause><clause id="idB7CCD6B1A67049C8BD4D26E3EFDF398B"><enum>(ii)</enum><text>the information
			 appears to pertain—</text>
								<subclause id="idfa4078c9ffe145da9131c7dbf1a3dfc3"><enum>(I)</enum><text>to a
			 cybersecurity crime which has been, is being, or is about to be
			 committed;</text>
								</subclause><subclause id="id3737aa4bffce4dba968af9588a2d568a"><enum>(II)</enum><text>to an imminent
			 threat of death or serious bodily harm; or</text>
								</subclause><subclause id="id5baf0eda962a4361ba939047e92999e8"><enum>(III)</enum><text>to a serious
			 threat to minors, including sexual exploitation and threats to physical
			 safety.</text>
								</subclause></clause></subparagraph><subparagraph id="id77649f59dedc4e1880247a949833b6ad"><enum>(B)</enum><header>Use by law
			 enforcement</header><text>A law enforcement entity may only use cybersecurity
			 threat indicators received by a Federal entity under paragraph (A) in
			 order—</text>
							<clause id="id61982f15a81a441f9b0cbc2d79d2e04b"><enum>(i)</enum><text>to
			 protect information systems from a cybersecurity threat or investigate,
			 prosecute, or disrupt a cybersecurity crime;</text>
							</clause><clause id="id01cdeccea009490daa695ac0d12fcf73"><enum>(ii)</enum><text>to
			 protect individuals from an imminent threat of death or serious bodily harm;
			 or</text>
							</clause><clause id="id1141f1bc7b234e25a8c4da14207387af"><enum>(iii)</enum><text>to protect
			 minors from any serious threat, including sexual exploitation and threats to
			 physical safety.</text>
							</clause></subparagraph></paragraph><paragraph id="id8ad9e82a172a41588ee0ce708736221e"><enum>(3)</enum><header>Privacy and
			 civil liberties</header>
						<subparagraph id="idfdbb7c16210e4e0dacfd54f273ee238d"><enum>(A)</enum><header>Requirement for
			 policies and procedures</header><text>The Secretary, in consultation with
			 privacy and civil liberties experts, the Director of National Intelligence, and
			 the Secretary of Defense, shall develop and periodically review policies and
			 procedures governing the receipt, retention, use, and disclosure of
			 cybersecurity threat indicators by a Federal entity obtained in connection with
			 activities authorized in this title. Such policies and procedures shall—</text>
							<clause id="id6ee5a7f3eb7848338a459ebe949c2394"><enum>(i)</enum><text>minimize the
			 impact on privacy and civil liberties, consistent with the need to protect
			 information systems from cybersecurity threats and mitigate cybersecurity
			 threats;</text>
							</clause><clause id="ida42dbee2e37f4865b78322bb4176321c"><enum>(ii)</enum><text>reasonably limit
			 the receipt, retention, use and disclosure of cybersecurity threat indicators
			 associated with specific persons consistent with the need to carry out the
			 responsibilities of this title, including establishing a process for the timely
			 destruction of cybersecurity threat indicators that are received pursuant to
			 this section that do not reasonably appear to be related to the purposes
			 identified in paragraph (1)(A);</text>
							</clause><clause id="id8067aefae40640ed9312d7d2a26cf391"><enum>(iii)</enum><text>include
			 requirements to safeguard cybersecurity threat indicators that may be used to
			 identify specific persons from unauthorized access or acquisition;</text>
							</clause><clause id="id79b4e15d9e43494bbea79aa54c26ad62"><enum>(iv)</enum><text>include
			 procedures for notifying entities, as appropriate, if information received
			 pursuant to this section is not a cybersecurity threat indicator; and</text>
							</clause><clause id="id19b51b655c9447c1b1f74d2613851132"><enum>(v)</enum><text>protect the
			 confidentiality of cybersecurity threat indicators associated with specific
			 persons to the greatest extent practicable and require recipients to be
			 informed that such indicators may only be used for the purposes identified in
			 paragraph (1)(A).</text>
							</clause></subparagraph><subparagraph id="id3c3d93fe526f469db0d62088ea395d26"><enum>(B)</enum><header>Adoption of
			 policies and procedures</header><text>The head of an agency responsible for a
			 Federal entity designated as a cybersecurity exchange under section 703 shall
			 adopt and comply with the policies and procedures developed under this
			 paragraph.</text>
						</subparagraph><subparagraph id="idcb73fd04d7214acd8a8a914869605e70"><enum>(C)</enum><header>Review by the
			 Attorney General</header><text>The policies and procedures developed under this
			 subsection shall be provided to the Attorney General for review not later than
			 1 year after the date of the enactment of this title, and shall not be issued
			 without the Attorney General’s approval.</text>
						</subparagraph><subparagraph id="id6b467638d575426e95193ce93f72429c"><enum>(D)</enum><header>Requirement for
			 interim policies and procedures</header><text>The Secretary shall issue interim
			 policies and procedures not later than 60 days after the date of the enactment
			 of this title.</text>
						</subparagraph><subparagraph id="id853073b02e704592874ae13dbed30548"><enum>(E)</enum><header>Provision to
			 Congress</header><text>The policies and procedures issued under this title and
			 any amendments to such policies and procedures shall be provided to Congress in
			 an unclassified form and be made public, but may include a classified
			 annex.</text>
						</subparagraph></paragraph><paragraph id="idc44fa010673e41c09c21246894dbd10f"><enum>(4)</enum><header>Oversight</header>
						<subparagraph id="id2e0910eaef4b480180ee24597e2b14af"><enum>(A)</enum><header>Requirement for
			 oversight</header><text>The Secretary and the Attorney General shall establish
			 a mandatory program to monitor and oversee compliance with the policies and
			 procedures issued under this subsection.</text>
						</subparagraph><subparagraph id="ide32653200a6e4982b1df006aa905ccc5"><enum>(B)</enum><header>Notification of
			 the Attorney General</header><text>The head of each Federal entity that
			 receives information under this title shall—</text>
							<clause id="ide4c97cedef9648e1b177c6a57afede49"><enum>(i)</enum><text>comply with the
			 policies and procedures developed by the Secretary and approved by the Attorney
			 General under paragraph (3);</text>
							</clause><clause id="id9509f883137a499c9e806e6230c8e3a8"><enum>(ii)</enum><text>promptly notify
			 the Attorney General of significant violations of such policies and procedures;
			 and</text>
							</clause><clause id="idb0c8480c15d5479398f8d60173b697cc"><enum>(iii)</enum><text>provide to the
			 Attorney General any information relevant to the violation that the Attorney
			 General requires.</text>
							</clause></subparagraph><subparagraph id="id394c454758974da1ae2f32908c739176"><enum>(C)</enum><header>Annual
			 report</header><text>On an annual basis, the Chief Privacy and Civil Liberties
			 Officer of the Department of Justice and the Chief Privacy Officer of the
			 Department, in consultation with the most senior privacy and civil liberties
			 officer or officers of any appropriate agencies, shall jointly submit to
			 Congress a report assessing the privacy and civil liberties impact of the
			 governmental activities conducted pursuant to this title.</text>
						</subparagraph></paragraph><paragraph id="id3b8692242d8342cdbb7412dd87b99d99"><enum>(5)</enum><header>Reports on
			 information sharing</header>
						<subparagraph id="iddd388a3475664626bacac0c52c448fa8"><enum>(A)</enum><header>Privacy and
			 Civil Liberties Oversight Board report</header><text>Not later than 2 years
			 after the date of the enactment of this title, and every 2 years thereafter,
			 the Privacy and Civil Liberties Oversight Board shall submit to Congress and
			 the President a report providing—</text>
							<clause id="idddf2a6d15a604e51ae3882f6c73b70db"><enum>(i)</enum><text>an
			 analysis of the practices of private entities that are performing, monitoring,
			 operating countermeasures, or disclosing cybersecurity threat indicators
			 pursuant to this title;</text>
							</clause><clause id="id6BD5A60DE1494D41AC5F5BBEC6F3299C"><enum>(ii)</enum><text>an
			 assessment of the privacy and civil liberties impact of the activities carried
			 out by the Federal entities under this title; and</text>
							</clause><clause id="ida69fc06533fb4ac3946ed7c51a1b26d4"><enum>(iii)</enum><text>recommendations
			 for improvements to or modifications of the law and the policies and procedures
			 established pursuant to paragraph (3) in order to address privacy and civil
			 liberties concerns.</text>
							</clause></subparagraph><subparagraph id="id75d2dbbb96e44d7a973cb8ebef8789c3"><enum>(B)</enum><header>Inspectors
			 General annual report</header><text>The Inspector General of the Department,
			 the Inspector General of the Intelligence Community, the Inspector General of
			 the Department of Justice, and the Inspector General of the Department of
			 Defense shall, on an annual basis, jointly submit to Congress a report on the
			 receipt, use and disclosure of information shared with a Federal cybersecurity
			 exchange under this title, including—</text>
							<clause id="idde071a18557a48d689f84f9f08328031"><enum>(i)</enum><text>a
			 review of the use by Federal entities of such information for a purpose other
			 than to protect information systems from cybersecurity threats and to mitigate
			 cybersecurity threats, including law enforcement access and use pursuant to
			 paragraph (2);</text>
							</clause><clause id="ide25987a6cc38419a85ba9562306ead68"><enum>(ii)</enum><text>a
			 review of the type of information shared with a Federal cybersecurity
			 exchange;</text>
							</clause><clause id="id907552a3e5b94a0a9e92934dc2dea259"><enum>(iii)</enum><text>a
			 review of the actions taken by Federal entities based on such
			 information;</text>
							</clause><clause id="ide313ee919ebc4fd391a10395dfc77066"><enum>(iv)</enum><text>appropriate
			 metrics to determine the impact of the sharing of such information with a
			 Federal cybersecurity exchange on privacy and civil liberties;</text>
							</clause><clause id="iddd44d63e971842beae8f028210ab783d"><enum>(v)</enum><text>a
			 list of Federal entities receiving such information;</text>
							</clause><clause id="iddeace51c6fdd4373aaa07d8fbc4ed86a"><enum>(vi)</enum><text>a
			 review of the sharing of such information among Federal entities to identify
			 inappropriate stovepiping of shared information; and</text>
							</clause><clause id="idb6f00af385ba4f6abad184673d7954d8"><enum>(vii)</enum><text>any
			 recommendations of the inspectors general for improvements or modifications to
			 the authorities under this title.</text>
							</clause></subparagraph><subparagraph id="id6465de025625435dade976dcf7d47280"><enum>(C)</enum><header>Form</header><text>Each
			 report required under this paragraph shall be submitted in unclassified form,
			 but may include a classified annex.</text>
						</subparagraph></paragraph><paragraph id="idd234becd4b194615b179a78cdef2cb41"><enum>(6)</enum><header>Sanctions</header><text>The
			 head of each Federal entity that conducts activities under this title shall
			 develop and enforce appropriate sanctions for officers, employees, or agents of
			 such entities who conducts such activities—</text>
						<subparagraph id="id53c46b1402624338aeec2b8b84aac913"><enum>(A)</enum><text>outside the
			 normal course of their specified duties;</text>
						</subparagraph><subparagraph id="id7313b29d33374956aa73c2891a585563"><enum>(B)</enum><text>in a manner
			 inconsistent with the discharge of the responsibilities of such entity;
			 or</text>
						</subparagraph><subparagraph id="id03da6723393a4a53b73185c1d498e9ab"><enum>(C)</enum><text>in contravention
			 of the requirements, policies, and procedures required by this
			 subsection.</text>
						</subparagraph></paragraph><paragraph id="id7211c1b47aee4fb9a25636bc8d660631"><enum>(7)</enum><header>Federal
			 Government liability for violations of this title</header>
						<subparagraph id="id5ab748cf3e324e428cd00a877c9e6883"><enum>(A)</enum><header>In
			 general</header><text>If a Federal entity intentionally or willfully violates a
			 provision of this title or a regulation promulgated under this title, the
			 United States shall be liable to a person adversely affected by such violation
			 in an amount equal to the sum of—</text>
							<clause id="ide552767784d14471a302579c49f0f743"><enum>(i)</enum><text>the
			 actual damages sustained by the person as a result of the violation or $1,000,
			 whichever is greater; and</text>
							</clause><clause id="ida7c937b713214f76b47b560bbad0d3a8"><enum>(ii)</enum><text>the costs of the
			 action together with reasonable attorney fees as determined by the
			 court.</text>
							</clause></subparagraph><subparagraph id="idb21e51ff71b04ff492a401d1ac04de77"><enum>(B)</enum><header>Venue</header><text>An
			 action to enforce liability created under this subsection may be brought in the
			 district court of the United States in—</text>
							<clause id="id23bcc8e9c4214f648ed883d8be689f65"><enum>(i)</enum><text>the
			 district in which the complainant resides;</text>
							</clause><clause id="iddfbe87b60ee84997a3d81513a3611cf0"><enum>(ii)</enum><text>the district in
			 which the principal place of business of the complainant is located;</text>
							</clause><clause id="idd6477e2a4757486dbfbd9714df839c06"><enum>(iii)</enum><text>the district in
			 which the Federal entity that disclosed the information is located; or</text>
							</clause><clause id="id3ed211475cc1493fac1e253868516c1b"><enum>(iv)</enum><text>the District of
			 Columbia.</text>
							</clause></subparagraph><subparagraph id="id1b6900315b0b47f7ab5c8afe35c5bb64"><enum>(C)</enum><header>Statute of
			 limitations</header><text>No action shall lie under this subsection unless such
			 action is commenced not later than 2 years after the date of the violation that
			 is the basis for the action.</text>
						</subparagraph><subparagraph id="id49ed39e0d86147988de9de411812b7f0"><enum>(D)</enum><header>Exclusive cause
			 of action</header><text>A cause of action under this subsection shall be the
			 exclusive means available to a complainant seeking a remedy for a disclosure of
			 information in violation of this title by a Federal entity.</text>
						</subparagraph></paragraph></subsection></section><section id="id5a94343ad9104cfe8c69577a3767e46a"><enum>705.</enum><header>Sharing of
			 classified cybersecurity threat indicators</header>
				<subsection id="id7b1eb640bb4d4f51be352e8ec15a65c4"><enum>(a)</enum><header>Sharing of
			 classified cybersecurity threat indicators</header><text>The procedures
			 established under section 703(a)(2) shall provide that classified cybersecurity
			 threat indicators may only be—</text>
					<paragraph id="id57d043750bf74f2fa91c0efe4a53534b"><enum>(1)</enum><text>shared with
			 certified entities;</text>
					</paragraph><paragraph id="id24262612816541deb335e5eca61de9e3"><enum>(2)</enum><text>shared in a
			 manner that is consistent with the need to protect the national security of the
			 United States;</text>
					</paragraph><paragraph id="id36f44d74a0f24f3687fd13403915a981"><enum>(3)</enum><text>shared with a
			 person with an appropriate security clearance to receive such cybersecurity
			 threat indicators; and</text>
					</paragraph><paragraph id="id7498decc19fb47798332506744361054"><enum>(4)</enum><text>used by a
			 certified entity in a manner that protects such cybersecurity threat indicators
			 from unauthorized disclosure.</text>
					</paragraph></subsection><subsection id="id426eb6eccd6a4ac382d015b9d66780b8"><enum>(b)</enum><header>Requirement for
			 guidelines</header><text>Not later than 60 days after the date of the enactment
			 of this title, the Director of National Intelligence shall issue guidelines
			 providing that appropriate Federal officials may, as the Director considers
			 necessary to carry out this title—</text>
					<paragraph id="id5e56ede47a344265b41ac911fb0e10a9"><enum>(1)</enum><text>grant a security
			 clearance on a temporary or permanent basis to an employee of a certified
			 entity;</text>
					</paragraph><paragraph id="idc33bba0fdc7d4dbba9246d74e8a03ef3"><enum>(2)</enum><text>grant a security
			 clearance on a temporary or permanent basis to a certified entity and approval
			 to use appropriate facilities; or</text>
					</paragraph><paragraph id="id23379983a9db4ab889a25f32f7be5b5a"><enum>(3)</enum><text>expedite the
			 security clearance process for such an employee or entity, if appropriate, in a
			 manner consistent with the need to protect the national security of the United
			 States.</text>
					</paragraph></subsection><subsection id="idb263d60e3b19440aaab152e9305873eb"><enum>(c)</enum><header>Distribution of
			 procedures and guidelines</header><text>Following the establishment of the
			 procedures under section 703(a)(2) and the issuance of the guidelines under
			 subsection (b), the Secretary and the Director of National Intelligence shall
			 expeditiously distribute such procedures and guidelines to—</text>
					<paragraph id="idd73ee5f5daae4529b5d31798c603f67e"><enum>(1)</enum><text>appropriate
			 governmental entities and private entities;</text>
					</paragraph><paragraph id="id7ae3cff84f28470db243b5cffbd7a659"><enum>(2)</enum><text>the Committee on
			 Armed Services, the Committee on Commerce, Science, and Transportation, the
			 Committee on Homeland Security and Governmental Affairs, the Committee on the
			 Judiciary, and the Select Committee on Intelligence of the Senate; and</text>
					</paragraph><paragraph id="id153acb9a56284d8b81bc70bcfc74149c"><enum>(3)</enum><text>the Committee on
			 Armed Services, the Committee on Energy and Commerce, the Committee on Homeland
			 Security, the Committee on the Judiciary, and the Permanent Select Committee on
			 Intelligence of the House of Representatives.</text>
					</paragraph></subsection></section><section id="id765bbb0cd3944786811c79e01531d934"><enum>706.</enum><header>Limitation on
			 liability and good faith defense for cybersecurity activities</header>
				<subsection id="idda48cdb2b0cf43dcbbebf4fb2a779d8e"><enum>(a)</enum><header>In
			 general</header><text>No civil or criminal cause of action shall lie or be
			 maintained in any Federal or State court against any entity acting as
			 authorized by this title, and any such action shall be dismissed promptly for
			 activities authorized by this title consisting of—</text>
					<paragraph id="id9fe43fea611b40beba42463709cf806a"><enum>(1)</enum><text>the cybersecurity
			 monitoring activities authorized by paragraph (1), (3) or (4) of section
			 701(a); or</text>
					</paragraph><paragraph id="idb54845d2f17741f1ac96dc6678981fac"><enum>(2)</enum><text>the voluntary
			 disclosure of a lawfully obtained cybersecurity threat indicator—</text>
						<subparagraph id="idd5d5a9c6457446c295e848f13ab570f1"><enum>(A)</enum><text>to a
			 cybersecurity exchange pursuant to section 704(a);</text>
						</subparagraph><subparagraph id="idbec48a4c8f1a4058979475099a219fe4"><enum>(B)</enum><text>by a provider of
			 cybersecurity services to a customer of that provider;</text>
						</subparagraph><subparagraph id="id459915ad823640f5b50726038233b3ef"><enum>(C)</enum><text>to a private
			 entity or governmental entity that provides or manages critical infrastructure
			 (as that term is used in section 1016 of the Critical Infrastructures
			 Protection Act of 2001 (42 U.S.C. 5195c)); or</text>
						</subparagraph><subparagraph id="id39c58e0cda7d4920801c750007ed2ba4"><enum>(D)</enum><text>to any other
			 private entity under section 702(a), if the cybersecurity threat indicator is
			 also disclosed within a reasonable time to a cybersecurity exchange.</text>
						</subparagraph></paragraph></subsection><subsection id="id86efee51f2ea4e89baa07b7e2adf3d95"><enum>(b)</enum><header>Good faith
			 defense</header><text>If a civil or criminal cause of action is not barred
			 under subsection (a), a reasonable good faith reliance that this title
			 permitted the conduct complained of is a complete defense against any civil or
			 criminal action brought under this title or any other law.</text>
				</subsection><subsection id="iddef9c6d8c59e44b093c741a24a5b8b6c"><enum>(c)</enum><header>Limitation on
			 use of cybersecurity threat indicators for regulatory enforcement
			 actions</header><text>No Federal entity may use a cybersecurity threat
			 indicator received pursuant to this title as evidence in a regulatory
			 enforcement action against the entity that lawfully shared the cybersecurity
			 threat indicator with a cybersecurity exchange that is a Federal entity.</text>
				</subsection><subsection id="id3ba487ccf5ca4af3b3a4e293a003c844"><enum>(d)</enum><header>Delay of
			 notification authorized for law enforcement, national security, or homeland
			 security purposes</header><text>No civil or criminal cause of action shall lie
			 or be maintained in any Federal or State court against any entity, and any such
			 action shall be dismissed promptly, for a failure to disclose a cybersecurity
			 threat indicator if—</text>
					<paragraph id="id543304466dfc48b89e2209224cfc82cb"><enum>(1)</enum><text>the Attorney
			 General or the Secretary determines that disclosure of a cybersecurity threat
			 indicator would impede a civil or criminal investigation and submits a written
			 request to delay notification for up to 30 days, except that the Attorney
			 General or the Secretary may, by a subsequent written request, revoke such
			 delay or extend the period of time set forth in the original request made under
			 this paragraph if further delay is necessary; or</text>
					</paragraph><paragraph id="id1abb3956c863432797d5aecbd84d6170"><enum>(2)</enum><text>the Secretary,
			 the Attorney General, or the Director of National Intelligence determines that
			 disclosure of a cybersecurity threat indicator would threaten national or
			 homeland security and submits a written request to delay notification, except
			 that the Secretary, the Attorney General, or the Director, may, by a subsequent
			 written request, revoke such delay or extend the period of time set forth in
			 the original request made under this paragraph if further delay is
			 necessary.</text>
					</paragraph></subsection><subsection id="id5fdfade9171742a2b42ab86040813a48"><enum>(e)</enum><header>Limitation on
			 liability for failure to act</header><text>No civil or criminal cause of action
			 shall lie or be maintained in any Federal or State court against any private
			 entity, or any officer, employee, or agent of such an entity, and any such
			 action shall be dismissed promptly, for the reasonable failure to act on
			 information received under this title.</text>
				</subsection><subsection id="id4f34b7a7d09a4eeba3c75f86e55ca27f"><enum>(f)</enum><header>Defense for
			 breach of contract</header><text>Compliance with lawful restrictions placed on
			 the disclosure or use of cybersecurity threat indicators is a complete defense
			 to any tort or breach of contract claim originating in a failure to disclose
			 cybersecurity threat indicators to a third party.</text>
				</subsection><subsection id="id746d340ac4294fdbb91b57b48b3799d2"><enum>(g)</enum><header>Limitation on
			 liability protections</header><text>Any person who, knowingly or acting in
			 gross negligence, violates a provision of this title or a regulation
			 promulgated under this title shall—</text>
					<paragraph id="idf3ed714ba1344ee6b7b1d016801512bf"><enum>(1)</enum><text>not receive the
			 protections of this title; and</text>
					</paragraph><paragraph id="id2eb997b122114539a5678eb793d5ad8a"><enum>(2)</enum><text>be subject to any
			 criminal or civil cause of action that may arise under any other State or
			 Federal law prohibiting the conduct in question.</text>
					</paragraph></subsection></section><section id="idf400513ce6124eb69b9eb0e3f3903422"><enum>707.</enum><header>Construction
			 and federal preemption</header>
				<subsection id="id1d5e43e9d31d411c905096b088824045"><enum>(a)</enum><header>Construction</header><text>Nothing
			 in this title may be construed—</text>
					<paragraph id="id9e5d086569ed4ed9a506179d6276d25e"><enum>(1)</enum><text>to limit any
			 other existing authority or lawful requirement to monitor information systems
			 and information that is stored on, processed by, or transiting such information
			 systems, operate countermeasures, and retain, use or disclose lawfully obtained
			 information;</text>
					</paragraph><paragraph id="idccf5185fae3644dfaa36c9c6380db69e"><enum>(2)</enum><text>to permit the
			 unauthorized disclosure of—</text>
						<subparagraph id="idaf6d5dadf12a4981aa3ff37c1ce3ac15"><enum>(A)</enum><text>information that
			 has been determined by the Federal Government pursuant to an Executive order or
			 statute to require protection against unauthorized disclosure for reasons of
			 national defense or foreign relations;</text>
						</subparagraph><subparagraph id="id0b4753ca07ca40c6ba80b80e48b56dad"><enum>(B)</enum><text>any restricted
			 data (as that term is defined in paragraph (y) of section 11 of the Atomic
			 Energy Act of 1954 (42 U.S.C. 2014));</text>
						</subparagraph><subparagraph id="idd6b8212a284e4c96b8506717a271286c"><enum>(C)</enum><text>information
			 related to intelligence sources and methods; or</text>
						</subparagraph><subparagraph id="idef1a5729aed5400abd5ce707af6b202c"><enum>(D)</enum><text>information that
			 is specifically subject to a court order or a certification, directive, or
			 other authorization by the Attorney General precluding such disclosure;</text>
						</subparagraph></paragraph><paragraph id="id6fcf8bcf575741a49819501709d46d66"><enum>(3)</enum><text>to provide
			 additional authority to, or modify an existing authority of, the Department of
			 Defense or the National Security Agency or any other element of the
			 intelligence community to control, modify, require, or otherwise direct the
			 cybersecurity efforts of a non-Federal entity or a Federal entity;</text>
					</paragraph><paragraph id="id458a9347ee00411db2a73b9c99a1ac88"><enum>(4)</enum><text>to limit or
			 modify an existing information sharing relationship;</text>
					</paragraph><paragraph id="idd9794015d8924988a2ac4af60ab05d0b"><enum>(5)</enum><text>to prohibit a new
			 information sharing relationship;</text>
					</paragraph><paragraph id="id89360f5784084a0ab4e4258fb28fb921"><enum>(6)</enum><text>to require a new
			 information sharing relationship between a Federal entity and a private
			 entity;</text>
					</paragraph><paragraph id="id7b0f7b8bbc1d41169f1ab7c7ee4eed40"><enum>(7)</enum><text>to limit the
			 ability of a non-Federal entity or a Federal entity to receive data about its
			 information systems, including lawfully obtained cybersecurity threat
			 indicators;</text>
					</paragraph><paragraph id="id61a2d8332dfa42dc9e9f4fe5d06358f7"><enum>(8)</enum><text>to authorize or
			 prohibit any law enforcement, homeland security, or intelligence activities not
			 otherwise authorized or prohibited under another provision of law;</text>
					</paragraph><paragraph id="id86e32c17664b4884b899d2bb140be6a3"><enum>(9)</enum><text>to permit
			 price-fixing, allocating a market between competitors, monopolizing or
			 attempting to monopolize a market, boycotting, or exchanges of price or cost
			 information, customer lists, or information regarding future competitive
			 planning;</text>
					</paragraph><paragraph id="id4f468f67a51f4783a10bcdc2ffc889d2"><enum>(10)</enum><text>to authorize or
			 limit liability for actions that would violate the regulations adopted by the
			 Federal Communications Commission on preserving the open Internet, or any
			 successor regulations thereto, nor to modify or alter the obligations of
			 private entities under such regulations; or</text>
					</paragraph><paragraph id="idef80619bf42e476ab9a1741ec002a90b"><enum>(11)</enum><text>to prevent a
			 governmental entity from using information not acquired through a cybersecurity
			 exchange for regulatory purposes.</text>
					</paragraph></subsection><subsection id="idc60d635bde3d4ab9abd5b8f4d33be303"><enum>(b)</enum><header>Federal
			 preemption</header><text>This title supersedes any law or requirement of a
			 State or political subdivision of a State that restricts or otherwise expressly
			 regulates the provision of cybersecurity services or the acquisition,
			 interception, retention, use or disclosure of communications, records, or other
			 information by private entities to the extent such law contains requirements
			 inconsistent with this title.</text>
				</subsection><subsection id="id524ae69681a5434da41ddd5b532cee84"><enum>(c)</enum><header>Preservation of
			 other State law</header><text>Except as expressly provided, nothing in this
			 title shall be construed to preempt the applicability of any other State law or
			 requirement.</text>
				</subsection><subsection id="id17b4d2db5c964ed6b861d22616a15790"><enum>(d)</enum><header>No creation of
			 a right to information</header><text>The provision of information to a
			 non-Federal entity under this title does not create a right or benefit to
			 similar information by any other non-Federal entity.</text>
				</subsection><subsection id="id5a6cd2b75eec40e297b005b513c18f1f"><enum>(e)</enum><header>Prohibition on
			 requirement to provide information to the federal
			 government</header><text>Nothing in this title may be construed to permit a
			 Federal entity—</text>
					<paragraph id="id9846296ec2e04392bd211ae3743f7dfc"><enum>(1)</enum><text>to require a
			 non-Federal entity to share information with the Federal Government;</text>
					</paragraph><paragraph id="id3665e869468c459db5a9d8ee4ab00f5b"><enum>(2)</enum><text>to condition the
			 disclosure of unclassified or classified cybersecurity threat indicators
			 pursuant to this title with a non-Federal entity on the provision of
			 cybersecurity threat information to the Federal Government; or</text>
					</paragraph><paragraph id="id8074c88bd21f4e3aab6f7907a7d88202"><enum>(3)</enum><text>to condition the
			 award of any Federal grant, contract or purchase on the provision of
			 cybersecurity threat indicators to a Federal entity, if the provision of such
			 indicators does not reasonably relate to the nature of activities, goods, or
			 services covered by the award.</text>
					</paragraph></subsection><subsection id="idbb4510ae4abf4790bdb64e6821d85852"><enum>(f)</enum><header>Limitation on
			 use of information</header><text>No cybersecurity threat indicators obtained
			 pursuant to this title may be used, retained, or disclosed by a Federal entity
			 or non-Federal entity, except as authorized under this title.</text>
				</subsection><subsection id="idb1b0295e86924e9d988c46e8f30977b8"><enum>(g)</enum><header>Declassification
			 and sharing of information</header><text>Consistent with the exemptions from
			 public disclosure of section 704(d), the Director of National Intelligence, in
			 consultation with the Secretary and the head of the Federal entity in
			 possession of the information, shall facilitate the declassification and
			 sharing of information in the possession of a Federal entity that is related to
			 cybersecurity threats, as the Director deems appropriate.</text>
				</subsection><subsection id="id6d2053050366466a9e74805a6f6430c0"><enum>(h)</enum><header>Report on
			 implementation</header><text>Not later than 2 years after the date of the
			 enactment of this title, the Secretary, the Director of National Intelligence,
			 the Attorney General, and the Secretary of Defense shall jointly submit to
			 Congress a report that—</text>
					<paragraph id="id305dc84c7b1744378f49ae8cfca17d9e"><enum>(1)</enum><text>describes the
			 extent to which the authorities conferred by this title have enabled the
			 Federal Government and the private sector to mitigate cybersecurity
			 threats;</text>
					</paragraph><paragraph id="id4b6c0aad467e46f28be8185d5bbecda9"><enum>(2)</enum><text>discloses any
			 significant acts of noncompliance by a non-Federal entity with this title, with
			 special emphasis on privacy and civil liberties, and any measures taken by the
			 Federal Government to uncover such noncompliance;</text>
					</paragraph><paragraph id="id328eea8fd6b34069b49a4bf76e1b4f69"><enum>(3)</enum><text>describes in
			 general terms the nature and quantity of information disclosed and received by
			 governmental entities and private entities under this title; and</text>
					</paragraph><paragraph id="id738fa7dc90f44488ae9b066a81e2d0cd"><enum>(4)</enum><text>identifies the
			 emergence of new threats or technologies that challenge the adequacy of the
			 law, including the definitions, authorities and requirements of this title, for
			 keeping pace with the threat.</text>
					</paragraph></subsection><subsection id="id017e36c2ea7f4a90af874f6f9a3343ff"><enum>(i)</enum><header>Requirement for
			 annual report</header><text>On an annual basis, the Director of National
			 Intelligence shall provide a report to the Select Committee on Intelligence of
			 the Senate and the Permanent Select Committee on Intelligence of the House of
			 Representatives on the implementation of section 705. Such report, which shall
			 be submitted in a classified and in an unclassified form, shall include a list
			 of private entities that receive classified cybersecurity threat indicators
			 under this title, except that the unclassified report shall not contain
			 information that may be used to identify specific private entities unless such
			 private entities consent to such identification.</text>
				</subsection></section><section id="id15083f7a4923427b8d28aad06663acac"><enum>708.</enum><header>Definitions</header><text display-inline="no-display-inline">In this title:</text>
				<paragraph id="idc021483f87f24ee3a7aea5f24edbaca1"><enum>(1)</enum><header>Certified
			 entity</header><text>The term <term>certified entity</term> means a protected
			 entity, a self-protected entity, or a provider of cybersecurity services
			 that—</text>
					<subparagraph id="id096c24791ed948569bb508541204138b"><enum>(A)</enum><text>possesses or is
			 eligible to obtain a security clearance, as determined by the Director of
			 National Intelligence; and</text>
					</subparagraph><subparagraph id="id2eb8c37803d0486cbd17f3d1a0b2162e"><enum>(B)</enum><text>is able to
			 demonstrate to the Director of National Intelligence that such provider or such
			 entity can appropriately protect and use classified cybersecurity threat
			 indicators.</text>
					</subparagraph></paragraph><paragraph id="id65453f0c7092430c837cb0fc13ea55df"><enum>(2)</enum><header>Countermeasure</header><text>The
			 term <term>countermeasure</term> means automated or manual actions to modify,
			 redirect, or block information that is stored on, processed by, or transiting
			 an information system that is known or suspected to contain cybersecurity
			 threat indicators for the purpose of protecting an information system from
			 cybersecurity threats, conducted on an information system owned or operated by
			 or on behalf of the party to be protected or operated by a private entity
			 acting as a provider of electronic communication services, remote computing
			 services, or cybersecurity services to the party to be protected.</text>
				</paragraph><paragraph id="id82ba79d162b648a1887bc6cd29651db9"><enum>(3)</enum><header>Cybersecurity
			 crime</header><text>The term <term>cybersecurity crime</term> means the
			 violation of a provision of State or Federal law relating to computer crimes,
			 including a violation of any provision of title 18, United States Code, enacted
			 or amended by the Computer Fraud and Abuse Act of 1986 (Public Law 99–474; 100
			 Stat. 1213).</text>
				</paragraph><paragraph id="id0e4f25a50ee74ebd84500d319bd853e2"><enum>(4)</enum><header>Cybersecurity
			 exchange</header><text>The term <term>cybersecurity exchange</term> means any
			 governmental entity or private entity designated by the Secretary of Homeland
			 Security, in consultation with the Director of National Intelligence, the
			 Attorney General, and the Secretary of Defense, to receive and distribute
			 cybersecurity threat indicators under section 703(a).</text>
				</paragraph><paragraph id="id22c087a2f2444ba0bd7f554b629ea8da"><enum>(5)</enum><header>Cybersecurity
			 services</header><text>The term <term>cybersecurity services</term> means
			 products, goods, or services intended to detect, mitigate, or prevent
			 cybersecurity threats.</text>
				</paragraph><paragraph id="idd4e2bc4dfa224267bd199cb1849ff969"><enum>(6)</enum><header>Cybersecurity
			 threat</header><text>The term <term>cybersecurity threat</term> means any
			 action that may result in unauthorized access to, exfiltration of, manipulation
			 of, harm of, or impairment to the integrity, confidentiality, or availability
			 of an information system or information that is stored on, processed by, or
			 transiting an information system, except that none of the following shall be
			 considered a cybersecurity threat—</text>
					<subparagraph id="ide7cf53ddcaed43aab8e564cb380497e5"><enum>(A)</enum><text>actions protected
			 by the first amendment to the Constitution of the United States; and</text>
					</subparagraph><subparagraph id="idb87236dd886c4930acfd21e2836e8aba"><enum>(B)</enum><text>exceeding
			 authorized access of an information system, if such access solely involves a
			 violation of consumer terms of service or consumer licensing agreements.</text>
					</subparagraph></paragraph><paragraph id="id504da716cb8b47ad8e011a0c7fa5664e"><enum>(7)</enum><header>Cybersecurity
			 threat indicator</header><text>The term <term>cybersecurity threat
			 indicator</term> means information—</text>
					<subparagraph id="idf59fb2d25131463fba78e473321dd4d1"><enum>(A)</enum><text>that is
			 reasonably necessary to describe—</text>
						<clause id="idd32316a81c7b4196b4f5ad889527a41c"><enum>(i)</enum><text>malicious
			 reconnaissance, including anomalous patterns of communications that reasonably
			 appear to be transmitted for the purpose of gathering technical information
			 related to a cybersecurity threat;</text>
						</clause><clause id="id8ad9d88039aa4968891b1fd057691e9f"><enum>(ii)</enum><text>a
			 method of defeating a technical control;</text>
						</clause><clause id="id84b8c2a9e32b4494a1c048ffb1849df6"><enum>(iii)</enum><text>a
			 technical vulnerability;</text>
						</clause><clause id="id7227e7f57c1748dcb9737930e5cbb7bb"><enum>(iv)</enum><text>a
			 method of defeating an operational control;</text>
						</clause><clause id="idf7835677b7894ca68f2f50e1e0a76d5a"><enum>(v)</enum><text>a
			 method of causing a user with legitimate access to an information system or
			 information that is stored on, processed by, or transiting an information
			 system to unwittingly enable the defeat of a technical control or an
			 operational control;</text>
						</clause><clause id="id1382fed0e3bf48318a492585d5291c54"><enum>(vi)</enum><text>malicious cyber
			 command and control;</text>
						</clause><clause id="id7e91ff6312ef4cc3ac0cdf032b047f98"><enum>(vii)</enum><text>the actual or
			 potential harm caused by an incident, including information exfiltrated as a
			 result of defeating a technical control or an operational control when it is
			 necessary in order to identify or describe a cybersecurity threat;</text>
						</clause><clause id="id77c1af22bf704d7f801e73d828e2d592"><enum>(viii)</enum><text>any other
			 attribute of a cybersecurity threat, if disclosure of such attribute is not
			 otherwise prohibited by law; or</text>
						</clause><clause id="id67e55e6c93284ce990bc940150a7501e"><enum>(ix)</enum><text>any combination
			 thereof; and</text>
						</clause></subparagraph><subparagraph id="id1155bc851c1042f1948b6d3e56387477"><enum>(B)</enum><text>from which
			 reasonable efforts have been made to remove information that can be used to
			 identify specific persons unrelated to the cybersecurity threat.</text>
					</subparagraph></paragraph><paragraph id="idb429551385ee43d7bda72c33ac48a11e"><enum>(8)</enum><header>Federal
			 cybersecurity center</header><text>The term <term>Federal cybersecurity
			 center</term> means the Department of Defense Cyber Crime Center, the
			 Intelligence Community Incident Response Center, the United States Cyber
			 Command Joint Operations Center, the National Cyber Investigative Joint Task
			 Force, the National Security Agency/Central Security Service Threat Operations
			 Center, the United States Computer Emergency Readiness Team, or successors to
			 such centers.</text>
				</paragraph><paragraph id="id6e1c973cd6654aa1a3a9e0b31163fd45"><enum>(9)</enum><header>Federal
			 entity</header><text>The term <term>Federal entity</term> means an agency or
			 department of the United States, or any component, officer, employee, or agent
			 of such an agency or department.</text>
				</paragraph><paragraph id="idc4bb3aaf8ce34e889a0b590ca7891358"><enum>(10)</enum><header>Governmental
			 entity</header><text>The term <term>governmental entity</term> means any
			 Federal entity and agency or department of a State, local, tribal, or
			 territorial government other than an educational institution, or any component,
			 officer, employee, or agent of such an agency or department.</text>
				</paragraph><paragraph id="id518c19885d2d4466b32faee5871e0a45"><enum>(11)</enum><header>Information
			 system</header><text>The term <term>information system</term> means a discrete
			 set of information resources organized for the collection, processing,
			 maintenance, use, sharing, dissemination, or disposition of information,
			 including communications with, or commands to, specialized systems such as
			 industrial and process control systems, telephone switching and private branch
			 exchanges, and environmental control systems.</text>
				</paragraph><paragraph id="id8bb90af9c8094651aaa84942b32a08aa"><enum>(12)</enum><header>Malicious
			 cyber command and control</header><text>The term <term>malicious cyber command
			 and control</term> means a method for remote identification of, access to, or
			 use of, an information system or information that is stored on, processed by,
			 or transiting an information system associated with a known or suspected
			 cybersecurity threat.</text>
				</paragraph><paragraph id="id430e19668fd64fd9b58602aeaa5f3797"><enum>(13)</enum><header>Malicious
			 reconnaissance</header><text>The term <term>malicious reconnaissance</term>
			 means a method for actively probing or passively monitoring an information
			 system for the purpose of discerning technical vulnerabilities of the
			 information system, if such method is associated with a known or suspected
			 cybersecurity threat.</text>
				</paragraph><paragraph id="id0e210f0dfaff4c2ea7aa9e5f69cf583f"><enum>(14)</enum><header>Monitor</header><text>The
			 term <term>monitor</term> means the interception, acquisition, or collection of
			 information that is stored on, processed by, or transiting an information
			 system for the purpose of identifying cybersecurity threats.</text>
				</paragraph><paragraph id="id739769e2c59f4f3490df3bf240864c5d"><enum>(15)</enum><header>Non-Federal
			 entity</header><text>The term <term>non-Federal entity</term> means a private
			 entity or a governmental entity other than a Federal entity.</text>
				</paragraph><paragraph id="idacf8651598024ff39c691f8e9869da8f"><enum>(16)</enum><header>Operational
			 control</header><text>The term <term>operational control</term> means a
			 security control for an information system that primarily is implemented and
			 executed by people.</text>
				</paragraph><paragraph id="idebb668a2050a49138b00b28deca26a77"><enum>(17)</enum><header>Private
			 entity</header><text>The term <term>private entity</term> has the meaning given
			 the term <term>person</term> in section 1 of title 1, United States Code, and
			 does not include a governmental entity.</text>
				</paragraph><paragraph id="idd292ba7fbc224804ac950dd8227cd091"><enum>(18)</enum><header>Protect</header><text>The
			 term <term>protect</term> means actions undertaken to secure, defend, or reduce
			 the vulnerabilities of an information system, mitigate cybersecurity threats,
			 or otherwise enhance information security or the resiliency of information
			 systems or assets.</text>
				</paragraph><paragraph id="idc82cbccad6ba4b8c828f169b38a23c95"><enum>(19)</enum><header>Technical
			 control</header><text>The term <term>technical control</term> means a hardware
			 or software restriction on, or audit of, access or use of an information system
			 or information that is stored on, processed by, or transiting an information
			 system that is intended to ensure the confidentiality, integrity, or
			 availability of that system.</text>
				</paragraph><paragraph id="id77c25a4f02e14762afd894a317adf844"><enum>(20)</enum><header>Technical
			 vulnerability</header><text>The term <term>technical vulnerability</term> means
			 any attribute of hardware or software that could enable or facilitate the
			 defeat of a technical control.</text>
				</paragraph><paragraph id="id3f8e585c8def42ef8430d385fdd4f6df"><enum>(21)</enum><header>Third
			 party</header><text>The term <term>third party</term> includes Federal entities
			 and non-Federal entities.</text>
				</paragraph></section></title></legis-body>
	<endorsement>
		<action-date>July 23, 2012</action-date>
		<action-desc>Read the second time and placed on the
		  calendar</action-desc>
	</endorsement>
</bill>
