<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 372</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110216">February 16, 2011</action-date>
			<action-desc><sponsor name-id="S308">Mr. Cardin</sponsor> (for himself
			 and <cosponsor name-id="S316">Mr. Whitehouse</cosponsor>) introduced the
			 following bill; which was read twice and referred to the
			 <committee-name committee-id="SSCM00">Committee on Commerce, Science, and
			 Transportation</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To reduce the ability of terrorists, spies, criminals,
		  and other malicious actors to compromise, disrupt, damage, and destroy computer
		  networks, critical infrastructure, and key resources, and for other purposes.
		  </official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Cybersecurity and Internet Safety
			 Standards Act</short-title></quote>.</text>
		</section><section id="id0C3508CB0F084445837A4038DBCAB9BF"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text>
			<paragraph id="idF9B3F03F87554F12B278F5DA15D82D29"><enum>(1)</enum><header>Computers</header><text>Except
			 as otherwise specifically provided, the term <quote>computers</quote> means
			 computers and other devices that connect to the Internet.</text>
			</paragraph><paragraph id="idEF7EFAD0CF4747F8B9BB6BBAE2EE0FFD"><enum>(2)</enum><header>Providers</header><text>The
			 term <quote>providers</quote> means Internet service providers, communications
			 service providers, electronic messaging providers, electronic mail providers,
			 and other persons who provide a service or capability to enable computers to
			 connect to the Internet.</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id3E5B4B3D8CE74D3980D38F29BF2D8FF4"><enum>(3)</enum><header>Secretary</header><text>Except
			 as otherwise specifically provided, the term <quote>Secretary</quote> means the
			 Secretary of Homeland Security.</text>
			</paragraph></section><section id="IDc70b6de9a8cc40b88d904270e8b3941b"><enum>3.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
			<paragraph id="ID667e449ec3564d3bac2ffa6cd029ac11"><enum>(1)</enum><text>While the
			 Internet has had a profound impact on the daily lives of the people of the
			 United States by enhancing communications, commerce, education, and
			 socialization between and among persons regardless of their location, computers
			 may be used, exploited, and compromised by terrorists, criminals, spies, and
			 other malicious actors, and, therefore, computers pose a risk to computer
			 networks, critical infrastructure, and key resources in the United States.
			 Indeed, users of computers are generally unaware that their computers may be
			 used, exploited, and compromised by others with spam, viruses, and other
			 malicious software and agents.</text>
			</paragraph><paragraph id="ID05ef9d318ba644f7b89b76448988fd58"><enum>(2)</enum><text>Since computer
			 networks, critical infrastructure, and key resources of the United States are
			 at risk of being compromised, disrupted, damaged, or destroyed by terrorists,
			 criminals, spies, and other malicious actors who use computers, cybersecurity
			 and Internet safety is an urgent homeland security issue that needs to be
			 addressed by providers, technology companies, and persons who use
			 computers.</text>
			</paragraph><paragraph id="IDc967af54f51c4a56b1c629624b371687"><enum>(3)</enum><text>The Government
			 and the private sector need to work together to develop and enforce minimum
			 voluntary or mandatory cybersecurity and Internet safety standards for users of
			 computers to prevent terrorists, criminals, spies, and other malicious actors
			 from compromising, disrupting, damaging, or destroying the computer networks,
			 critical infrastructure, and key resources of the United States.</text>
			</paragraph></section><section id="id9DBA95B1775B40648881CDE7E9F1C00D"><enum>4.</enum><header>Cost-benefit
			 analysis</header>
			<subsection id="id2A66D63F7D4E460C893A4C4F506F6461"><enum>(a)</enum><header>Requirement for
			 analysis</header><text display-inline="yes-display-inline">The Secretary, in
			 consultation with the Attorney General, the Secretary of Commerce, and the
			 Director of National Intelligence, shall conduct an analysis to determine the
			 costs and benefits of requiring providers to develop and enforce voluntary or
			 mandatory minimum cybersecurity and Internet safety standards for users of
			 computers to prevent terrorists, criminals, spies, and other malicious actors
			 from compromising, disrupting, damaging, or destroying computer networks,
			 critical infrastructure, and key resources.</text>
			</subsection><subsection id="id76150D8EDC084956BA283B88A282DC4F"><enum>(b)</enum><header>Factors</header><text display-inline="yes-display-inline">In conducting the analysis required by
			 subsection (a), the Secretary shall consider—</text>
				<paragraph id="id98BFF8BF093F4747ADCE9DA4C0835D67"><enum>(1)</enum><text display-inline="yes-display-inline">all relevant factors, including the effect
			 that the development and enforcement of minimum voluntary or mandatory
			 cybersecurity and Internet safety standards may have on homeland security, the
			 global economy, innovation, individual liberty, and privacy; and</text>
				</paragraph><paragraph id="idDCE0DE04281645ED902DB0759FC0F17D"><enum>(2)</enum><text display-inline="yes-display-inline">any legal impediments that may exist to the
			 implementation of such standards.</text>
				</paragraph></subsection></section><section id="id9E8403CECB9649E293CB412A618017C9"><enum>5.</enum><header>Consultation</header><text display-inline="no-display-inline">In conducting the analysis required by
			 section 4, the Secretary shall consult with the Attorney General, the Secretary
			 of Commerce, the Director of National Intelligence, the Federal Communications
			 Commission, and relevant stakeholders in the Government and the private sector,
			 including the academic community, groups, or other institutions, that have
			 scientific and technical expertise related to standards for computer networks,
			 critical infrastructure, or key resources.</text>
		</section><section id="id7C77E5BC351443BA80F045E23FC2F659"><enum>6.</enum><header>Report</header>
			<subsection id="ID86a7d403187149a4bfa6fc2bb6ec6ea9"><enum>(a)</enum><header>In
			 general</header><text>Not later than 1 year after the date of the enactment of
			 this Act, the Secretary shall submit to the appropriate committees of Congress
			 a final report on the results of the analysis required by section 4. Such
			 report shall include the consensus recommendations, if any, for minimum
			 voluntary or mandatory cybersecurity and Internet safety standards that should
			 be developed and enforced for users of computers to prevent terrorists,
			 criminals, spies, and other malicious actors from compromising, disrupting,
			 damaging, or destroying computer networks, critical infrastructure, and key
			 resources.</text>
			</subsection><subsection id="ID1ac9d65dcad84d1792ecf2e9ec138561"><enum>(b)</enum><header>Appropriate
			 committees of Congress</header><text>In this section, the term
			 <quote>appropriate committees of Congress</quote> means—</text>
				<paragraph id="idA62F2409DB7B4430BD588C6E0E362C2A"><enum>(1)</enum><text>the Committee on
			 Commerce, Science, and Transportation, the Committee on Homeland Security and
			 Governmental Affairs, and the Committee on the Judiciary of the Senate;
			 and</text>
				</paragraph><paragraph id="idCC0E6A7887594A2683750950C4BB3AD3"><enum>(2)</enum><text>the Committee on
			 Energy and Commerce, the Committee on Homeland Security, the Committee on the
			 Judiciary, and the Committee on Oversight and Government Reform of the House of
			 Representatives.</text>
				</paragraph></subsection></section></legis-body>
</bill>
