<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public">
	<form>
		<distribution-code display="yes">II</distribution-code>
		<congress>112th CONGRESS</congress>
		<session>1st Session</session>
		<legis-num>S. 813</legis-num>
		<current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber>
		<action>
			<action-date date="20110413">April 13, 2011</action-date>
			<action-desc><sponsor name-id="S316">Mr. Whitehouse</sponsor> (for
			 himself and <cosponsor name-id="S243">Mr. Kyl</cosponsor>) introduced the
			 following bill; which was read twice and referred to the
			 <committee-name committee-id="SSGA00">Committee on Homeland Security and
			 Governmental Affairs</committee-name></action-desc>
		</action>
		<legis-type>A BILL</legis-type>
		<official-title>To promote public awareness of cyber
		  security.</official-title>
	</form>
	<legis-body>
		<section id="S1" section-type="section-one"><enum>1.</enum><header>Short
			 title</header><text display-inline="no-display-inline">This Act may be cited as
			 the <quote><short-title>Cyber Security Public Awareness
			 Act of 2011</short-title></quote>.</text>
		</section><section id="idFE38BD128C3E45808E9192914FA7BC40"><enum>2.</enum><header>Findings</header>
			<subsection id="idA0ECD1F1003843299AA605078B3120D7"><enum>(a)</enum><text>Congress finds
			 the following:</text>
				<paragraph id="IDad1ee29c49bc4292a5094fe8bc48d9c0"><enum>(1)</enum><text>Information
			 technology is central to the effectiveness, efficiency, and reliability of the
			 industry and commercial services, Armed Forces and national security systems,
			 and the critical infrastructure of the United States.</text>
				</paragraph><paragraph id="ID8f8cebd6face4b26a2bd3dca609616a5"><enum>(2)</enum><text>Cyber criminals,
			 terrorists, and agents of foreign powers have taken advantage of the
			 connectivity of the United States to inflict substantial damage to the economic
			 and national security interests of the Nation.</text>
				</paragraph><paragraph id="IDa2cbf0ddb9c44c92a02456aa83129497"><enum>(3)</enum><text>The cyber
			 security threat is sophisticated, relentless, and massive, exposing all
			 consumers in the United States to the risk of substantial harm.</text>
				</paragraph><paragraph id="ID179a6e50e1a14cd98c76dd8665a9de8f"><enum>(4)</enum><text>Businesses in the
			 United States are bearing enormous losses as a result of criminal cyber
			 attacks, depriving businesses of hard-earned profits that could be reinvested
			 in further job-producing innovation.</text>
				</paragraph><paragraph id="ID5cd14cf36aa94ed5860161395a00a1f8"><enum>(5)</enum><text>Hackers
			 continuously probe the networks of Federal and State agencies, the Armed
			 Forces, and the commercial industrial base of the Armed Forces, and already
			 have caused substantial damage and compromised sensitive and classified
			 information.</text>
				</paragraph><paragraph id="ID088c3767f85a49a39c020e41c01f8a47"><enum>(6)</enum><text>Severe cyber
			 security threats will continue, and will likely grow, as the economy of the
			 United States grows more connected, criminals become increasingly sophisticated
			 in efforts to steal from consumers, industries, and businesses in the United
			 States, and terrorists and foreign nations continue to use cyberspace as a
			 means of attack against the national and economic security of the United
			 States.</text>
				</paragraph><paragraph id="IDc89b0735a889441abc3311a2ae97f22c"><enum>(7)</enum><text>Public awareness
			 of cyber security threats is essential to cyber security defense. Only a
			 well-informed public and Congress can make the decisions necessary to protect
			 consumers, industries, and the national and economic security of the United
			 States.</text>
				</paragraph><paragraph id="ID7fc451d6ef81431dbce3ef309c673abd"><enum>(8)</enum><text>As of 2011, the
			 level of public awareness of cyber security threats is unacceptably low. Only a
			 tiny portion of relevant cyber security information is released to the public.
			 Information about attacks on Federal Government systems is usually classified.
			 Information about attacks on private systems is ordinarily kept confidential.
			 Sufficient mechanisms do not exist to provide meaningful threat reports to the
			 public in unclassified and anonymized form.</text>
				</paragraph></subsection></section><section id="id6D15C4BCB13844A58CB2AA0A34E9105A"><enum>3.</enum><header>Cyber incidents
			 against government networks</header>
			<subsection id="id6A8FA65D930B4FA2A0118F4A637A83CB"><enum>(a)</enum><header>Department of
			 Homeland Security</header><text display-inline="yes-display-inline">Not later
			 than 180 days after the date of enactment of this Act, and annually thereafter,
			 the Secretary of Homeland Security shall submit to Congress a report
			 that—</text>
				<paragraph id="IDe54a26c288344bea987f940492ed6e1f"><enum>(1)</enum><text>summarizes major
			 cyber incidents involving networks of executive agencies (as defined in section
			 105 of title 5, United States Code), except for the Department of
			 Defense;</text>
				</paragraph><paragraph id="IDb62e4131cd3944268068f40975ebe6c3"><enum>(2)</enum><text>provides
			 aggregate statistics on the number of breaches of networks of executive
			 agencies, the volume of data exfiltrated, and the estimated cost of remedying
			 the breaches; and</text>
				</paragraph><paragraph id="idB9759234451E418F84B5814B94F067E6"><enum>(3)</enum><text>discusses the
			 risk of cyber sabotage.</text>
				</paragraph></subsection><subsection id="id001FC78AA9AF4845ADFD331A3A03289B"><enum>(b)</enum><header>Department of
			 Defense</header><text>Not later than 180 days after the date of enactment of
			 this Act, and annually thereafter, the Secretary of Defense shall submit to
			 Congress a report that—</text>
				<paragraph id="ID9d27967bd6fa4b338a0612a7a64ba0ea"><enum>(1)</enum><text>summarizes major
			 cyber incidents against networks of the Department of Defense and the military
			 departments;</text>
				</paragraph><paragraph id="IDf1d7b8af1ce745e9b7be2943e218310f"><enum>(2)</enum><text>provides
			 aggregate statistics on the number of breaches against networks of the
			 Department of Defense and the military departments, the volume of data
			 exfiltrated, and the estimated cost of remedying the breaches; and</text>
				</paragraph><paragraph id="id691128DB3F8B4816B6DE474157EF1E6B"><enum>(3)</enum><text>discusses the
			 risk of cyber sabatoge.</text>
				</paragraph></subsection><subsection id="id1974344098C34D5CB1147587AE762C18"><enum>(c)</enum><header>Form of
			 reports</header><text>Each report submitted under this section shall be in
			 unclassified form, but may include a classified annex as necessary to protect
			 sources, methods, and national security.</text>
			</subsection></section><section id="id5D7660A3A06A407D9305FF33B51242E1"><enum>4.</enum><header>Prosecution for
			 cybercrime</header>
			<subsection id="id425C0221A56D4335AB97EA96374D62DE"><enum>(a)</enum><header>In
			 general</header><text>Not later than 180 days after the date of enactment of
			 this Act, the Attorney General and the Director of the Federal Bureau of
			 Investigation shall submit to Congress reports—</text>
				<paragraph id="ID09ace6b401fe4764892ab529837976bf"><enum>(1)</enum><text>describing
			 investigations and prosecutions by the Department of Justice relating to cyber
			 intrusions or other cybercrimes the preceding year, including—</text>
					<subparagraph id="ID3a3648d2e247474ea5b277e215339d7b"><enum>(A)</enum><text>the number of
			 investigations initiated relating to such crimes;</text>
					</subparagraph><subparagraph id="ID33f13276e0dc4e0b9956ca9399083680"><enum>(B)</enum><text>the number of
			 arrests relating to such crimes;</text>
					</subparagraph><subparagraph id="id897316F90DD34E2DA44EDED41E8C7D6A"><enum>(C)</enum><text>the number and
			 description of instances in which investigations or prosecutions relating to
			 such crimes have been delayed or prevented because of an inability to extradite
			 a criminal defendant in a timely manner; and</text>
					</subparagraph><subparagraph id="IDde94faac91484edebaa9ed1b216476cf"><enum>(D)</enum><text>the number of
			 prosecutions for such crimes, including—</text>
						<clause id="IDea6517ec775947de97cf195c3d59e6f7"><enum>(i)</enum><text>the
			 number of defendants prosecuted;</text>
						</clause><clause id="ID668ed67da388496889eea36f2c61fb3d"><enum>(ii)</enum><text>whether the
			 prosecutions resulted in a conviction;</text>
						</clause><clause id="ID0a8753d5361e4b71abd351bbc4a2ef41"><enum>(iii)</enum><text>the sentence
			 imposed and the statutory maximum for each such crime for which a defendant was
			 convicted; and</text>
						</clause><clause id="idAD20A7822FC148669E8D4603C05136AF"><enum>(iv)</enum><text>the average
			 sentence imposed for a conviction of such crimes;</text>
						</clause></subparagraph></paragraph><paragraph id="ID3a6035daa0224342870d7d54c90fefd1"><enum>(2)</enum><text>identifying the
			 number of employees, financial resources, and other resources (such as
			 technology and training) devoted to the enforcement, investigation, and
			 prosecution of cyber intrusions or other cybercrimes, including the number of
			 investigators, prosecutors, and forensic specialists dedicated to investigating
			 and prosecuting cyber intrusions or other cybercrimes; and</text>
				</paragraph><paragraph id="IDb3321a209823469d965761f4636345b2"><enum>(3)</enum><text>discussing any
			 impediments under the laws of the United States or international law to
			 prosecutions for cyber intrusions or other cybercrimes.</text>
				</paragraph></subsection><subsection id="IDbf74bf2b11954640bd2e45126735a0e8"><enum>(b)</enum><header>Updates</header><text>The
			 Attorney General and the Director of the Federal Bureau of Investigation shall
			 annually submit to Congress reports updating the reports submitted under
			 section (a) at the same time the Attorney General and Director submit annual
			 reports under section 404 of the Prioritizing Resources and Organization for
			 Intellectual Property Act of 2008 (42 U.S.C. 3713d).</text>
			</subsection></section><section id="id4F16B043AF0A4084A6681D98438EE59C"><enum>5.</enum><header>Assistance plan
			 for significant private cyber incidents</header>
			<subsection id="id17976EB010524C859193F92895E1612F"><enum>(a)</enum><header>In
			 general</header><text display-inline="yes-display-inline">Not later than 180
			 days after the date of enactment of this Act, and annually thereafter, the
			 Secretary of Homeland Security shall submit to Congress a report that describes
			 policies and procedures for Federal agencies to assist a private sector entity
			 in the defending of the information networks of the private sector entity
			 against cyber threats that could result in loss of life or significant harm to
			 the national economy or national security.</text>
			</subsection><subsection id="idEE0513C8A6B74C87BF279317EFCB61FC"><enum>(b)</enum><header>Form of
			 reports</header><text>Each report submitted under this section shall be in
			 unclassified form, but may include a classified annex as necessary to protect
			 sources, methods, proprietary or sensitive business information, and national
			 security.</text>
			</subsection></section><section id="id2CA8479C20A84C7EBB05A5310B26BB98"><enum>6.</enum><header>Cybercrime
			 reporting to shareholders</header><text display-inline="no-display-inline">Not
			 later than 180 days after the date of enactment of this Act, the Securities and
			 Exchange Commission, in consultation with the Secretary of Homeland Security,
			 shall submit to Congress a report on—</text>
			<paragraph id="IDcbf84ad4691b4445af9ac908cfccd88d"><enum>(1)</enum><text>the extent of
			 financial risk to issuers of securities caused by cyber intrusions or other
			 cybercrimes, and any resulting legal liability; and</text>
			</paragraph><paragraph id="IDfb97504904484a138dc3c09c0d3b2ff6"><enum>(2)</enum><text>whether current
			 financial statements of issuers transparently reflect the risk described in
			 paragraph (1) to shareholders.</text>
			</paragraph></section><section id="ID7971dbac564f4be78f5dc767ff33ea7c"><enum>7.</enum><header>Primary
			 regulators of critical infrastructure</header>
			<subsection id="id82BC2250F28F4044B415F5F09D8AD33A"><enum>(a)</enum><header>Definitions</header><text>In
			 this section the term <quote>primary regulators responsible for the physical
			 and economic security of each critical industry</quote> means—</text>
				<paragraph id="id2BA1E69725BB4F22AA13F06A074163C5"><enum>(1)</enum><text>for the energy
			 industry, the Federal Energy Regulatory Commission, the Nuclear Regulatory
			 Commission, and the Secretary of Energy;</text>
				</paragraph><paragraph id="id0C729C5B50774E9DB19BB52D4BCBDFA7"><enum>(2)</enum><text>for the financial
			 services industry, the Federal Deposit Insurance Commission, the Secretary of
			 the Treasury, and the Chairman of the Securities and Exchange
			 Commission;</text>
				</paragraph><paragraph id="id8D2B71B87ACC4242A24CF418DE5497F1"><enum>(3)</enum><text>for the air,
			 rail, and ground transportation industry, the Secretary of
			 Transportation;</text>
				</paragraph><paragraph id="id49CBF0C2C85048468BFB1436AB53D58E"><enum>(4)</enum><text>for the
			 communications industry, the Federal Communications Commission;</text>
				</paragraph><paragraph id="id1CC9AD7A6D1B42C09096029B76E7167C"><enum>(5)</enum><text>for the food
			 supply industry, the Commissioner of Food and Drugs;</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4A89E9614E504CD18ABCEBFCA8AE864C"><enum>(6)</enum><text>for the water
			 supply industry, the Administrator of the Environmental Protection Agency;
			 and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2A64C4A0BFF14AD1B3F4A805E1FE9D12"><enum>(7)</enum><text>for any other
			 element of the economy determined to be critical by the Secretary of Homeland
			 Security, the Federal Trade Commission.</text>
				</paragraph></subsection><subsection id="id67AEFDEF005542C08132E07FB4C6BB60"><enum>(b)</enum><header>Reports</header><text>Not
			 later than 180 days after the date of enactment of this Act, and annually
			 thereafter for 3 years, the primary regulator for each critical industry, in
			 consultation with the Secretary of Homeland Security, shall submit to Congress
			 a report that describes the—</text>
				<paragraph id="ID6012c88d8ee64b86927975a9050eb327"><enum>(1)</enum><text>nature and state
			 of the vulnerabilities to cyber attacks of each industry described in
			 subsection (a);</text>
				</paragraph><paragraph id="ID10bbf751d43e407787e6637d79c8f6d8"><enum>(2)</enum><text>prevalence and
			 seriousness of cyber attacks in each industry described in subsection
			 (a);</text>
				</paragraph><paragraph id="ID775dcd291d6b4924a0fa87517691d83f"><enum>(3)</enum><text>recommended steps
			 to thwart or diminish cyber attacks; and</text>
				</paragraph><paragraph id="idDD62146A9A204AEC80BFA09EBCC6FBAA"><enum>(4)</enum><text>whether the
			 concept of cyber security and information assurance cooperative activities with
			 private sector partners developed by the Defense Industrial Base of the
			 Department of Defense may be applied to the critical industries described in
			 subsection (a).</text>
				</paragraph></subsection><subsection id="id28DD32950AD340E29AF71B1513353A02"><enum>(c)</enum><header>Form of
			 reports</header><text>Each report submitted under this section—</text>
				<paragraph id="idD6811ED750A34AABA9098B5D20F013F1"><enum>(1)</enum><text>shall be—</text>
					<subparagraph id="idF7BE512D1BB848DA80BDC83020B0D6B2"><enum>(A)</enum><text>in unclassified
			 form; and</text>
					</subparagraph><subparagraph id="id42C58B4F79FD447294812758C333AFA9"><enum>(B)</enum><text>anonymized as the
			 Secretary determines necessary to protect confidential business information;
			 and</text>
					</subparagraph></paragraph><paragraph id="idDC4C77CE1E8D40728FA87B6084B65F88"><enum>(2)</enum><text>may include a
			 classified annex as necessary to protect sources, methods, proprietary or
			 sensitive business information, and national security.</text>
				</paragraph></subsection></section><section id="ID8a464d6d711e46f1b882d60df9f4a23c"><enum>8.</enum><header>Research report
			 on improving security of information networks of critical infrastructure
			 entities</header>
			<subsection id="idEE2AA6CFD4D74C8CA8B64578DE0AF8CB"><enum>(a)</enum><header>Definition</header><text>In
			 this section, the term <quote>critical infrastructure</quote> has the meaning
			 given that term in section 1016(e) of the USA PATRIOT Act (42 U.S.C.
			 5195c(e)).</text>
			</subsection><subsection id="id0588A6C99B514750912794410052FA2B"><enum>(b)</enum><header>Reports</header>
				<paragraph id="id6C6FAB9B3D804EEBAE593310F4E2F10C"><enum>(1)</enum><header>In
			 general</header><text>The Secretary of Homeland Security shall enter into a
			 contract with the National Research Council, or another federally funded
			 research and development corporation, under which the Council or corporation
			 shall submit to Congress reports on available technical options, consistent
			 with Constitutional and statutory privacy rights, for enhancing the security of
			 the information networks of entities that own or manage critical infrastructure
			 through—</text>
					<subparagraph id="ID35793a20e0104273af4ffd8ee533e8a1"><enum>(A)</enum><text>technical
			 improvements, including developing a secure domain; or</text>
					</subparagraph><subparagraph id="IDa13b7c7633564feca1a373671063d3d1"><enum>(B)</enum><text>increased notice
			 of and consent to the use of technologies to scan for, detect, and defeat cyber
			 security threats, such as technologies used in a secure domain.</text>
					</subparagraph></paragraph><paragraph id="idC45E74C22E7344CFA8D1CA54F73D8468"><enum>(2)</enum><header>Timing</header><text>The
			 contract entered into under paragraph (1) shall require that the report
			 described in paragraph (1) be submitted—</text>
					<subparagraph id="idD3B35DF9AA4B4A2C8CDED5D5E4E89D52"><enum>(A)</enum><text>not later than
			 180 days after the date of enactment of this Act;</text>
					</subparagraph><subparagraph id="idC97FEF424C344D6CA23D466AD2768A4F"><enum>(B)</enum><text>annually, after
			 the first report submitted under paragraph (1), for 3 years; and</text>
					</subparagraph><subparagraph id="idE62A56EACC034E2892AA383078CE8D4F"><enum>(C)</enum><text>more frequently,
			 as determined appropriate by the Secretary of Homeland Security in response to
			 new risks or technologies that emerge.</text>
					</subparagraph></paragraph></subsection></section><section id="id942B7744051E4270B4229DAAADE0C0F3"><enum>9.</enum><header>Preparedness of
			 Federal courts to promote cyber security</header><text display-inline="no-display-inline">Not later than 180 days after the date of
			 enactment of this Act, the Attorney General, in coordination with the
			 Administrative Office of the United States Courts, shall submit to Congress a
			 report—</text>
			<paragraph id="IDd92c30523f894fa3bd9a4466c69b993a"><enum>(1)</enum><text>on whether
			 Federal courts have granted timely relief in matters relating to botnets and
			 other cybercrime and cyber security threats; and</text>
			</paragraph><paragraph id="ID760fe7e8657543dc9646f8980e384dfd"><enum>(2)</enum><text>that includes, as
			 appropriate, recommendations on changes or improvements to—</text>
				<subparagraph id="IDbc60413338e44344802710d9c41a8174"><enum>(A)</enum><text>the Federal Rules
			 of Civil Procedure or the Federal Rules of Criminal Procedure;</text>
				</subparagraph><subparagraph id="ID5f12d574e9c044ddbb30af331b704477"><enum>(B)</enum><text>the training and
			 other resources available to support the Federal judiciary;</text>
				</subparagraph><subparagraph id="ID5eb63fedcffb4042900bdfd239cb48b3"><enum>(C)</enum><text>the capabilities
			 and specialization of courts to which such cases may be assigned; and</text>
				</subparagraph><subparagraph id="ID2f7f3d0e02de4d44b0b5b4e20c929ce6"><enum>(D)</enum><text>Federal civil and
			 criminal laws.</text>
				</subparagraph></paragraph></section><section id="ID75d302d6883f47459aaf566dd476967d"><enum>10.</enum><header>Impediments to
			 public awareness</header><text display-inline="no-display-inline">Not later
			 than 180 days after the date of enactment of this Act, and annually thereafter
			 for 3 years (or more frequently if determined appropriate by the Secretary of
			 Homeland Security) the Secretary of Homeland Security shall submit to Congress
			 a report on—</text>
			<paragraph id="ID45cf100a50a44a52ba57a5252cd3806e"><enum>(1)</enum><text>legal or other
			 impediments to appropriate public awareness of—</text>
				<subparagraph id="ID3c8d565addd94113be90c47a5a5aa046"><enum>(A)</enum><text>the nature of,
			 methods of propagation of, and damage caused by common cyber security threats
			 such as computer viruses, phishing techniques, and malware;</text>
				</subparagraph><subparagraph id="IDbb8b2c71866a4744b96febd77e672464"><enum>(B)</enum><text>the minimal
			 standards of computer security necessary for responsible Internet use;
			 and</text>
				</subparagraph><subparagraph id="IDbf0d92021465427c99a6830248643367"><enum>(C)</enum><text>the availability
			 of commercial off the shelf technology that allows consumers to meet such
			 levels of computer security;</text>
				</subparagraph></paragraph><paragraph id="ID59fdd6a187d847f5a1daa5725a205916"><enum>(2)</enum><text>a summary of the
			 plans of the Secretary of Homeland Security to enhance public awareness of
			 common cyber security threats, including a description of the metrics used by
			 the Department of Homeland Security for evaluating the efficacy of public
			 awareness campaigns; and</text>
			</paragraph><paragraph id="ID17df938ac892471ab6b74847e0c6ab8d"><enum>(3)</enum><text>recommendations
			 for congressional actions to address these impediments to appropriate public
			 awareness of common cyber security threats.</text>
			</paragraph></section><section id="id8F95B926DC2D4829B248463D2A0F0896"><enum>11.</enum><header>Protecting the
			 information technology supply chain of the United States</header>
			<subsection id="id84B73BEB95EE43898198F9059915AB5E"><enum>(a)</enum><header>Definitions</header><text>In
			 this section—</text>
				<paragraph id="id826C2DF78E8E453D896DE6ABE42F0155"><enum>(1)</enum><text>the term
			 <quote>information technology supply chain of the United States</quote> means
			 the public and private telecommunications networks of the United States;
			 and</text>
				</paragraph><paragraph id="id5C4AF95A0CC848F7B33959A7DDF49D55"><enum>(2)</enum><text>the term
			 <term>telecommunications networks of the United States</term> includes—</text>
					<subparagraph id="id2073242104AA41D7B4E7AEB91DFE6822"><enum>(A)</enum><text>telephone
			 systems;</text>
					</subparagraph><subparagraph id="id2B520369B2D146FD9AA55B363E7599EB"><enum>(B)</enum><text>Internet
			 systems;</text>
					</subparagraph><subparagraph id="idC7F525F70B8341759E03FC7CDAA4FB8D"><enum>(C)</enum><text>fiber optic
			 lines, including cable landings;</text>
					</subparagraph><subparagraph id="idC7EC230DD6E345F39950BA124761F731"><enum>(D)</enum><text>computer
			 networks; and</text>
					</subparagraph><subparagraph id="idF5749AAC2E4A4627A6B81BBCD286B5D7"><enum>(E)</enum><text>smart grid
			 technology under development by the Department of Energy.</text>
					</subparagraph></paragraph></subsection><subsection id="idAA246A4AF4E44A3C93A987791F3D9362"><enum>(b)</enum><header>Report</header><text>Not
			 later than 90 days after the date of enactment of this Act, and annually
			 thereafter, the Secretary of Homeland Security shall submit to Congress a
			 report that—</text>
				<paragraph id="idD3D46C1F5DC44C5795626E3D4A907F4F"><enum>(1)</enum><text>identifies
			 foreign suppliers of information technology (including equipment, software, and
			 services) that are linked directly or indirectly to a foreign government,
			 including—</text>
					<subparagraph id="idF7524700AB4144BFAB75974F26294A24"><enum>(A)</enum><text>by ties to the
			 military forces of a foreign government; or</text>
					</subparagraph><subparagraph id="idCCCF958F5DBF449397CD35144A455F85"><enum>(B)</enum><text>by being the
			 beneficiaries of significant low interest or no interest loans, loan
			 forgiveness, or other support by a foreign government;</text>
					</subparagraph></paragraph><paragraph id="id0CA0B1CDA740499CA05CB0B4BD77CDA6"><enum>(2)</enum><text>discusses the
			 extent to which goods produced by suppliers identified under paragraph (2) have
			 been integrated into the information technology supply chain of the United
			 States;</text>
				</paragraph><paragraph id="idA96B560FE99B449896F336E1A618AF6B"><enum>(3)</enum><text>identifies
			 specific telecommunications networks of the United States that include
			 information technology identified under paragraph (1); and</text>
				</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idA623F5EEDEE540939EAD064F4C52EC4B"><enum>(4)</enum><text>assesses the
			 vulnerability to malicious activity, including cyber crime or espionage, of the
			 telecommunications networks of the United States identified under paragraph (3)
			 due to the presence of technology produced by suppliers identified under
			 paragraph (1).</text>
				</paragraph></subsection></section><section commented="no" display-inline="no-display-inline" id="id7CCBA85B0B644DA3B75F384DB175975D"><enum>12.</enum><header>Protecting the
			 electrical grid of the United States</header><text display-inline="no-display-inline">Not later than 180 days after the date of
			 enactment of this Act, the Secretary of Homeland Security, in consultation with
			 the Secretary of Defense and the Director of National Intelligence, shall
			 submit to Congress a report on—</text>
			<paragraph commented="no" display-inline="no-display-inline" id="id57C5879E24BF47C08F5CC19D1108F15F"><enum>(1)</enum><text>the threat of a
			 cyber attack disrupting the electrical grid of the United States;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id2B3CD7EF713241999C74AB246AEAE935"><enum>(2)</enum><text>the implications
			 for the national security of the United States if the electrical grid is
			 disrupted;</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="id9E834196FA764DAF85FCCCFD4131EBA9"><enum>(3)</enum><text>the options
			 available to the United States and private sector entities to quickly
			 reconstitute electrical service to provide for the national security of the
			 United States, and, within a reasonable time frame, the reconstitution of all
			 electrical service within the United States; and</text>
			</paragraph><paragraph commented="no" display-inline="no-display-inline" id="idFD6F679924F54C35958854CFEFDB797A"><enum>(4)</enum><text>a plan to prevent
			 disruption of the electric grid of the United States caused by a cyber
			 attack.</text>
			</paragraph></section></legis-body>
</bill>
