<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-House" dms-id="H88B7FF0BF9264FF185145AD9576E023C" public-private="public" key="H" bill-type="olc" stage-count="1"> 
<metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 1833 EH: DHS Industrial Control Systems Capabilities Enhancement Act of 2021</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session> 
<legis-num display="yes">H. R. 1833</legis-num> 
<current-chamber display="no">IN THE HOUSE OF REPRESENTATIVES</current-chamber> 
<legis-type>AN ACT</legis-type> 
<official-title display="yes">To amend the Homeland Security Act of 2002 to provide for the responsibility of the Cybersecurity and Infrastructure Security Agency to maintain capabilities to identify threats to industrial control systems, and for other purposes.</official-title> 
</form> 
<legis-body id="H7918183E627145C29A841953FA345F86" style="OLC"> 
<section id="HF298A691388B43999F01DA31E958149C" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>DHS Industrial Control Systems Capabilities Enhancement Act of 2021</short-title></quote>.</text></section> <section id="HA3ECEFC8F012459DA3DB74E2965BDC48"><enum>2.</enum><header>Capabilities of the Cybersecurity and Infrastructure Security Agency to identify threats to industrial control systems</header> <subsection id="HC6EB1AD9E0B448CBA96485550380AC99"><enum>(a)</enum><header>In general</header><text>Section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>) is amended—</text> 
<paragraph id="HC1073453316F46C5B67BDF7203ADA2C3"><enum>(1)</enum><text>in subsection (e)(1)—</text> <subparagraph id="H53FFF7A313D6488C893E00CBDDB94E56"><enum>(A)</enum><text>in subparagraph (G), by striking <quote>and</quote> after the semicolon;</text></subparagraph> 
<subparagraph id="HF2370AE32DEC406F8CE760E46867D558"><enum>(B)</enum><text>in subparagraph (H), by inserting <quote>and</quote> after the semicolon; and</text></subparagraph> <subparagraph id="HB2D1F3BB5E3F420E81B302A611CA9ED7"><enum>(C)</enum><text>by adding at the end the following new subparagraph:</text> 
<quoted-block id="H637FE1E76C7E440EA85024524222E91D" style="OLC"> 
<subparagraph id="HAE6905D119D4493386BD4DCC01482F90"><enum>(I)</enum><text>activities of the Center address the security of both information technology and operational technology, including industrial control systems;</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph> <paragraph id="H364171FA2FF44C9587C9D587D169400B"><enum>(2)</enum><text>by adding at the end the following new subsection:</text> 
<quoted-block id="H4FB6D9F5EFE64A0AAF2AA4AD3EE74B0B" style="OLC"> 
<subsection id="H4676ECEDA5E9459194AF58E977ABBC8B"><enum>(p)</enum><header>Industrial control systems</header><text>The Director shall maintain capabilities to identify and address threats and vulnerabilities to products and technologies intended for use in the automated control of critical infrastructure processes. In carrying out this subsection, the Director shall—</text> <paragraph id="H76DBEDE165CC47A2A9DEB31AC064E689"><enum>(1)</enum><text display-inline="yes-display-inline">lead Federal Government efforts, in consultation with Sector Risk Management Agencies, as appropriate, to identify and mitigate cybersecurity threats to industrial control systems, including supervisory control and data acquisition systems;</text></paragraph> 
<paragraph id="HC58300CE2D37477BA210E493A214CCC5"><enum>(2)</enum><text>maintain threat hunting and incident response capabilities to respond to industrial control system cybersecurity risks and incidents;</text></paragraph> <paragraph id="H3FFBD913142F46D09386643D7DCDE470"><enum>(3)</enum><text display-inline="yes-display-inline">provide cybersecurity technical assistance to industry end-users, product manufacturers, Sector Risk Management Agencies, other Federal agencies, and other industrial control system stakeholders to identify, evaluate, assess, and mitigate vulnerabilities;</text></paragraph> 
<paragraph id="H3874D8F1BF9146ABA9B50ED162CFA122"><enum>(4)</enum><text display-inline="yes-display-inline">collect, coordinate, and provide vulnerability information to the industrial control systems community by, as appropriate, working closely with security researchers, industry end-users, product manufacturers, Sector Risk Management Agencies, other Federal agencies, and other industrial control systems stakeholders; and</text></paragraph> <paragraph id="H708237FB41684D14B2D109F98095B91F"><enum>(5)</enum><text>conduct such other efforts and assistance as the Secretary determines appropriate.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection> 
<subsection id="HE04F5D2114554010A716FD4E81CDFB0E"><enum>(b)</enum><header>Report to Congress</header><text>Not later than 180 days after the date of the enactment of this Act and every six months thereafter during the subsequent 4-year period, the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing on the industrial control systems capabilities of the Agency under section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>), as amended by subsection (a).</text></subsection> <subsection id="H90D83245F4994D59AD3146925F28212B"><enum>(c)</enum><header>GAO review</header><text display-inline="yes-display-inline">Not later than 2 years after the date of the enactment of this Act, the Comptroller General of the United States shall review implementation of the requirements of subsections (e)(1)(I) and (p) of section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>), as amended by subsection (a), and submit to the Committee on Homeland Security in the House of Representatives and the Committee on Homeland Security and Government Affairs of the Senate a report containing findings and recommendations relating to such implementation. Such report shall include information on the following:</text> 
<paragraph id="H520FE1059F4E4AACA7BD5C06C47DC68D"><enum>(1)</enum><text>Any interagency coordination challenges to the ability of the Director of the Cybersecurity and Infrastructure Agency of the Department of Homeland Security to lead Federal efforts to identify and mitigate cybersecurity threats to industrial control systems pursuant to subsection (p)(1) of such section.</text></paragraph> <paragraph id="H6B680AF80D37473CA6CF2BCEF8CED179"><enum>(2)</enum><text display-inline="yes-display-inline">The degree to which the Agency has adequate capacity, expertise, and resources to carry out threat hunting and incident response capabilities to mitigate cybersecurity threats to industrial control systems pursuant to subsection (p)(2) of such section, as well as additional resources that would be needed to close any operational gaps in such capabilities.</text></paragraph> 
<paragraph id="H8F618240C07041EE9CAD56787D1344A4"><enum>(3)</enum><text>The extent to which industrial control system stakeholders sought cybersecurity technical assistance from the Agency pursuant to subsection (p)(3) of such section, and the utility and effectiveness of such technical assistance.</text></paragraph> <paragraph id="H914364EC1E204EEFBD0C6363F4166D1B"><enum>(4)</enum><text>The degree to which the Agency works with security researchers and other industrial control systems stakeholders, pursuant to subsection (p)(4) of such section, to provide vulnerability information to the industrial control systems community.</text></paragraph></subsection></section> 
</legis-body> <attestation><attestation-group><attestation-date date="20210720" chamber="House">Passed the House of Representatives July 20, 2021.</attestation-date><attestor display="no">Cheryl L. Johnson,</attestor><role>Clerk.</role></attestation-group></attestation>
<endorsement display="yes"></endorsement>
</bill> 


