<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H973C018ECEB148E7BC62A0F7D4DEA2D8" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 HR 4910 IH: State Cyber Resiliency Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2021-08-03</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 4910</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20210803">August 3, 2021</action-date><action-desc><sponsor name-id="K000381">Mr. Kilmer</sponsor> (for himself and <cosponsor name-id="M001157">Mr. McCaul</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HHM00">Committee on Homeland Security</committee-name>, and in addition to the Committee on <committee-name committee-id="HPW00">Transportation and Infrastructure</committee-name>, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned</action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To provide grants to assist States in developing and implementing plans to address cybersecurity threats or vulnerabilities, and for other purposes.</official-title></form><legis-body id="H172996F75CEA4980B8AEDF41C51143F0" style="OLC"><section id="H51F839D874F2466E952F29A4EEC2E4DA" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>State Cyber Resiliency Act</short-title></quote>.</text></section><section id="HABBAD186806D4711944107E9E1CD4500"><enum>2.</enum><header>Establishment of State Cyber Resiliency Grant Program</header><subsection id="H5354986C6C6C4CF9B43A6969AA51796D"><enum>(a)</enum><header>Establishment</header><text display-inline="yes-display-inline">There is established the State Cyber Resiliency Grant Program to assist State, local, and tribal governments in preventing, preparing for, protecting against, and responding to cyber threats, which shall be administered by the Administrator.</text></subsection><subsection id="HF4E1C59AE8484B21BA33C39296320255"><enum>(b)</enum><header>Eligibility</header><text display-inline="yes-display-inline">Each State shall be eligible to apply for grants under the Program.</text></subsection><subsection id="H1F66776CC7424AD0A4000FD7A57E3CD8"><enum>(c)</enum><header>Grants authorized for each State</header><text>Subject to the funds available under a funding allocation determined under <internal-xref idref="HC61A2BC4E96C45E5B9F336C521571685" legis-path="2.(f)">subsection (f)</internal-xref> for a State, the Secretary of Homeland Security may award to the State—</text><paragraph id="H707F8BAC65E14CC59C308766FF7896D7"><enum>(1)</enum><text>up to 2 planning grants under <internal-xref idref="HCEFCE2F7BD6B4877BAB6347690DAAF27" legis-path="2.(c)">subsection (e)</internal-xref> to develop or revise a cyber resiliency plan; and</text></paragraph><paragraph id="H24BB31EF810E4CBC881840B34B00440D"><enum>(2)</enum><text display-inline="yes-display-inline">up to 2 implementation grants under <internal-xref idref="HC82905571DEC444E9E1A7ECB27C7F0E5" legis-path="2.(d)">subsection (f)</internal-xref> to implement an active cyber resiliency plan.</text></paragraph></subsection><subsection id="H9203AD230951449EB568B18DD616ADE1"><enum>(d)</enum><header>Approval of cyber resiliency plans</header><paragraph id="H0C27762F25BD4C319E3E12A01A3114EF"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Secretary shall approve a cyber resiliency plan submitted by a State if the Secretary determines, after considering the recommendations of the Review Committee established under <internal-xref idref="HFAE0C84EA5734DA5922B9E90F744D3EB" legis-path="2.(g)">subsection (i)</internal-xref>, that the plan meets all of the following criteria:</text><subparagraph id="HB90A86DB221549D4831186D1BEAF7846"><enum>(A)</enum><text>The plan incorporates, to the extent practicable, any existing plans of such State to protect against cybersecurity threats or vul­ner­a­bil­i­ties.</text></subparagraph><subparagraph id="HB737D77B94F7455F9ECF2EF783017F03"><enum>(B)</enum><text display-inline="yes-display-inline">The plan is designed to achieve each of the following objectives, with respect to the essential functions of such State:</text><clause id="H01E19AD12F334AB5BA94A44E31811B78"><enum>(i)</enum><text display-inline="yes-display-inline">Enhancing the preparation, response, and resiliency of computer networks, industrial control systems, and communications systems performing such functions against cybersecurity threats or vul­ner­a­bil­i­ties.</text></clause><clause id="HEF4BB7419F674FB2826F1D398A37110E"><enum>(ii)</enum><text display-inline="yes-display-inline">Implementing a process of continuous cybersecurity vulnerability assessments and threat mitigation practices to prevent the disruption of such functions by an incident within the State.</text></clause><clause id="H2027796BE3684DE69B200383D34A2DF5"><enum>(iii)</enum><text display-inline="yes-display-inline">Ensuring that entities performing such functions within the State adopt generally recognized best practices and methodologies with respect to cybersecurity, such as the practices provided in the cybersecurity framework developed by the National Institute of Standards and Technology.</text></clause><clause id="HE0C63B9E179D46638D787D890066B2AF"><enum>(iv)</enum><text display-inline="yes-display-inline">Mitigating talent gaps in the State government cybersecurity workforce, enhancing recruitment and retention efforts for such workforce, and bolstering the knowledge, skills, and abilities of State government personnel to protect against cybersecurity threats and vulnerabilities.</text></clause><clause id="HD9FADF673A1B4884A917765D6C6E0E0A"><enum>(v)</enum><text display-inline="yes-display-inline">Protecting public safety answering points and other emergency communications and data networks from cybersecurity threats or vulnerabilities.</text></clause><clause id="H6598B97E737F496CB227CE9832681B3E"><enum>(vi)</enum><text display-inline="yes-display-inline">Ensuring continuity of communications and data networks between entities performing such functions within the State, in the event of a catastrophic disruption of such communications or networks.</text></clause><clause id="H04C9855ABFA94FABAF5DA31C838487F8"><enum>(vii)</enum><text display-inline="yes-display-inline">Accounting for and mitigating, to the greatest degree possible, cybersecurity threats or vulnerabilities related to critical infrastructure or key resources, the degradation of which may impact the performance of such functions within the State or threaten public safety.</text></clause><clause id="H1FF9AE93B7DF4BAEA9A51CA97591EEE9"><enum>(viii)</enum><text display-inline="yes-display-inline">Providing appropriate communications capabilities to ensure cybersecurity intelligence information sharing and the command and coordination capabilities among entities performing such functions.</text></clause><clause id="H4B24E96391194AF1966FF3168F3E9B64"><enum>(ix)</enum><text>Developing and coordinating strategies with respect to cybersecurity threats or vulnerabilities in consultation with—</text><subclause id="H767BEC042C3B4D36BF8710519006D0AE"><enum>(I)</enum><text display-inline="yes-display-inline">neighboring States or members of an information sharing and analysis organization; and</text></subclause><subclause id="H85F59AA85E5A488FA537E16B6974349D"><enum>(II)</enum><text>as applicable, neighboring countries.</text></subclause></clause></subparagraph></paragraph><paragraph id="HF003BA2414AC444C9835322F0874BC52"><enum>(2)</enum><header>Duration of approval</header><subparagraph id="H8F853A5ED46C465295402B111A5B159E"><enum>(A)</enum><header>Initial duration</header><text>An approval under <internal-xref idref="H0C27762F25BD4C319E3E12A01A3114EF" legis-path="2.(b)(1)">paragraph (1)</internal-xref> shall be initially effective for the 2-year period beginning on the date of the determination described in such paragraph.</text></subparagraph><subparagraph id="HFB98ACD001EC41D2BF82FE70C7083D18"><enum>(B)</enum><header>Annual extension</header><text display-inline="yes-display-inline">The Secretary may annually extend such approval for a 1-year period, if the Secretary determines, after considering the recommendations of the Review Committee, that the plan continues to meet the criteria described in <internal-xref idref="H0C27762F25BD4C319E3E12A01A3114EF" legis-path="2.(b)(1)">paragraph (1)</internal-xref> after the State makes such revisions as the Secretary may determine to be necessary.</text></subparagraph></paragraph><paragraph id="HD9CE1DF822DF4337AD9C76803338EDF0"><enum>(3)</enum><header>Essential functions</header><text display-inline="yes-display-inline">For purposes of this subsection, the term <quote>essential functions</quote> includes, with respect to a State, those functions that enhance the cybersecurity posture of the State, local and tribal governments of the State, and the public services they provide.</text></paragraph></subsection><subsection id="HCEFCE2F7BD6B4877BAB6347690DAAF27"><enum>(e)</enum><header>Planning grants</header><paragraph id="H535C2FDE15FE4C4B9B5442918385C5ED"><enum>(1)</enum><header>Initial planning grant</header><text>The Secretary shall require, as a condition of awarding an initial planning grant, that the State seeking the grant—</text><subparagraph id="H196D4094F21F488F853DA6CC4445CD18"><enum>(A)</enum><text>agrees to use the funds to develop a cyber resiliency plan designed to meet the criteria described in <internal-xref idref="H0C27762F25BD4C319E3E12A01A3114EF" legis-path="2.(b)(1)">subsection (d)(1)</internal-xref>; and</text></subparagraph><subparagraph id="H513BB21636A64503A39152BE913E1C63"><enum>(B)</enum><text>submits an application including such information as the Secretary may determine to be necessary.</text></subparagraph></paragraph><paragraph id="H7C5F4C3357034B5883A5D20DE312BC6B"><enum>(2)</enum><header>Eligibility for initial planning grant</header><text>A State shall not be eligible to receive an initial planning grant after the date on which the State first submits a cyber resiliency plan to the Secretary for a determination under <internal-xref idref="H0C27762F25BD4C319E3E12A01A3114EF" legis-path="2.(b)(1)">subsection (d)(1)</internal-xref>.</text></paragraph><paragraph id="H5EAD27C2867A4AC0985E59CBC6C2900C"><enum>(3)</enum><header>Additional planning grant</header><text display-inline="yes-display-inline">The Secretary may award an additional planning grant to a State if the State agrees to use the funds to revise a cyber resiliency plan in order to receive an extension in accordance with <internal-xref idref="HFB98ACD001EC41D2BF82FE70C7083D18" legis-path="2.(b)(2)(B)">subsection (d)(2)(B)</internal-xref>, and submits an application including such information as the Secretary may determine to be necessary.</text></paragraph><paragraph id="H7751F6EAF2CF4FDDA69C18EBECBA946C"><enum>(4)</enum><header>Limitations on number and timing of grants</header><text>A State shall not be eligible to receive—</text><subparagraph id="HA41B87142E9444959ADFD2B343895568"><enum>(A)</enum><text>more than 2 planning grants under this subsection; or</text></subparagraph><subparagraph id="H4009AC54FC384EF1B8EB8B9C0B18275A"><enum>(B)</enum><text>an additional planning grant for the fiscal year following the fiscal year for which it receives an initial planning grant.</text></subparagraph></paragraph></subsection><subsection id="HC82905571DEC444E9E1A7ECB27C7F0E5"><enum>(f)</enum><header>Implementation grants</header><paragraph id="H27521EFFB6294F7FB3B4CE258CE6719E"><enum>(1)</enum><header>Application requirements</header><text display-inline="yes-display-inline">The Secretary shall require, as a condition of awarding a biennial implementation grant, that the State seeking the grant submits an application including the following:</text><subparagraph id="H9E7C2365881E4790A03710438DC7462F"><enum>(A)</enum><text display-inline="yes-display-inline">A proposal, including a description and timeline, of the activities to be funded by the grant as described by a cyber resiliency plan of the State approved under subsection (d).</text></subparagraph><subparagraph id="H7086DB3665024DECA76F090E9BD8B7B8"><enum>(B)</enum><text>A description of how each activity proposed to be funded by the grant would achieve one or more of the objectives described in <internal-xref idref="HB737D77B94F7455F9ECF2EF783017F03" legis-path="2.(b)(1)(B)">subsection (d)(1)(B)</internal-xref>.</text></subparagraph><subparagraph id="HE0B79A60D4C846A4A39E3913DC865F25"><enum>(C)</enum><text display-inline="yes-display-inline">A description, if applicable, of how any prior biennial implementation grant awarded under this section was spent, and to what extent the criteria described in <internal-xref idref="H0C27762F25BD4C319E3E12A01A3114EF" legis-path="2.(b)(1)">subsection (d)(1)</internal-xref> were met.</text></subparagraph><subparagraph id="HEED6146270C94734A8D001021020B602"><enum>(D)</enum><text display-inline="yes-display-inline">The share of any amounts awarded as a biennial implementation grant proposed to be distributed to local or tribal governments within such State.</text></subparagraph><subparagraph id="H358D18F6865D42F8B649ECAE1536644F"><enum>(E)</enum><text display-inline="yes-display-inline">Such other information as the Secretary may determine to be necessary in consultation with the chief information officer, emergency managers, and senior public safety officials of the State.</text></subparagraph></paragraph><paragraph id="H777B7B4926DD4061A77D76EBAFF67C07"><enum>(2)</enum><header>Approval of application</header><text display-inline="yes-display-inline">The Secretary shall consider the recommendations of the Review Committee in approving or disapproving an application for a biennial implementation grant.</text></paragraph><paragraph id="H1C6EEA794BE643E4AA6E8A33EE09C955"><enum>(3)</enum><header>Distribution to local and tribal governments</header><subparagraph id="HCA1AE5BE640B401AA2E8DD00B618D8CD"><enum>(A)</enum><header>In general</header><text>Not later than 45 days after the date that a biennial implementation grant is awarded, not less than 50 percent of any share proposed under <internal-xref idref="HEED6146270C94734A8D001021020B602" legis-path="2.(d)(1)(D)">paragraph (1)(D)</internal-xref> shall be distributed to local or tribal governments, in the same manner that amounts awarded under section 2004 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/605">6 U.S.C. 605</external-xref>) are distributed to such governments, except that—</text><clause id="H2183379B79114D9988419618F75CCC60"><enum>(i)</enum><text>no such distribution may be made to a federally recognized Indian tribe that is a State under <internal-xref idref="H2690907738064D4E8CC963368FE97BA4" legis-path="2.(i)(9)(B)">subsection (k)(11)(B)</internal-xref>; and</text></clause><clause id="H27FAE7BC9AC7440AADCE902C31ECB510"><enum>(ii)</enum><text>in applying section 2004(c)(1) of such Act with respect to distributions under this subparagraph, <quote>100 percent</quote> shall be substituted for <quote>80 percent</quote> each place that term appears.</text></clause></subparagraph><subparagraph id="H021334FB36E4463D8FB476861B211BD3"><enum>(B)</enum><header>Consultation</header><text>In determining how an implementation grant is distributed within a State, the State shall consult with local and regional chief information officers, emergency managers, and senior public safety officials of the State.</text></subparagraph></paragraph><paragraph display-inline="no-display-inline" id="HE3C0895E70B3498DB4611A3D392AF10C"><enum>(4)</enum><header>Competitive award</header><text>Except as provided in subsection (h), biennial implementation grants shall be awarded—</text><subparagraph id="H8C02A4A6804D4EEF9951EDAABA1FDE6F"><enum>(A)</enum><text>exclusively on a competitive basis; and</text></subparagraph><subparagraph id="HE765795EC95C4ED1BDE3865090A032AE"><enum>(B)</enum><text>based on the recommendations of the Review Committee.</text></subparagraph></paragraph><paragraph id="H03D9A983213246E785032A1EA7B5B281"><enum>(5)</enum><header>Limitation on number of grants</header><text display-inline="yes-display-inline">The Secretary may award to a State not more than 2 biennial implementation grants under this section.</text></paragraph></subsection><subsection id="H19E51BCE7E264FC29C70EAD21B9F59EE"><enum>(g)</enum><header>Use of grant funds</header><paragraph id="H8F2A75C20258410DB4B186AA2FCA0A5D"><enum>(1)</enum><header>Limitations</header><text display-inline="yes-display-inline">Any grant awarded under this section shall supplement and not supplant State or local funds or, as applicable, funds supplied by the Bureau of Indian Affairs, and may not be used—</text><subparagraph id="HC1DE6151FD52431DAD385C1EFB03D560"><enum>(A)</enum><text display-inline="yes-display-inline">to provide any Federal cost-sharing contribution on behalf of a State; or</text></subparagraph><subparagraph id="H617D71E68B8B4204BE8571E52FD7E716"><enum>(B)</enum><text>for any recreational or social purpose.</text></subparagraph></paragraph><paragraph id="HD9D7D37AB4404CD9A40B191F49118908"><enum>(2)</enum><header>Approved activities for implementation grants</header><text display-inline="yes-display-inline">A State or a government entity that receives funds through a biennial implementation grant may use such funds for one or more of the following activities, to the extent that such activities are proposed under <internal-xref idref="H9E7C2365881E4790A03710438DC7462F" legis-path="2.(d)(1)(A)">subsection (f)(1)(A)</internal-xref>:</text><subparagraph id="HBCB3824136744A6782C8AB189D655C7C"><enum>(A)</enum><text display-inline="yes-display-inline">Supporting or enhancing information sharing and analysis organizations.</text></subparagraph><subparagraph id="H65834C95750E4F6B9D68270E7726CE79"><enum>(B)</enum><text display-inline="yes-display-inline">Implementing or coordinating systems and services that use cyber threat indicators (as such term is defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref>)) to address cybersecurity threats or vulnerabilities.</text></subparagraph><subparagraph id="H7FAF35B7FC074CCE9E4F84EE90D189B2"><enum>(C)</enum><text display-inline="yes-display-inline">Supporting dedicated cybersecurity and communications coordination planning, including the coordination of—</text><clause id="H2E76DA90EF6A446C944AA69E364567A4"><enum>(i)</enum><text>emergency management elements of such State;</text></clause><clause id="HA2B1394BE66F4A93A4D43B0227E3C5FD"><enum>(ii)</enum><text>National Guard units, as appropriate;</text></clause><clause id="HE8E8736F576F437FB243EC22F83E28EF"><enum>(iii)</enum><text display-inline="yes-display-inline">entities associated with critical infrastructure or key resources;</text></clause><clause id="H8076F0C69E034E92AABDE0A4BD747A9E"><enum>(iv)</enum><text>information sharing and analysis organizations;</text></clause><clause id="HF5C5E7ED15F843D1AE6035386B46F96B"><enum>(v)</enum><text display-inline="yes-display-inline">public safety answering points; or</text></clause><clause id="HA9ACA9D5B908435CA8867553EB3A9C86"><enum>(vi)</enum><text display-inline="yes-display-inline">nongovernmental organizations engaged in cybersecurity research as a formally designated information analysis and sharing organization.</text></clause></subparagraph><subparagraph id="H8FC8F403C1E24F838DE83D1E64900FB3"><enum>(D)</enum><text display-inline="yes-display-inline">Establishing programs, such as scholarships or apprenticeships, to provide financial assistance to State residents who—</text><clause id="H1492C73517974127835E1A4DF61FB9DC"><enum>(i)</enum><text>pursue formal education, training, and industry-recognized certifications for careers in cybersecurity as identified by the National Initiative for Cybersecurity Education; and</text></clause><clause id="H591D6BC282824B93804A444166382144"><enum>(ii)</enum><text>commit to working for State government for a specified period of time.</text></clause></subparagraph></paragraph></subsection><subsection display-inline="no-display-inline" id="HC61A2BC4E96C45E5B9F336C521571685"><enum>(h)</enum><header>Funding allocations</header><paragraph id="H683C2864E1714BD6B656958DEA493F71"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">From any amount appropriated for a fiscal year that is not reserved for use by the Secretary in carrying out this section, the Secretary shall allocate the entire amount among the States (including the District of Columbia) eligible for grants under this section taking into consideration the factors specified in <internal-xref idref="H351A876218E34A3B9856C00292A6F1E7" legis-path="2.(f)(2)">paragraph (2)</internal-xref> and consistent with the following:</text><subparagraph id="H58BEE1E02BC1464898F2657AE3265C6D"><enum>(A)</enum><header>Allocations for the several States</header><text display-inline="yes-display-inline">Of the amount subject to allocation, a funding allocation for any of such States shall be—</text><clause id="HD43E56E4C6F54D1D9EC8F817881A8F64"><enum>(i)</enum><text display-inline="yes-display-inline">not less than 0.001 percent, with respect to an initial planning grant, and not more than 0.001 percent, with respect to any additional planning grants; and</text></clause><clause id="HDBDB4AC3F8BF4E8EAC9245647900EC4B"><enum>(ii)</enum><text display-inline="yes-display-inline">not less than 0.5 percent and not more than 3 percent, with respect to biennial implementation grants.</text></clause></subparagraph><subparagraph id="HBB917DC7EDF7404CBD7C9357F1C7BE5D"><enum>(B)</enum><header>Allocations for the territories and possessions</header><text display-inline="yes-display-inline">Of the amount subject to allocation, a funding allocation for any of the territories and possessions of the United States eligible for grants under this section shall be—</text><clause id="HC4A5E50B08C24041A75CDFFCEF02656A"><enum>(i)</enum><text display-inline="yes-display-inline">not less than 0.001 percent, with respect to an initial planning grant, and not more than 0.001 percent, with respect to any additional planning grant; and</text></clause><clause id="H4EC50904CC074FC59D7162F17915213C"><enum>(ii)</enum><text display-inline="yes-display-inline">not less than 0.1 percent and not more than 1 percent, with respect to biennial implementation grants.</text></clause></subparagraph></paragraph><paragraph id="H351A876218E34A3B9856C00292A6F1E7"><enum>(2)</enum><header>Considerations for funding allocations</header><text>In determining a funding allocation under <internal-xref idref="H683C2864E1714BD6B656958DEA493F71" legis-path="2.(f)(1)">paragraph (1)</internal-xref> for a State, the Secretary shall consider each of the following factors:</text><subparagraph id="H62CED9551AE049DF89887626911EB60F"><enum>(A)</enum><text display-inline="yes-display-inline">The considerations described in section 1809(h)(1) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/579">6 U.S.C. 579(h)(1)</external-xref>) with respect to the State, and the degree of exposure of the State and protected government entities within the State to threats, vulnerabilities, or consequences resulting from cybersecurity risks or incidents.</text></subparagraph><subparagraph id="H7A23C0C0CDCB4F9C8C387FF63AB2D35D"><enum>(B)</enum><text>The degree of exposure of the State and protected government entities within the State to threats, vulnerabilities, or consequences resulting from cybersecurity risks or incidents.</text></subparagraph><subparagraph id="H2F71AE48D3454426A82E1E8897CF522C"><enum>(C)</enum><text display-inline="yes-display-inline">The effectiveness of, relative to evolving cyber threats against, cybersecurity assets, secure communications capabilities, and data network protections, of the State and its partners.</text></subparagraph><subparagraph id="H7B52F810C58C41B583A0938A7DFB9618"><enum>(D)</enum><text display-inline="yes-display-inline">The extent to which the State is vulnerable to cyber threats because it has not implemented best practices such as the cybersecurity framework developed by the National Institute of Standards and Technology.</text></subparagraph><subparagraph id="HB68076CD30514713BD4F29A1817D1377"><enum>(E)</enum><text display-inline="yes-display-inline">The extent to which a State government may face low cybersecurity workforce supply and high cybersecurity workforce demand, as identified by the National Institute of Standards and Technology.</text></subparagraph></paragraph></subsection><subsection id="HFAE0C84EA5734DA5922B9E90F744D3EB"><enum>(i)</enum><header>Review Committee for Cyber Resiliency Grants</header><paragraph id="HC0F2AFF110B54BE1ADD222737491777D"><enum>(1)</enum><header>Establishment</header><text>There is established a committee to be known as the <quote>Review Committee for Cyber Resiliency Grants</quote> (in this section referred to as the <quote>Review Committee</quote>).</text></paragraph><paragraph id="H3E592C28ED7E41B488C3428EF23715CB"><enum>(2)</enum><header>Consideration of submissions</header><text display-inline="yes-display-inline">The Secretary shall forward a copy of each cyber resiliency plan submitted for approval under <internal-xref idref="H0C27762F25BD4C319E3E12A01A3114EF" legis-path="2.(b)(1)">subsection (d)(1)</internal-xref>, each application for an additional planning grant submitted under <internal-xref idref="H5EAD27C2867A4AC0985E59CBC6C2900C" legis-path="2.(c)(3)">subsection (e)(3)</internal-xref>, and each application for a biennial implementation grant submitted under <internal-xref idref="H27521EFFB6294F7FB3B4CE258CE6719E" legis-path="2.(d)(1)">subsection (d)(1)</internal-xref> to the Review Committee for consideration under this subsection.</text></paragraph><paragraph id="H38FEACFEB0B847B485CC338BC4ADD189"><enum>(3)</enum><header>Duties</header><text>The Review Committee shall—</text><subparagraph id="HAA16CCC39E8B417FA5F51C6D73AD4921"><enum>(A)</enum><text display-inline="yes-display-inline">promulgate guidance for the development of applications for grants under this section;</text></subparagraph><subparagraph id="H21147515A0404708AD41871382AD30CA"><enum>(B)</enum><text>review any plan or application forwarded under <internal-xref idref="H3E592C28ED7E41B488C3428EF23715CB" legis-path="2.(g)(2)">paragraph (2)</internal-xref>;</text></subparagraph><subparagraph id="H4D75C2A85EFE49A0BAD96EB4B05D9A5F"><enum>(C)</enum><text display-inline="yes-display-inline">provide to the State and to the Secretary the recommendations of the Review Committee regarding the approval or disapproval of such plan or application and, if applicable, possible improvements to such plan or application;</text></subparagraph><subparagraph id="HE380AA21673E4EB8AB9A17CCAE5ACA8E"><enum>(D)</enum><text display-inline="yes-display-inline">provide to the Secretary an evaluation of any progress made by a State in implementing an active cyber resiliency plan using a prior biennial implementation grant; and</text></subparagraph><subparagraph id="HCDE32EBB912B40B6B21F033A50CDE948"><enum>(E)</enum><text>submit to Congress an annual report on the progress made in implementing active cyber resiliency plans.</text></subparagraph></paragraph><paragraph id="H4EF634F74B01480C8253BD1FB08EDEF2"><enum>(4)</enum><header>Membership</header><subparagraph id="H8CC7BD774A2C4EA1B0DD4834B651A452"><enum>(A)</enum><header>Number and appointment</header><text display-inline="yes-display-inline">The Review Committee shall be composed of 15 members appointed by the Secretary as follows:</text><clause id="H2680A52C93A143078A085BD9582BD969"><enum>(i)</enum><text>At least 2 individuals rec­om­mend­ed to the Secretary by the National Governors Association.</text></clause><clause id="H48617AC908A644EA93EEECDE9D5351E3"><enum>(ii)</enum><text display-inline="yes-display-inline">At least 1 individual recommended to the Secretary by the National Association of State Chief Information Officers.</text></clause><clause id="H7DD3936454B1459BAE8E036BAAC4E43B"><enum>(iii)</enum><text display-inline="yes-display-inline">At least 1 individual rec­om­mend­ed to the Secretary by the National Guard Bureau.</text></clause><clause id="H0C7E6F02E647427B926C22FBA194C02B"><enum>(iv)</enum><text display-inline="yes-display-inline">At least 1 individual rec­om­mend­ed to the Secretary by the National Association of Counties.</text></clause><clause id="HCB743D20E27B40A98286C66681B7CCA2"><enum>(v)</enum><text>At least 1 individual recommended to the Secretary by the National League of Cities.</text></clause><clause id="H7E0F3536E19F42589A45128B173FE2A6"><enum>(vi)</enum><text>Not more than 9 other individuals who have educational and professional experience related to cybersecurity analysis or policy.</text></clause></subparagraph><subparagraph id="HB3E46D3B9F9E41F6A3EB3D35EDFED230"><enum>(B)</enum><header>Terms</header><text>Each member shall be appointed for a term of 1 year. Any member appointed to fill a vacancy occurring before the expiration of the term for which the member’s predecessor was appointed shall be appointed only for the remainder of that term. A member may serve after the expiration of that member’s term until a successor has taken office. A vacancy in the Commission shall be filled in the manner in which the original appointment was made.</text></subparagraph><subparagraph id="HC98AE17AFDD146549F470D92F2F2F91F"><enum>(C)</enum><header>Pay</header><text>Members shall serve without pay.</text></subparagraph><subparagraph id="H9D85E1711E6743D09C2385293B1F5444"><enum>(D)</enum><header>Chairperson; Vice Chairperson</header><text display-inline="yes-display-inline">The Secretary, or a designee of the Secretary, shall serve as the Chairperson of the Review Committee. The Administrator of the Federal Emergency Management Agency, or a designee of the Administrator, shall serve as the Vice Chairperson of the Review Committee.</text></subparagraph></paragraph><paragraph id="HF5423B7B1E1C4F17BEA4082FAC1023A5"><enum>(5)</enum><header>Staff and experts</header><text>The Review Committee may—</text><subparagraph id="HBBB0A3EAC9C94043BB6234F08E428277"><enum>(A)</enum><text>appoint additional personnel as it considers appropriate, without regard to the provisions of title 5, United States Code, governing appointments in the competitive service;</text></subparagraph><subparagraph id="H737AF99F4E6B42C7900A23B0F1520DF7"><enum>(B)</enum><text>fix the pay of such additional personnel, without regard to the provisions of chapter 51 and subchapter III of chapter 53 of such title relating to classification and General Schedule pay rates; and</text></subparagraph><subparagraph id="H3681093EF7C049649EB69EA60D94E589"><enum>(C)</enum><text>procure temporary and intermittent services under section 3109(b) of such title.</text></subparagraph></paragraph><paragraph id="HA4A49A56C1F3489AA57F61C409325FA7"><enum>(6)</enum><header>Detailees</header><text display-inline="yes-display-inline">Upon request of the Review Committee, the head of any Federal department or agency may detail, on a reimbursable basis, any of the personnel of that department or agency to the Commission to assist it in carrying out the duties under this Act.</text></paragraph><paragraph id="HE744D0C8F8AC4A92A886413F46CF02E4"><enum>(7)</enum><header>Federal Advisory Committee Act</header><text display-inline="yes-display-inline">The Federal Advisory Committee Act (5 U.S.C. App.) shall not apply to the Review Committee.</text></paragraph><paragraph id="HD2F95A61B76C46D59D49826CF3B45102"><enum>(8)</enum><header>Termination</header><text display-inline="yes-display-inline">The authority of the Review Committee shall terminate on the day after the end of the 5-fiscal-year period described in <internal-xref idref="H5354986C6C6C4CF9B43A6969AA51796D" legis-path="2.(a)">subsection (j)</internal-xref>.</text></paragraph></subsection><subsection id="H243C936FAF5545FD9646631BDA8E699B"><enum>(j)</enum><header>Funding</header><text display-inline="yes-display-inline">There is authorized to be appropriated for grants under this section such sums as are necessary for fiscal years 2020 through 2025.</text></subsection><subsection id="HF2220FCBE43E48CAAFCD74C2DC4DA187"><enum>(k)</enum><header>Definitions</header><text display-inline="yes-display-inline">In this section:</text><paragraph id="HC9E275618AC14F6391887528EABC7744"><enum>(1)</enum><header>Active cyber resiliency plan</header><text display-inline="yes-display-inline">The term <quote>active cyber resiliency plan</quote> means a cyber resiliency plan for which an approval is in effect in accordance with <internal-xref idref="H8F853A5ED46C465295402B111A5B159E" legis-path="2.(b)(2)(A)">subsection (d)(2)(A)</internal-xref> or for which the Secretary extends such approval in accordance with <internal-xref idref="HFB98ACD001EC41D2BF82FE70C7083D18" legis-path="2.(b)(2)(B)">subsection (d)(2)(B)</internal-xref>.</text></paragraph><paragraph id="H2B5C05F9D89E42729E3EE29578C77BEA"><enum>(2)</enum><header>Administrator</header><text>The term <quote>Administrator</quote> means the Administrator of the Federal Emergency Management Agency.</text></paragraph><paragraph id="HF27AA15946824035B5741B5944E0AAC8"><enum>(3)</enum><header>Critical infrastructure</header><text display-inline="yes-display-inline">The term <quote>critical infrastructure</quote> has the meaning given that term in section 2 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/101">6 U.S.C. 101</external-xref>).</text></paragraph><paragraph display-inline="no-display-inline" id="H1F77B557B33D4DCE96CE25F2F4F2F5E2"><enum>(4)</enum><header>Cyber resiliency plan</header><text display-inline="yes-display-inline">The term <quote>cyber resiliency plan</quote> means, with respect to a State, a plan that addresses the cybersecurity threats or vulnerabilities faced by the State through a statewide plan and decisionmaking process to respond to cybersecurity risks or incidents.</text></paragraph><paragraph id="H81F755FE49B244D88804A0302BC181FA"><enum>(5)</enum><header>Cybersecurity risk</header><text display-inline="yes-display-inline">The term <quote>cybersecurity risk</quote> has the meaning given that term in section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>).</text></paragraph><paragraph id="HC4B2CE66023447A1A639639B32178EFA"><enum>(6)</enum><header>Incident</header><text display-inline="yes-display-inline">The term <quote>incident</quote> has the meaning given that term in section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>).</text></paragraph><paragraph id="HB20223891CB046CFBD0264488C9DFCF8"><enum>(7)</enum><header>Information sharing and analysis organization</header><text>The term <quote>information sharing and analysis organization</quote> has the meaning given that term in section 2222 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/671">6 U.S.C. 671</external-xref>).</text></paragraph><paragraph id="HAFE8500D3C164CDB9CD673179A6ED2D4"><enum>(8)</enum><header>Key resources</header><text display-inline="yes-display-inline">The term <quote>key resources</quote> has the meaning given that term in section 2 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/101">6 U.S.C. 101</external-xref>).</text></paragraph><paragraph id="HD9C3BFD0B14D4BDBAAD3FC14C052BE06"><enum>(9)</enum><header>Program</header><text display-inline="yes-display-inline">The term <quote>Program</quote> means the State Cyber Resiliency Grant Program established by this section.</text></paragraph><paragraph id="H3BAE4E709B1346EDB2FE3F05967E1BC0"><enum>(10)</enum><header>Public safety answering points</header><text display-inline="yes-display-inline">The term <quote>public safety answering points</quote> has the meaning given that term in section 222(h) of the Communications Act of 1934 (<external-xref legal-doc="usc" parsable-cite="usc/47/222">47 U.S.C. 222(h)</external-xref>).</text></paragraph><paragraph id="HBD79CD1012BB4AEFBA2291E28425BE48"><enum>(11)</enum><header>State</header><text display-inline="yes-display-inline">The term <quote>State</quote>—</text><subparagraph id="HBC9ADA5E82AA434EB0F5E22E9EEC33ED"><enum>(A)</enum><text>means each of the several States, the District of Columbia, and the territories and possessions of the United States; and</text></subparagraph><subparagraph id="H2690907738064D4E8CC963368FE97BA4"><enum>(B)</enum><text display-inline="yes-display-inline">includes any federally recognized Indian tribe that notifies the Secretary, not later than 120 days after the date of the enactment of this Act or not later than 120 days before the start of any fiscal year during the 5-fiscal-year period described in <internal-xref idref="H5354986C6C6C4CF9B43A6969AA51796D" legis-path="2.(a)">subsection (j)</internal-xref>, that the tribe intends to develop a cyber resiliency plan and agrees to forfeit any distribution under <internal-xref idref="H1C6EEA794BE643E4AA6E8A33EE09C955" legis-path="2.(d)(3)">subsection (f)(3)</internal-xref>.</text></subparagraph></paragraph></subsection></section></legis-body></bill> 

