<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN21248-R8L-XX-8J5"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1316 IS: Cyber Response and Recovery Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-04-22</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 1316</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210422">April 22, 2021</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself and <cosponsor name-id="S349">Mr. Portman</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend the Homeland Security Act of 2002 to authorize the Secretary of Homeland Security to make a declaration of a significant incident, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Response and Recovery Act of 2021</short-title></quote>.</text></section><section id="id3286B3A0C9A24B19A05438A4F489708D"><enum>2.</enum><header>Declaration of a significant incident</header><subsection id="id17A6FEB4735144E3B134ECB2B428DC21"><enum>(a)</enum><header>In general</header><text>Title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651</external-xref> et seq.) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="idA6F08AFB459742938C1ACF467367286D"><subtitle id="id299D5C0B482643CC8AF38CCB82B33A3C" style="OLC"><enum>C</enum><header>Declaration of a significant incident</header><section id="id8F10C899DEAB4347A9A7163119ADF9E5"><enum>2231.</enum><header>Definitions</header><text display-inline="no-display-inline">For the purposes of this subtitle:</text><paragraph id="id3D16EAD0AC034B228F35193DC7AC8DB9"><enum>(1)</enum><header>Asset response activity</header><text>The term <term>asset response activity</term> means an activity to support an entity impacted by an incident with the response to, remediation of, or recovery from, the incident, including—</text><subparagraph id="id6E82E8D466CC4E79B5DC9DEA5557F641"><enum>(A)</enum><text>furnishing technical and advisory assistance to the entity to protect the assets of the entity, mitigate vulnerabilities, and reduce the related impacts; </text></subparagraph><subparagraph id="idCF811201F95041BF836E217F59E2921E"><enum>(B)</enum><text>assessing potential risks to the critical infrastructure sector or geographic region impacted by the incident, including potential cascading effects of the incident on other critical infrastructure sectors or geographic regions;</text></subparagraph><subparagraph id="id4189E61465E2486CA27B1D7C374C7110"><enum>(C)</enum><text>developing courses of action to mitigate the risks assessed under subparagraph (B);</text></subparagraph><subparagraph id="idA1E68C18CCC5434794BA2AAB9DC112D2"><enum>(D)</enum><text>facilitating information sharing and operational coordination with entities performing threat response activities; and</text></subparagraph><subparagraph id="id73EABE7C797E472897D84963DAAF3EFB"><enum>(E)</enum><text>providing guidance on how best to use Federal resources and capabilities in a timely, effective manner to speed recovery from the incident.</text></subparagraph></paragraph><paragraph id="id1907BEAA9684480D8ED76A9A9D7D2BE3"><enum>(2)</enum><header>Declaration</header><text>The term <term>declaration</term> means a declaration of the Secretary under section 2232(a)(1).</text></paragraph><paragraph id="idE56441373F68496F8A9127BC2B0949FF"><enum>(3)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph><paragraph id="id95AC0B4D1FDE451C8FBD6E75717DC146"><enum>(4)</enum><header>Federal agency</header><text>The term <term>Federal agency</term> has the meaning given the term <quote>agency</quote> in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="id662528EC801B4832BE33E8D32848C704"><enum>(5)</enum><header>Fund</header><text>The term <term>Fund</term> means the Cyber Response and Recovery Fund established under section 2233(a).</text></paragraph><paragraph id="idECB6F75180444F84963FAAF4C61F1247"><enum>(6)</enum><header>Incident</header><text>The term <term>incident</term> has the meaning given the term in section 3552 of title 44, United States Code.</text></paragraph><paragraph id="id476F4B4AE6604CE3877A2EBAB7E60A73"><enum>(7)</enum><header>Renewal</header><text>The term <term>renewal</term> means a renewal of a declaration under section 2232(d).</text></paragraph><paragraph id="id78F94DDBD2CA431FA96B3FAC1793D5C5"><enum>(8)</enum><header>Significant incident</header><text>The term <term>significant incident</term>—</text><subparagraph id="id78D7990B85634EB198AAF42231D021C9"><enum>(A)</enum><text>means an incident or a group of related incidents that results, or is likely to result, in demonstrable harm to—</text><clause id="idEA911F6119B145628FDCC09E9330B616"><enum>(i)</enum><text>the national security interests, foreign relations, or economy of the United States; or</text></clause><clause id="idEFC84F8AC3954E6DAB3E5987464C75B9"><enum>(ii)</enum><text>the public confidence, civil liberties, or public health and safety of the people of the United States; and</text></clause></subparagraph><subparagraph id="id26592ADD190E4E8F8182F99C0403CB5A"><enum>(B)</enum><text>does not include an incident or a portion of a group of related incidents that occurs on—</text><clause id="id20A2345C927A465EA0A871591508F410"><enum>(i)</enum><text>a national security system (as defined in section 3552 of title 44, United States Code); or</text></clause><clause id="idEC046CC58056432EBDF20DEEFD589F9B"><enum>(ii)</enum><text>an information system described in paragraph (2) or (3) of section 3553(e) of title 44, United States Code.</text></clause></subparagraph></paragraph></section><section id="id7CA20F79A3F043FE8A9EE94C903F51FF"><enum>2232.</enum><header>Declaration</header><subsection id="idc67a18ed63eb4c88a71f67beac48161b"><enum>(a)</enum><header>In general</header><paragraph id="idAEDB51CF1BC64F34BFD2A3D5E12AD0BB"><enum>(1)</enum><header>Declaration</header><text>The Secretary, in consultation with the National Cyber Director, may make a declaration of a significant incident in accordance with this section if the Secretary determines that—</text><subparagraph id="idc3b2754c59124eb1a3bc13cc3d559732"><enum>(A)</enum><text>a specific significant incident—</text><clause id="id0d0d10dcef354a469a59a51823e15e44"><enum>(i)</enum><text>has occurred; or</text></clause><clause id="id369ea4c373c544e9b88b3ae650855bf4"><enum>(ii)</enum><text>is likely to occur imminently; and</text></clause></subparagraph><subparagraph id="idd4f7c889fbe4461a9c063ecbda171a2f"><enum>(B)</enum><text>otherwise available resources, other than the Fund, are likely insufficient to respond effectively to, or to mitigate effectively, the specific significant incident described in subparagraph (A).</text></subparagraph></paragraph><paragraph id="id2E57F9144AAF44418B0BC4E8EA117C54"><enum>(2)</enum><header>Prohibition on delegation</header><text>The Secretary may not delegate the authority provided to the Secretary under paragraph (1).</text></paragraph></subsection><subsection id="idfecdca1c19814e2bab427f1631ed825c"><enum>(b)</enum><header>Asset response activities</header><text>Upon a declaration, the Director shall coordinate—</text><paragraph id="id1f75cf2fa3d349188daaa23e102dea9a"><enum>(1)</enum><text>the asset response activities of each Federal agency in response to the specific significant incident associated with the declaration; and</text></paragraph><paragraph id="id3ff34119bca04fbcb3c3de33d3fbf977"><enum>(2)</enum><text>with appropriate entities, which may include—</text><subparagraph id="id858FA98C25DF4FFBAF7D998785CC9FF4"><enum>(A)</enum><text>public and private entities and State and local governments with respect to the asset response activities of those entities and governments; and</text></subparagraph><subparagraph id="id74daaa95008749b3907cf5b35be982af"><enum>(B)</enum><text>Federal, State, local, and Tribal law enforcement agencies with respect to investigations and threat response activities of those law enforcement agencies.</text></subparagraph></paragraph></subsection><subsection id="idd792e03063a047179f2533997b3fdba7"><enum>(c)</enum><header>Duration</header><text>Subject to subsection (d), a declaration shall terminate upon the earlier of—</text><paragraph id="idC5D54A67314F418F9506B3C0272FCB27"><enum>(1)</enum><text>a determination by the Secretary that the declaration is no longer necessary; or</text></paragraph><paragraph id="id75D2917592934A2AA03D0F23326BA483"><enum>(2)</enum><text>the expiration of the 120-day period beginning on the date on which the Secretary makes the declaration.</text></paragraph></subsection><subsection id="ide70459116deb4471b17edc277ab17892"><enum>(d)</enum><header>Renewal</header><text>The Secretary, without delegation, may renew a declaration as necessary.</text></subsection><subsection id="id19D317D24DC74377B1242094EA10FE2E"><enum>(e)</enum><header>Publication</header><text>Not later than 72 hours after a declaration or a renewal, the Secretary shall publish the declaration or renewal in the Federal Register.</text></subsection><subsection id="id3F22DF2DD28F4003A1E4C3D250E4BBEB"><enum>(f)</enum><header>Advance actions</header><text>The Secretary—</text><paragraph id="id1E526EC1375445659DBC033BCAA16DFB"><enum>(1)</enum><text>shall assess the resources available to respond to a potential declaration; and</text></paragraph><paragraph id="id90E0F7BD317541D98C2D56713F0AFB07"><enum>(2)</enum><text>may take actions before and while a declaration is in effect to arrange or procure additional resources for asset response activities or technical assistance the Secretary determines necessary, which may include entering into standby contracts with private entities for cybersecurity services or incident responders in the event of a declaration. </text></paragraph></subsection></section><section id="id7198EA18754343839144FF9608273816"><enum>2233.</enum><header>Cyber response and recovery fund</header><subsection id="id6646b5e8e010418ab873c0084e6bb54c"><enum>(a)</enum><header>In general</header><text>There is established a Cyber Response and Recovery Fund, which shall be available for—</text><paragraph id="idad58a0cb5129485ab446e30b9741d34e"><enum>(1)</enum><text>the coordination of activities described in section 2232(b);</text></paragraph><paragraph id="ide43fa35421a948fea3d1a8a72d7e0e14"><enum>(2)</enum><text>response and recovery support for the specific significant incident associated with a declaration to Federal, State, local, and Tribal, entities and public and private entities on a reimbursable or non-reimbursable basis, including through asset response activities and technical assistance, such as—</text><subparagraph id="id07892F584C1B4EEAB38A37F1CDC115F7"><enum>(A)</enum><text>vulnerability assessments and mitigation;</text></subparagraph><subparagraph id="idB47C13CC248E49C7A4C4647A4CB2A757"><enum>(B)</enum><text>technical incident mitigation;</text></subparagraph><subparagraph id="idD43FCA62A4784C95BB3BEAE81898D251"><enum>(C)</enum><text>malware analysis;</text></subparagraph><subparagraph id="id52E60E11E11C4D22BBAE829082EC6B93"><enum>(D)</enum><text>analytic support;</text></subparagraph><subparagraph id="idE22FA74DF56545D19C7BA1B0A99A7E51"><enum>(E)</enum><text>threat detection and hunting; and</text></subparagraph><subparagraph id="idB754CA9654914260B757E5F2AD712997"><enum>(F)</enum><text>network protections;</text></subparagraph></paragraph><paragraph id="id12c84f2a63274d2cbe3de9f19fac0cb9"><enum>(3)</enum><text>as the Director determines appropriate, grants for, or cooperative agreements with, Federal, State, local, and Tribal public and private entities to respond to, and recover from, the specific significant incident associated with a declaration, such as—</text><subparagraph id="idCE1F6574C8A54B1F99EA43C482BBDA59"><enum>(A)</enum><text>hardware or software to replace, update, improve, harden, or enhance the functionality of existing hardware, software, or systems; and</text></subparagraph><subparagraph id="id63CCB6C3BB8D4FDDAFCDFD34AFE27110"><enum>(B)</enum><text>technical contract personnel support; and</text></subparagraph></paragraph><paragraph id="idb474017ab3514679a63558a8b59a8570"><enum>(4)</enum><text>advance actions taken by the Secretary under section 2232(f)(2).</text></paragraph></subsection><subsection id="idf9abae41605b4784b05ddeeadbd42fb8"><enum>(b)</enum><header>Deposits</header><text>Money shall be deposited into the Fund from—</text><paragraph id="id6fd5f4e1af0845cfb746ed456b58f789"><enum>(1)</enum><text>appropriations to the Fund for activities of the Fund;</text></paragraph><paragraph id="id4738af39b33a49888230ba471c859ab8"><enum>(2)</enum><text>reimbursement from Federal agencies for the activities described in paragraphs (1), (2), and (4) of subsection (a); and</text></paragraph><paragraph id="idbd01f7ce7d604d54ad8b60d1204b82c6"><enum>(3)</enum><text>any other income incident to activities of the Fund.</text></paragraph></subsection><subsection id="id3bdf5c271cf54220b98298f5ce9c6c6b"><enum>(c)</enum><header>Supplement not supplant</header><text>Amounts in the Fund shall be used to supplement, not supplant, other Federal, State, local, or Tribal funding for activities in response to a declaration.</text></subsection></section><section id="id9CC429551ECE49AEA5DE2A708BC2E28A"><enum>2234.</enum><header>Notification and reporting</header><subsection id="ide2c0da7f42814312a709b9cdf5a23735"><enum>(a)</enum><header>Notification</header><text>Upon a declaration or renewal, the Secretary shall immediately notify the National Cyber Director and appropriate congressional committees and include in the notification—</text><paragraph id="idd36e7b537a744d7eae7e206240fea9c4"><enum>(1)</enum><text>an estimation of the planned duration of the declaration;</text></paragraph><paragraph id="id65105f321f0c4eb7bb2033d39311b0e3"><enum>(2)</enum><text>with respect to a notification of a declaration, the reason for the declaration, including information relating to the specific significant incident or imminent specific significant incident, including—</text><subparagraph id="idbf49242d350846b3a515288959fb621e"><enum>(A)</enum><text>the operational or mission impact or anticipated impact of the specific significant incident on Federal and non-Federal entities;</text></subparagraph><subparagraph id="idda82d97efab54c5e81c904c46af4de0e"><enum>(B)</enum><text>if known, the perpetrator of the specific significant incident; and</text></subparagraph><subparagraph id="id9d62a17114be4b3aa8d68e95a0411f9f"><enum>(C)</enum><text>the scope of the Federal and non-Federal entities impacted or anticipated to be impacted by the specific significant incident;</text></subparagraph></paragraph><paragraph id="idd7834fc07208468994864ec29c9dc2f3"><enum>(3)</enum><text>with respect to a notification of a renewal, the reason for the renewal;</text></paragraph><paragraph id="id2da361ce559342608030cf7d13f282a2"><enum>(4)</enum><text>justification as to why available resources, other than the Fund, are insufficient to respond to or mitigate the specific significant incident; and</text></paragraph><paragraph id="id47c2c6565b68495da0e3a508a68ed3d7"><enum>(5)</enum><text>a description of the coordination activities described in section 2232(b) that the Secretary anticipates the Director to perform.</text></paragraph></subsection><subsection id="id8de1b84ee67e4b5f9200e2352b491412"><enum>(b)</enum><header>Report to Congress</header><text>Not later than 180 days after the date of a declaration or renewal, the Secretary shall submit to the appropriate congressional committees a report that includes—</text><paragraph id="ide391acdb58dc4433ad30b0b6411d7f07"><enum>(1)</enum><text>the reason for the declaration or renewal, including information and intelligence relating to the specific significant incident that led to the declaration or renewal;</text></paragraph><paragraph id="id5a908a820b0f49f7aa2d6cd8caa85637"><enum>(2)</enum><text>the use of any funds from the Fund for the purpose of responding to the incidents or threat described in paragraph (1);</text></paragraph><paragraph id="id91587d5970164d71815917a93ec74350"><enum>(3)</enum><text>a description of the actions, initiatives, and projects undertaken by the Department and State and local governments and public and private entities in responding to and recovering from the specific significant incident described in paragraph (1);</text></paragraph><paragraph id="idC4345454B169411F945D3B71926AE50C"><enum>(4)</enum><text>an accounting of the specific obligations and outlays of the Fund; and</text></paragraph><paragraph id="id97ab4748496e4831b0683766ecc64c8a"><enum>(5)</enum><text>an analysis of—</text><subparagraph id="id2BE27273743B4989880B6E0A9D1A3678"><enum>(A)</enum><text>the impact of the specific significant incident described in paragraph (1) on Federal and non-Federal entities;</text></subparagraph><subparagraph id="id69E4B97E1FBE401EA9D4B750B6AB2C83"><enum>(B)</enum><text>the impact of the declaration or renewal on the response to, and recovery from, the specific significant incident described in paragraph (1); and</text></subparagraph><subparagraph id="idE536B286D9AA4F52A9DF509EB8B762E4"><enum>(C)</enum><text>the impact of the funds made available from the Fund as a result of the declaration or renewal on the recovery from, and response to, the specific significant incident described in paragraph (1).</text></subparagraph></paragraph></subsection><subsection id="idb6b39fbf26784fbbb786d27fe15ea37c"><enum>(c)</enum><header>Classification</header><text>Each notification made under subsection (a) and each report submitted under subsection (b)—</text><paragraph id="id957EBB8460F143B3B3AD86E237E7D5FE"><enum>(1)</enum><text>shall be in an unclassified form; and</text></paragraph><paragraph id="id061BFA77DCD94AF698852CBF57E17C6A"><enum>(2)</enum><text>may include a classified annex.</text></paragraph></subsection><subsection id="id4E95407787E0412A909DC4879593344D"><enum>(d)</enum><header>Consolidated report</header><text>The Secretary shall not be required to submit multiple reports under subsection (b) for multiple declarations or renewals if the Secretary determines that the declarations or renewals substantively relate to the same specific significant incident.</text></subsection><subsection id="idE7FC3AD69907441685A6B2618890D208"><enum>(e)</enum><header>Exemption</header><text>The requirements of subchapter I of <external-xref legal-doc="usc-chapter" parsable-cite="usc-chapter/44/35">chapter 35</external-xref> of title 44 (commonly known as the <quote>Paperwork Reduction Act</quote>) shall not apply to the voluntary collection of information by the Department during an investigation of, a response to, or an immediate post-response review of, the specific significant incident leading to a declaration or renewal.</text></subsection></section><section id="idB8A5093CEE2F491D85628931124E08B3"><enum>2235.</enum><header>Rule of construction</header><text display-inline="no-display-inline">Nothing in this subtitle shall be construed to impair or limit the ability of the Director to carry out the authorized activities of the Cybersecurity and Infrastructure Security Agency.</text></section><section id="id1BF291FC7964449AA30220D62187528E"><enum>2236.</enum><header>Authorization of appropriations</header><text display-inline="no-display-inline">There are authorized to be appropriated to the Fund $20,000,000 for fiscal year 2022, which shall remain available to be expended until September 30, 2028.</text></section><section id="id0EDF3EE64F5F4CE89D34ECCBEC50C503"><enum>2237.</enum><header>Sunset</header><text display-inline="no-display-inline">The authorities granted to the Secretary or the Director under this subtitle shall expire on the date that is 7 years after the date of enactment of the <short-title>Cyber Response and Recovery Act of 2021</short-title>.</text></section></subtitle><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idF64C2985F8784285A5112F16A4209BFF"><enum>(b)</enum><header>Clerical amendment</header><text>The table of contents in section 1(b) of the Homeland Security Act of 2002 (<external-xref legal-doc="public-law" parsable-cite="pl/107/296">Public Law 107–296</external-xref>; 116 Stat. 2135) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id70925A3F81814FE187B11A376481A954"><toc><toc-entry level="subtitle" idref="id299D5C0B482643CC8AF38CCB82B33A3C">Subtitle C—Declaration of a significant incident </toc-entry><toc-entry level="section" idref="id8F10C899DEAB4347A9A7163119ADF9E5">Sec. 2231. Definitions. </toc-entry><toc-entry level="section" idref="id7CA20F79A3F043FE8A9EE94C903F51FF">Sec. 2232. Declaration. </toc-entry><toc-entry level="section" idref="id7198EA18754343839144FF9608273816">Sec. 2233. Cyber response and recovery fund. </toc-entry><toc-entry level="section" idref="id9CC429551ECE49AEA5DE2A708BC2E28A">Sec. 2234. Notification and reporting. </toc-entry><toc-entry level="section" idref="idB8A5093CEE2F491D85628931124E08B3">Sec. 2235. Rule of construction. </toc-entry><toc-entry level="section" idref="id1BF291FC7964449AA30220D62187528E">Sec. 2236. Authorization of appropriations. </toc-entry><toc-entry level="section" idref="id0EDF3EE64F5F4CE89D34ECCBEC50C503">Sec. 2237. Sunset.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body></bill> 

