<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MIR21622-2RN-5S-SHJ"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>107 S1350 IS: National Risk Management Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-04-22</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 1350</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210422">April 22, 2021</action-date><action-desc><sponsor name-id="S388">Ms. Hassan</sponsor> (for herself and <cosponsor name-id="S382">Mr. Sasse</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Homeland Security to establish a national risk management cycle, and for other purposes.</official-title></form><legis-body><section id="id75e892c9e86f4298952fdc619f373b92" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>National Risk Management Act of 2021</short-title></quote>.</text></section><section id="id3F749FAE935D4C6A81EE9401B8B3DD58"><enum>2.</enum><header>National risk management cycle</header><subsection id="idAFCECDB1C1E54E7A95858775A0D3167C"><enum>(a)</enum><header>In general</header><text>Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651</external-xref> et seq.), is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id977C22F679C5406784E320A6AB27C4BA"><section id="id137501DB16F54E6C9BC3592C16B83300"><enum>2218.</enum><header>National risk management cycle</header><subsection id="id90b2df7336614de7879d1f3d035c0c75"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idece006e1af6e467b959822da093f6f94"><enum>(1)</enum><header>Critical infrastructure</header><text>The term <term>critical infrastructure</term> has the meaning given the term in section 1016(e) of the Critical Infrastructures Protection Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>).</text></paragraph><paragraph id="idaafbd2102b204db0861922d2d1279500"><enum>(2)</enum><header>National critical functions</header><text>The term <term>national critical functions</term> means the functions of government and the private sector so vital to the United States that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.</text></paragraph></subsection><subsection id="idb4024b47c37141f99242c1b01a345f3d"><enum>(b)</enum><header>National risk management cycle</header><paragraph id="idf78f6c7690e8402dafc24203de1a99b6"><enum>(1)</enum><header>Risk identification and assessment</header><subparagraph id="id4f47e395998643f6a022e6b188d3f680"><enum>(A)</enum><header>In general</header><text>The Secretary, acting through the Director, shall establish a process by which to identify, assess, and prioritize risks to critical infrastructure, considering both cyber and physical threats, vulnerabilities, and consequences.</text></subparagraph><subparagraph id="ide01c41a935504d8cb7516eea3254e00f"><enum>(B)</enum><header>Consultation</header><text>In establishing the process required under subparagraph (A), the Secretary shall consult with Sector Risk Management Agencies, critical infrastructure owners and operators, and the National Cyber Director.</text></subparagraph><subparagraph id="id9701ddae920f48fc89deefaff559d850"><enum>(C)</enum><header>Publication</header><text>Not later than 180 days after the date of enactment of this section, the Secretary shall publish in the Federal Register procedures for the process established under subparagraph (A).</text></subparagraph><subparagraph id="idf5a47733ba784e30aaf018e88aa3d384"><enum>(D)</enum><header>Report</header><text>The Secretary shall submit to the President, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives a report on the risks identified by the process established under subparagraph (A)— </text><clause id="idA2A4A9A6BA21459CB54F432E5D875F3D"><enum>(i)</enum><text>not later than 1 year after the date of enactment of this section; and</text></clause><clause id="idFCFB1C82B7CE47BAAA9B3DA540BAB694"><enum>(ii)</enum><text>not later than 1 year after the date on which the Secretary submits a periodic evaluation described in section 9002(b)(2) of title XC of division H of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/283">Public Law 116–283</external-xref>).</text></clause></subparagraph></paragraph><paragraph id="id9ef540169eef4a8fb0b39036a3609da7"><enum>(2)</enum><header>National critical infrastructure resilience strategy</header><subparagraph id="id399b3d5bf3a0425893327e8075ae3bb9"><enum>(A)</enum><header>In general</header><text>Not later than 1 year after the date on which the Secretary delivers each report required under paragraph (1), the President shall deliver to majority and minority leaders of the Senate, the Speaker and minority leader of the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives a national critical infrastructure resilience strategy designed to address the risks identified by the Secretary.</text></subparagraph><subparagraph id="id82357f1ad6644cc6a8f3573d6dd5693f"><enum>(B)</enum><header>Elements</header><text>In each strategy delivered under subparagraph (A), the President shall—</text><clause id="idaca48a7c3df14298aa9aa2c4b807e137"><enum>(i)</enum><text>identify, assess, and prioritize areas of risk to critical infrastructure that would compromise, disrupt, or impede their ability to support the national critical functions of national security, economic security, or public health and safety;</text></clause><clause id="id0e8326d1cf104da8ab9d8ac1e55d996b"><enum>(ii)</enum><text>assess the implementation of the previous national critical infrastructure resilience strategy, as applicable;</text></clause><clause id="idc1752deebb90493f9ed50197a30d94a4"><enum>(iii)</enum><text>identify and outline current and proposed national-level actions, programs, and efforts to be taken to address the risks identified;</text></clause><clause id="idc7f002a5bca74c03954ea41c6afb0686"><enum>(iv)</enum><text>identify the Federal departments or agencies responsible for leading each national-level action, program, or effort and the relevant critical infrastructure sectors for each;</text></clause><clause id="idd0fdec6b2cc4491e9fc67517f14f6cb7"><enum>(v)</enum><text>outline the budget plan required to provide sufficient resources to successfully execute the full range of activities proposed or described by the strategy; and</text></clause><clause id="id6c75208cd55d4f75956cc3ede2d63b48"><enum>(vi)</enum><text>request any additional authorities or resources necessary to successfully execute the strategy.</text></clause></subparagraph><subparagraph id="id55474e1c7edf49e591b717d7b859af72"><enum>(C)</enum><header>Form</header><text>Each strategy delivered under subparagraph (A) shall be unclassified, but may contain a classified annex.</text></subparagraph></paragraph><paragraph id="idda0d9afb212b42ebadd401350d69acc2"><enum>(3)</enum><header>Congressional briefing</header><text>Not later than 1 year after the date on which the President delivers a strategy under this section, and every year thereafter, the Secretary, in coordination with Sector Risk Management Agencies, shall brief the appropriate committees of Congress on the national risk management cycle activities undertaken pursuant to the strategy.</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idD6D9FB521DB148539639813FDFC56050"><enum>(b)</enum><header>Technical and conforming amendment</header><text>The table of contents in section 1(b) of the Homeland Security Act of 2002 (<external-xref legal-doc="public-law" parsable-cite="pl/107/296">Public Law 107–296</external-xref>; 116 Stat. 2135) is amended by inserting after the item relating to section 2217 the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id9BAA0428A04F4AA88434DC9769BFEF64"><toc><toc-entry level="section" bold="off">Sec. 2218. National risk management cycle.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body></bill> 

