<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN21526-HYD-CR-HHS" star-print="no-star-print" bill-type="olc" stage-count="1" public-print="no"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1917 ES: K–12 Cybersecurity Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form display="yes">
<congress display="yes">117th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">S. 1917</legis-num><current-chamber display="no">IN THE SENATE OF THE UNITED STATES</current-chamber><legis-type display="yes">AN ACT</legis-type><official-title display="yes">To establish a K–12 education cybersecurity initiative, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause"><section id="S1" section-type="section-one" commented="no" display-inline="no-display-inline"><enum>1.</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>K–12 Cybersecurity Act of 2021</short-title></quote>.</text></section><section id="id57DCF862508B4059893A880E3DBCC8B5" commented="no" display-inline="no-display-inline" section-type="subsequent-section"><enum>2.</enum><header display-inline="yes-display-inline">Findings</header><text display-inline="no-display-inline">Congress finds the following:</text><paragraph id="id96C4110B42844BC79FBBF4843B72F0EF" commented="no" display-inline="no-display-inline"><enum>(1)</enum><text display-inline="yes-display-inline">K–12 educational institutions across the United States are facing cyber attacks.</text></paragraph><paragraph id="idA9442E232DEF4AA483C9BE08D9A1B171" commented="no" display-inline="no-display-inline"><enum>(2)</enum><text display-inline="yes-display-inline">Cyber attacks place the information systems of K–12 educational institutions at risk of possible disclosure of sensitive student and employee information, including—</text><subparagraph id="id6086755B1BED47AD9D4550D5350366EB" commented="no" display-inline="no-display-inline"><enum>(A)</enum><text display-inline="yes-display-inline">grades and information on scholastic development;</text></subparagraph><subparagraph id="id007AE098605D49D7A3E6BD57F4EC950F" commented="no" display-inline="no-display-inline"><enum>(B)</enum><text display-inline="yes-display-inline">medical records;</text></subparagraph><subparagraph id="id0203847F2C2F4FD48346E523D6B1BA35" commented="no" display-inline="no-display-inline"><enum>(C)</enum><text display-inline="yes-display-inline">family records; and</text></subparagraph><subparagraph id="idCFB47AE35E474BA0A26E49939DBC7E83" commented="no" display-inline="no-display-inline"><enum>(D)</enum><text display-inline="yes-display-inline">personally identifiable information.</text></subparagraph></paragraph><paragraph id="id61096D4601FA491C966836934238DB89" commented="no" display-inline="no-display-inline"><enum>(3)</enum><text display-inline="yes-display-inline">Providing K–12 educational institutions with resources to aid cybersecurity efforts will help K–12 educational institutions prevent, detect, and respond to cyber events.</text></paragraph></section><section id="idBCDE982194F74CDBBF119285804BEB02" commented="no" display-inline="no-display-inline" section-type="subsequent-section"><enum>3.</enum><header display-inline="yes-display-inline">K–12 education cybersecurity initiative</header><subsection id="idF08232AEB2DB44D0B081B04066FC0856" commented="no" display-inline="no-display-inline"><enum>(a)</enum><header display-inline="yes-display-inline">Definitions</header><text display-inline="yes-display-inline">In this section:</text><paragraph id="idEC391BFC9A9E40BDAFC65AE135BB4D6D" commented="no" display-inline="no-display-inline"><enum>(1)</enum><header display-inline="yes-display-inline">Cybersecurity risk</header><text display-inline="yes-display-inline">The term <term>cybersecurity risk</term> has the meaning given the term in section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>).</text></paragraph><paragraph id="id389CEF2B646741EBAFADC94E54471E7D" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header display-inline="yes-display-inline">Director</header><text display-inline="yes-display-inline">The term <term>Director</term> means the Director of Cybersecurity and Infrastructure Security.</text></paragraph><paragraph id="id579A332D81524FE2B40E993FA54BA265" commented="no" display-inline="no-display-inline"><enum>(3)</enum><header display-inline="yes-display-inline">Information system</header><text display-inline="yes-display-inline">The term <term>information system</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="idBDF97E0F367D49B9BFE75388FDFFA249" commented="no" display-inline="no-display-inline"><enum>(4)</enum><header display-inline="yes-display-inline">K–12 educational institution</header><text display-inline="yes-display-inline">The term <term>K–12 educational institution</term> means an elementary school or a secondary school, as those terms are defined in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph></subsection><subsection id="id3780A432D98B4F1A8D5CCCA416E77808" commented="no" display-inline="no-display-inline"><enum>(b)</enum><header display-inline="yes-display-inline">Study</header><paragraph id="id17E77BE16D8341AAAE7E10B1A5F5184D" commented="no" display-inline="no-display-inline"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">Not later than 120 days after the date of enactment of this Act, the Director, in accordance with subsection (g)(1), shall conduct a study on the specific cybersecurity risks facing K–12 educational institutions that—</text><subparagraph id="id21A047C805574D3981E1E6F313EAB6DC" commented="no" display-inline="no-display-inline"><enum>(A)</enum><text display-inline="yes-display-inline">analyzes how identified cybersecurity risks specifically impact K–12 educational institutions;</text></subparagraph><subparagraph id="idE1F0903ECFB943E984B3FE33CC921EC0" commented="no" display-inline="no-display-inline"><enum>(B)</enum><text display-inline="yes-display-inline">includes an evaluation of the challenges K–12 educational institutions face in—</text><clause id="id273769348E724493AB1B9717981587F6" commented="no" display-inline="no-display-inline"><enum>(i)</enum><text display-inline="yes-display-inline">securing—</text><subclause id="idC9EAE3EFECC04499AFC382D6E6239BCC" commented="no" display-inline="no-display-inline"><enum>(I)</enum><text display-inline="yes-display-inline">information systems owned, leased, or relied upon by K–12 educational institutions; and</text></subclause><subclause id="idBF6EE4D0F5F54FC88ABC4F87497E37DE" commented="no" display-inline="no-display-inline"><enum>(II)</enum><text display-inline="yes-display-inline">sensitive student and employee records; and</text></subclause></clause><clause id="idD1951F5E16364340877F65B096A34F0F" commented="no" display-inline="no-display-inline"><enum>(ii)</enum><text display-inline="yes-display-inline">implementing cybersecurity protocols;</text></clause></subparagraph><subparagraph id="id19FCE77054D442E08E6EAAA2135B5D03" commented="no" display-inline="no-display-inline"><enum>(C)</enum><text display-inline="yes-display-inline">identifies cybersecurity challenges relating to remote learning; and</text></subparagraph><subparagraph id="id933D5CCF29014723BF2D8730BC901407" commented="no" display-inline="no-display-inline"><enum>(D)</enum><text display-inline="yes-display-inline">evaluates the most accessible ways to communicate cybersecurity recommendations and tools.</text></subparagraph></paragraph><paragraph id="idD9201D9B9CD94D89B47C6F42D3255992" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header display-inline="yes-display-inline">Congressional briefing</header><text display-inline="yes-display-inline">Not later than 120 days after the date of enactment of this Act, the Director shall provide a Congressional briefing on the study conducted under paragraph (1).</text></paragraph></subsection><subsection id="id620DE62594A84B3DAF1B475995DB3C7F" commented="no" display-inline="no-display-inline"><enum>(c)</enum><header display-inline="yes-display-inline">Cybersecurity Recommendations</header><text display-inline="yes-display-inline">Not later than 60 days after the completion of the study required under subsection (b)(1), the Director, in accordance with subsection (g)(1), shall develop recommendations that include cybersecurity guidelines designed to assist K–12 educational institutions in facing the cybersecurity risks described in subsection (b)(1), using the findings of the study.</text></subsection><subsection id="id6C760DDFDB324887A71BCA4A0D5E6C35" commented="no" display-inline="no-display-inline"><enum>(d)</enum><header display-inline="yes-display-inline">Online training toolkit</header><text display-inline="yes-display-inline">Not later than 120 days after the completion of the development of the recommendations required under subsection (c), the Director shall develop an online training toolkit designed for officials at K–12 educational institutions to—</text><paragraph id="idBAABD4FCE84546BC9C4B5BB34761AB96" commented="no" display-inline="no-display-inline"><enum>(1)</enum><text display-inline="yes-display-inline">educate the officials about the cybersecurity recommendations developed under subsection (c); and </text></paragraph><paragraph id="id7F677FFDE79F4E69B6281B99C4333779" commented="no" display-inline="no-display-inline"><enum>(2)</enum><text display-inline="yes-display-inline">provide strategies for the officials to implement the recommendations developed under subsection (c).</text></paragraph></subsection><subsection id="id3ADAB3C382BA41D994B428B54A54A2D9" commented="no" display-inline="no-display-inline"><enum>(e)</enum><header display-inline="yes-display-inline">Public availability</header><text display-inline="yes-display-inline">The Director shall make available on the website of the Department of Homeland Security with other information relating to school safety the following:</text><paragraph id="id68A6E82BF7994C75A12F3E3C319ADA0B" commented="no" display-inline="no-display-inline"><enum>(1)</enum><text display-inline="yes-display-inline">The findings of the study conducted under subsection (b)(1).</text></paragraph><paragraph id="idBDBD08AC37C64CC6ABAC39A61A93A999" commented="no" display-inline="no-display-inline"><enum>(2)</enum><text display-inline="yes-display-inline">The cybersecurity recommendations developed under subsection (c).</text></paragraph><paragraph id="id99A05980071D48EF8D069516AAAAFBC4" commented="no" display-inline="no-display-inline"><enum>(3)</enum><text display-inline="yes-display-inline">The online training toolkit developed under subsection (d).</text></paragraph></subsection><subsection id="id21BEFF1C726D4AF1A692F892E43DD34E" commented="no" display-inline="no-display-inline"><enum>(f)</enum><header display-inline="yes-display-inline">Voluntary use</header><text display-inline="yes-display-inline">The use of the cybersecurity recommendations developed under (c) by K–12 educational institutions shall be voluntary.</text></subsection><subsection id="id3BF96D71745643369508D9DA6226113A" commented="no" display-inline="no-display-inline"><enum>(g)</enum><header display-inline="yes-display-inline">Consultation</header><paragraph id="id1F2C1C0F7FA34805A500806CC6DC1724" commented="no" display-inline="no-display-inline"><enum>(1)</enum><header display-inline="yes-display-inline">In general</header><text display-inline="yes-display-inline">In the course of the conduction of the study required under subsection (b)(1) and the development of the recommendations required under subsection (c), the Director shall consult with individuals and entities focused on cybersecurity and education, as appropriate, including—</text><subparagraph id="id12285BF193974D55B860502AF8C2B665" commented="no" display-inline="no-display-inline"><enum>(A)</enum><text display-inline="yes-display-inline">teachers;</text></subparagraph><subparagraph id="id9A14B192D97747CCA7BEEE9757C2A1B7" commented="no" display-inline="no-display-inline"><enum>(B)</enum><text display-inline="yes-display-inline">school administrators;</text></subparagraph><subparagraph id="id5F1749E615BA44899F04695DDA683003" commented="no" display-inline="no-display-inline"><enum>(C)</enum><text display-inline="yes-display-inline">Federal agencies;</text></subparagraph><subparagraph id="id42DC0E12AAF74E56B404953889236DA4" commented="no" display-inline="no-display-inline"><enum>(D)</enum><text display-inline="yes-display-inline">non-Federal cybersecurity entities with experience in education issues; and</text></subparagraph><subparagraph id="id52F32CA0C8374D0885A26E9B67A4A1B2" commented="no" display-inline="no-display-inline"><enum>(E)</enum><text display-inline="yes-display-inline">private sector organizations.</text></subparagraph></paragraph><paragraph id="id622AD55C71344E1F82ADE690D0D05ED9" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header display-inline="yes-display-inline">Inapplicability of FACA</header><text display-inline="yes-display-inline">The Federal Advisory Committee Act (5 U.S.C App.) shall not apply to any consultation under paragraph (1).</text></paragraph></subsection></section></legis-body><attestation><attestation-group><attestation-date date="20210809" chamber="Senate">Passed the Senate August 9, 2021.</attestation-date><attestor display="no"></attestor><role>Secretary</role></attestation-group></attestation><endorsement display="yes"></endorsement></bill> 

