<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN21419-7M7-G8-DPP"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S1917 IS: K–12 Cybersecurity Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-05-27</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 1917</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210527">May 27, 2021</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself and <cosponsor name-id="S404">Mr. Scott of Florida</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To establish a K–12 education cybersecurity initiative, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>K–12 Cybersecurity Act of 2021</short-title></quote>.</text></section><section id="id57DCF862508B4059893A880E3DBCC8B5"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text><paragraph id="id96C4110B42844BC79FBBF4843B72F0EF"><enum>(1)</enum><text>K–12 educational institutions across the United States are facing cyber attacks.</text></paragraph><paragraph id="idA9442E232DEF4AA483C9BE08D9A1B171"><enum>(2)</enum><text>Cyber attacks place the information systems of K–12 educational institutions at risk of possible disclosure of sensitive student and employee information, including—</text><subparagraph id="id6086755B1BED47AD9D4550D5350366EB"><enum>(A)</enum><text>grades and information on scholastic development;</text></subparagraph><subparagraph id="id007AE098605D49D7A3E6BD57F4EC950F"><enum>(B)</enum><text>medical records;</text></subparagraph><subparagraph id="id0203847F2C2F4FD48346E523D6B1BA35"><enum>(C)</enum><text>family records; and</text></subparagraph><subparagraph id="idCFB47AE35E474BA0A26E49939DBC7E83"><enum>(D)</enum><text>personally identifiable information.</text></subparagraph></paragraph><paragraph id="id61096D4601FA491C966836934238DB89"><enum>(3)</enum><text>Providing K–12 educational institutions with resources to aid cybersecurity efforts will help K–12 educational institutions prevent, detect, and respond to cyber events.</text></paragraph></section><section id="idBCDE982194F74CDBBF119285804BEB02"><enum>3.</enum><header>K–12 education cybersecurity initiative</header><subsection id="idF08232AEB2DB44D0B081B04066FC0856"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idEC391BFC9A9E40BDAFC65AE135BB4D6D"><enum>(1)</enum><header>Cybersecurity risk</header><text>The term <term>cybersecurity risk</term> has the meaning given the term in section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>).</text></paragraph><paragraph id="id389CEF2B646741EBAFADC94E54471E7D"><enum>(2)</enum><header>Director</header><text>The term <term>Director</term> means the Director of Cybersecurity and Infrastructure Security.</text></paragraph><paragraph id="id579A332D81524FE2B40E993FA54BA265"><enum>(3)</enum><header>Information system</header><text>The term <term>information system</term> has the meaning given the term in section 3502 of title 44, United States Code.</text></paragraph><paragraph id="idBDF97E0F367D49B9BFE75388FDFFA249"><enum>(4)</enum><header>K–12 educational institution</header><text>The term <term>K–12 educational institution</term> means an elementary school or a secondary school, as those terms are defined in section 8101 of the Elementary and Secondary Education Act of 1965 (<external-xref legal-doc="usc" parsable-cite="usc/20/7801">20 U.S.C. 7801</external-xref>).</text></paragraph></subsection><subsection id="id3780A432D98B4F1A8D5CCCA416E77808"><enum>(b)</enum><header>Study</header><paragraph id="id17E77BE16D8341AAAE7E10B1A5F5184D"><enum>(1)</enum><header>In general</header><text>Not later than 120 days after the date of enactment of this Act, the Director, in accordance with subsection (g)(1), shall conduct a study on the specific cybersecurity risks facing K–12 educational institutions that—</text><subparagraph id="id21A047C805574D3981E1E6F313EAB6DC"><enum>(A)</enum><text>analyzes how identified cybersecurity risks specifically impact K–12 educational institutions;</text></subparagraph><subparagraph id="idE1F0903ECFB943E984B3FE33CC921EC0"><enum>(B)</enum><text>includes an evaluation of the challenges K–12 educational institutions face in—</text><clause id="id273769348E724493AB1B9717981587F6"><enum>(i)</enum><text>securing—</text><subclause id="idC9EAE3EFECC04499AFC382D6E6239BCC"><enum>(I)</enum><text>information systems owned, leased, or relied upon by K–12 educational institutions; and</text></subclause><subclause id="idBF6EE4D0F5F54FC88ABC4F87497E37DE"><enum>(II)</enum><text>sensitive student and employee records; and</text></subclause></clause><clause id="idD1951F5E16364340877F65B096A34F0F"><enum>(ii)</enum><text>implementing cybersecurity protocols;</text></clause></subparagraph><subparagraph id="id19FCE77054D442E08E6EAAA2135B5D03"><enum>(C)</enum><text>identifies cybersecurity challenges relating to remote learning; and</text></subparagraph><subparagraph id="id933D5CCF29014723BF2D8730BC901407"><enum>(D)</enum><text>evaluates the most accessible ways to communicate cybersecurity recommendations and tools.</text></subparagraph></paragraph><paragraph id="idD9201D9B9CD94D89B47C6F42D3255992"><enum>(2)</enum><header>Congressional briefing</header><text>Not later than 120 days after the date of enactment of this Act, the Director shall provide a Congressional briefing on the study conducted under paragraph (1).</text></paragraph></subsection><subsection id="id620DE62594A84B3DAF1B475995DB3C7F"><enum>(c)</enum><header>Cybersecurity Recommendations</header><text>Not later than 60 days after the completion of the study required under subsection (b)(1), the Director, in accordance with subsection (g)(1), shall develop recommendations that include cybersecurity guidelines designed to assist K–12 educational institutions in facing the cybersecurity risks described in subsection (b)(1), using the findings of the study.</text></subsection><subsection id="id6C760DDFDB324887A71BCA4A0D5E6C35"><enum>(d)</enum><header>Online training toolkit</header><text>Not later than 120 days after the completion of the development of the recommendations required under subsection (c), the Director shall develop an online training toolkit designed for officials at K–12 educational institutions to—</text><paragraph id="idBAABD4FCE84546BC9C4B5BB34761AB96"><enum>(1)</enum><text>educate the officials about the cybersecurity recommendations developed under subsection (c); and </text></paragraph><paragraph id="id7F677FFDE79F4E69B6281B99C4333779"><enum>(2)</enum><text>provide strategies for the officials to implement the recommendations developed under subsection (c).</text></paragraph></subsection><subsection id="id3ADAB3C382BA41D994B428B54A54A2D9"><enum>(e)</enum><header>Public availability</header><text>The Director shall make available on the website of the Department of Homeland Security with other information relating to school safety the following:</text><paragraph id="id68A6E82BF7994C75A12F3E3C319ADA0B"><enum>(1)</enum><text>The findings of the study conducted under subsection (b)(1).</text></paragraph><paragraph id="idBDBD08AC37C64CC6ABAC39A61A93A999"><enum>(2)</enum><text>The cybersecurity recommendations developed under subsection (c).</text></paragraph><paragraph id="id99A05980071D48EF8D069516AAAAFBC4"><enum>(3)</enum><text>The online training toolkit developed under subsection (d).</text></paragraph></subsection><subsection id="id21BEFF1C726D4AF1A692F892E43DD34E"><enum>(f)</enum><header>Voluntary use</header><text>The use of the cybersecurity recommendations developed under (c) by K–12 educational institutions shall be voluntary.</text></subsection><subsection id="id3BF96D71745643369508D9DA6226113A"><enum>(g)</enum><header>Consultation</header><paragraph id="id1F2C1C0F7FA34805A500806CC6DC1724"><enum>(1)</enum><header>In general</header><text>In the course of the conduction of the study required under subsection (b)(1) and the development of the recommendations required under subsection (c), the Director shall consult with individuals and entities focused on cybersecurity and education, as appropriate, including—</text><subparagraph id="id12285BF193974D55B860502AF8C2B665"><enum>(A)</enum><text>teachers;</text></subparagraph><subparagraph id="id9A14B192D97747CCA7BEEE9757C2A1B7"><enum>(B)</enum><text>school administrators;</text></subparagraph><subparagraph id="id5F1749E615BA44899F04695DDA683003"><enum>(C)</enum><text>Federal agencies;</text></subparagraph><subparagraph id="id42DC0E12AAF74E56B404953889236DA4"><enum>(D)</enum><text>non-Federal cybersecurity entities with experience in education issues; and</text></subparagraph><subparagraph id="id52F32CA0C8374D0885A26E9B67A4A1B2" commented="no" display-inline="no-display-inline"><enum>(E)</enum><text>private sector organizations.</text></subparagraph></paragraph><paragraph id="id622AD55C71344E1F82ADE690D0D05ED9" commented="no" display-inline="no-display-inline"><enum>(2)</enum><header>Inapplicability of FACA</header><text>The Federal Advisory Committee Act (5 U.S.C App.) shall not apply to any consultation under paragraph (1).</text></paragraph></subsection></section></legis-body></bill> 

