<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-PAT21600-C2L-C1-9HR"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2199 IS: Cyber Sense Act of 2020</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-06-23</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 2199</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210623">June 23, 2021</action-date><action-desc><sponsor name-id="S402">Ms. Rosen</sponsor> (for herself, <cosponsor name-id="S344">Mr. Hoeven</cosponsor>, <cosponsor name-id="S363">Mr. King</cosponsor>, <cosponsor name-id="S323">Mr. Risch</cosponsor>, and <cosponsor name-id="S384">Mr. Tillis</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSEG00">Committee on Energy and Natural Resources</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Energy to establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Cyber Sense Act of 2020</short-title></quote>.</text></section><section id="id7C79FA3FE6EA441D96BC6510687E7A53"><enum>2.</enum><header>Cyber Sense program</header><subsection id="idc08e9acfa71e49f581c8c873323ab15b"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="id4278DCB7C7CF47D5B669AE2F3C2056BD"><enum>(1)</enum><header>Bulk-power system</header><text>The term <term>bulk-power system</term> has the meaning given the term in section 215(a) of the Federal Power Act (<external-xref legal-doc="usc" parsable-cite="usc/16/824o">16 U.S.C. 824o(a)</external-xref>).</text></paragraph><paragraph id="id0459388A3C4F4C7185959A70E18685E3"><enum>(2)</enum><header>Critical electric infrastructure</header><text>The term <term>critical electric infrastructure</term> has the meaning given the term in section 215A(a) of the Federal Power Act (<external-xref legal-doc="usc" parsable-cite="usc/16/824o-1">16 U.S.C. 824o–1(a)</external-xref>).</text></paragraph><paragraph id="id27D7B9DDD2B645A49E412C834D284C15"><enum>(3)</enum><header>Program</header><text>The term <term>program</term> means the voluntary Cyber Sense program established under subsection (b).</text></paragraph><paragraph id="id71977F06AF1B40D695BF89E4AC5EECC0"><enum>(4)</enum><header>Secretary</header><text>The term <term>Secretary</term> means the Secretary of Energy.</text></paragraph></subsection><subsection id="idB56E1CC264CF409CA02F46CDA81B3417"><enum>(b)</enum><header>Establishment</header><text>The Secretary, in coordination with the heads of other relevant Federal agencies, shall establish a voluntary Cyber Sense program to test the cybersecurity of products and technologies intended for use in the bulk-power system.</text></subsection><subsection id="ide510359246e740c680b39f687b8978d7"><enum>(c)</enum><header>Program requirements</header><text>In carrying out subsection (b), the Secretary shall—</text><paragraph id="ida395ce7373c4491aabbdcc68afeae209"><enum>(1)</enum><text>establish a testing process under the program to test the cybersecurity of products and technologies intended for use in the bulk-power system, including products relating to industrial control systems and operational technologies, such as supervisory control and data acquisition systems;</text></paragraph><paragraph id="id05aaafd3fd284328a05cd897339bc416"><enum>(2)</enum><text>for products and technologies tested under the program, establish and maintain cybersecurity vulnerability reporting processes and a related database;</text></paragraph><paragraph id="id767df7979d0b47fb8e95423e3affe990"><enum>(3)</enum><text>provide technical assistance to electric utilities, product manufacturers, and other electricity sector stakeholders to develop solutions to mitigate identified cybersecurity vulnerabilities in products and technologies tested under the program;</text></paragraph><paragraph id="idc363cd41514046e8807e66bfda5278b6"><enum>(4)</enum><text>biennially review products and technologies tested under the program for cybersecurity vulnerabilities and provide analysis with respect to how those products and technologies respond to and mitigate cyber threats;</text></paragraph><paragraph id="id5a93cf5dc0ea468f95c67c65a5d30926"><enum>(5)</enum><text>develop guidance that is informed by analysis and testing results under the program for electric utilities for the procurement of products and technologies;</text></paragraph><paragraph id="idae30cf73de3449ce99d7e199682109c8"><enum>(6)</enum><text>provide reasonable notice to, and solicit comments from, the public prior to establishing or revising the testing process under the program;</text></paragraph><paragraph id="id89fae29a77e0447a8f2b444ef8b18e3c"><enum>(7)</enum><text>oversee the testing of products and technologies under the program; and</text></paragraph><paragraph id="idaa5454bf2a5b4ec987a0c92455d1d478"><enum>(8)</enum><text>consider incentives to encourage the use of analysis and results of testing under the program in the design of products and technologies for use in the bulk-power system.</text></paragraph></subsection><subsection id="id5d4c9fad7cc748dd90514397cbcc91a0"><enum>(d)</enum><header>Disclosure of information</header><text>Any cybersecurity vulnerability reported pursuant to a process established under subsection (c)(2), the disclosure of which the Secretary reasonably foresees would cause harm to critical electric infrastructure, shall be considered to be critical electric infrastructure information for purposes of section 215A(d) of the Federal Power Act (<external-xref legal-doc="usc" parsable-cite="usc/16/824o-1">16 U.S.C. 824o–1(d)</external-xref>).</text></subsection><subsection id="idcebd804c961f41ee92dea6174fc5df0d"><enum>(e)</enum><header>Federal government liability</header><text>Nothing in this section authorizes the commencement of an action against the United States with respect to the testing of a product or technology under the program.</text></subsection></section></legis-body></bill> 

