<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ALB21A63-F9J-WH-22P"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2292 IS: Study on Cyber-Attack Response Options Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-06-24</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 2292</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210624">June 24, 2021</action-date><action-desc><sponsor name-id="S375">Mr. Daines</sponsor> (for himself and <cosponsor name-id="S316">Mr. Whitehouse</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Homeland Security to study the potential consequences and benefits of amending the Computer Fraud and Abuse Act to allow private companies to take proportional actions in response to an unlawful network breach. </official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Study on Cyber-Attack Response Options Act</short-title></quote>.</text></section><section id="idA0C05EE48BF8410D90CA311C4EF0E0E6"><enum>2.</enum><header>Study relating to consequences and benefits of amending the CFAA</header><subsection id="id261A7EBF7D0448A5BF382BE653FE94C1"><enum>(a)</enum><header>Study</header><text>The Secretary of Homeland Security, in consultation with other Federal agencies as appropriate, shall conduct a study on the potential benefits and risks of amending section 1030 of title 18, United States Code (commonly known as the <quote>Computer Fraud and Abuse Act</quote>), to allow private entities to take proportional actions in response to an unlawful network breach, subject to oversight and regulation by a designated Federal agency.</text></subsection><subsection id="id4A1521D6F5504619985BC678C8A68AFC"><enum>(b)</enum><header>Report</header><paragraph id="id4E9A13A9B8DC45D3AF7E1BF08FB6A703"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Secretary of Homeland Security shall submit a report on the findings of the study conducted under subsection (a), including any recommendations, to Congress. </text></paragraph><paragraph id="id573457A39E014FCDA48D5B375D2230BF"><enum>(2)</enum><header>Required contents</header><text>The report required under paragraph (1) shall—</text><subparagraph id="idA364D2A7E5B64427A406B918C97F5FF5"><enum>(A)</enum><text>address any impact on national security and foreign affairs; and</text></subparagraph><subparagraph id="idCB664486B9BA40EE9517C593BF69BC00"><enum>(B)</enum><text>include recommendations for—</text><clause id="id6F4289C1C90E48F99EDF09046DF33216"><enum>(i)</enum><text>which Federal agency or agencies may authorize proportional actions by private entities; </text></clause><clause id="id8A0FE864248E42A1B31359C08083A008"><enum>(ii)</enum><text>what level of certainty regarding the identity of the attacker is needed before such actions would be authorized; </text></clause><clause id="idE9F4AF0C16FD4E30BD7767D289E29914"><enum>(iii)</enum><text>which entities would be allowed to take such actions and under what circumstances; </text></clause><clause id="id8B9968BEFB83488787F282F3AFA55778"><enum>(iv)</enum><text>what actions would be permissible; and</text></clause><clause id="id84725AC049E54522AEDCADC031116C19"><enum>(v)</enum><text>what safeguards should be in place. </text></clause></subparagraph></paragraph></subsection></section></legis-body></bill> 

