<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Engrossed-in-Senate" dms-id="A1" public-private="public" star-print="no-star-print" bill-type="olc" stage-count="1" public-print="no"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2520 ES: State and Local Government Cybersecurity Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date></dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form display="yes">
<congress display="yes">117th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">S. 2520</legis-num><current-chamber display="no">IN THE SENATE OF THE UNITED STATES</current-chamber><legis-type display="yes">AN ACT</legis-type><official-title display="yes">To amend the Homeland Security Act of 2002 to provide for engagements with State, local, Tribal, and territorial governments, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause"><section commented="no" display-inline="no-display-inline" section-type="section-one" id="idef4d03ec-e40d-4526-afd1-58b560c5adcb" changed="not-changed"><enum>1.</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>State and Local Government Cybersecurity Act of 2021</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" section-type="subsequent-section" id="id44fd7e53-077f-4b02-90a2-2c7551fea1aa" changed="not-changed"><enum>2.</enum><header display-inline="yes-display-inline">Amendments to the Homeland Security Act of 2002</header><text display-inline="no-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id73a41587-8c0d-4858-8352-968ecf6457a7" changed="not-changed"><enum>(1)</enum><text display-inline="yes-display-inline">in section 2201 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651</external-xref>), by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id899fb21b-3200-4ea2-b82f-5a8fbaade1b0" changed="not-changed"><paragraph commented="no" display-inline="no-display-inline" id="id0f801ac2-539f-48d6-9f9d-8d9c3f79f849" changed="not-changed"><enum>(7)</enum><header display-inline="yes-display-inline">SLTT entity</header><text display-inline="yes-display-inline">The term <term>SLTT entity</term> means a domestic government entity that is a State government, local government, Tribal government, territorial government, or any subdivision thereof.</text></paragraph><after-quoted-block display="yes">; and</after-quoted-block></quoted-block></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idcaf00dde-1295-4c48-924f-b6a21c4b17bf" changed="not-changed"><enum>(2)</enum><text display-inline="yes-display-inline">in section 2209 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id94c90d04-537d-4246-ac21-b44ed654bd7d" changed="not-changed"><enum>(A)</enum><text display-inline="yes-display-inline">in subsection (c)(6), by inserting <quote>operational and</quote> before <quote>timely</quote>;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida3519193-b2bb-479f-a792-20649bb99800" changed="not-changed"><enum>(B)</enum><text display-inline="yes-display-inline">in subsection (d)(1)(E), by inserting <quote>, including an entity that collaborates with election officials,</quote> after <quote>governments</quote>; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7510557a-d6b0-434b-bb2b-6bd476e99660" changed="not-changed"><enum>(C)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text><quoted-block id="idc3114009-ec6d-4ebb-bac0-3f089820cd05" changed="not-changed" display-inline="no-display-inline" style="OLC"><subsection commented="no" display-inline="no-display-inline" id="ida5ffb522-5d0d-4bbc-9e72-c1cf83c5649d" changed="not-changed"><enum>(p)</enum><header display-inline="yes-display-inline">Coordination on cybersecurity for SLTT entities</header><paragraph commented="no" display-inline="no-display-inline" id="idb9e0cabe-a209-4da4-997a-69abe0e81991" changed="not-changed"><enum>(1)</enum><header display-inline="yes-display-inline">Coordination</header><text display-inline="yes-display-inline">The Center shall, upon request and to the extent practicable, and in coordination as appropriate with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center—</text><subparagraph commented="no" display-inline="no-display-inline" id="id4d29b84a-0e74-4d03-b3f9-3ea095969405" changed="not-changed"><enum>(A)</enum><text display-inline="yes-display-inline">conduct exercises with SLTT entities;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idaeb6179a-fa08-44b5-970e-0f24458493f3" changed="not-changed"><enum>(B)</enum><text display-inline="yes-display-inline">provide operational and technical cybersecurity training to SLTT entities to address cybersecurity risks or incidents, with or without reimbursement, related to—</text><clause commented="no" display-inline="no-display-inline" id="idC771117ABB614A08BC9BC9041B437D33" changed="not-changed"><enum>(i)</enum><text display-inline="yes-display-inline">cyber threat indicators;</text></clause><clause commented="no" display-inline="no-display-inline" id="id805BEE315C884C14B3A3B742ECB1E295" changed="not-changed"><enum>(ii)</enum><text display-inline="yes-display-inline">defensive measures;</text></clause><clause commented="no" display-inline="no-display-inline" id="id52C10D0487394F4DA3545115329B7C56" changed="not-changed"><enum>(iii)</enum><text display-inline="yes-display-inline">cybersecurity risks;</text></clause><clause commented="no" display-inline="no-display-inline" id="id4CCC97C17A134F75B920E2ECD1F45B9F" changed="not-changed"><enum>(iv)</enum><text display-inline="yes-display-inline">vulnerabilities; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id63F8A240CE75435298D92E8D251F2D38" changed="not-changed"><enum>(v)</enum><text display-inline="yes-display-inline">incident response and management;</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3064db48-3652-4843-a419-49b3c3ecbe40" changed="not-changed"><enum>(C)</enum><text display-inline="yes-display-inline"> in order to increase situational awareness and help prevent incidents, assist SLTT entities in sharing, in real time, with the Federal Government as well as among SLTT entities, actionable—</text><clause id="id2e718f2cf8944175a4cd80d0a9bef58d" changed="not-changed" commented="no" display-inline="no-display-inline"><enum>(i)</enum><text display-inline="yes-display-inline">cyber threat indicators;</text></clause><clause id="idf9c3960ecc984225ace9706a19e7d584" changed="not-changed" commented="no" display-inline="no-display-inline"><enum>(ii)</enum><text display-inline="yes-display-inline">defensive measures;</text></clause><clause id="id2423e7de10ba4873af19e242b08d33ed" changed="not-changed" commented="no" display-inline="no-display-inline"><enum>(iii)</enum><text display-inline="yes-display-inline">information about cybersecurity risks; and</text></clause><clause id="idee3cc7bb34f04c04a0b0bb682ca41d74" changed="not-changed" commented="no" display-inline="no-display-inline"><enum>(iv)</enum><text display-inline="yes-display-inline">information about incidents; </text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idd920fa97-5681-427e-9c5a-6e0e5f6b3b2d" changed="not-changed"><enum>(D)</enum><text display-inline="yes-display-inline">provide SLTT entities notifications containing specific incident and malware information that may affect them or their residents;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idede9df05-7ae2-47a9-861d-68b1f59ec6d8" changed="not-changed"><enum>(E)</enum><text display-inline="yes-display-inline">provide to, and periodically update, SLTT entities via an easily accessible platform and other means—</text><clause commented="no" display-inline="no-display-inline" id="id44FAC54C1B784EF3BC5F0AD21F212F4B" changed="not-changed"><enum>(i)</enum><text display-inline="yes-display-inline">information about tools; </text></clause><clause commented="no" display-inline="no-display-inline" id="id45843B009AD841858E62990722919812" changed="not-changed"><enum>(ii)</enum><text display-inline="yes-display-inline">information about products;</text></clause><clause commented="no" display-inline="no-display-inline" id="idCF840BF302E04764AD99DEC7D4F1AF77" changed="not-changed"><enum>(iii)</enum><text display-inline="yes-display-inline">resources;</text></clause><clause commented="no" display-inline="no-display-inline" id="idB736CC82693E45D7AE03F76D9DB0FB8D" changed="not-changed"><enum>(iv)</enum><text display-inline="yes-display-inline">policies;</text></clause><clause commented="no" display-inline="no-display-inline" id="idA265169AB9DD405EA410EAB2171BB05D" changed="not-changed"><enum>(v)</enum><text display-inline="yes-display-inline">guidelines;</text></clause><clause commented="no" display-inline="no-display-inline" id="id2E8C9F43A63A4AFEB36C1CF504C8215B" changed="not-changed"><enum>(vi)</enum><text display-inline="yes-display-inline">controls; and </text></clause><clause commented="no" display-inline="no-display-inline" id="idCA75C14B6F8046E7B9413248C415D8EF" changed="not-changed"><enum>(vii)</enum><text display-inline="yes-display-inline">other cybersecurity standards and best practices and procedures related to information security, including, as appropriate, information produced by other Federal agencies; </text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9575d5fa-e441-4cb6-b664-9dd27d892ff7" changed="not-changed"><enum>(F)</enum><text display-inline="yes-display-inline">work with senior SLTT entity officials, including chief information officers and senior election officials and through national associations, to coordinate the effective implementation by SLTT entities of tools, products, resources, policies, guidelines, controls, and procedures related to information security to secure the information systems, including election systems, of SLTT entities;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id3b0a554c-bbe4-48f9-9753-f92f24e52c9b" changed="not-changed"><enum>(G)</enum><text display-inline="yes-display-inline">provide operational and technical assistance to SLTT entities to implement tools, products, resources, policies, guidelines, controls, and procedures on information security;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ide75b26ab-a0b7-402b-bc35-b6543653a0cd" changed="not-changed"><enum>(H)</enum><text display-inline="yes-display-inline">assist SLTT entities in developing policies and procedures for coordinating vulnerability disclosures consistent with international and national standards in the information technology industry; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id29d6f980-f05d-4c8f-b41a-2dd65535fbc2" changed="not-changed"><enum>(I)</enum><text display-inline="yes-display-inline">promote cybersecurity education and awareness through engagements with Federal agencies and non-Federal entities.</text></subparagraph></paragraph></subsection><subsection id="id52986d13-6180-43a1-8a7b-72edd68dbb06" changed="not-changed" commented="no" display-inline="no-display-inline"><enum>(q)</enum><header display-inline="yes-display-inline">Report</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this subsection, and every 2 years thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the services and capabilities that the Agency directly and indirectly provides to SLTT entities.</text></subsection><after-quoted-block display="yes">.</after-quoted-block></quoted-block></subparagraph></paragraph></section></legis-body><attestation><attestation-group><attestation-date date="20220111" legis-day="20220110" chamber="Senate">Passed the Senate January 11 (legislative day, January 10), 2022.</attestation-date><attestor display="no"></attestor><role>Secretary</role></attestation-group></attestation><endorsement display="yes"></endorsement></bill> 

