<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-MIR21B70-N2R-MR-H64"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2520 IS: State and Local Government Cybersecurity Act of 2021</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-07-28</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 2520</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210728">July 28, 2021</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To amend the Homeland Security Act of 2002 to provide for engagements with State, local, Tribal, and territorial governments, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause"><section commented="no" display-inline="no-display-inline" section-type="section-one" id="S1"><enum>1.</enum><header display-inline="yes-display-inline">Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>State and Local Government Cybersecurity Act of 2021</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" section-type="subsequent-section" id="id773C986BEBC145B39615955BD7D76E32"><enum>2.</enum><header display-inline="yes-display-inline">Amendments to the Homeland Security Act of 2002</header><text display-inline="no-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="idAA2E3F9828B44E99AEC72237A1BC1C7A"><enum>(1)</enum><text display-inline="yes-display-inline">in section 2201 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651</external-xref>)—</text><subparagraph commented="no" display-inline="no-display-inline" id="idC21305313BCA48D49D7677D37ABF7B03"><enum>(A)</enum><text display-inline="yes-display-inline">by redesignating paragraphs (4), (5), and (6) as paragraphs (5), (6), and (7), respectively; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id934966CBE00A4C5AA7F355BB8AFFA08A"><enum>(B)</enum><text display-inline="yes-display-inline">by inserting after paragraph (3) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id636A036E027F460F90D4997A4481527C"><paragraph commented="no" display-inline="no-display-inline" id="idC263C30E5B364546B02DDEE1FB8048D3"><enum>(4)</enum><header display-inline="yes-display-inline">Entity</header><text display-inline="yes-display-inline">The term <term>entity</term> shall include—</text><subparagraph commented="no" display-inline="no-display-inline" id="idE68324D9B78C402EBA8525140D62EAB9"><enum>(A)</enum><text display-inline="yes-display-inline">an association, corporation, whether for-profit or nonprofit, partnership, proprietorship, organization, institution, establishment, or individual, whether domestic or foreign;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id7B7071C9674248CDAB0CAC98DC15D635"><enum>(B)</enum><text display-inline="yes-display-inline">a governmental agency or other governmental entity, whether domestic or foreign, including State, local, Tribal, and territorial government entities; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id04235A68728546C0B0572C9882AE5C16"><enum>(C)</enum><text display-inline="yes-display-inline">the general public.</text></subparagraph></paragraph><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="idE1F94277F9DD471CB002F03B367C38D5"><enum>(2)</enum><text display-inline="yes-display-inline">in section 2202 (<external-xref legal-doc="usc" parsable-cite="usc/6/652">6 U.S.C. 652</external-xref>)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id30C96A2D40B04739B4611427BC392E03"><enum>(A)</enum><text display-inline="yes-display-inline">in subsection (c)—</text><clause commented="no" display-inline="no-display-inline" id="idAE8728AAAC094C7BAA9931548645926D"><enum>(i)</enum><text display-inline="yes-display-inline">in paragraph (11), by striking <quote>and</quote> at the end;</text></clause><clause display-inline="no-display-inline" commented="no" id="idFBEB10AD23C54801B04953996B459622"><enum>(ii)</enum><text>in the first paragraph (12), by striking <quote>and</quote> at the end;</text></clause><clause display-inline="no-display-inline" commented="no" id="id478F6461A9164D7BA3767D570FD7394D"><enum>(iii)</enum><text>by redesignating the second and third paragraphs (12) as paragraphs (13) and (15), respectively;</text></clause><clause display-inline="no-display-inline" commented="no" id="id9F3B0A11ACFC4135AC5468780748408A"><enum>(iv)</enum><text>in paragraph (13), as so redesignated, by striking <quote>and</quote> at the end; and</text></clause><clause display-inline="no-display-inline" commented="no" id="idCFFD2DD714134D80B134C1A85B05D359"><enum>(v)</enum><text>by inserting after paragraph (13), as so redesignated, the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id44216B43EB4B42BD925F6152A6A5DA5A"><paragraph commented="no" display-inline="no-display-inline" id="id916BCD26C8F74C6BBF01B7859B022DB7"><enum>(14)</enum><text display-inline="yes-display-inline">carry out the authority of the Secretary under subsection (e)(1)(S); and</text></paragraph><after-quoted-block>; and</after-quoted-block></quoted-block></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idDE2C4E8B266F43BAB771AEBCA6DCB8C7"><enum>(B)</enum><text display-inline="yes-display-inline">in subsection (e)(1), by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id64BEE850B8684B24B3A3D3FA8F55A515"><subparagraph commented="no" display-inline="no-display-inline" id="idc62c7c0031604388b477a158e92573e2"><enum>(S)</enum><text display-inline="yes-display-inline">To make grants to and enter into cooperative agreements or contracts with States, local, Tribal, and territorial governments, and other non-Federal entities as the Secretary determines necessary to carry out the responsibilities of the Secretary related to cybersecurity and infrastructure security under this Act and any other provision of law, including grants, cooperative agreements, and contracts that provide assistance and education related to cyber threat indicators, defensive measures and cybersecurity technologies, cybersecurity risks, incidents, analysis, and warnings.</text></subparagraph><after-quoted-block>; and</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id37CBDA3F52EE42A78E92CBEFA4E7B436"><enum>(3)</enum><text display-inline="yes-display-inline">in section 2209 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>)—</text><subparagraph commented="no" display-inline="no-display-inline" id="id2E2CDC92E26244C899EC1CA3CD1773B4"><enum>(A)</enum><text display-inline="yes-display-inline">in subsection (c)(6), by inserting <quote>operational and</quote> before <quote>timely</quote>;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id81D39586DAA04B969184E787335E8D48"><enum>(B)</enum><text display-inline="yes-display-inline">in subsection (d)(1)(E), by inserting <quote>, including an entity that collaborates with election officials,</quote> after <quote>governments</quote>; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id1C567B5C7CFF43C28884DA85F174CDE6"><enum>(C)</enum><text display-inline="yes-display-inline">by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id7EB6C93A21AB44DCB43DF576B92D7A38"><subsection commented="no" display-inline="no-display-inline" id="idDF745C2E5D6940C5B3A86BAB3F5769D5"><enum>(p)</enum><header display-inline="yes-display-inline">Coordination on cybersecurity for Federal and non-Federal entities</header><paragraph commented="no" display-inline="no-display-inline" id="idBA7D4086C25B4F33BD8667DFB18E28AC"><enum>(1)</enum><header display-inline="yes-display-inline">Coordination</header><text display-inline="yes-display-inline">The Center shall, to the extent practicable, and in coordination as appropriate with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center—</text><subparagraph commented="no" display-inline="no-display-inline" id="ide2ce794becac4421b4ee28228711c943"><enum>(A)</enum><text display-inline="yes-display-inline">conduct exercises with Federal and non-Federal entities;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idd5714cd6087f4e56bc2e9b353217408c"><enum>(B)</enum><text display-inline="yes-display-inline">provide operational and technical cybersecurity training related to cyber threat indicators, proactive and defensive measures, cybersecurity risks and vulnerabilities, and incident response and management to Federal and non-Federal entities to address cybersecurity risks or incidents, with or without reimbursement;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id64f9f7aa741042278df376b1a8f19667"><enum>(C)</enum><text display-inline="yes-display-inline">assist Federal and non-Federal entities, upon request, in sharing actionable and real time cyber threat indicators, defensive measures, cybersecurity risks, and incidents from and to the Federal Government as well as among Federal and non-Federal entities, in order to increase situational awareness and help prevent incidents;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id2e21c0f504304613a81471eddba243d9"><enum>(D)</enum><text display-inline="yes-display-inline">provide notifications containing specific incident and malware information that may affect them or their customers and residents;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id480409db0d474350bdb3efacd4dc61fd"><enum>(E)</enum><text display-inline="yes-display-inline">provide and periodically update via an easily accessible platform and other means tools, products, resources, policies, guidelines, controls, and other cybersecurity standards and best practices and procedures related to information security;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id240f6c8a7fab43b593c2dcbe502864c2"><enum>(F)</enum><text display-inline="yes-display-inline">work with senior Federal and non-Federal officials, including State, local, Tribal, and territorial Chief Information Officers, senior election officials, and through national associations, to coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, controls, and procedures related to information security to secure and ensure the resiliency of Federal and non-Federal information systems, including election systems;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ida53e435c31884f279690684ce245e2e9"><enum>(G)</enum><text display-inline="yes-display-inline">provide, upon request, operational and technical assistance to Federal and non-Federal entities to implement tools, products, resources, policies, guidelines, controls, and procedures on information security, including by, as appropriate, deploying and sustaining cybersecurity technologies, such as an intrusion and threat detection capability, to assist those Federal and non-Federal entities in detecting cybersecurity risks and incidents;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idf9ed0d40667b4fc8b4258e126f061845"><enum>(H)</enum><text display-inline="yes-display-inline">assist Federal and non-Federal entities in developing policies and procedures for coordinating vulnerability disclosures, to the extent practicable, consistent with international and national standards in the information technology industry;</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id61e7194776624c59a8e486721ba86a8f"><enum>(I)</enum><text display-inline="yes-display-inline">ensure that Federal and non-Federal entities, as appropriate, are made aware of the tools, products, resources, policies, guidelines, controls, and procedures on information security developed by the Department and other appropriate Federal departments and agencies for ensuring the security and resiliency of civilian information systems; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id70eba9a19bca4d249b06e641d6be0c67"><enum>(J)</enum><text display-inline="yes-display-inline">promote cybersecurity education and awareness through engagements with Federal and non-Federal entities.</text></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="idAA917CC843BA4DB599AAFB9DD0FA1B5A"><enum>(q)</enum><header display-inline="yes-display-inline">Report</header><text display-inline="yes-display-inline">Not later than 1 year after the date of enactment of this subsection, and every 2 years thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on—</text><paragraph commented="no" display-inline="no-display-inline" id="idA25839587E634642B70FD206B128D8C1"><enum>(1)</enum><text display-inline="yes-display-inline">the status of cybersecurity measures that are in place, and any gaps that exist, in each State and in the largest urban areas of the United States;</text></paragraph><paragraph id="idca535d8353f94e8fbe6c1dc6d0b89a5e"><enum>(2)</enum><text>the services and capabilities that the Agency directly provides to governmental agencies or other governmental entities; and</text></paragraph><paragraph id="idEBACE088FDE84CA5B9B5A483E73079E4"><enum>(3)</enum><text>the services and capabilities that the Agency indirectly provides to governmental agencies or other governmental entities through an entity described in section 2201(4)(B).</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph></section></legis-body></bill> 

