<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-BAG21H03-D5M-JS-F6N" key="S"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S2699 RS: American Cybersecurity Literacy Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2021-12-17</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 221</calendar><congress>117th CONGRESS</congress><session>1st Session</session><legis-num>S. 2699</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20210810">August 10, 2021</action-date><action-desc><sponsor name-id="S311">Ms. Klobuchar</sponsor> (for herself and <cosponsor name-id="S303">Mr. Thune</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20211217">December 17, 2021</action-date><action-desc>Reported by <sponsor name-id="S275">Ms. Cantwell</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To establish a cybersecurity literacy campaign, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H5E05AD1999514D99B9E624630FEC054A"><section section-type="section-one" id="HAAE2FE195CEF40E0934F3CEC6AD49AA3" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>American Cybersecurity Literacy Act</short-title></quote>.</text></section><section id="HEEBA4DED03E64C679374325CD8D0EE7B" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>2.</enum><header>Sense of Congress</header><text display-inline="no-display-inline">It is the sense of the Congress that the United States has a national security and economic interest in promoting cybersecurity literacy amongst the general public.</text></section><section id="H579E4A55AFB547868B563373552D86D2" changed="deleted" reported-display-style="strikethrough" committee-id="SSCM00"><enum>3.</enum><header>Establishment of cybersecurity literacy campaign</header><subsection id="H4D9CC839A0EF4CBA9A714914969F8608"><enum>(a)</enum><header>In general</header><text>The Assistant Secretary for Communications and Information (referred to in this section as the <quote>Assistant Secretary</quote>) shall, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, develop and conduct a cybersecurity literacy campaign to increase the knowledge and awareness of people in the United States of best practices to reduce cybersecurity risks.</text></subsection><subsection id="HA5CBADDDE73742B5A88D43B801CB6F17"><enum>(b)</enum><header>Campaign</header><text>To reduce cybersecurity risks, the Assistant Secretary shall—</text><paragraph id="H33A33BFFAF694D72A2FD78196C8148A1"><enum>(1)</enum><text>identify the critical areas of an IT system that present cybersecurity risks and educate people in the United States on how to prevent and mitigate such attacks by—</text><subparagraph id="H5C428568FE7C4C0B9861D2D1170B016A"><enum>(A)</enum><text>instructing such people on how to identify—</text><clause id="HD2E8A1F16AB04AF8B8631386A1A7B2A5"><enum>(i)</enum><text>phishing emails; and</text></clause><clause id="H5120E501AA7E4FD49CEAC1B6AC84C7F2"><enum>(ii)</enum><text>secure websites;</text></clause></subparagraph><subparagraph id="H2EAD836F27134BD08662E3DC7536DBDF"><enum>(B)</enum><text display-inline="yes-display-inline">instructing such people on the need to change default passwords on hardware and software technology;</text></subparagraph><subparagraph id="H8B0C840D130F4178B8B2B2AEC026A0CC"><enum>(C)</enum><text>encouraging the use of cybersecurity tools, including—</text><clause id="HC2B78C6F6F1C471C9317521FAA389C16"><enum>(i)</enum><text>multi-factor authentication;</text></clause><clause id="HCE009901EF4949A5A47DF5EBE8BA996D"><enum>(ii)</enum><text>complex passwords;</text></clause><clause id="HF5C03A0483124CD3B5CDCBEB7290CB10"><enum>(iii)</enum><text>firewalls; and</text></clause><clause id="H907E8336420743BB92494AC96470FBA4"><enum>(iv)</enum><text>anti-virus software;</text></clause></subparagraph><subparagraph id="H3F3B77CD3A80456EB5B48A196F3201AE"><enum>(D)</enum><text>identifying the devices that could pose possible cybersecurity risks, including—</text><clause id="HCB0B4FAD2E1E452784C6A53ADB4FEC0D"><enum>(i)</enum><text>personal computers;</text></clause><clause id="H7D9AC171C2194017B3D246C83EED8CEB"><enum>(ii)</enum><text>smartphones;</text></clause><clause id="H05D02E0F7A8441639B0EA3ED8783AC17"><enum>(iii)</enum><text>tablets;</text></clause><clause id="HC519B4742A77486492A8D80AB64DD878"><enum>(iv)</enum><text>Wi-Fi routers; and</text></clause><clause id="HFE62A7252A554BDD9866F0212B750675"><enum>(v)</enum><text>smart home appliances;</text></clause></subparagraph><subparagraph id="H183DE9C3A2B545399657DDF9F02A0B48"><enum>(E)</enum><text display-inline="yes-display-inline">encouraging such people to—</text><clause id="HEE3BF67E58F944B0BF9301DCF8B532C2"><enum>(i)</enum><text>regularly review mobile application permissions;</text></clause><clause id="H4AF6F4B1ACA946B0BB31B373834250DF"><enum>(ii)</enum><text>decline privilege requests from mobile applications that are unnecessary;</text></clause><clause id="HFC93C0EA35E44E0CBCD9F0ACFFE11620"><enum>(iii)</enum><text>download applications only from trusted vendors or sources; and</text></clause><clause id="HD19DC44F66134DD5A1410747F2A7061C"><enum>(iv)</enum><text>connect internet of things or devices to a separate and dedicated network; and</text></clause></subparagraph><subparagraph id="HF9B3108C474A4EA6986D7A5B27CB7FC5"><enum>(F)</enum><text>identifying the potential cybersecurity risks of using publicly available Wi-Fi networks and the methods a user may utilize to limit such risks; and</text></subparagraph></paragraph><paragraph id="H5482DE796E594759BF1E3EB9E99E7E65"><enum>(2)</enum><text>direct people and businesses in the United States to Federal resources to help mitigate the cybersecurity risks identified in this subsection.</text></paragraph></subsection></section><section section-type="section-one" id="id52BBEB5986AE4496ABDE51544D444C20" changed="added" reported-display-style="italic"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>American Cybersecurity Literacy Act of 2021</short-title></quote>.</text></section><section id="id8CC3A1F36AE647C2A24F47B4467C23A4" changed="added" reported-display-style="italic"><enum>2.</enum><header>Sense of Congress</header><text display-inline="no-display-inline">It is the sense of the Congress that the United States has a national security and economic interest in promoting cybersecurity literacy amongst the general public.</text></section><section id="id4385C5A921F5417E81050BC0B319C6BF" changed="added" reported-display-style="italic"><enum>3.</enum><header>Establishment of cybersecurity literacy campaign</header><subsection id="idC410829741144A59B089B2CBFBBF12E6"><enum>(a)</enum><header>In general</header><text>The Director of the National Institute of Standards and Technology shall, in consultation with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, develop and conduct a cybersecurity literacy campaign to increase the knowledge and awareness of people in the United States of best practices to reduce cybersecurity risks.</text></subsection><subsection id="id83ACEA334CAA4D6B92533B0A9781D155"><enum>(b)</enum><header>Elements</header><text>In carrying out subsection (a), the Director of the Institute shall—</text><paragraph id="id02C00EE2031B43F3850E254A2A5116B4"><enum>(1)</enum><text>identify the critical areas of an information technology system that presents cybersecurity risks and educate people in the United States on how to prevent and mitigate such risks by—</text><subparagraph id="id68D65B8853B84C37B32C9586A3653DE2"><enum>(A)</enum><text>instructing such people on how to identify—</text><clause id="idEEA983F66FDA45E0B46FDBB005B223BA"><enum>(i)</enum><text>phishing emails; and</text></clause><clause id="idD30431B6C33947959C1BFCF176F8D554"><enum>(ii)</enum><text>secure websites;</text></clause></subparagraph><subparagraph id="id02E0BA620BA64F8BB197022A40057274"><enum>(B)</enum><text display-inline="yes-display-inline">instructing such people on the need to change default passwords on hardware and software technology;</text></subparagraph><subparagraph id="id1E6476B86CD641EA9B43C122711A1786"><enum>(C)</enum><text>encouraging the use of cybersecurity tools, including—</text><clause id="idE3A29A9A9E664080BBC1EB1B79CAA517"><enum>(i)</enum><text>multi-factor authentication;</text></clause><clause id="idA455B6778C614210A645589819597E5B"><enum>(ii)</enum><text>complex passwords;</text></clause><clause id="idB63A40A640A745F38DB72BCE64DEB892"><enum>(iii)</enum><text>firewalls; and</text></clause><clause id="id124EFB42C5574FF0A4D01AA92D2F61C0"><enum>(iv)</enum><text>anti-virus software;</text></clause></subparagraph><subparagraph id="idE914DAEDBBDE437391DFEFBF17634FE8"><enum>(D)</enum><text>identifying the devices that could pose possible cybersecurity risks, including—</text><clause id="id389C2FFBA57B45C5B7D9BEBFA3EC1F55"><enum>(i)</enum><text>personal computers;</text></clause><clause id="id6E535FF4AA094BB8A6D85FCD7A9FB090"><enum>(ii)</enum><text>smartphones;</text></clause><clause id="id29C0C7CF46B9421ABED9CB3E051F2B87"><enum>(iii)</enum><text>tablets;</text></clause><clause id="id9D538384C5CF41B781C6BE32CD23A268"><enum>(iv)</enum><text>Wi-Fi routers; and</text></clause><clause id="id793BD3F8097B4EE69E282557518E235C"><enum>(v)</enum><text>smart home appliances;</text></clause></subparagraph><subparagraph id="idCA8194B4B1FE4943A250F3D3C985A93C"><enum>(E)</enum><text display-inline="yes-display-inline">encouraging such people to—</text><clause id="id5113228F0EE743179704BD46C63A2E93"><enum>(i)</enum><text>regularly review mobile application permissions;</text></clause><clause id="id176DE6B429DC46E4859E29F92BA58E80"><enum>(ii)</enum><text>decline privilege requests from mobile applications that are unnecessary;</text></clause><clause id="idA6537DD7183F493CA4F1C34BC6CFCA8E"><enum>(iii)</enum><text>download applications only from trusted vendors or sources; and</text></clause><clause id="idADEA513847F14EA0AA9869ADD78FAFD4"><enum>(iv)</enum><text>connect internet of things or devices to a separate and dedicated network; and</text></clause></subparagraph><subparagraph id="idC5BA90E0DF394FB798D12A5167AECBCC"><enum>(F)</enum><text>identifying the potential cybersecurity risks of using publicly available Wi-Fi networks and the methods a user may utilize to limit such risks; and</text></subparagraph></paragraph><paragraph id="idF32C73ACD01B48BF82D6C2BAC889A219" commented="no" display-inline="no-display-inline"><enum>(2)</enum><text>direct people and businesses in the United States to Federal resources to help mitigate the cybersecurity risks identified in this subsection. </text></paragraph></subsection></section></legis-body><endorsement><action-date date="20211217">December 17, 2021</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

