<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-ALB21H65-NKW-VG-0WG"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 S2993 RS: CISA Cyber Exercise Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-12-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 674</calendar><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 2993</legis-num><associated-doc role="report">[Report No. 117–275]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20211019">October 19, 2021</action-date><action-desc><sponsor name-id="S402">Ms. Rosen</sponsor> (for herself, <cosponsor name-id="S382">Mr. Sasse</cosponsor>, and <cosponsor name-id="S363">Mr. King</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20221219">December 19, 2022</action-date><action-desc>Reported by <sponsor name-id="S380">Mr. Peters</sponsor>, with an amendment</action-desc><action-instruction>Strike out all after the enacting clause and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To amend the Homeland Security Act of 2002 to establish in the Cybersecurity and Infrastructure Security Agency the National Cyber Exercise Program, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="H47AEC7C1049F49DBA03C1F09B7E918B0"><section section-type="section-one" id="H018CA32923854021AEC558D815BD0725" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>CISA Cyber Exercise Act</short-title></quote>.</text></section><section id="H6F8322E7BEE34507896696776FCF91B7" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><enum>2.</enum><header>National Cyber Exercise Program</header><subsection id="HB671B9ECE5C648E6B787320A0DF76EC5"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following new section:</text><quoted-block style="OLC" display-inline="no-display-inline" id="HED0660C674E24CA8AC94E01207BAE837" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="H52A87D82E6734E8CB11C2E178C131B4D"><enum>2220A.</enum><header>National Cyber Exercise Program</header><subsection id="H7E87DEE075194FB68008263E8E3C9C19"><enum>(a)</enum><header>Establishment of program</header><paragraph id="H9AB5620DAC304A4DB546E738366DCF03"><enum>(1)</enum><header>In general</header><text>There is established in the Agency the National Cyber Exercise Program (referred to in this section as the <quote>Exercise Program</quote>) to evaluate the National Cyber Incident Response Plan, and other related plans and strategies.</text></paragraph><paragraph id="H0D64E5B3BD504228A00DAF9571F0B1BE"><enum>(2)</enum><header>Requirements</header><subparagraph id="H947BA2543B454982AA110662C469FE24"><enum>(A)</enum><header>In general</header><text>The Exercise Program shall be—</text><clause id="H2CFEDC2D99DA494A96DA760DF54E9789"><enum>(i)</enum><text>based on current risk assessments, including credible threats, vulnerabilities, and consequences;</text></clause><clause id="HAB60A2DB840A44EB86F30418588C6538"><enum>(ii)</enum><text>designed, to the extent practicable, to simulate the partial or complete incapacitation of a government or critical infrastructure network resulting from a cyber incident;</text></clause><clause id="H86C268DE901844B0B933DEEA2C8ACFD8"><enum>(iii)</enum><text>designed to provide for the systematic evaluation of cyber readiness and enhance operational understanding of the cyber incident response system and relevant information sharing agreements; and</text></clause><clause id="H8740BCDE67B64570872104D02985E5D8"><enum>(iv)</enum><text>designed to promptly develop after-action reports and plans that can quickly incorporate lessons learned into future operations.</text></clause></subparagraph><subparagraph id="HBFACCE892CDA4189AA751A93F377CB0D"><enum>(B)</enum><header>Model exercise selection</header><text>The Exercise Program shall—</text><clause id="HF675230B777049C0AF14ED1520F2718F"><enum>(i)</enum><text>include a selection of model exercises that government and private entities can readily adapt for use; and</text></clause><clause id="H9A026187B1FA423D847603EF744D29DA"><enum>(ii)</enum><text>aid such governments and private entities with the design, implementation, and evaluation of exercises that—</text><subclause id="HF72E875AE5894BA8847B6ADC4177F0F5"><enum>(I)</enum><text>conform to the requirements described in subparagraph (A);</text></subclause><subclause id="H62F47C6847294D05B18EC67570FD0B90"><enum>(II)</enum><text>are consistent with any applicable national, State, local, or Tribal strategy or plan; and</text></subclause><subclause id="H5E424E465E3B45F4AAF8DB1E621DEDC7"><enum>(III)</enum><text>provide for systematic evaluation of readiness.</text></subclause></clause></subparagraph></paragraph><paragraph id="HD1FF323680B848C588A608008B03B707"><enum>(3)</enum><header>Consultation</header><text>In carrying out the Exercise Program, the Director may consult with appropriate representatives from Sector Risk Management Agencies, the Office of the National Cyber Director, cybersecurity research stakeholders, and Sector Coordinating Councils.</text></paragraph></subsection><subsection id="HC3A9992D32DA4DA997DBE5945393E50F"><enum>(b)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H79DBFB80BFE84AA3A300902F6872FD1B"><enum>(1)</enum><header>State</header><text>The term <quote>State</quote> means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.</text></paragraph><paragraph id="H5DD1EEFA965644D58C322CD1876190FC"><enum>(2)</enum><header>Private entity</header><text>The term <quote>private entity</quote> has the meaning given such term in section 102 of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref>).</text></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="HDF87C61657224B78B8709F971AE39B0D"><enum>(b)</enum><header>Technical amendments</header><paragraph id="H827587AF44304ED9919F1E65CD744FD0"><enum>(1)</enum><header>Homeland Security Act of 2002</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended—</text><subparagraph id="H5C69A3F90CAC4ADCBD667421D6CD0145"><enum>(A)</enum><text display-inline="yes-display-inline">in the first section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665">6 U.S.C. 665</external-xref>; relating to the duties and authorities relating to .gov internet domain), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H6B41A6F5A8FB4733B10C911990AE81BE" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="H765526698C434B1FA515AA4BE2558E42"><enum>2215.</enum><header>Duties and authorities relating to .gov internet domain</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="H92DB4F4C423342D0AA2EC9CF9A7857CF"><enum>(B)</enum><text display-inline="yes-display-inline">in the second section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665b">6 U.S.C. 665b</external-xref>; relating to the joint cyber planning office), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H539C82161C084E34AA8876A0D7464B5E" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="H8650EC986606443387BE1FAE31646A2B"><enum>2216.</enum><header>Joint cyber planning office</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="H47EFE7CB7DDE4900BBE5E121F404103D"><enum>(C)</enum><text display-inline="yes-display-inline">in the third section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665c">6 U.S.C. 665c</external-xref>; relating to the Cybersecurity State Coordinator), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="HF59F5CD2C5EE4D21AE3B0928A7D09562" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="H619AE6B3250E4B1A9D2DB8A408746024"><enum>2217.</enum><header>Cybersecurity State Coordinator</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="H8B65C79EE82141AE84ECAE3B8C3A7E94"><enum>(D)</enum><text display-inline="yes-display-inline">in the fourth section 2215 (<external-xref legal-doc="usc" parsable-cite="usc/6/665d">6 U.S.C. 665d</external-xref>; relating to Sector Risk Management Agencies), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H5736EA42A06940B3818678B2EEFFEBDB" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="H4852F4F21A034AD6A13154D882D1250A"><enum>2218.</enum><header>Sector Risk Management Agencies</header></section><after-quoted-block>;</after-quoted-block></quoted-block></subparagraph><subparagraph id="HBFBF179E2CD9415FB2548F174272B0B2"><enum>(E)</enum><text display-inline="yes-display-inline">in section 2216 (<external-xref legal-doc="usc" parsable-cite="usc/6/665e">6 U.S.C. 665e</external-xref>; relating to the Cybersecurity Advisory Committee), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H7BF7CEA66CB04DDD9D85205344D1DF62"><section id="H2655EE4037BD4FE7ACBC9B9773644A36"><enum>2219.</enum><header>Cybersecurity Advisory Committee</header></section><after-quoted-block>;</after-quoted-block></quoted-block><continuation-text continuation-text-level="subparagraph">and</continuation-text></subparagraph><subparagraph id="H6A8BEF2BB2274340BE7AADB0E37F9D3A"><enum>(F)</enum><text display-inline="yes-display-inline">in section 2217 (<external-xref legal-doc="usc" parsable-cite="usc/6/665f">6 U.S.C. 665f</external-xref>; relating to Cybersecurity Education and Training Programs), by amending the section enumerator and heading to read as follows:</text><quoted-block style="OLC" display-inline="no-display-inline" id="H03896D0923594FD5BC7460294A531EB2" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><section id="HFD349506ED4A4BD2AD6C9F649A1103F8"><enum>2220.</enum><header>Cybersecurity Education and Training Programs</header></section><after-quoted-block>.</after-quoted-block></quoted-block></subparagraph></paragraph><paragraph id="H65195993C88E4DFCAA5F869A64CEAB92"><enum>(2)</enum><header>Consolidated Appropriations Act, 2021</header><text display-inline="yes-display-inline">Paragraph (1) of section 904(b) of division U of the Consolidated Appropriations Act, 2021 (<external-xref legal-doc="public-law" parsable-cite="pl/116/260">Public Law 116–260</external-xref>) is amended, in the matter preceding subparagraph (A), by inserting <quote>of 2002</quote> after <quote>Homeland Security Act</quote>. </text></paragraph></subsection><subsection id="HD3C1B9491EAD4C77A434E18383A9A673"><enum>(c)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by striking the items relating to sections 2214 through 2217 and inserting the following new items:</text><quoted-block style="OLC" display-inline="no-display-inline" id="HAC155358FA49498BAB9DD16995EF3D60" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc regeneration="no-regeneration" changed="deleted" reported-display-style="strikethrough" committee-id="SSGA00"><toc-entry level="section">Sec. 2214. National Asset Database. </toc-entry><toc-entry level="section">Sec. 2215. Duties and authorities relating to .gov internet domain. </toc-entry><toc-entry level="section">Sec. 2216. Joint cyber planning office. </toc-entry><toc-entry level="section">Sec. 2217. Cybersecurity State Coordinator. </toc-entry><toc-entry level="section">Sec. 2218. Sector Risk Management Agencies. </toc-entry><toc-entry level="section">Sec. 2219. Cybersecurity Advisory Committee. </toc-entry><toc-entry level="section">Sec. 2220. Cybersecurity Education and Training Programs. </toc-entry><toc-entry level="section">Sec. 2220A. National Cyber Exercise Program.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body><legis-body display-enacting-clause="no-display-enacting-clause"><section section-type="section-one" id="id81a7fb2a-7693-4601-900c-dc44491c5353" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>CISA Cyber Exercise Act</short-title></quote>.</text></section><section id="ida299dbe4-bfb9-4302-950d-85669f6113c8" changed="added" reported-display-style="italic" committee-id="SSGA00"><enum>2.</enum><header>National Cyber Exercise Program</header><subsection id="idffe95bbc-c2cd-4e0a-a8ec-a53a6f6abc6b"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following new section:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id36af4467-ca7a-4486-a49b-4f7de0998e91" changed="added" reported-display-style="italic" committee-id="SSGA00"><section id="id3b0ea1ca-0eda-49c7-a686-b66d4e44ffcc"><enum>2220A.</enum><header>National Cyber Exercise Program</header><subsection id="id7ba0c5c8-eb19-4192-879b-299d2003f06b"><enum>(a)</enum><header>Establishment of program</header><paragraph id="id5c419340-aecf-4f1a-80a6-5cf8ce636cfb"><enum>(1)</enum><header>In general</header><text>There is established in the Agency the National Cyber Exercise Program (referred to in this section as the <quote>Exercise Program</quote>) to evaluate the National Cyber Incident Response Plan, and other related plans and strategies.</text></paragraph><paragraph id="id27e6f85f-f69b-43a5-b0f8-1d4fe1cc2f08"><enum>(2)</enum><header>Requirements</header><subparagraph id="id3317a1b6-1a96-4960-abe4-afab1650e77b"><enum>(A)</enum><header>In general</header><text>The Exercise Program shall be—</text><clause id="idab0dd417-735c-4f9b-ab07-f3868fe30c2e"><enum>(i)</enum><text>based on current risk assessments, including credible threats, vulnerabilities, and consequences;</text></clause><clause id="idc0329939-46a5-485a-b4f3-f3446e0f7788"><enum>(ii)</enum><text>designed, to the extent practicable, to simulate the partial or complete incapacitation of a government or critical infrastructure network resulting from a cyber incident;</text></clause><clause id="id4bed23de-f791-490d-aa7e-fc0bb3fcc27d"><enum>(iii)</enum><text>designed to provide for the systematic evaluation of cyber readiness and enhance operational understanding of the cyber incident response system and relevant information sharing agreements; and</text></clause><clause id="idccc67acf-3657-46b3-8b69-e3c23735d63f"><enum>(iv)</enum><text>designed to promptly develop after-action reports and plans that can quickly incorporate lessons learned into future operations.</text></clause></subparagraph><subparagraph id="idec1bd7ac-59cc-4a6c-8c25-a3fed9dae734"><enum>(B)</enum><header>Model exercise selection</header><text>The Exercise Program shall—</text><clause id="id3e6a86ff-1d98-4a64-ad8c-a0b304dec65a"><enum>(i)</enum><text>include a selection of model exercises that government and private entities can readily adapt for use; and</text></clause><clause id="id719d8b18-dc43-4aad-8f9a-248bce151631"><enum>(ii)</enum><text>aid such governments and private entities with the design, implementation, and evaluation of exercises that—</text><subclause id="id0375a727-46bd-4d6f-811c-b60c8638f45b"><enum>(I)</enum><text>conform to the requirements described in subparagraph (A);</text></subclause><subclause id="id290691fa-1dcc-47f2-a1e5-549ce688d635"><enum>(II)</enum><text>are consistent with any applicable national, State, local, or Tribal strategy or plan; and</text></subclause><subclause id="id87ee9339-2dd0-43fa-9add-f7f8d62451db"><enum>(III)</enum><text>provide for systematic evaluation of readiness.</text></subclause></clause></subparagraph></paragraph><paragraph id="ida9d26ca4-bd56-4bcb-bdaf-24b0d5660319"><enum>(3)</enum><header>Consultation</header><text>In carrying out the Exercise Program, the Director may consult with appropriate representatives from Sector Risk Management Agencies, the Office of the National Cyber Director, cybersecurity research stakeholders, and Sector Coordinating Councils.</text></paragraph></subsection><subsection id="id6e0aea43-f014-40c3-8906-3eb209cef047"><enum>(b)</enum><header>Definitions</header><text>In this section:</text><paragraph id="idfa06371e-69ae-404c-9052-0f09fa777ea3"><enum>(1)</enum><header>State</header><text>The term <quote>State</quote> means any State of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the Northern Mariana Islands, the United States Virgin Islands, Guam, American Samoa, and any other territory or possession of the United States.</text></paragraph><paragraph id="id7868168d-8874-42e5-87e2-fe102a50135b"><enum>(2)</enum><header>Private entity</header><text>The term <quote>private entity</quote> has the meaning given such term in section 102 of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref>).</text></paragraph></subsection><subsection id="idba790facd1c44fb4988143c6c75d0760"><enum>(c)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to affect the authority or responsibilities of the Administrator of the Federal Emergency Management Agency pursuant to section 648 of the Post-Katrina Emergency Management Reform Act of 2006 (<external-xref legal-doc="usc" parsable-cite="usc/6/748">6 U.S.C. 748</external-xref>). </text></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="idc7f815ac-bf53-47d6-8424-a23f7da06973"><enum>(b)</enum><header>Clerical amendment</header><text display-inline="yes-display-inline">The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 2217 the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id324acfe3-0183-4e74-8796-01feab91cfe3" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc regeneration="no-regeneration" changed="added" reported-display-style="italic" committee-id="SSGA00"><toc-entry level="section">Sec. 2220A. National Cyber Exercise Program.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body><endorsement><action-date date="20221219">December 19, 2022</action-date><action-desc>Reported with an amendment</action-desc></endorsement></bill> 

