<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-DUN22044-9JD-H7-H68"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>117 S3511 IS: Satellite Cybersecurity Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2022-01-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>117th CONGRESS</congress><session>2d Session</session><legis-num>S. 3511</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20220113" legis-day="20220110">January 13 (legislative day, January 10), 2022</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself and <cosponsor name-id="S287">Mr. Cornyn</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require a report on Federal support to the cybersecurity of commercial satellite systems, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Satellite Cybersecurity Act</short-title></quote>.</text></section><section id="id27e67882fb714dbbbcc09a6e923bf6ac"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id17a7cf2a3f8049c386897529f80c6fcd"><enum>(1)</enum><header>Commercial satellite system</header><text>The term <term>commercial satellite system</term> means an earth satellite owned and operated by a non-Federal entity.</text></paragraph><paragraph id="idCB37F0456D79410BA532AF1DBB3A8C0C"><enum>(2)</enum><header>Critical infrastructure</header><text>The term <term>critical infrastructure</term> has the meaning given the term in subsection (e) of the Critical Infrastructure Protection Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c(e)</external-xref>).</text></paragraph><paragraph commented="no" id="idF96BCED1C24C43AA8E7B79A023EA63F1"><enum>(3)</enum><header>Cybersecurity risk</header><text>The term <term>cybersecurity risk</term> has the meaning given the term in section 2209 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/659">6 U.S.C. 659</external-xref>). </text></paragraph><paragraph id="id61a857eb38874eb49d9b3a23271a8899"><enum>(4)</enum><header>Cybersecurity threat</header><text>The term <term>cybersecurity threat</term> has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (<external-xref legal-doc="usc" parsable-cite="usc/6/1501">6 U.S.C. 1501</external-xref>).</text></paragraph></section><section id="idaf6963ea9ab04641a58a4f7dfdd36d77"><enum>3.</enum><header>Report on commercial satellite cybersecurity</header><subsection id="ide145bb7f93dd49c9894e52e02f1354fc"><enum>(a)</enum><header>Study</header><text>The Comptroller General of the United States shall conduct a study on the actions the Federal Government has taken to support the cybersecurity of commercial satellite systems, including as part of any action to address the cybersecurity of critical infrastructure sectors.</text></subsection><subsection id="id781c1f4eb4384ea4883cdf96201af4fd"><enum>(b)</enum><header>Report</header><text>Not later than 1 year after the date of enactment of this Act, the Comptroller General of the United States shall report to Congress on the study conducted under subsection (a), which shall include information on—</text><paragraph id="id68b647a788fb497a9e649f1840d9463b"><enum>(1)</enum><text>the effectiveness of efforts of the Federal Government in improving the cybersecurity of commercial satellite systems;</text></paragraph><paragraph id="ide7a407f55f65462d8734d099e7b60625"><enum>(2)</enum><text>the resources made available to the public by Federal agencies to address cybersecurity threats to commercial satellite systems;</text></paragraph><paragraph id="id0dffc564a5ba4caaa9b6242c4a97b452"><enum>(3)</enum><text>the extent to which commercial satellite systems are reliant on or are relied on by critical infrastructure and an analysis of how commercial satellite systems, and the threats to such systems, are integrated into Federal and non-Federal critical infrastructure risk analyses and protection plans;</text></paragraph><paragraph id="idd35a70dbcdeb46a6b5a065ce61d5c743"><enum>(4)</enum><text>the extent to which Federal agencies are reliant on commercial satellite systems and how Federal agencies mitigate cybersecurity risks associated with those systems; and</text></paragraph><paragraph id="idd0b48784fd5148e3bce3460845f4f52a"><enum>(5)</enum><text>the extent to which Federal agencies coordinate or duplicate authorities and take other actions focused on the cybersecurity of commercial satellite systems.</text></paragraph></subsection><subsection id="idb9088c0374f84dc3a2560505ad28797a"><enum>(c)</enum><header>Consultation</header><text>In carrying out subsections (a) and (b), the Comptroller General of the United States shall coordinate with—</text><paragraph id="idbe0a54efecbd422c91b3d4ed7f4b8d59"><enum>(1)</enum><text>the Secretary of Homeland Security;</text></paragraph><paragraph id="ida7a648b5092145ffa8c523bf4bf4fb16"><enum>(2)</enum><text>the Director of the National Institute of Standards and Technology;</text></paragraph><paragraph id="id2fcbae1b45cc469f8be8f9617fff274c"><enum>(3)</enum><text>the Secretary of Defense;</text></paragraph><paragraph id="id84ebb504d30c4f289b9a5e0c11c5216b"><enum>(4)</enum><text>the Federal Communications Commission;</text></paragraph><paragraph id="idfcf9f615be73425da53c691e886a93a9"><enum>(5)</enum><text>the National Oceanic and Atmospheric Administration;</text></paragraph><paragraph id="idF9D147980EBD4D8BA81F9665A6798BE6"><enum>(6)</enum><text>the National Aeronautics and Space Administration;</text></paragraph><paragraph id="id499e7c111e7b45079b5ccd9815bf4f4c"><enum>(7)</enum><text>the Federal Aviation Administration; and</text></paragraph><paragraph id="id2043fa68cd234654b5cf8ad4e26910e0"><enum>(8)</enum><text>the head of any other Federal agency determined appropriate by the Comptroller General of the United States.</text></paragraph></subsection></section><section id="ida5b2238578264da9be48fb79c75c96d4"><enum>4.</enum><header>Responsibilities of the Cybersecurity and Infrastructure Security Agency</header><subsection id="id6d553794239146e8873d010bbb9f8954"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="iddbccd79150714840a0988f8ffe2db220"><enum>(1)</enum><header>Clearinghouse</header><text>The term <term>clearinghouse</term> means the commercial satellite system cybersecurity clearinghouse required to be developed and maintained under subsection (b)(1).</text></paragraph><paragraph id="idf85237bec0534f078cf90236014d9812"><enum>(2)</enum><header>Director</header><text>The term <term>Director</term> means the Director of the Cybersecurity and Infrastructure Security Agency.</text></paragraph><paragraph id="id73ee8acd020944ad922b5c5bb8a22dcd"><enum>(3)</enum><header>Small business concern</header><text>The term <term>small business concern</term> has the meaning given the term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></paragraph></subsection><subsection id="id3c6211ad2bab4769be7f8502e83a9ab0"><enum>(b)</enum><header>Establishment of commercial satellite system cybersecurity clearinghouse</header><paragraph id="id479adca315d34d46bd19c6799fb7cbcf"><enum>(1)</enum><header>In general</header><text>Not later than 180 days after the date of enactment of this Act, the Director shall develop and maintain a commercial satellite system cybersecurity clearinghouse.</text></paragraph><paragraph id="id0958396b6b264e698111e71a6a2a0454"><enum>(2)</enum><header>Requirements</header><text>The clearinghouse shall—</text><subparagraph id="id1cac4c39d653439b84144c68f28fdba0"><enum>(A)</enum><text>be publicly available online;</text></subparagraph><subparagraph id="idd747173c34aa4453ae224779ce25b167"><enum>(B)</enum><text>contain publicly available commercial satellite system cybersecurity resources, including the recommendations developed under subsection (c), and any other materials developed by entities in the Federal Government, for reference by entities that develop commercial satellite systems; and</text></subparagraph><subparagraph id="id8ecce0dfb0754913a0022922dbcd26c4"><enum>(C)</enum><text>include materials specifically aimed at assisting small business concerns with the secure development, operation, and maintenance of commercial satellite systems.</text></subparagraph></paragraph><paragraph id="id498e299029cc4149a3df841fc65dc9bc"><enum>(3)</enum><header>Content maintenance</header><text>The Director shall maintain current and relevant cybersecurity information on the clearinghouse.</text></paragraph><paragraph id="idc52b17baf46e42fea6db825e4ead32b0"><enum>(4)</enum><header>Existing platform or website</header><text>The Director may establish and maintain the clearinghouse on an online platform or a website that is in existence as of the date of enactment of this Act.</text></paragraph></subsection><subsection id="id19261a87546c4b988cbfa4db9ec194d2"><enum>(c)</enum><header>Development of commercial satellite system cybersecurity recommendations</header><paragraph id="idc0b1ebbb3778426d8df82846de7aebed"><enum>(1)</enum><header>In general</header><text>The Director shall develop voluntary cybersecurity recommendations designed to assist in the development, maintenance, and operation of commercial satellite systems.</text></paragraph><paragraph id="id1d384dbfba9a4ed3b6e6e8f113fede56"><enum>(2)</enum><header>Requirements</header><text>The recommendations required under paragraph (1) shall include materials addressing the following:</text><subparagraph id="idf934cb82fb0e461987441e150253f239"><enum>(A)</enum><text>Risk-based, cybersecurity-informed engineering, including continuous monitoring and resiliency.</text></subparagraph><subparagraph id="id6c6f6afa01b34c928fb5f0ee7398a265"><enum>(B)</enum><text>Planning for retention or recovery of positive control of commercial satellite systems in the event of a cybersecurity incident.</text></subparagraph><subparagraph id="idd3e0c1061f264eb1aec2fa9454137299"><enum>(C)</enum><text>Protection against unauthorized access to vital commercial satellite system functions.</text></subparagraph><subparagraph id="ide335595a0d9344cb880284fe33712d19"><enum>(D)</enum><text>Physical protection measures designed to reduce the vulnerabilities of a commercial satellite system’s command, control, and telemetry receiver systems.</text></subparagraph><subparagraph id="idce629887fcc44a5aa2e62bed67c3d09d"><enum>(E)</enum><text>Protection against communications jamming and spoofing.</text></subparagraph><subparagraph id="id311D662F69BA41A3A40F85B51A8EB12E"><enum>(F)</enum><text>Security against threats throughout a commercial satellite system’s mission lifetime.</text></subparagraph><subparagraph id="id0b675c68ad5f42d9972493d186eb8460"><enum>(G)</enum><text>Management of supply chain risks that affect cybersecurity of commercial satellite systems.</text></subparagraph><subparagraph id="id0E5321D9DEDC4DD78055D0D63BC45C5E"><enum>(H)</enum><text>As appropriate, the findings and recommendations from the study conducted by the Comptroller General of the United States under section 3(a).</text></subparagraph><subparagraph id="id749d1411291a44b49b2ac0586964d311"><enum>(I)</enum><text>Any other recommendations to ensure the confidentiality, availability, and integrity of data residing on or in transit through commercial satellite systems.</text></subparagraph></paragraph></subsection><subsection id="id1290d1f773fb4d0283c099206f5e51e9"><enum>(d)</enum><header>Consultation</header><text>With respect to the collation and development of clearinghouse content under subsection (b)(2) and the recommendations developed pursuant to subsection (c), the Director shall consult with—</text><paragraph id="id5DCAC3BF29784E2DBF6432E9BD82DED4"><enum>(1)</enum><text>the heads of appropriate Federal agencies with expertise and experience in satellite operations; and</text></paragraph><paragraph id="id1B09970E2C584E8FB3057B3789101496"><enum>(2)</enum><text>non-Federal entities developing commercial satellite systems or otherwise supporting the cybersecurity of commercial satellite systems.</text></paragraph></subsection></section></legis-body></bill> 

