<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-LEW23186-RJ7-V3-8KS"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>107 S1835 IS: National Cybersecurity Awareness Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-06-06</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 1835</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230606">June 6, 2023</action-date><action-desc><sponsor name-id="S380">Mr. Peters</sponsor> (for himself and <cosponsor name-id="S373">Mr. Cassidy</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security to develop a campaign program to raise awareness regarding the importance of cybersecurity in the United States.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>National Cybersecurity Awareness Act</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="id624303ef8fe741e49370f392c030ba16"><enum>2.</enum><header>Findings</header><text display-inline="no-display-inline">Congress finds the following:</text><paragraph id="idf56e65b521504b678c78cb1b58f547a6"><enum>(1)</enum><text>The presence of ubiquitous internet-connected devices in the everyday lives of citizens of the United States has created opportunities for constant connection and modernization.</text></paragraph><paragraph id="id5e7b4135a8b2402eb9b95f61489bf875"><enum>(2)</enum><text>A connected society is subject to cybersecurity threats that can compromise even the most personal and sensitive of information.</text></paragraph><paragraph id="id0e9ba9398c8d4e1fac89de6fff0ff4a4"><enum>(3)</enum><text>Connected critical infrastructure is subject to cybersecurity threats that can compromise fundamental economic and health and safety functions.</text></paragraph><paragraph id="ida250570bfc504a77b0698c631cf87b67"><enum>(4)</enum><text>The Government of the United States plays an important role in safeguarding the nation from malicious cyber activity.</text></paragraph><paragraph id="id92bb48b9509d4a8d9f67fb350e7600b9"><enum>(5)</enum><text>A citizenry that is knowledgeable regarding cybersecurity is critical to building a robust cybersecurity posture and reducing the threat of cyber attackers stealing sensitive information and causing public harm.</text></paragraph><paragraph id="id3de31ffa70be4900aedab9ac75416ae3"><enum>(6)</enum><text>While Cybersecurity Awareness Month is critical to supporting national cybersecurity awareness, it cannot be a once-a-year activity and must be a sustained, constant effort. </text></paragraph></section><section id="id4daa0357161f49e8b8b68f7fe6e6368f"><enum>3.</enum><header>Cybersecurity awareness</header><subsection commented="no" display-inline="no-display-inline" id="ida26b016b659c41e19c1f8265385d2aa2"><enum>(a)</enum><header>In general</header><text>Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following: </text><quoted-block style="OLC" display-inline="no-display-inline" id="id4EDE34650DF94A4686D5932D3EAF6AB4"><section id="idDDBB6EEA98F249C4BFA09D10EC71ED94" section-type="subsequent-section"><enum>2220F.</enum><header>Cybersecurity Awareness Campaigns</header><subsection commented="no" display-inline="no-display-inline" id="id31a32cc33453459383a62b8bd4334743"><enum>(a)</enum><header display-inline="yes-display-inline">Definition</header><text display-inline="yes-display-inline">In this section, the term <quote>Campaign Program</quote> means the campaign program established under subsection (b).</text></subsection><subsection id="ide8da9c5ac614464bb8347238762d0e42"><enum>(b)</enum><header>Awareness Campaign Program</header><paragraph commented="no" display-inline="no-display-inline" id="id968810ae989144dcb9e9dc523ff0966c"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 90 days after the date of enactment of the <short-title>National Cybersecurity Awareness Act</short-title>, the Director shall establish a program for planning and coordinating Federal cybersecurity awareness campaigns.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id98620dc4cc4f4b48a0f3eaeab068c26b"><enum>(2)</enum><header>Activities</header><text>In carrying out the Campaign Program, the Director shall—</text><subparagraph id="idfe7f5aae6ad84de2b3f1ffef4dd2ed36"><enum>(A)</enum><text>inform non-Federal entities of voluntary cyber hygiene best practices, including information on how to—</text><clause commented="no" display-inline="no-display-inline" id="idf846e94188454406b8de1ddb84c6daa6"><enum>(i)</enum><text display-inline="yes-display-inline">prevent cyberattacks; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id7252083f17fd49bd82da6e2e1fd8de81"><enum>(ii)</enum><text>mitigate cybersecurity risks; and</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idfe9c4a0f04c54515b972ebdc852d6aa4"><enum>(B)</enum><text display-inline="yes-display-inline">consult with private sector entities, State, local, Tribal, and territorial governments, academia, and civil society—</text><clause commented="no" display-inline="no-display-inline" id="idcd885f071fff4e73b25c8a8c7d6878d4"><enum>(i)</enum><text display-inline="yes-display-inline">to promote cyber hygiene best practices, including by focusing on tactics that are cost effective and result in significant cybersecurity improvement, such as—</text><subclause commented="no" display-inline="no-display-inline" id="idfe49c9c9eab74cc09f08eb6f7715380a"><enum>(I)</enum><text display-inline="yes-display-inline">maintaining strong passwords and the use of password managers;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id32a6dd73e1244fb093faf104aca9af1b"><enum>(II)</enum><text display-inline="yes-display-inline">enabling multi-factor authentication, including phishing-resistant multi-factor authentication;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id1f88d701e0c043608605a110add40ffc"><enum>(III)</enum><text display-inline="yes-display-inline">regularly installing software updates;</text></subclause><subclause commented="no" display-inline="no-display-inline" id="id50c4a2364a5c42a8929583764985380c"><enum>(IV)</enum><text display-inline="yes-display-inline">using caution with email attachments and website links; and</text></subclause><subclause commented="no" display-inline="no-display-inline" id="idcccbfe60a2d948f892b56983326f4252"><enum>(V)</enum><text display-inline="yes-display-inline">other cyber hygienic considerations, as appropriate;</text></subclause></clause><clause id="id0e657c8f390e484298578bfa0f608e89"><enum>(ii)</enum><text>to promote awareness of cybersecurity risks and mitigation with respect to malicious applications on internet-connected devices, including applications to control those devices or use devices for unauthorized surveillance of users; </text></clause><clause id="id73c361ff56814603a02e25cb5bd55052"><enum>(iii)</enum><text>to help consumers identify products that are designed to support user and product security, such as products designed using the Secure-by-Design and Secure-by-Default principles of the Agency; </text></clause><clause id="id5f088314db7c43d9b32fcc96b6ad9871"><enum>(iv)</enum><text>to coordinate with other Federal agencies and departments, as determined appropriate by the Director, to—</text><subclause id="ide28a1990de1c42c1a88c1e3a02f4307f"><enum>(I)</enum><text>promote relevant cybersecurity-related awareness activities; and</text></subclause><subclause id="id10f3eaf7a14140d4b20e75d0b580308f"><enum>(II)</enum><text>ensure the Federal Government is coordinated in communicating accurate and timely cybersecurity information; and</text></subclause></clause><clause id="ided0c04aee81541979c5895557b444199"><enum>(v)</enum><text>to expand nontraditional outreach mechanisms to ensure that entities including low-income and rural communities, small and medium sized businesses and institutions, and State, local, Tribal, and territorial partners receive cybersecurity awareness outreach in an equitable manner.</text></clause></subparagraph></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id6c89d83e380841b38d20ab9050e12eda"><enum>(3)</enum><header>Reporting</header><subparagraph commented="no" display-inline="no-display-inline" id="id56581357a2ee4f248fdd9afddd80e9e3"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of enactment of the <short-title>National Cybersecurity Awareness Act</short-title>, and annually thereafter, the Director shall, in consultation with the heads of appropriate Federal agencies, submit to the appropriate congressional committees a report regarding the Campaign Program. </text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id369ece03d1fc4a268a98c7eace6b80e4"><enum>(B)</enum><header>Contents</header><text>Each report submitted pursuant to subparagraph (A) shall include—</text><clause id="id33826730cc764e5e89708c262c8536b7"><enum>(i)</enum><text>a summary of the activities of the Agency that support promoting cybersecurity awareness under the Campaign Program, including consultations made under paragraph (2)(B);</text></clause><clause id="id948345593cd74792a71d7e7e64e2e766"><enum>(ii)</enum><text>an assessment of the effectiveness of techniques and methods used to promote national cybersecurity awareness under the Campaign Program; and</text></clause><clause id="id7f04f2cb7a33428992a2ad75061e8946"><enum>(iii)</enum><text>recommendations on how to best promote cybersecurity awareness nationally.</text></clause></subparagraph></paragraph></subsection><subsection commented="no" display-inline="no-display-inline" id="id05373ebd90824bc0ada6a0257a4f9952"><enum>(c)</enum><header>Cybersecurity campaign resources</header><paragraph commented="no" display-inline="no-display-inline" id="idd177c563880748f7b17fe11bea3f0af0"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of enactment of the <short-title>National Cybersecurity Awareness Act</short-title>, the Director shall develop and maintain a central repository for the resources, tools, and public communications of the Agency that promote cybersecurity awareness.</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id4f91681214f04ac18ca003a13aefe590"><enum>(2)</enum><header>Requirements</header><text display-inline="yes-display-inline">The resources described in paragraph (1) shall be—</text><subparagraph commented="no" display-inline="no-display-inline" id="iddfba13d0e01f453bb73554eb92a8eb52"><enum>(A)</enum><text display-inline="yes-display-inline">made publicly available online; and</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idee01c4009c8e46a8bf97db70b8a0c9d8"><enum>(B)</enum><text display-inline="yes-display-inline">regularly updated to ensure the public has access to relevant and timely cybersecurity awareness information.</text></subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection commented="no" display-inline="no-display-inline" id="id0b1e837855784f85af16be7c5abecc03"><enum>(b)</enum><header>Responsibilities of the Cybersecurity and Infrastructure Security Agency</header><text>Section 2202(c) of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/652">6 U.S.C. 652(c)</external-xref>) is amended—</text><paragraph commented="no" display-inline="no-display-inline" id="id567b3b6d2e22401fb0a807c60a119d4d"><enum>(1)</enum><text display-inline="yes-display-inline">in paragraph (13), by striking <quote>; and</quote> and inserting a semicolon;</text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="ide5aefb36a0b042439f9ce745b8ea048a"><enum>(2)</enum><text>by redesignating paragraph (14) as paragraph (15); and</text></paragraph><paragraph id="ide5f7d1d4c8d4422daebd6464780d7dd2"><enum>(3)</enum><text>by inserting after paragraph (13) the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id8F876F57C8444B01BCAA4511578ECDDA"><paragraph commented="no" display-inline="no-display-inline" id="ide8aacaee6bc743d582ea1b787c173821"><enum>(14)</enum><text>lead and coordinate Federal efforts to promote national cybersecurity awareness; and</text></paragraph><after-quoted-block>.</after-quoted-block></quoted-block></paragraph></subsection><subsection id="idc56457d1e63541d48fd30d387101ff91"><enum>(c)</enum><header>Clerical amendment</header><text>The table of contents in section 1(b) of the Homeland Security Act of 2002 (<external-xref legal-doc="public-law" parsable-cite="pl/107/296">Public Law 107–296</external-xref>; 116 Stat. 2135) is amended by inserting after the item relating to section 2220E the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id083D95F2A4BE4E7A9969CD3156086A49"><toc><toc-entry level="section" bold="off">Sec. 2220F. Cybersecurity awareness campaigns</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body></bill> 

