<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-type="olc" bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-OLL23696-H6J-WW-XL2"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S2393 IS: Food and Agriculture Industry Cybersecurity Support Act</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-07-19</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 2393</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230719">July 19, 2023</action-date><action-desc><sponsor name-id="S381">Mr. Rounds</sponsor> (for himself and <cosponsor name-id="S385">Ms. Cortez Masto</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To establish a food and agriculture cybersecurity clearinghouse in the National Telecommunications and Information Administration, and for other purposes.</official-title></form><legis-body style="OLC" display-enacting-clause="yes-display-enacting-clause" id="HDACA20DA6F6A4EEEA335FC2B7233ADDE"><section section-type="section-one" id="H2E2E79E222F840D7BC36BB06FB968880"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Food and Agriculture Industry Cybersecurity Support Act</short-title></quote>.</text></section><section id="H99B6D62AFC524347ACAE2AD28A3642BD"><enum>2.</enum><header>NTIA food and agriculture cybersecurity clearinghouse</header><subsection id="H554E295FAE5F45808755F06F17339441"><enum>(a)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H10967C2475E74A8D8C8F020217156A43"><enum>(1)</enum><header>Assistant Secretary</header><text>The term <term>Assistant Secretary</term> means the Assistant Secretary of Commerce for Communications and Information.</text></paragraph><paragraph id="HF1EB0C4CE3624215B6C35533EF7E6D00"><enum>(2)</enum><header>Cybersecurity risk</header><text>The term <term>cybersecurity risk</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H193ABDC63B4246C8A8C1EC479B9F357B"><enum>(3)</enum><header>Cybersecurity threat</header><text display-inline="yes-display-inline">The term <term>cybersecurity threat</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H173D89DACBE140C0A9BBEEAC38CD7134"><enum>(4)</enum><header>Food and agriculture industry</header><text>The term <term>food and agriculture industry</term> means—</text><subparagraph id="H697A6F010E714B1682DD2688C3917FFB"><enum>(A)</enum><text>equipment and systems utilized in the food and agriculture supply chain, such as computer vision algorithms for precision agriculture, grain silos, and related food and agriculture storage infrastructure;</text></subparagraph><subparagraph id="HEB33F5CEB0E64766AD29BA942BEC2358"><enum>(B)</enum><text>food and agriculture goods processors, growers, and distributors; and</text></subparagraph><subparagraph id="H732A3A537B0F45BDA25D39FB339F5FE5"><enum>(C)</enum><text>information technology systems of businesses engaged in farming, ranching, planting, harvesting, food and agriculture product storage, food or animal genetic modification, the design or production of agrochemicals, or the design or production of food and agriculture tools.</text></subparagraph></paragraph><paragraph id="H1B7E3E3C18504E86BF5618E11833F0AC"><enum>(5)</enum><header>Incident</header><text display-inline="yes-display-inline">The term <term>incident</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H2439945D64F746FC8D36C65D8EA8B0C7"><enum>(6)</enum><header>NTIA</header><text>The term <term>NTIA</term> means the National Telecommunications and Information Administration.</text></paragraph><paragraph id="H035F7C81588F40EABE51FF1935964F93"><enum>(7)</enum><header>Sector Risk Management Agency</header><text display-inline="yes-display-inline">The term <term>Sector Risk Management Agency</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="H6DAAEA3A016E4065A70E6C037BCCE4B8"><enum>(8)</enum><header>Security vulnerability</header><text display-inline="yes-display-inline">The term <term>security vulnerability</term> has the meaning given the term in section 2200 of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/650">6 U.S.C. 650</external-xref>).</text></paragraph><paragraph id="HD43C68054C8D46AF94C28284A78AE883"><enum>(9)</enum><header>Small business concern</header><text>The term <term>small business concern</term> has the meaning given the term in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></paragraph><paragraph id="H6261FA3E14774098B873EAA1E68048CE" commented="no" display-inline="no-display-inline"><enum>(10)</enum><header>Software bill of materials</header><text>The term <term>software bill of materials</term> has the meaning given the term in section 10 of Executive Order 14028 (86 Fed. Reg. 26633; relating to improving the nation’s cybersecurity).</text></paragraph></subsection><subsection id="HADC2D0A8141647509E2691FD3F5811ED"><enum>(b)</enum><header>NTIA food and agriculture cybersecurity clearinghouse</header><paragraph id="HB03BED64731F452D926C9846199D18AE"><enum>(1)</enum><header>Establishment</header><subparagraph id="H84EC6575431C4D1FAA8CE9E769FBD364"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than 180 days after the date of enactment of this Act, the Assistant Secretary shall establish in the NTIA a food and agriculture cybersecurity clearinghouse (in this section referred to as the <quote>clearinghouse</quote>).</text></subparagraph><subparagraph id="HE9C44D67843243559170E2A8BDE3A787"><enum>(B)</enum><header>Requirements</header><text>The clearinghouse shall—</text><clause id="H73FF7A453D9448A5A5453D1CC6D8F9C2"><enum>(i)</enum><text>be publicly available online;</text></clause><clause commented="no" id="HE6F8147CA42D490DBADA409AF9B0D9D2"><enum>(ii)</enum><text display-inline="yes-display-inline">contain current, relevant, and publicly available cybersecurity resources focused on the food and agriculture industry, including the recommendations described in paragraph (2), and any other appropriate materials for reference by entities that develop products with potential security vulnerabilities for the food and agriculture industry;</text></clause><clause commented="no" id="HF48CB3D3D45545B2B8E26C0FF8485E93"><enum>(iii)</enum><text>contain a mechanism for individuals or entities in the food and agriculture industry to request in-person or virtual support from the NTIA for cybersecurity related issues;</text></clause><clause id="HF02940CE54714853BB7BE265CCEF0B94"><enum>(iv)</enum><text display-inline="yes-display-inline">contain a section, updated not less frequently than annually, with answers to the top 20 most frequently asked questions relevant to the cybersecurity of the food and agriculture industry; and</text></clause><clause commented="no" id="HDE5AC101A9444F2A813B8D0CC0A5FE39"><enum>(v)</enum><text display-inline="yes-display-inline">include materials specifically aimed at assisting small business concerns and non-technical users in the food and agriculture industry with critical cybersecurity protections related to the food and agriculture industry, including recommendations on how to respond to a ransomware attack and resources for additional information, including the <quote>Stop Ransomware</quote> website hosted by the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security.</text></clause></subparagraph><subparagraph id="HFFC1F7E506344BB998DA6B7D88931EB7"><enum>(C)</enum><header>Existing platform or website</header><text>The Assistant Secretary may establish the clearinghouse on an online platform or a website that is in existence as of the date of enactment of this Act.</text></subparagraph></paragraph><paragraph id="HE212B770BF78485C82A9463E23663335"><enum>(2)</enum><header>Consolidation of food and agriculture industry cybersecurity recommendations</header><subparagraph commented="no" id="H29960D8709D64CE7963F67E8EB64CD79"><enum>(A)</enum><header>In general</header><text display-inline="yes-display-inline">The Assistant Secretary, in consultation with the Administrator of the Farm Service Agency of the Department of Agriculture and relevant Sector Risk Management Agencies, shall consolidate public and private sector best practices to produce a set of voluntary cybersecurity recommendations relating to the development, maintenance, and operation of the food and agriculture industry.</text></subparagraph><subparagraph id="H565BA4DD32494800B8B48AF8ADE1570F"><enum>(B)</enum><header>Requirements</header><text>The recommendations consolidated under subparagraph (A) shall include, to the greatest extent practicable, materials addressing the following:</text><clause id="H8D426385971F4360A8A1981055C6A9E5"><enum>(i)</enum><text>Risk-based, cybersecurity-informed engineering, including continuous monitoring and resiliency.</text></clause><clause commented="no" id="H18B3825012A44DBC9E421164FA71270C"><enum>(ii)</enum><text display-inline="yes-display-inline">Planning for retention or recovery of positive control of systems in the food and agriculture industry in the event of a cybersecurity incident.</text></clause><clause commented="no" id="HEE67378EA04C459889CACD00F4B68500"><enum>(iii)</enum><text display-inline="yes-display-inline">Protection against unauthorized access to critical functions of the food and agriculture industry.</text></clause><clause commented="no" id="H62D93B83D98E42B29FADCE513AD41569"><enum>(iv)</enum><text display-inline="yes-display-inline">Cybersecurity against threats to products of the food and agriculture industry throughout the lifetimes of those products.</text></clause><clause id="HB9EE04D5B6D14F27B1712162914F72B3"><enum>(v)</enum><text display-inline="yes-display-inline">How businesses in the food and agriculture industry should respond to ransomware attacks, including details on the legal obligations of those businesses in the event of such an attack, including reporting requirements and Federal resources for support.</text></clause><clause commented="no" id="H18BC7C5C1E354FC8A4FF5DE821DE12EF"><enum>(vi)</enum><text>Any other recommendations to ensure the confidentiality, availability, and integrity of data residing on or in transit through systems in the food and agriculture industry.</text></clause></subparagraph></paragraph><paragraph id="HDD068B4338424DC28CB4EE7D9691CA95"><enum>(3)</enum><header>Implementation</header><text>In implementing this subsection, the Assistant Secretary shall—</text><subparagraph commented="no" id="H211ABDEE520A4798B785EC51B5E98DBD"><enum>(A)</enum><text>to the extent practicable, consult with the private sector; </text></subparagraph><subparagraph commented="no" id="H716CE9911E794D46855F65410DB30678"><enum>(B)</enum><text>consult with non-Federal entities developing equipment and systems utilized in the food and agriculture industry, including private, consensus organizations that develop relevant standards;</text></subparagraph><subparagraph id="H11B8502375584DA580CD3B28EDCC87C4"><enum>(C)</enum><text display-inline="yes-display-inline">consult with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security;</text></subparagraph><subparagraph commented="no" id="H2EA28FA772D6499DAE7EA0B33E865AC2"><enum>(D)</enum><text display-inline="yes-display-inline">consult with food and agriculture industry trade groups;</text></subparagraph><subparagraph id="H8B4240DA5A1E4B47B109D6F16FE655BB"><enum>(E)</enum><text display-inline="yes-display-inline">consult with relevant Sector Risk Management Agencies;</text></subparagraph><subparagraph id="H5F6D63B00AFE43A19E783A31D930176B"><enum>(F)</enum><text>consult with civil society organizations;</text></subparagraph><subparagraph id="H78FB0D05B8914AD3BC67F1B97EC61749"><enum>(G)</enum><text>consult with the Administrator of the Small Business Administration; and</text></subparagraph><subparagraph id="H7E661E1566C24F4489F867773B1B8BFB"><enum>(H)</enum><text display-inline="yes-display-inline">consider the development of an advisory board to advise the Assistant Secretary on implementing this subsection, including the collection of data through the clearinghouse and the disclosure of that data.</text></subparagraph></paragraph></subsection><subsection id="HE3894D0D991F4DF9BF562355A79D7883"><enum>(c)</enum><header>Study</header><paragraph commented="no" id="HC07C660C0E74474A983F6772CC74FAE6"><enum>(1)</enum><header>In general</header><text display-inline="yes-display-inline">The Comptroller General of the United States shall conduct a study on the actions the Federal Government has taken or may take to improve the cybersecurity of the food and agriculture industry.</text></paragraph><paragraph id="HC184A3EEB82E4E9BB8A0A90C9F02DE76"><enum>(2)</enum><header>Report</header><text>Not later than 90 days after the date of enactment of this Act, the Comptroller General shall submit to Congress a report on the study conducted under paragraph (1), which shall include information on the following:</text><subparagraph commented="no" id="H9F6199C3210B4EA2BF790C4819DD9549"><enum>(A)</enum><text display-inline="yes-display-inline">The effectiveness of efforts of the Federal Government to improve the cybersecurity of the food and agriculture industry.</text></subparagraph><subparagraph commented="no" id="H19499F0B946146C38B74F2C7EFCE69C1"><enum>(B)</enum><text display-inline="yes-display-inline">The resources made available to the public, as of the date of the submission, by Federal agencies to improve the cybersecurity of the food and agriculture industry, including to address cybersecurity risks and cybersecurity threats to the food and agriculture industry.</text></subparagraph><subparagraph commented="no" id="HED6275E5C0974BEC9F9A7C98C72BC620"><enum>(C)</enum><text>The extent to which Federal agencies coordinate or duplicate authorities and take other actions for the improvement of the cybersecurity of the food and agriculture industry.</text></subparagraph><subparagraph id="H530557986E7F4534A5AFA515BA09774D"><enum>(D)</enum><text>Whether an appropriate plan is in place to prevent or adequately mitigate the risks of a coordinated attack on the food and agriculture industry.</text></subparagraph><subparagraph id="HFA7A7BE7BBA94B0C9964F7279F092EDF" commented="no"><enum>(E)</enum><text display-inline="yes-display-inline">The benefits of the Food and Agriculture—Information Sharing and Analysis Center (commonly known as the <quote>Food and Ag-ISAC</quote>) established by the Information Technology-Information Sharing and Analysis Center and any additional needs of the Food and Ag-ISAC, including—</text><clause commented="no" display-inline="no-display-inline" id="id79b611f49fc84dcca30b60d85be741ae"><enum>(i)</enum><text display-inline="yes-display-inline">required actions by, and expected costs to, the Federal Government to enhance the Food and Ag-ISAC; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id06d7b017c8364f4fad517420b87ace1e"><enum>(ii)</enum><text display-inline="yes-display-inline">identification of industry and civil society partners that could assist the Food and Ag-ISAC.</text></clause></subparagraph><subparagraph id="H0669923AC7C949699741658E3D5B012E"><enum>(F)</enum><text display-inline="yes-display-inline">The advantages and disadvantages of the creation by the Assistant Secretary of a database containing a software bill of materials for the most common internet-connected hardware and software applications used in the food and agriculture industry and recommendations for how the Assistant Secretary can maintain and update such database.</text></subparagraph></paragraph><paragraph id="H8D71093244E34B7F9A6D11DD1B542DAF"><enum>(3)</enum><header>Coordination</header><text>In carrying out paragraphs (1) and (2), the Comptroller General shall coordinate with appropriate Federal agencies, including the following:</text><subparagraph id="H253C9EA6899243A8B48C9514B73FEB35"><enum>(A)</enum><text display-inline="yes-display-inline">The Department of Health and Human Services.</text></subparagraph><subparagraph id="H52F9D1606C2845A694007E74BCE59F88"><enum>(B)</enum><text>The Department of Commerce.</text></subparagraph><subparagraph id="H66AD5C1CF147407D9E0E3A7EEEA838AE"><enum>(C)</enum><text>The Department of Agriculture.</text></subparagraph><subparagraph id="H30939FD7ABC04AC59DF4939FEBF4F15D"><enum>(D)</enum><text>The Federal Communications Commission.</text></subparagraph><subparagraph id="H025E295174F9417189923A63E6E617FA"><enum>(E)</enum><text display-inline="yes-display-inline">The Department of Energy.</text></subparagraph><subparagraph id="H34EA211184BF4ACF9E27FC443BEDD334"><enum>(F)</enum><text>The Small Business Administration.</text></subparagraph></paragraph><paragraph id="H57677C9D7516479596082541CE9CC108"><enum>(4)</enum><header>Process for studying the Food and Agriculture-Information Sharing and Analysis Center</header><text display-inline="yes-display-inline">In studying the Food and Ag-ISAC for purposes of including in the report required by paragraph (2) the information required by subparagraph (E) of that paragraph, the Comptroller General shall convene stakeholders that include civil society organizations, individual food and agriculture producers, and the Federal agencies described in paragraph (3).</text></paragraph><paragraph id="H78FB9AC7F0544C6BA091066977AC60E4"><enum>(5)</enum><header>Briefing</header><text>Not later than 90 days after the date on which the Comptroller General submits the report under paragraph (2), the Comptroller General shall provide to Congress a briefing regarding the report.</text></paragraph><paragraph id="HCD869C87143B4C5780245F15371B66F0"><enum>(6)</enum><header>Classification</header><text>The report under paragraph (2) shall be unclassified but may include a classified annex.</text></paragraph></subsection><subsection id="H7683B056255849CAA43288A923B3CA8A"><enum>(d)</enum><header>Sunset</header><text>This section shall have no force or effect after the date that is 7 years after the date of enactment of this Act.</text></subsection></section></legis-body></bill> 

