<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-LEW23134-C70-TD-G0F"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>107 S824 RS: National Risk Management Act of 2023</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-05-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 59</calendar><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 824</legis-num><associated-doc role="report">[Report No. 118–20]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230315">March 15, 2023</action-date><action-desc><sponsor name-id="S388">Ms. Hassan</sponsor> (for herself and <cosponsor name-id="S401">Mr. Romney</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSGA00">Committee on Homeland Security and Governmental Affairs</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20230509">May 9, 2023</action-date><action-desc>Reported by <sponsor name-id="S380">Mr. Peters</sponsor>, with amendments</action-desc><action-instruction>Omit the part struck through and insert the part printed in italic</action-instruction></action><legis-type>A BILL</legis-type><official-title>To require the Secretary of Homeland Security to establish a national risk management cycle, and for other purposes.</official-title></form><legis-body><section id="S1" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>National Risk Management Act of 2023</short-title></quote>.</text></section><section commented="no" display-inline="no-display-inline" id="id91d4e109e54b4164b15de642b94e381c"><enum>2.</enum><header>National risk management cycle</header><subsection id="iddc0b503d48d446489c5ea4059909b2c4"><enum>(a)</enum><header>In general</header><text>Subtitle A of title XXII of the Homeland Security Act of 2002 (<external-xref legal-doc="usc" parsable-cite="usc/6/651">6 U.S.C. 651 et seq.</external-xref>) is amended by adding at the end the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id8044aee90f2a40a597e863a7c5fc53ac"><section id="id6b28b56d54d14a6290892f803288303e"><enum>2220F.</enum><header>National risk management cycle</header><subsection id="id608dffcf568445a7b545224a1f4e05ae"><enum>(a)</enum><header>National critical functions defined</header><text>In this section, the term <term>national critical functions</term> means the functions of government and the private sector so vital to the United States that their disruption, corruption, or dysfunction would have a debilitating effect on security, national economic security, national public health or safety, or any combination thereof.</text></subsection><subsection id="idc61dff87ece24c03b0e7570887b11dee"><enum>(b)</enum><header>National risk management cycle</header><paragraph id="ida35d967faaae477fbbd6dff2a9a50636"><enum>(1)</enum><header>Risk identification and assessment</header><subparagraph id="id00410afbd57844268a1219e360e0d894"><enum>(A)</enum><header>In general</header><text>The Secretary, acting through the Director, shall establish a recurring process by which to identify and assess risks to critical infrastructure, considering both cyber and physical threats and the associated likelihoods, vulnerabilities, and consequences.</text></subparagraph><subparagraph id="id9541136d3a0d460aabfd747b22cb4002"><enum>(B)</enum><header>Consultation</header><text>In establishing the process required under subparagraph (A), the Secretary shall consult— </text><clause commented="no" display-inline="no-display-inline" id="id31a48af6143e45faace26cdac5098b6a"><enum>(i)</enum><text display-inline="yes-display-inline">Sector Risk Management Agencies; </text></clause><clause commented="no" display-inline="no-display-inline" id="id80f111bf59184b43aa865cbdb0ce5463"><enum>(ii)</enum><text display-inline="yes-display-inline">critical infrastructure owners and operators; </text></clause><clause commented="no" display-inline="no-display-inline" id="id4719ca77dddf4a9695be9be92aef023a"><enum>(iii)</enum><text display-inline="yes-display-inline">the Assistant to the President for National Security Affairs; </text></clause><clause commented="no" display-inline="no-display-inline" id="id6a2b97aaf3c74b0f8fe4f65ce987db1c"><enum>(iv)</enum><text display-inline="yes-display-inline">the Assistant to the President for Homeland Security; and</text></clause><clause commented="no" display-inline="no-display-inline" id="id15c480d9c09b471e9a1a2c3468f75b72"><enum>(v)</enum><text display-inline="yes-display-inline">the National Cyber Director.</text></clause></subparagraph><subparagraph id="id630fd9a23efd402db45e59857c6b09d0"><enum>(C)</enum><header>Process elements</header><text>The process established under subparagraph (A) shall include elements to—</text><clause id="id39c9bc5aa04944a18d41f57438c5c811"><enum>(i)</enum><text>collect relevant information, collected pursuant to section 2218, from Sector Risk Management Agencies relating to the threats, vulnerabilities, and consequences related to the particular sectors of those Sector Risk Management Agencies; </text></clause><clause id="id0808592d27d34d248cfd3ad3688ea698"><enum>(ii)</enum><text>allow critical infrastructure owners and operators to submit relevant information to the Secretary for consideration; and</text></clause><clause id="idf3350ee5c33f45e78d59cf0d5077e2dc"><enum>(iii)</enum><text>outline how the Secretary will solicit input from other Federal departments and agencies.</text></clause></subparagraph><subparagraph id="id48c4dc9abccb4e1d9501c25090b296a2"><enum>(D)</enum><header>Publication</header><text>Not later than 180 days after the date of enactment of this section, the Secretary shall publish in the Federal Register procedures for the process established under subparagraph (A), subject to any redactions the Secretary determines are necessary to protect classified or other sensitive information.</text></subparagraph><subparagraph id="id3311283daa9b456e80fa0d5c6e635299"><enum>(E)</enum><header>Report</header><text>The Secretary shall submit to the President, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives a report on the risks identified by the process established under subparagraph (A)—</text><clause id="id9a463a559ad946a1a63b224e3996755f"><enum>(i)</enum><text>not later than 1 year after the date of enactment of this section; and</text></clause><clause id="id1eb5c26cc619462fa258b7b6d8a8cb92"><enum>(ii)</enum><text>not later than 1 year after the date on which the Secretary submits a periodic evaluation described in section 9002(b)(2) of title XC of division H of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (<external-xref legal-doc="usc" parsable-cite="usc/6/652a">6 U.S.C. 652a(b)(2)</external-xref>).</text></clause></subparagraph></paragraph><paragraph id="id30bd564575b64a479603a9c601c0dc5d"><enum>(2)</enum><header>National critical infrastructure resilience strategy</header><subparagraph id="id6132b078adfb4c89b0f8e8231d05272b"><enum>(A)</enum><header>In general</header><text>Not later than 1 year after the date on which the Secretary delivers each report required under paragraph (1), the President shall deliver to majority and minority leaders of the Senate, the Speaker and minority leader of the House of Representatives, the Committee on Homeland Security and Governmental Affairs of the Senate, and the Committee on Homeland Security of the House of Representatives a national critical infrastructure resilience strategy designed to address the risks identified by the Secretary.</text></subparagraph><subparagraph id="ida09a987df0a0423bbb3bd5bd167b4107"><enum>(B)</enum><header>Elements</header><text>Each strategy delivered under subparagraph (A) shall—</text><clause id="id91d09ab418ba4888bf0c32f1fe3100b2"><enum>(i)</enum><text>prioritize areas of risk to critical infrastructure that would compromise or disrupt national critical functions impacting national security, economic security, or public health and safety;</text></clause><clause id="ided8019a5f36444be818d2d4f9591b0af"><enum>(ii)</enum><text>assess the implementation of the previous national critical infrastructure resilience strategy, as applicable;</text></clause><clause id="id71333d98364b49f09aa5e01f0d33171b"><enum>(iii)</enum><text>identify and outline current and proposed national-level actions, programs, and efforts, including resource requirements, to be taken to address the risks identified;</text></clause><clause id="idd6051e8009a644b88e3c7d2f89e7252e"><enum>(iv)</enum><text>identify the Federal departments or agencies responsible for leading each national-level action, program, or effort and the relevant critical infrastructure sectors for each; and</text></clause><clause id="id4b87360028f048f0a31af2a6e3a3d732"><enum>(v)</enum><text>request any additional authorities necessary to successfully execute the strategy.</text></clause></subparagraph><subparagraph id="id1e1a2540d26a45d2a92f6dfdb03b9d69"><enum>(C)</enum><header>Form</header><text>Each strategy delivered under subparagraph (A) shall be unclassified, but may contain a classified annex.</text></subparagraph></paragraph><paragraph id="id42a30aa245ca49b0b72b90946d62764f"><enum>(3)</enum><header>Congressional briefing</header><text>Not later than 1 year after the date on which the President delivers the first strategy required under paragraph (2)(A), and each year thereafter, the Secretary, in coordination with Sector Risk Management Agencies, shall brief the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives on—</text><subparagraph id="id79eb7ef0593f41929a0b68247b30c386"><enum>(A)</enum><text>the national risk management cycle activities undertaken pursuant to the strategy delivered under <deleted-phrase reported-display-style="strikethrough">subparagraph (A)</deleted-phrase><added-phrase reported-display-style="italic">paragraph (2)(A)</added-phrase>; and</text></subparagraph><subparagraph id="id423be9d9ba3f4da2be6c7285fde017cd"><enum>(B)</enum><text>the amounts and timeline for funding that the Secretary has determined would be necessary to address risks and successfully execute the full range of activities proposed by the strategy delivered <deleted-phrase reported-display-style="strikethrough">subparagraph (A)</deleted-phrase><added-phrase reported-display-style="italic">under paragraph (2)(A)</added-phrase>.</text></subparagraph></paragraph></subsection></section><after-quoted-block>.</after-quoted-block></quoted-block></subsection><subsection id="id3d825bfaa4814131aa8e9160ab8b2a20"><enum>(b)</enum><header>Technical and conforming amendment</header><text>The table of contents in section 1(b) of the Homeland Security Act of 2002 (<external-xref legal-doc="public-law" parsable-cite="pl/107/296">Public Law 107–296</external-xref>; 116 Stat. 2135) is amended by inserting after the item relating to section 2220E the following:</text><quoted-block style="OLC" display-inline="no-display-inline" id="id20376F3AF8AB41569A12573FF466DE8C"><toc><toc-entry level="section" bold="off">Sec. 2220F. National risk management cycle.</toc-entry></toc><after-quoted-block>.</after-quoted-block></quoted-block></subsection></section></legis-body><endorsement><action-date date="20230509">May 9, 2023</action-date><action-desc>Reported with amendments</action-desc></endorsement></bill> 

