[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5211 Introduced in Senate (IS)]

<DOC>






119th CONGRESS
  2d Session
                                S. 5211

 To require the Under Secretary of Defense for Policy and the Chairman 
of the Joint Chiefs of Staff to submit a strategy for cyber cooperation 
          in the Indo-Pacific region, and for other purposes.


_______________________________________________________________________


                   IN THE SENATE OF THE UNITED STATES

                             August 3, 2026

  Mr. Rounds (for himself and Ms. Duckworth) introduced the following 
  bill; which was read twice and referred to the Committee on Foreign 
                               Relations

_______________________________________________________________________

                                 A BILL


 
 To require the Under Secretary of Defense for Policy and the Chairman 
of the Joint Chiefs of Staff to submit a strategy for cyber cooperation 
          in the Indo-Pacific region, and for other purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. STRATEGY FOR CYBER COOPERATION IN THE INDO-PACIFIC REGION.

    (a) In General.--Not later than 180 days after the date of the 
enactment of this Act, the Under Secretary of Defense for Policy and 
the Chairman of the Joint Chiefs of Staff, in coordination with the 
Commander of the United States Indo-Pacific Command and the Commander 
of the United States Cyber Command, shall develop, submit to the 
congressional defense committees (as defined in section 101 of title 
10, United States Code), and commence implementation of a strategy to 
enhance and institutionalize cyber cooperation between the Department 
of Defense and allies and partners in the Indo-Pacific region.
    (b) Elements.--The strategy required by subsection (a) shall 
include the following:
            (1) An identification of the current and projected cyber 
        cooperation requirements of the Department of Defense in the 
        Indo-Pacific region through 2040, including requirements 
        identified in theater security cooperation plans, relating to--
                    (A) defensive cyberspace operations;
                    (B) offensive cyber operations;
                    (C) secure information sharing;
                    (D) cyber training, exercises, and workforce 
                development;
                    (E) protection of critical infrastructure, 
                communications networks, and defense industrial base 
                networks;
                    (F) joint planning and operational integration; and
                    (G) command and control structures for joint cyber 
                integration.
            (2) An identification of existing cyber cooperation 
        activities, agreements, and capability gaps between the 
        Department of Defense and allies and partners in the Indo-
        Pacific region.
            (3) A strategic review of the cybersecurity capacity and 
        cyber resilience of allies and partners in the Indo-Pacific 
        region that includes the following:
                    (A) With respect to each such ally or partner--
                            (i) an assessment of the extent to which 
                        the ally or partner has expressed interest or 
                        has participated in existing United States 
                        Government or Department of Defense programs to 
                        assist in the the expansion of cybersecurity 
                        capacity across policies, technical 
                        architecture, and practices of the ally or 
                        partner, the results of any such participation, 
                        and an identification of any barriers to 
                        effective participation;
                            (ii) an assessment of the extent to which 
                        the responsibility for cybersecurity 
                        capabilities and any exposure resulting from 
                        gaps in such capabilities lie with the 
                        military, another government entity, or the 
                        commercial sector of the ally or partner, and 
                        an assessment of the manner in which the 
                        structure contributes to opportunities for, or 
                        risks to, collaboration with the United States 
                        Armed Forces;
                            (iii) an identification of the 
                        cybersecurity standards used by each ally or 
                        partner, and an assessment of the extent to 
                        which such standards overlap with United States 
                        cybersecurity standards; and
                            (iv) in the case of an ally or partner that 
                        does not have shared cybersecurity standards 
                        with the United States, a review of the 
                        differences between standards, the manner in 
                        which such differences may create barriers to 
                        interoperability and collaboration with the 
                        Department of Defense, existing Department of 
                        Defense mitigation measures to ensure 
                        collaboration, and recommendations for more 
                        permanent solutions.
                    (B) An identification of additional resources or 
                authorities required to help address gaps in the 
                cybersecurity architecture or practices of such allies 
                and partners, including with respect to the National 
                Guard's State Partnership Program and consultations 
                provided by the Department of State and the Department 
                of Homeland Security.
                    (C) An identification of any capability gaps of 
                such allies and partners with respect to cybersecurity 
                capacity and cyber resilience that the Department of 
                Defense may be able to address through security 
                cooperation initiatives.
            (4) An identification of--
                    (A) actions necessary to strengthen cyber 
                cooperation, interoperability, intelligence and 
                information sharing, cyber defense and cybersecurity 
                integration, and combined cyber planning with such 
                allies and partners;
                    (B) any authorities, force posture adjustments, 
                organizational changes, or legislative actions required 
                to improve cybersecurity in the Indo-Pacific region; 
                and
                    (C) opportunities--
                            (i) to expand bilateral and multilateral 
                        cyber exercises, cyber workforce exchanges, 
                        cyber capacity-building initiatives, and 
                        operational collaboration with such allies and 
                        partners;
                            (ii) to leverage existing security 
                        cooperation mechanisms and multilateral 
                        partnerships to support the objectives of the 
                        strategy; and
                            (iii) to enhance collaboration between the 
                        Joint Staff, the Office of the Secretary of 
                        Defense, the United States Cyber Command, and 
                        the United States Indo-Pacific Command on 
                        cybersecurity cooperation with allies and 
                        partners in the Indo-Pacific region.
    (c) Funding Plan.--Not later than 180 days after the date of the 
enactment of this Act, the Under Secretary of Defense for Policy and 
the Chairman of the Joint Chiefs of Staff, in coordination with the 
Commander of the United States Indo-Pacific Command and the Commander 
of the United States Cyber Command, shall submit to the congressional 
defense committees a report that includes--
            (1) a plan for funding and resourcing the implementation of 
        the strategy developed under subsection (a) across the period 
        covered by the most recent future-years defense program 
        submitted to Congress under section 221 of title 10, United 
        States Code, as of the date of the report; and
            (2) an identification of any resource gaps that would 
        impede implementation of such strategy.
    (d) Briefing.--Not later than 180 days after the date of the 
enactment of this Act, the Under Secretary of Defense for Policy and 
the Chairman of the Joint Chiefs of Staff shall provide the 
congressional defense committees with a briefing on the strategy 
required by subsection (a).
    (e) Implementation Report.--Not later than March 15, 2028, the 
Under Secretary of Defense for Policy and the Chairman of the Joint 
Chiefs of Staff shall submit to the congressional defense committees a 
report on the progress of the implementation of such strategy, 
including--
            (1) a description of actions taken to implement the 
        strategy;
            (2) an assessment of remaining operational and capability 
        gaps;
            (3) an identification of any barriers to implementation; 
        and
            (4) recommendations for any additional authorities or 
        resources required to carry out the strategy.
    (f) Form.--The strategy, briefing, and report required by this 
section shall be submitted in unclassified form but may include a 
classified annex.
                                 <all>