[Congressional Record Volume 161, Number 125 (Tuesday, August 4, 2015)]
[Senate]
[Pages S6306-S6307]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2573. Mr. FLAKE submitted an amendment intended to be proposed by
him to the bill S. 754, to improve cybersecurity in the United States
through enhanced sharing of information about cybersecurity threats,
and for other purposes; which was ordered to lie on the table; as
follows:
At the appropriate place, insert the following:
SEC. ____. CRITICAL ELECTRIC INFRASTRUCTURE SECURITY.
(a) In General.--Part II of the Federal Power Act is
amended by inserting after section 215 (16 U.S.C. 824o) the
following:
``SEC. 215A. CRITICAL ELECTRIC INFRASTRUCTURE SECURITY.
``(a) Definitions.--In this section:
``(1) Bulk-power system; electric reliability organization;
regional entity.--The terms `bulk-power system', `Electric
Reliability Organization', and `regional entity' have the
meanings given those terms in section 215.
``(2) Critical electric infrastructure.--The term `critical
electric infrastructure' means a system or asset of the bulk-
power system, whether physical or virtual, the incapacity or
destruction of which would negatively affect national
security, economic security, public health or safety, or any
combination of those matters.
``(3) Critical electric infrastructure information.--
``(A) In general.--The term `critical electric
infrastructure information' means information related to
critical electric infrastructure, or proposed critical
electric infrastructure, generated by or provided to the
Commission or other Federal agency, other than classified
national security information, that is designated as critical
electric infrastructure information by the Commission under
subsection (c)(2).
``(B) Inclusions.--The term `critical electric
infrastructure information' includes information that
qualifies as critical energy infrastructure information under
regulations promulgated by the Commission.
``(4) Cybersecurity threat.--The term ``cybersecurity
threat' means the imminent danger of an act that severely
disrupts, attempts to severely disrupt, or poses a
significant risk of severely disrupting the operation of
programmable electronic devices or communications networks
(including hardware, software, and data) essential to the
reliable operation of the bulk-power system.
``(5) Electromagnetic pulse.--The term `electromagnetic
pulse' means 1 or more pulses of electromagnetic energy
emitted by
[[Page S6307]]
a device capable of disabling or disrupting operation of, or
destroying, electronic devices or communications networks,
including hardware, software, and data, by means of such a
pulse.
``(6) Geomagnetic storm.--The term `geomagnetic storm'
means a temporary disturbance of the magnetic field of the
Earth resulting from solar activity.
``(7) Grid security emergency.--The term `grid security
emergency' means the imminent danger of--
``(A) a malicious act using electronic communication or an
electromagnetic pulse, or a geomagnetic storm event, that
could disrupt the operation of those electronic devices or
communications networks, including hardware, software, and
data, that are essential to the reliability of the bulk-power
system; and
``(B) disruption of the operation of such devices or
networks, with significant adverse effects on the reliability
of the bulk-power system, as a result of such act or event.
``(8) Secretary.--The term `Secretary' means the Secretary
of Energy.
``(b) Authority to Address Grid Security Emergency.--
``(1) Authority.--
``(A) In general.--If the President issues and provides to
the Secretary a written directive or determination
identifying a cybersecurity threat or grid security
emergency, the Secretary may, with or without notice,
hearing, or report, issue such orders for emergency measures
as are necessary in the judgment of the Secretary to protect
the bulk-power system during the cybersecurity threat or grid
security emergency.
``(B) Rules.--As soon as practicable but not later than 180
days after the date of enactment of this section, the
Secretary shall, after notice and opportunity for comment,
establish rules of procedure that ensure that the authority
described in subparagraph (A) can be exercised expeditiously.
``(2) Notification of congress.--If the President issues
and provides to the Secretary a written directive or
determination under paragraph (1), the President shall
promptly notify congressional committees of relevant
jurisdiction, including the Committee on Energy and Commerce
of the House of Representatives and the Committee on Energy
and Natural Resources of the Senate, of the contents of, and
justification for, the directive or determination.
``(3) Consultation.--Before issuing an order for emergency
measures under paragraph (1), the Secretary shall, to the
extent practicable in light of the nature of the
cybersecurity threat or grid security emergency and the
urgency of the need for action, consult with appropriate
governmental authorities in Canada and Mexico, entities
described in paragraph (4), the Commission, and other
appropriate Federal agencies regarding implementation of the
emergency measures.
``(4) Application.--An order for emergency measures under
this subsection may apply to--
``(A) the Electric Reliability Organization;
``(B) a regional entity; or
``(C) any owner, user, or operator of the bulk-power
system.
``(5) Expiration and reissuance.--
``(A) In general.--Except as provided in subparagraph (B),
an order for emergency measures issued under paragraph (1)
shall expire not later than 30 days after the issuance of the
order.
``(B) Extensions.--The Secretary may reissue an order for
emergency measures issued under paragraph (1) for subsequent
periods, not to exceed 30 days for each such period, if the
President, for each such period, issues and provides to the
Secretary a written directive or determination that the
cybersecurity threat or grid security emergency identified
under paragraph (1) continues to exist or that the emergency
measure continues to be required.
``(6) Cost recovery for critical electric infrastructure.--
If the Commission determines that owners, operators, or users
of the critical electric infrastructure have incurred
substantial costs to comply with an order for emergency
measures issued under this subsection and that such costs
were prudently incurred and cannot reasonably be recovered
through regulated rates or market prices for the electric
energy or services sold by such owners, operators, or users,
the Commission may, after notice and an opportunity for
comment, prescribe standards for a public utility to seek to
recover such costs by filing a rate schedule or tariff
pursuant to section 205 for sales of electric energy or the
transmission of electric energy subject to the jurisdiction
of the Commission.
``(7) Temporary access to classified information.--The
Secretary, and other appropriate Federal agencies, shall, to
the extent practicable and consistent with the obligations of
the Secretary and Federal agencies to protect classified
information, provide temporary access to classified
information related to a cybersecurity threat or grid
security emergency for which emergency measures are issued
under paragraph (1) to key personnel of any entity subject to
the emergency measures to enable optimum communication
between the entity and the Secretary and other appropriate
Federal agencies regarding the cybersecurity threat or grid
security emergency.
``(c) Protection and Sharing of Critical Electric
Infrastructure Information.--
``(1) Protection of critical electric infrastructure.--
Critical electric infrastructure information--
``(A) shall be exempt from disclosure under section
552(b)(3) of title 5, United States Code; and
``(B) shall not be made available by any State, political
subdivision, or tribal authority pursuant to any State,
political subdivision, or tribal law requiring disclosure of
information or records.
``(2) Designation and sharing of critical electric
infrastructure information.--Not later than 1 year after the
date of enactment of this section, the Commission, in
consultation with the Secretary, shall promulgate such
regulations and issue such orders as necessary--
``(A) to designate critical electric infrastructure
information;
``(B) to prohibit the unauthorized disclosure of critical
electric infrastructure information; and
``(C) to ensure there are appropriate sanctions in place
for Commissioners, officers, employees, or agents of the
Commission who knowingly and willfully disclose critical
electric infrastructure information in a manner that is not
authorized under this section.
``(3) Considerations.--In promulgating regulations and
issuing orders under paragraph (2), the Commission shall take
into consideration the role of State commissions in--
``(A) reviewing the prudence and cost of investments;
``(B) determining the rates and terms of conditions for
electric services; and
``(C) ensuring the safety and reliability of the bulk-power
system and distribution facilities within the respective
jurisdictions of the State commissions.
``(4) No required sharing of information.--Nothing in this
section requires a person or entity in possession of critical
electric infrastructure information to share the information
with Federal, State, local, or tribal authorities, or any
other person or entity.
``(5) Disclosure of noncritical electric infrastructure
information.--In carrying out this section, the Commission
shall segregate critical electric infrastructure information
within documents and electronic communications, wherever
feasible, to facilitate disclosure of information that is not
designated as critical electric infrastructure information.
``(d) Security Clearances.--
``(1) In general.--The Secretary shall facilitate and, to
the extent practicable, expedite the acquisition of adequate
security clearances by key personnel of any entity subject to
this section, to enable optimum communication with Federal
agencies regarding threats to the security of the critical
electric infrastructure.
``(2) Sharing.--The Secretary, the Commission, and other
appropriate Federal agencies shall, to the extent practicable
and consistent with the obligations of the Secretary,
Commission, and Federal agencies to protect classified and
critical electric infrastructure information, share timely
actionable information regarding grid security with
appropriate key personnel of owners, operators, and users of
the critical electric infrastructure.
``(e) Clarifications of Liability.--
``(1) In general.--Except as provided in paragraph (3), to
the extent any action or omission taken by an entity that is
necessary to comply with an order for emergency measures
issued under subsection (b)(1), including any action or
omission taken to voluntarily comply with the order, results
in noncompliance with, or causes the entity not to comply
with, any rule, order, regulation, or provision of this Act,
including any reliability standard approved by the Commission
pursuant to section 215, the action or omission shall not be
considered a violation of the rule, order, regulation, or
provision.
``(2) Relationship to other law.--Except as provided in
paragraph (3), an action or omission taken by an owner,
operator, or user of the bulk-power system to comply with an
order for emergency measures issued under subsection (b)(1)
shall be treated as an action or omission taken to comply
with an order issued under section 202(c) for purposes of
section 215.
``(3) Administration.--Nothing in this subsection requires
dismissal of a cause of action against an entity that, in the
course of complying with an order for emergency measures
issued under subsection (b)(1) by taking an action or
omission for which the entity would be liable but for
paragraph (1) or (2), takes the action or omission in a
grossly negligent manner.''.
(b) Conforming Amendments.--Section 201 of the Federal
Power Act (16 U.S.C. 824) is amended by inserting ``215A,''
after ``215,'' each place it appears in subsections (b)(2)
and (e).
______