[Congressional Record Volume 161, Number 125 (Tuesday, August 4, 2015)]
[Senate]
[Pages S6310-S6311]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2579. Mr. VITTER submitted an amendment intended to be proposed by
him to the bill S. 754, to improve cybersecurity in the United States
through enhanced sharing of information about cybersecurity threats,
and for other purposes; which was ordered to lie on the table; as
follows:
At the appropriate place, insert the following:
SEC. ___. SMALL BUSINESS CYBER SECURITY OPERATIONS CENTER.
(a) Findings.--Congress finds the following:
(1) The Federal Government has been hit by a barrage of
high-profile cyber assaults over the past year, including the
attacks on the Office of Personnel Management and the
Department of State.
(2) These attacks exposed the most sensitive personal
information of millions of Federal employees and their
families.
(3) The President has instituted emergency procedures to
immediately deploy so-called indicators, or tell-tale signs
of cybercrime operations, into agency anti-malware tools.
(4) According to the Federal Bureau of Investigation, small
business concerns have lost more than $1,000,000,000 during
the period beginning October 2013 and ending June 2015 as a
result of cyber corporate account takeover and business email
fraud.
(5) The Federal Government leverages the creative genius of
small business concerns across the country to accomplish its
missions.
(6) The Federal Acquisition Regulations dictates that a
percentage of all Federal Government acquisition be set aside
for small business concerns.
(7) Over 90 percent of small business concerns use the
Internet through the course of their activities to conduct
business.
(8) Small business concerns tend to have weaker online
security and do not have necessary funding for high-end
encryption technology or staff expertise.
(9) Industry reports indicate that 30 percent of cyber
attacks target small business concerns and of those
businesses that are attacked, 59 percent have no contingency
plan, while according to a First Data report, the average
cost for a data breach at a small business concern is $36,000
and rising annually.
(10) A 2012 Verizon study shows that in 855 data breaches
examined, 71 percent occurred in businesses with fewer than
100 employees.
(11) Small business concerns are increasingly attacked with
data breaches and ransomware, where an attacker encrypts the
businesses data until a ransom is paid to the attacker.
(12) It is imperative that small business concerns are
provided improved secured guidance to limit negative impacts
on the economy of the United States.
(13) There is a vast cyber threat facing the business
sector of the United States, which poses a direct threat
against the national security of the United States, the
Department of Defense, private industry, and critical
infrastructure components.
(14) The current layer of protection from cyber threats
does not exist for small business concerns.
(b) Definitions.--In this section--
(1) the term ``Center'' means the Small Business Cyber
Security Operations Center established under subsection (c);
(2) the term ``cyber lab'' means--
(A) a Joint Cyber Training Lab; and
(B) a facility that works in conjunction with the National
Guard Cyber Teams;
(3) the term ``Secretary'' means the Secretary of Homeland
Security; and
(4) the term ``small business concern'' has the meaning
given that term under section 3 of the Small Business Act (15
U.S.C. 632).
(c) Establishment.--Not later than 1 year after the date of
enactment of this Act, the Secretary shall begin carrying out
a 3-year pilot program to establish a cybersecurity
operations center for small business concerns, to be known as
the Small Business Cyber Security Operations Center.
(d) Part of Existing Center.--The Secretary shall establish
the Center as part of and co-locate the Center with a center
providing situational awareness information to businesses on
the date of enactment of this Act.
(e) Duties.--The Center shall--
(1) work with cyber labs to provide realistic scenario
based training to network managers and security personnel of
small business concerns, including monitoring, detection,
analysis (such as trend and pattern analysis), and response
and restoration activities;
(2) provide periodic sharing, through publication and
targeted outreach, of cybersecurity best practices that are
developed based on ongoing analysis of cyber threat
indicators and information in possession of--
(A) the Federal Government;
(B) the Business Emergency Operations Center operated by
the Federal Emergency Management Agency; and
(C) other technology and cyber research centers, as
determined appropriate by the Secretary;
[[Page S6311]]
(3) collaborate with private industry, academia, and the
Department of Defense to develop a secure business supply
chain which is capable of adapting, evolving, and responding
to emergent cybersecurity threats;
(4) review and develop the necessary tools to--
(A) facilitate security information flow and mitigation
actions;
(B) provide cyber attack sensing, warning, and response
services;
(5) place an emphasis on accessibility and relevance to
small business concerns; and
(6) review the policy limitations and restrictions on
information sharing relating to cybersecurity.
(f) Authorization of Appropriations.--
(1) In general.--There is authorized to be appropriated to
carry out this section $2,000,000 for each of fiscal years
2016 through 2019, to remain available until expended.
(2) Offset.--Section 21(a)(4)(C)(vii) of the Small Business
Act (15 U.S.C. 648(a)(4)(C)(vii)) is amended--
(A) in subclause (I), by striking ``and'' at the end;
(B) in subclause (II), by striking the period at the end
and inserting ``; and''; and
(C) by adding at the end the following:
``(III) $133,000,000 for each of fiscal years 2016 through
2019.''.
______