[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Pages S6411-S6412]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2623. Ms. COLLINS (for herself, Ms. Hirono, Mr. Warner, and Mr. 
Coats) submitted an amendment intended to be proposed by her to the 
bill S. 754, to improve cybersecurity in the United States through 
enhanced sharing of information about cybersecurity threats, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. ___. REPORTING ON INTRUSIONS OF INFORMATION SYSTEMS 
                   ESSENTIAL TO OPERATION OF CRITICAL 
                   INFRASTRUCTURE AT GREATEST RISK.

       (a) Definitions.--In this section:
       (1) Appropriate agency.--The term ``appropriate agency'' 
     means, with respect to a covered entity--
       (A) except as provided in subparagraph (B), the applicable 
     sector-specific agency; or
       (B) in the case of a covered entity that is regulated by a 
     Federal entity, such Federal entity.
       (2) Appropriate agency head.--The term ``appropriate agency 
     head'' means, with respect to a covered entity, the head of 
     the appropriate agency.
       (3) Covered entity.--The term ``covered entity'' means an 
     entity that owns or controls critical cyber infrastructure.
       (4) Critical infrastructure.--The term ``critical 
     infrastructure'' means a system or asset, whether physical or 
     virtual, that is so vital to the United States that the 
     incapacity or destruction of such system or asset would have 
     a debilitating impact on security, national economic 
     security, national public health or safety, or any 
     combination of those matters.
       (5) Critical cyber infrastructure.--The term ``critical 
     cyber infrastructure'' means critical infrastructure 
     identified pursuant to section 9(a) of Executive Order 13636 
     of February 12, 2013 (78 Fed. Reg. 11742; relating to

[[Page S6412]]

     identification of critical infrastructure where a 
     cybersecurity incident could reasonably result in 
     catastrophic regional or national effects on public health or 
     safety, economic security, or national security), or any 
     successor order.
       (6) Secretary.--The term ``Secretary'' means the Secretary 
     of Homeland Security.
       (7) Sector-specific agency.--The term ``sector specific 
     agency'' has the meaning given such term in Presidential 
     Policy Directive-21, issued February 12, 2013, or any 
     successor directive.
       (b) Reporting Required.--
       (1) In general.--Notwithstanding subsections (f) and (h) of 
     section 8, if an information system of a covered entity that 
     is essential to the operation of critical cyber 
     infrastructure is successfully intruded upon, such covered 
     entity shall submit to the Secretary or the appropriate 
     agency head a report on such intrusion as soon as practicable 
     after the covered entity discovers such intrusion.
       (2) Elements.--Each report submitted by a covered entity 
     under paragraph (1) with respect to an intrusion shall 
     include the following:
       (A) A description of the technique or method used in such 
     intrusion.
       (B) A sample of the malicious software, if discovered and 
     isolated by the covered entity, involved in such intrusion.
       (C) Damage assessment.
       (D) Such other matters as the Secretary or the appropriate 
     agency head, as the case may be, consider appropriate.
       (3) Consistency.--Reports submitted under paragraph (1) 
     shall be submitted in a manner that is consistent with the 
     other requirements of this Act.
       (c) Protection From Liability.--A submittal of a report 
     under subsection (b)(1) shall be treated as a sharing of a 
     cyber threat indicator or defensive measure under section 
     4(c) for purposes of section 6.
       (d) Policies and Procedures.--
       (1) In general.--Not later than 120 days after the date of 
     the enactment of this Act, the Secretary shall, in 
     consultation with the appropriate agency heads of covered 
     entities, promulgate policies and procedures to carry out 
     this section.
       (2) Elements.--The policies and procedures promulgated 
     under paragraph (1) shall include the following:
       (A) Policies and procedures for submitting reports under 
     subsection (b).
       (B) Policies and procedures for making cyber threat 
     indicators available under subsection (e).
       (C) Policies and procedures for taking action under 
     subsection (f).
       (3) Existing processes, roles, and responsibilities.--The 
     Secretary shall ensure that the policies and procedures 
     promulgated pursuant to paragraph (1) incorporate, to the 
     greatest extent practicable, processes, roles, and 
     responsibilities of appropriate agencies and entities, 
     including sector specific information sharing and analysis 
     centers, that were in effect on the day before the date of 
     the enactment of this Act.
       (e) Two-way Sharing.--In a case in which the Secretary or 
     an appropriate agency head receives a report under subsection 
     (b) from a covered entity, the Secretary or appropriate 
     agency head, as the case may be, shall, pursuant to section 3 
     and to the greatest extent practicable, make available to 
     such covered entity such cyber threat indicators as the 
     Secretary or appropriate agency head considers appropriate.
       (f) Protection From Identification.--In a case in which the 
     Secretary or an appropriate agency head shares with a non-
     Federal entity information from or information derived from a 
     report submitted by a covered entity under this section, the 
     Secretary or the appropriate agency head (as the case may be) 
     shall take such actions as the Secretary or the appropriate 
     agency head (as the case may be) considers appropriate to 
     protect from disclosure the identity of the covered entity.
       (g) Effective Date.--The requirements of subsection (b) 
     shall take effect on the date on which the Secretary first 
     promulgates policies and procedures under subsection (d)(1) 
     and shall apply with respect to intrusions of critical cyber 
     infrastructure occurring on or after such date.
                                 ______