[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Pages S6411-S6412]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2623. Ms. COLLINS (for herself, Ms. Hirono, Mr. Warner, and Mr.
Coats) submitted an amendment intended to be proposed by her to the
bill S. 754, to improve cybersecurity in the United States through
enhanced sharing of information about cybersecurity threats, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. REPORTING ON INTRUSIONS OF INFORMATION SYSTEMS
ESSENTIAL TO OPERATION OF CRITICAL
INFRASTRUCTURE AT GREATEST RISK.
(a) Definitions.--In this section:
(1) Appropriate agency.--The term ``appropriate agency''
means, with respect to a covered entity--
(A) except as provided in subparagraph (B), the applicable
sector-specific agency; or
(B) in the case of a covered entity that is regulated by a
Federal entity, such Federal entity.
(2) Appropriate agency head.--The term ``appropriate agency
head'' means, with respect to a covered entity, the head of
the appropriate agency.
(3) Covered entity.--The term ``covered entity'' means an
entity that owns or controls critical cyber infrastructure.
(4) Critical infrastructure.--The term ``critical
infrastructure'' means a system or asset, whether physical or
virtual, that is so vital to the United States that the
incapacity or destruction of such system or asset would have
a debilitating impact on security, national economic
security, national public health or safety, or any
combination of those matters.
(5) Critical cyber infrastructure.--The term ``critical
cyber infrastructure'' means critical infrastructure
identified pursuant to section 9(a) of Executive Order 13636
of February 12, 2013 (78 Fed. Reg. 11742; relating to
[[Page S6412]]
identification of critical infrastructure where a
cybersecurity incident could reasonably result in
catastrophic regional or national effects on public health or
safety, economic security, or national security), or any
successor order.
(6) Secretary.--The term ``Secretary'' means the Secretary
of Homeland Security.
(7) Sector-specific agency.--The term ``sector specific
agency'' has the meaning given such term in Presidential
Policy Directive-21, issued February 12, 2013, or any
successor directive.
(b) Reporting Required.--
(1) In general.--Notwithstanding subsections (f) and (h) of
section 8, if an information system of a covered entity that
is essential to the operation of critical cyber
infrastructure is successfully intruded upon, such covered
entity shall submit to the Secretary or the appropriate
agency head a report on such intrusion as soon as practicable
after the covered entity discovers such intrusion.
(2) Elements.--Each report submitted by a covered entity
under paragraph (1) with respect to an intrusion shall
include the following:
(A) A description of the technique or method used in such
intrusion.
(B) A sample of the malicious software, if discovered and
isolated by the covered entity, involved in such intrusion.
(C) Damage assessment.
(D) Such other matters as the Secretary or the appropriate
agency head, as the case may be, consider appropriate.
(3) Consistency.--Reports submitted under paragraph (1)
shall be submitted in a manner that is consistent with the
other requirements of this Act.
(c) Protection From Liability.--A submittal of a report
under subsection (b)(1) shall be treated as a sharing of a
cyber threat indicator or defensive measure under section
4(c) for purposes of section 6.
(d) Policies and Procedures.--
(1) In general.--Not later than 120 days after the date of
the enactment of this Act, the Secretary shall, in
consultation with the appropriate agency heads of covered
entities, promulgate policies and procedures to carry out
this section.
(2) Elements.--The policies and procedures promulgated
under paragraph (1) shall include the following:
(A) Policies and procedures for submitting reports under
subsection (b).
(B) Policies and procedures for making cyber threat
indicators available under subsection (e).
(C) Policies and procedures for taking action under
subsection (f).
(3) Existing processes, roles, and responsibilities.--The
Secretary shall ensure that the policies and procedures
promulgated pursuant to paragraph (1) incorporate, to the
greatest extent practicable, processes, roles, and
responsibilities of appropriate agencies and entities,
including sector specific information sharing and analysis
centers, that were in effect on the day before the date of
the enactment of this Act.
(e) Two-way Sharing.--In a case in which the Secretary or
an appropriate agency head receives a report under subsection
(b) from a covered entity, the Secretary or appropriate
agency head, as the case may be, shall, pursuant to section 3
and to the greatest extent practicable, make available to
such covered entity such cyber threat indicators as the
Secretary or appropriate agency head considers appropriate.
(f) Protection From Identification.--In a case in which the
Secretary or an appropriate agency head shares with a non-
Federal entity information from or information derived from a
report submitted by a covered entity under this section, the
Secretary or the appropriate agency head (as the case may be)
shall take such actions as the Secretary or the appropriate
agency head (as the case may be) considers appropriate to
protect from disclosure the identity of the covered entity.
(g) Effective Date.--The requirements of subsection (b)
shall take effect on the date on which the Secretary first
promulgates policies and procedures under subsection (d)(1)
and shall apply with respect to intrusions of critical cyber
infrastructure occurring on or after such date.
______