[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Page S6411]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2620. Mr. WHITEHOUSE (for himself and Mr. Blunt) submitted an 
amendment intended to be proposed by him to the bill S. 754, to improve 
cybersecurity in the United States through enhanced sharing of 
information about cybersecurity threats, and for other purposes; which 
was ordered to lie on the table; as follows:

       At the end, add the following:

              TITLE II--CYBERSECURITY PUBLIC AWARENESS ACT

     SEC. 201. SHORT TITLE.

       This title may be cited as the ``Cybersecurity Public 
     Awareness Act of 2015''.

     SEC. 202. ENFORCEMENT OF CYBERSECURITY LAWS.

       (a) Prosecution for Cybercrime.--
       (1) In general.--Not later than 180 days after the date of 
     enactment of this Act, the Attorney General, in consultation 
     with the Director of the United States Secret Service, the 
     Director of U.S. Immigration and Customs Enforcement, and the 
     Director of the Federal Bureau of Investigation, shall submit 
     to Congress a report--
       (A) describing investigations and prosecutions relating to 
     cyber intrusions, computer or network compromise, or other 
     forms of illegal hacking the preceding year, including--
       (i) the number of investigations initiated relating to such 
     crimes;
       (ii) the number of arrests relating to such crimes;
       (iii) the number and description of instances in which 
     investigations or prosecutions relating to such crimes have 
     been delayed or prevented because of an inability to 
     extradite a criminal defendant in a timely manner; and
       (iv) the number of prosecutions for such crimes, 
     including--

       (I) the number of defendants prosecuted;
       (II) whether the prosecutions resulted in a conviction; and
       (III) the sentence imposed and the statutory maximum for 
     each such crime for which a defendant was convicted;

       (B) identifying the number of employees, financial 
     resources, and other resources (such as technology and 
     training) devoted to the enforcement, investigation, and 
     prosecution of cyber intrusions, computer or network 
     compromised, or other forms of illegal hacking, including the 
     number of investigators, prosecutors, and forensic 
     specialists dedicated to investigating and prosecuting cyber 
     intrusions, computer or network compromise, or other forms of 
     illegal hacking; and
       (C) discussing any impediments under the laws of the United 
     States or international law to prosecutions for cyber 
     intrusions, computer or network compromise, or other forms of 
     illegal hacking, including discussion of ways to improve the 
     mutual legal assistance process used to obtain evidence 
     abroad and to provide domestic evidence to foreign 
     requestors.
       (2) Updates.--The Attorney General, in consultation with 
     the Director of the United States Secret Service, the 
     Director of Immigration and Customs Enforcement, and the 
     Director of the Federal Bureau of Investigation, shall 
     annually submit to Congress a report updating the report 
     submitted under paragraph (1) at the same time the Attorney 
     General submits annual reports under section 404 of the 
     Prioritizing Resources and Organization for Intellectual 
     Property Act of 2008 (42 U.S.C. 3713d).
       (b) Preparedness of Federal Courts to Promote 
     Cybersecurity.--Not later than 180 days after the date of 
     enactment of this Act, the Attorney General, in coordination 
     with the Administrative Office of the United States Courts, 
     shall submit to Congress a report--
       (1) on whether Federal courts have granted timely relief in 
     matters relating to botnets and other cybercrime and cyber 
     threats; and
       (2) that includes, as appropriate, recommendations on 
     changes or improvements to--
       (A) the Federal Rules of Civil Procedure or the Federal 
     Rules of Criminal Procedure;
       (B) the training and other resources available to support 
     the Federal judiciary;
       (C) the capabilities and specialization of courts to which 
     such cases may be assigned; and
       (D) Federal civil and criminal laws.

     SEC. 203. CYBERSECURITY PUBLIC AWARENESS CAMPAIGNS.

       (a) Evaluation of Existing Cybersecurity Public Awareness 
     Campaigns.--Not later than 180 days after the date of 
     enactment of this Act, the Comptroller General of the United 
     States shall submit to Congress a report examining--
       (1) the number of cybersecurity public awareness campaigns 
     run by Federal agencies;
       (2) the estimated costs of Federal cybersecurity public 
     awareness campaigns; and
       (3) the effectiveness of Federal cybersecurity public 
     awareness campaigns.
       (b) Recommendations for Improving Cybersecurity Public 
     Awareness Campaigns.--The report required under subsection 
     (a) shall include recommendations for improving and, if 
     appropriate, consolidating Federal cybersecurity public 
     awareness campaigns.

     SEC. 204. DEVELOPING TECHNOLOGIES TO ENHANCE CRITICAL 
                   INFRASTRUCTURE CYBERSECURITY.

       (a) Definition.--In this section, the term ``critical 
     infrastructure sector'' has the meaning given the term in 
     section 203.
       (b) Reports.--
       (1) In general.--The Secretary of Homeland Security shall 
     enter into a contract with the National Research Council, or 
     another Federally funded research and development 
     corporation, under which the Council or corporation shall 
     submit to Congress a report on opportunities to develop 
     innovative or experimental technologies or technological 
     approaches that would enhance the cybersecurity of the 
     critical infrastructure sector.
       (2) Limitations.--The report required under paragraph (1) 
     shall--
       (A) consider only technologies or technological options 
     that can be deployed consistent with constitutional and 
     statutory privacy rights; and
       (B) identify any technologies or technological options 
     described in subparagraph (A) that merit Federal research 
     support.
       (3) Timing.--The contract entered into under paragraph (1) 
     shall require that the report described in paragraph (1) be 
     submitted not later than 1 year after the date of enactment 
     of this Act. The Secretary of Homeland Security may enter 
     into additional subsequent contracts as appropriate.
                                 ______