[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Page S6411]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2620. Mr. WHITEHOUSE (for himself and Mr. Blunt) submitted an
amendment intended to be proposed by him to the bill S. 754, to improve
cybersecurity in the United States through enhanced sharing of
information about cybersecurity threats, and for other purposes; which
was ordered to lie on the table; as follows:
At the end, add the following:
TITLE II--CYBERSECURITY PUBLIC AWARENESS ACT
SEC. 201. SHORT TITLE.
This title may be cited as the ``Cybersecurity Public
Awareness Act of 2015''.
SEC. 202. ENFORCEMENT OF CYBERSECURITY LAWS.
(a) Prosecution for Cybercrime.--
(1) In general.--Not later than 180 days after the date of
enactment of this Act, the Attorney General, in consultation
with the Director of the United States Secret Service, the
Director of U.S. Immigration and Customs Enforcement, and the
Director of the Federal Bureau of Investigation, shall submit
to Congress a report--
(A) describing investigations and prosecutions relating to
cyber intrusions, computer or network compromise, or other
forms of illegal hacking the preceding year, including--
(i) the number of investigations initiated relating to such
crimes;
(ii) the number of arrests relating to such crimes;
(iii) the number and description of instances in which
investigations or prosecutions relating to such crimes have
been delayed or prevented because of an inability to
extradite a criminal defendant in a timely manner; and
(iv) the number of prosecutions for such crimes,
including--
(I) the number of defendants prosecuted;
(II) whether the prosecutions resulted in a conviction; and
(III) the sentence imposed and the statutory maximum for
each such crime for which a defendant was convicted;
(B) identifying the number of employees, financial
resources, and other resources (such as technology and
training) devoted to the enforcement, investigation, and
prosecution of cyber intrusions, computer or network
compromised, or other forms of illegal hacking, including the
number of investigators, prosecutors, and forensic
specialists dedicated to investigating and prosecuting cyber
intrusions, computer or network compromise, or other forms of
illegal hacking; and
(C) discussing any impediments under the laws of the United
States or international law to prosecutions for cyber
intrusions, computer or network compromise, or other forms of
illegal hacking, including discussion of ways to improve the
mutual legal assistance process used to obtain evidence
abroad and to provide domestic evidence to foreign
requestors.
(2) Updates.--The Attorney General, in consultation with
the Director of the United States Secret Service, the
Director of Immigration and Customs Enforcement, and the
Director of the Federal Bureau of Investigation, shall
annually submit to Congress a report updating the report
submitted under paragraph (1) at the same time the Attorney
General submits annual reports under section 404 of the
Prioritizing Resources and Organization for Intellectual
Property Act of 2008 (42 U.S.C. 3713d).
(b) Preparedness of Federal Courts to Promote
Cybersecurity.--Not later than 180 days after the date of
enactment of this Act, the Attorney General, in coordination
with the Administrative Office of the United States Courts,
shall submit to Congress a report--
(1) on whether Federal courts have granted timely relief in
matters relating to botnets and other cybercrime and cyber
threats; and
(2) that includes, as appropriate, recommendations on
changes or improvements to--
(A) the Federal Rules of Civil Procedure or the Federal
Rules of Criminal Procedure;
(B) the training and other resources available to support
the Federal judiciary;
(C) the capabilities and specialization of courts to which
such cases may be assigned; and
(D) Federal civil and criminal laws.
SEC. 203. CYBERSECURITY PUBLIC AWARENESS CAMPAIGNS.
(a) Evaluation of Existing Cybersecurity Public Awareness
Campaigns.--Not later than 180 days after the date of
enactment of this Act, the Comptroller General of the United
States shall submit to Congress a report examining--
(1) the number of cybersecurity public awareness campaigns
run by Federal agencies;
(2) the estimated costs of Federal cybersecurity public
awareness campaigns; and
(3) the effectiveness of Federal cybersecurity public
awareness campaigns.
(b) Recommendations for Improving Cybersecurity Public
Awareness Campaigns.--The report required under subsection
(a) shall include recommendations for improving and, if
appropriate, consolidating Federal cybersecurity public
awareness campaigns.
SEC. 204. DEVELOPING TECHNOLOGIES TO ENHANCE CRITICAL
INFRASTRUCTURE CYBERSECURITY.
(a) Definition.--In this section, the term ``critical
infrastructure sector'' has the meaning given the term in
section 203.
(b) Reports.--
(1) In general.--The Secretary of Homeland Security shall
enter into a contract with the National Research Council, or
another Federally funded research and development
corporation, under which the Council or corporation shall
submit to Congress a report on opportunities to develop
innovative or experimental technologies or technological
approaches that would enhance the cybersecurity of the
critical infrastructure sector.
(2) Limitations.--The report required under paragraph (1)
shall--
(A) consider only technologies or technological options
that can be deployed consistent with constitutional and
statutory privacy rights; and
(B) identify any technologies or technological options
described in subparagraph (A) that merit Federal research
support.
(3) Timing.--The contract entered into under paragraph (1)
shall require that the report described in paragraph (1) be
submitted not later than 1 year after the date of enactment
of this Act. The Secretary of Homeland Security may enter
into additional subsequent contracts as appropriate.
______