[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Page S6412]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2624. Mr. MENENDEZ submitted an amendment intended to be proposed 
by him to the bill S. 754, to improve cybersecurity in the United 
States through enhanced sharing of information about cybersecurity 
threats, and for other purposes; which was ordered to lie on the table; 
as follows:

       On page 15, lines 4 and 5, strike ``paragraph (2)'' and 
     insert ``paragraphs (2) and (3)''.

       On page 15, between lines 16 and 17, insert the following:
       (3) Compliance with cybersecurity cross-agency priority 
     goal.--
       (A) Definitions.--In this paragraph--
       (i) the term ``appropriate committees of Congress'' means--

       (I) the Committee on the Judiciary, the Committee on 
     Homeland Security and Governmental Affairs, and the Select 
     Committee on Intelligence of the Senate; and
       (II) the Committee on the Judiciary, the Committee on 
     Homeland Security, the Permanent Select Committee on 
     Intelligence, and the Committee on Oversight and Government 
     Reform of the House of Representatives; and

       (ii) the term ``independent auditor'' means--

       (I) for each Federal entity with an Inspector General 
     appointed under the Inspector General Act of 1978, the 
     Inspector General or an independent external auditor, as 
     determined by the Inspector General of the Federal entity; 
     and
       (II) for each Federal entity not described in subclause 
     (I), an independent external auditor as determined by the 
     head of the Federal entity.

       (B) Requirements.--A Federal entity may not receive 
     defensive measures under this Act unless the independent 
     auditor for the Federal entity certifies that the Federal 
     entity--
       (i) is capable of properly using any defensive measures 
     received; and
       (ii) meets any additional metrics, as determined by 
     Secretary of Homeland Security.
       (C) Rules.--Not later than 120 days after the date of 
     enactment of this Act, the Secretary of Homeland Security, in 
     consultation with the Director of the Office of Management 
     and Budget, shall promulgate rules for updating the 
     certification of the compliance of a Federal entity with the 
     Cybersecurity Cross-Agency Priority Goal for purposes of 
     receiving defensive measures.
       (D) Report to congress.--
       (i) In general.--Not later than 1 year after the date of 
     enactment of this Act, the independent auditor for each 
     Federal entity, in consultation with the Secretary of 
     Homeland Security, shall submit to the appropriate committees 
     of Congress and the head of the Federal entity a report 
     detailing whether the Federal entity is capable of--

       (I) adequately protecting the information shared or 
     received under this Act;
       (II) determining the original source of a cybersecurity 
     threat; and
       (III) determining whether a cybersecurity threat originates 
     from a foreign entity.

       (ii) Form.--Each report required under clause (i) shall be 
     submitted in writing and in unclassified form, but may 
     include a classified annex.

       On page 15, line 17, strike ``(3)'' and insert ``(4)''
                                 ______