[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Page S6419]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2629. Mr. GARDNER submitted an amendment intended to be proposed 
by him to the bill S. 754, to improve cybersecurity in the United 
States through enhanced sharing of information about cybersecurity 
threats, and for other purposes; which was ordered to lie on the table; 
as follows:

       At the appropriate place, insert the following:

     SEC. ___. REPORT ON ACCOUNTABILITY FOR THE DATA BREACH OF THE 
                   OFFICE OF PERSONNEL MANAGEMENT.

       (a) Definitions.--In this section:
       (1) Appropriate committees of congress.--The term 
     ``appropriate committees of Congress'' means--
       (A) the Committee on Foreign Relations, the Select 
     Committee on Intelligence, and the Committee on Homeland 
     Security and Governmental Affairs of the Senate; and
       (B) the Committee on Foreign Affairs, the Committee on 
     Homeland Security, and the Permanent Select Committee on 
     Intelligence of the House of Representatives.
       (2) Data breach.--The term ``data breach'' means the data 
     breach of systems of the Office of Personnel Management that 
     occurred during fiscal year 2015 which resulted in the theft 
     of sensitive information of at least 21,500,000 Federal 
     employees and their families.
       (b) Requirement for Report.--Not later than 30 days after 
     date of the enactment of this Act, the President shall submit 
     to the appropriate committees of Congress and make available 
     to the public a report that--
       (1) identifies the perpetrator, including any state 
     sponsor, of the data breach;
       (2) includes a plan to impose penalties on such perpetrator 
     under United States law; and
       (3) describes a strategy to initiate diplomatic discussions 
     with any state sponsor of the data breach.
       (c) Elements.--The report required by subsection (a) shall 
     include the following:
       (1) Identification of any individual perpetrator of the 
     data breach, by name and nationality.
       (2) Identification of any state sponsor of the data breach, 
     including each agency of the government of the state sponsor 
     that was responsible for authorizing, performing, or 
     endorsing the data breach.
       (3) A description of the actions proposed to penalize each 
     individual identified under paragraph (1) under United States 
     law.
       (4) The strategy required by subsection (a)(3) shall 
     include--
       (A) a description of any action the President has 
     undertaken to initiate or carry out diplomatic discussions 
     with any state sponsor identified under paragraph (2); and
       (B) a strategy to initiate or carry out diplomatic 
     discussions in high-level forums and interactions during the 
     180-day period beginning on the date of the enactment of this 
     Act.
                                 ______