[Congressional Record Volume 161, Number 126 (Wednesday, August 5, 2015)]
[Senate]
[Page S6419]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2629. Mr. GARDNER submitted an amendment intended to be proposed
by him to the bill S. 754, to improve cybersecurity in the United
States through enhanced sharing of information about cybersecurity
threats, and for other purposes; which was ordered to lie on the table;
as follows:
At the appropriate place, insert the following:
SEC. ___. REPORT ON ACCOUNTABILITY FOR THE DATA BREACH OF THE
OFFICE OF PERSONNEL MANAGEMENT.
(a) Definitions.--In this section:
(1) Appropriate committees of congress.--The term
``appropriate committees of Congress'' means--
(A) the Committee on Foreign Relations, the Select
Committee on Intelligence, and the Committee on Homeland
Security and Governmental Affairs of the Senate; and
(B) the Committee on Foreign Affairs, the Committee on
Homeland Security, and the Permanent Select Committee on
Intelligence of the House of Representatives.
(2) Data breach.--The term ``data breach'' means the data
breach of systems of the Office of Personnel Management that
occurred during fiscal year 2015 which resulted in the theft
of sensitive information of at least 21,500,000 Federal
employees and their families.
(b) Requirement for Report.--Not later than 30 days after
date of the enactment of this Act, the President shall submit
to the appropriate committees of Congress and make available
to the public a report that--
(1) identifies the perpetrator, including any state
sponsor, of the data breach;
(2) includes a plan to impose penalties on such perpetrator
under United States law; and
(3) describes a strategy to initiate diplomatic discussions
with any state sponsor of the data breach.
(c) Elements.--The report required by subsection (a) shall
include the following:
(1) Identification of any individual perpetrator of the
data breach, by name and nationality.
(2) Identification of any state sponsor of the data breach,
including each agency of the government of the state sponsor
that was responsible for authorizing, performing, or
endorsing the data breach.
(3) A description of the actions proposed to penalize each
individual identified under paragraph (1) under United States
law.
(4) The strategy required by subsection (a)(3) shall
include--
(A) a description of any action the President has
undertaken to initiate or carry out diplomatic discussions
with any state sponsor identified under paragraph (2); and
(B) a strategy to initiate or carry out diplomatic
discussions in high-level forums and interactions during the
180-day period beginning on the date of the enactment of this
Act.
______