[Congressional Record Volume 161, Number 154 (Wednesday, October 21, 2015)]
[Senate]
[Pages S7415-S7416]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2722. Mr. GARDNER submitted an amendment intended to be proposed 
by him to the bill S. 754, to improve cybersecurity in the United 
States through enhanced sharing of information about cybersecurity 
threats, and for other purposes; which was ordered to lie on the table; 
as follows:

       At the appropriate place, insert the following:

     SEC. ___. BIENNIAL CYBER REVIEW.

       (a) Requirement for Review.--Beginning in 2016 and not less 
     frequently than once every two years thereafter, the 
     President shall complete a review of the cyber posture of the 
     United States, including an unclassified summary of roles, 
     missions, accomplishments, plans, and programs.

[[Page S7416]]

       (b) Purposes.--The purposes of each such review are--
       (1) to assess the cyber security of the United States;
       (2) to determine and express the cyber strategy of the 
     United States; and
       (3) to establish a revised cyber program for the next 2-
     year period.
       (c) Content.--Each review required by subsection (a) shall 
     include--
       (1) a comprehensive examination of the cyber strategy, 
     force structure, personnel, modernization plans, 
     infrastructure, and budget plan of the United States;
       (2) an assessment of the ability of the United States to 
     recover from a cyber emergency;
       (3) an assessment of other elements of the cyber program of 
     the United States;
       (4) an assessment of critical national security 
     infrastructure and data that is vulnerable to cyberattacks 
     and cybertheft; and
       (5) an assessment of international engagement efforts to 
     establish viable norms of behavior in cyberspace to implement 
     the 2011 International Strategy for Cyberspace.
       (d) Involvement of Cybersecurity Advisory Panel.--
       (1) Requirement to inform.--The President shall inform the 
     Cybersecurity Advisory Panel established or designated under 
     section ___, on an ongoing basis, of the actions carried out 
     to conduct each review required by subsection (a).
       (2) Assessment prior to completion of review.--Not later 
     than 1 year prior to the date of completion of each review 
     required by subsection (a), the Chairman of the Cybersecurity 
     Advisory Panel shall submit to the President, the assessment 
     of such Panel of actions carried out to conduct the review as 
     of the date of the submission, including any recommendations 
     of the Panel for improvements to the review or for additional 
     matters to be covered in the review.
       (3) Assessment of completed review.--At the time each 
     review required by subsection (a) is completed and in time to 
     be included in a report required by subsection (d), the 
     Chairman of the Cybersecurity Advisory Panel shall submit to 
     the President, on behalf of the Panel, an assessment of such 
     review.
       (e) Report.--Not later than September 30, 2016, and not 
     less frequently than once every two years thereafter, the 
     President shall submit to Congress a comprehensive report on 
     each review required by subsection (a). Each report shall 
     include--
       (1) the results of the review, including a comprehensive 
     discussion of the cyber strategy of the United States and the 
     collaboration between the public and private sectors best 
     suited to implement that strategy;
       (2) a description of the threats examined for purposes of 
     the review and the scenarios developed in the examination of 
     such threats;
       (3) the assumptions used in the review, including 
     assumptions relating to the cooperation of other countries 
     and levels of acceptable risk; and
       (4) the assessment of the Cybersecurity Advisory Panel 
     submitted under subsection (c)(3).

     SEC. ___. CYBERSECURITY ADVISORY PANEL.

       (a) In General.--The President shall establish or designate 
     a Cybersecurity Advisory Panel.
       (b) Appointment.--The President--
       (1) shall appoint as members of the Cybersecurity Advisory 
     Panel representatives of industry, academic, nonprofit 
     organizations, interest groups, and advocacy organizations, 
     and State and local governments who are qualified to provide 
     advice and information on cybersecurity research, 
     development, demonstrations, education, personnel, technology 
     transfer, commercial application, or societal and civil 
     liberty concerns;
       (2) shall appoint a Chairman of the Panel from among the 
     members of the Panel; and
       (3) may seek and give consideration to recommendations for 
     appointments to the Panel from Congress, industry, the 
     cybersecurity community, the defense community, State and 
     local governments, and other appropriate organizations.
       (c) Duties.--The Cybersecurity Advisory Panel shall advise 
     the President on matters relating to the national 
     cybersecurity program and strategy and shall assess--
       (1) trends and developments in cybersecurity science 
     research and development;
       (2) progress made in implementing the strategy;
       (3) the need to revise the strategy;
       (4) the readiness and capacity of the Federal and national 
     workforces to implement the national cybersecurity program 
     and strategy, and the steps necessary to improve workforce 
     readiness and capacity;
       (5) the balance among the components of the national 
     strategy, including funding for program components;
       (6) whether the strategy, priorities, and goals are helping 
     to maintain United States leadership and defense in 
     cybersecurity;
       (7) the management, coordination, implementation, and 
     activities of the strategy;
       (8) whether the concerns of Federal, State, and local law 
     enforcement entities are adequately addressed; and
       (9) whether societal and civil liberty concerns are 
     adequately addressed.
       (d) Reports.--Not less frequently than once every 4 years, 
     the Cybersecurity Advisory Panel shall submit to the 
     President a report on its assessments under subsection (c) 
     and its recommendations for ways to improve the strategy.
       (e) Travel Expenses of Non-Federal Members.--Non-Federal 
     members of the Cybersecurity Advisory Panel, while attending 
     meetings of the Panel or while otherwise serving at the 
     request of the head of the Panel while away from their homes 
     or regular places of business, may be allowed travel 
     expenses, including per diem in lieu of subsistence, as 
     authorized by section 5703 of title 5, United States Code, 
     for individuals in the Government serving without pay. 
     Nothing in this subsection shall be construed to prohibit 
     members of the Panel who are officers or employees of the 
     United States from being allowed travel expenses, including 
     per diem in lieu of subsistence, in accordance with law.
       (f) Exemption From FACA Sunset.--Section 14 of the Federal 
     Advisory Committee Act (5 U.S.C. App.) shall not apply to the 
     Cybersecurity Advisory Panel.
                                 ______