[Congressional Record Volume 162, Number 19 (Tuesday, February 2, 2016)]
[Senate]
[Page S501]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 3197. Ms. COLLINS (for herself, Ms. Mikulski, and Ms. Hirono)
submitted an amendment intended to be proposed to amendment SA 2953
proposed by Ms. Murkowski to the bill S. 2012, to provide for the
modernization of the energy policy of the United States, and for other
purposes; which was ordered to lie on the table; as follows:
On page 157, strike line 24 and insert the following:
tion.
``SEC. 225. CRITICAL ELECTRIC INFRASTRUCTURE AT GREATEST
RISK.
``(a) Definitions.--In this section:
``(1) Appropriate congressional committees.--The term
`appropriate congressional committees' means--
``(A) the Select Committee on Intelligence of the Senate;
``(B) the Permanent Select Committee on Intelligence of the
House of Representatives;
``(C) the Committee on Energy and Natural Resources of the
Senate; and
``(D) the Committee on Energy and Commerce of the House of
Representatives.
``(2) Critical electric infrastructure.--The term `critical
electric infrastructure' means a system or asset of the bulk-
power system, whether physical or virtual, the incapacity or
destruction of which would negatively affect national
security, economic security, public health or safety, or any
combination of those matters.
``(3) Covered entity.--The term `covered entity' means an
entity identified pursuant to section 9(a) of Executive Order
13636 of February 12, 2013 (78 Fed. Reg. 11742), relating to
identification of critical infrastructure where a
cybersecurity incident could reasonably result in
catastrophic regional or national effects on public health or
safety, economic security, or national security, that owns or
operates critical electric infrastructure.
``(4) Secretary.--The term `Secretary' means the Secretary
of Energy.
``(b) Mitigation Strategy Required for Critical Electric
Infrastructure at Greatest Risk.--Not later than 1 year after
the date of enactment of this Act, the Commission, in
consultation with the Secretary and each covered entity,
shall identify and propose prioritized, risk-based actions to
mitigate cyber risk for each covered entity such that, to the
greatest extent practicable, a cyber security incident
affecting that covered entity would be less likely to result
in catastrophic regional or national effects on public health
or safety, economic security, or national security, given
current and projected cyber risks.
``(c) Report Required.--Not later than 60 days after the
date on which the Commission has taken the actions required
under subsection (b), the Commission shall submit to the
appropriate congressional committees a report describing--
``(1) the current and projected cyber risks considered by
the Commission; and
``(2) a summary of the type of actions proposed by the
Commission.''.
______