[Congressional Record Volume 162, Number 52 (Wednesday, April 6, 2016)]
[Senate]
[Page S1757]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 3468. Mr. MARKEY submitted an amendment intended to be proposed by
him to the bill H.R. 636, to amend the Internal Revenue Code of 1986 to
permanently extend increased expensing limitations, and for other
purposes; which was ordered to lie on the table; as follows:
On page 356, between lines 12 and 13, insert the following:
(f) Disclosure of Cyberattacks by the Aviation Industry.--
(1) In general.--Not later than 270 days after the date of
the enactment of this Act, the Secretary of Transportation
shall prescribe regulations requiring covered air carriers
and covered manufacturers to disclose to the Federal Aviation
Administration any attempted or successful cyberattack on any
system on board an aircraft, whether or not the system is
critical to the safe and secure operation of the aircraft, or
any maintenance or ground support system for aircraft,
operated by the air carrier or produced by the manufacturer,
as the case may be.
(2) Use of disclosures by the federal aviation
administration.--The Administrator of the Federal Aviation
Administration shall use the information obtained through
disclosures made under paragraph (1) to improve the
regulations of the Federal Aviation Administration and to
notify air carriers, aircraft manufacturers, and other
Federal agencies of cybersecurity vulnerabilities in systems
on board an aircraft or maintenance or ground support systems
for aircraft.
(g) Annual Report on Cyberattacks on Aircraft Systems and
Maintenance and Ground Support Systems.--Not later than one
year after the date of the enactment of this Act, and
annually thereafter, the Administrator of the Federal
Aviation Administration shall submit to the appropriate
committees of Congress a report on attempted and successful
cyberattacks on any system on board an aircraft, whether or
not the system is critical to the safe and secure operation
of the aircraft, and on maintenance or ground support systems
for aircraft, that includes--
(1) the number of such cyberattacks during the year
preceding the submission of the report;
(2) with respect to each such cyberattack--
(A) an identification of the system that was targeted;
(B) a description of the effect on the safety of the
aircraft as a result of the cyberattack; and
(C) a description of the measures taken to counter or
mitigate the cyberattack;
(3) recommendations for preventing a future cyberattack;
(4) an analysis of potential vulnerabilities to
cyberattacks in systems on board an aircraft and in
maintenance or ground support systems for aircraft; and
(5) recommendations for improving the regulatory oversight
of aircraft cybersecurity.
(h) Definitions.--In subsections (f) and (g):
(1) Covered air carrier.--The term ``covered air carrier''
means an air carrier or a foreign air carrier (as those terms
are defined in section 40102 of title 49, United States
Code).
(2) Covered manufacturer.--The term ``covered
manufacturer'' means an entity that--
(A) manufactures or otherwise produces aircraft and holds a
production certificate under section 44704(c) of title 49,
United States Code; or
(B) manufactures or otherwise produces electronic control,
communications, maintenance, or ground support systems for
aircraft.
(3) Cyberattack.--The term ``cyberattack'' means the
unauthorized access to aircraft electronic control or
communications systems or maintenance or ground support
systems for aircraft, either wirelessly or through a wired
connection.
______