[Congressional Record Volume 162, Number 52 (Wednesday, April 6, 2016)]
[Senate]
[Page S1757]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 3468. Mr. MARKEY submitted an amendment intended to be proposed by 
him to the bill H.R. 636, to amend the Internal Revenue Code of 1986 to 
permanently extend increased expensing limitations, and for other 
purposes; which was ordered to lie on the table; as follows:

       On page 356, between lines 12 and 13, insert the following:
       (f) Disclosure of Cyberattacks by the Aviation Industry.--
       (1) In general.--Not later than 270 days after the date of 
     the enactment of this Act, the Secretary of Transportation 
     shall prescribe regulations requiring covered air carriers 
     and covered manufacturers to disclose to the Federal Aviation 
     Administration any attempted or successful cyberattack on any 
     system on board an aircraft, whether or not the system is 
     critical to the safe and secure operation of the aircraft, or 
     any maintenance or ground support system for aircraft, 
     operated by the air carrier or produced by the manufacturer, 
     as the case may be.
       (2) Use of disclosures by the federal aviation 
     administration.--The Administrator of the Federal Aviation 
     Administration shall use the information obtained through 
     disclosures made under paragraph (1) to improve the 
     regulations of the Federal Aviation Administration and to 
     notify air carriers, aircraft manufacturers, and other 
     Federal agencies of cybersecurity vulnerabilities in systems 
     on board an aircraft or maintenance or ground support systems 
     for aircraft.
       (g) Annual Report on Cyberattacks on Aircraft Systems and 
     Maintenance and Ground Support Systems.--Not later than one 
     year after the date of the enactment of this Act, and 
     annually thereafter, the Administrator of the Federal 
     Aviation Administration shall submit to the appropriate 
     committees of Congress a report on attempted and successful 
     cyberattacks on any system on board an aircraft, whether or 
     not the system is critical to the safe and secure operation 
     of the aircraft, and on maintenance or ground support systems 
     for aircraft, that includes--
       (1) the number of such cyberattacks during the year 
     preceding the submission of the report;
       (2) with respect to each such cyberattack--
       (A) an identification of the system that was targeted;
       (B) a description of the effect on the safety of the 
     aircraft as a result of the cyberattack; and
       (C) a description of the measures taken to counter or 
     mitigate the cyberattack;
       (3) recommendations for preventing a future cyberattack;
       (4) an analysis of potential vulnerabilities to 
     cyberattacks in systems on board an aircraft and in 
     maintenance or ground support systems for aircraft; and
       (5) recommendations for improving the regulatory oversight 
     of aircraft cybersecurity.
       (h) Definitions.--In subsections (f) and (g):
       (1) Covered air carrier.--The term ``covered air carrier'' 
     means an air carrier or a foreign air carrier (as those terms 
     are defined in section 40102 of title 49, United States 
     Code).
       (2) Covered manufacturer.--The term ``covered 
     manufacturer'' means an entity that--
       (A) manufactures or otherwise produces aircraft and holds a 
     production certificate under section 44704(c) of title 49, 
     United States Code; or
       (B) manufactures or otherwise produces electronic control, 
     communications, maintenance, or ground support systems for 
     aircraft.
       (3) Cyberattack.--The term ``cyberattack'' means the 
     unauthorized access to aircraft electronic control or 
     communications systems or maintenance or ground support 
     systems for aircraft, either wirelessly or through a wired 
     connection.
                                 ______