[Congressional Record Volume 163, Number 98 (Thursday, June 8, 2017)]
[Senate]
[Pages S3366-S3367]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 226. Mr. VAN HOLLEN submitted an amendment intended to be proposed 
by him to the bill S. 722, to impose sanctions with respect to Iran in 
relation to Iran's ballistic missile program, support for acts of 
international terrorism, and violations of human rights, and for other 
purposes; which was ordered to lie on the table; as follows:

       At the end of the bill, add the following:

     SEC. 13. STRENGTHENING ALLIED CYBERSECURITY.

       (a) Short Title.--This section may be cited as the 
     ``Strengthening Allied Cybersecurity Act of 2017''.
       (b) Findings.--Congress makes the following findings:
       (1) In January 2017, the Director of National Intelligence 
     (referred to in this Act as the ``DNI''), in coordination 
     with the Central Intelligence Agency, the Federal Bureau of 
     Investigation (referred to in this Act as the ``FBI''), and 
     the National Security Agency, judged with high confidence 
     that Russian President Vladimir Putin ordered an influence 
     campaign aimed at the 2016 United States presidential 
     election.
       (2) The DNI report stated, ``[The Department of Homeland 
     Security] assesses that the types of systems Russian actors 
     targeted or compromised were not involved in vote 
     tallying.''.
       (3) On January 10, 2017, the DNI stated, in testimony 
     before the Select Committee on Intelligence of the Senate, 
     ``We can say that we did not see evidence of the Russians 
     altering vote tallies.''.
       (4) On March 20, 2017, FBI Director James Comey stated, in 
     testimony before the Permanent Select Committee on 
     Intelligence of the House of Representatives, ``We also, as a 
     government, supplied information to all the states so they 
     could equip themselves to make sure there was no successful 
     effort to affect the vote and there was none, as we said 
     earlier.''.

[[Page S3367]]

       (5) The DNI, in coordination with the Central Intelligence 
     Agency, the FBI, and the National Security Agency, judged 
     that Russia's intelligence services conducted cyber 
     operations against targets associated with the 2016 United 
     States presidential election.
       (6) The DNI assessed that the Russian Government's campaign 
     aimed at the United States election featured--
       (A) disclosures of data obtained through Russian cyber 
     operations;
       (B) intrusions into United States state and local election 
     boards; and
       (C) overt propaganda.
       (7) Russia's use of public disclosures of Russian-collected 
     data during the United States election was unprecedented.
       (8) The DNI, in coordination with the Central Intelligence 
     Agency, the FBI, and the National Security Agency, assessed 
     that Russia will apply lessons learned from its Putin-ordered 
     campaign aimed at the United States presidential election to 
     influence future elections worldwide, including against 
     United States allies and their election processes.
       (9) In May 2016, Germany's domestic intelligence agency 
     assessed that hackers linked to the Russian Government had 
     targeted Chancellor Angela Merkel's Christian Democratic 
     Union party and German state computers.
       (10) The head of Germany's foreign intelligence service, 
     Bruno Kahl, later asserted that Germany had ``evidence that 
     cyber-attacks are taking place that have no other purpose 
     than to elicit political uncertainty. The perpetrators are 
     interested in delegitimizing the democratic process as such, 
     regardless of who that ends of helping. We have indications 
     that [the attacks] come from the Russian region.'' In 
     November 2016, German Chancellor Merkel, said, ``such cyber-
     attacks, or hybrid conflicts as they are known in Russian 
     doctrine, are now part of daily life and we must learn to 
     cope with them''.
       (11) On May 9, 2017, Admiral Michael Rogers, United States 
     Cyber Command commander and Director of the National Security 
     Agency, testified before the Committee on Armed Services of 
     the Senate that the United States surveilled Russian hackers 
     attack French computer systems as the French election 
     approached. In his testimony, Rogers said, ``We had talked to 
     our French counterparts prior to the public announcements of 
     the events that were publicly attributed this past weekend, 
     and gave them a heads up, `Look we're watching the Russians, 
     we're seeing them penetrate some of your infrastructure.'.''.
       (12) In February 2017, the United Kingdom's Defence 
     Secretary Fallon stated that--
       (A) all North Atlantic Treaty Organization (NATO) countries 
     must support reform ``to make NATO more agile, resilient, and 
     better configured to operate in the contemporary environment 
     including against hybrid and cyber-attacks''; and
       (B) ``NATO must defend itself as effectively in the cyber 
     sphere as it does in the air, on land, and at sea.''.
       (c) Definitions.--In this section:
       (1) Appropriate federal agencies.--The term ``appropriate 
     Federal agencies'' means--
       (A) the Department of Defense;
       (B) the Department of Homeland Security;
       (C) the Department of Justice;
       (D) the Department of the Treasury;
       (E) the Office of the Director of National Intelligence; 
     and
       (F) the Department of Commerce
       (2) Hybrid warfare.--The term ``hybrid warfare'' means a 
     military strategy that blends conventional warfare, irregular 
     warfare, informational warfare, and cyber warfare.
       (3) Relevant congressional committees.--The term ``relevant 
     congressional committees'' means--
       (A) the Committee on Foreign Relations of the Senate;
       (B) the Committee on Foreign Affairs of the House of 
     Representatives;
       (C) the Subcommittee on State, Foreign Operations, and 
     Related Programs of the Committee on Appropriations of the 
     Senate;
       (D) the Subcommittee on State, Foreign Operations, and 
     Related Programs of the Committee on Appropriations of the 
     House of Representatives;
       (E) the Select Committee on Intelligence of the Senate;
       (F) the Permanent Select Committee on Intelligence of the 
     House of Representatives;
       (G) the Committee on Homeland Security and Governmental 
     Affairs of the Senate;
       (H) the Committee on Homeland Security of the House of 
     Representatives;
       (I) the Committee on Armed Services of the Senate;
       (J) the Committee on Armed Services of the House of 
     Representatives;
       (K) the Committee on the Judiciary of the Senate; and
       (L) the Committee on the Judiciary of the House of 
     Representatives.
       (d) Trans-Atlantic Cybersecurity Cooperation Strategy.--
       (1) In general.--Not later than 120 days after the date of 
     the enactment of this Act, the Secretary of State, in 
     coordination with the heads of the appropriate Federal 
     agencies, shall develop, and submit to the relevant 
     congressional committees, a trans-Atlantic cybersecurity 
     strategy, with a classified annex, if necessary, that 
     includes--
       (A) a plan of action to guide United States cooperation 
     with North Atlantic Treaty Organization (NATO) allies to 
     respond to Russia's hybrid warfare against NATO allies;
       (B) a plan of action to guide United States cooperation 
     with European partners, including non-NATO nations, to 
     counter Russia's cyber efforts to undermine democratic 
     elections in the United States and Europe;
       (C) an assessment of nonmilitary tools and tactics, 
     including sanctions, indictments, or other actions that the 
     United States can use, unilaterally or in cooperation with 
     like-minded nations, to counter Russia's malicious cyber 
     activity in the United States and Europe; and
       (D) a review of resources required by the Department of 
     State and appropriate Federal agencies to conduct activities 
     to build cooperation with NATO allies and European partners 
     on countering Russia's hybrid warfare and disinformation 
     efforts.
       (2) Civil liberties and privacy.--The Secretary of State 
     shall ensure that the implementation of the strategy 
     described in paragraph (1) is consistent with United States 
     standards for civil liberties and privacy protections.
       (e) Federal Cybersecurity Liaison to United States 
     Presidential Campaigns and Major National Political Party 
     Committees.--The Director of the Federal Bureau of 
     Investigation shall appoint, at the rank of Executive 
     Assistant Director, a cybersecurity liaison for presidential 
     campaigns and major national political party committees, who, 
     at the request of presidential campaigns and major national 
     political party committees, shall--
       (1) regularly share cybersecurity best practices and 
     protocols with each presidential campaign, the Democratic 
     National Committee, the Republican National Committee, the 
     Democratic Senatorial Campaign Committee, the National 
     Republican Senatorial Committee, the Democratic Congressional 
     Campaign Committee, and the National Republican Congressional 
     Committee; and
       (2) provide the timely sharing of cybersecurity threats to 
     such campaigns and committees to prevent or mitigate adverse 
     effects from such cybersecurity threats.
       (f) Reporting Requirement.--The Secretary of State, in 
     coordination with the heads of the appropriate Federal 
     agencies, shall submit an annual report to the relevant 
     congressional committees on the implementation of the trans-
     Atlantic cybersecurity cooperation strategy developed under 
     subsection (d).
                                 ______