[Congressional Record Volume 163, Number 127 (Thursday, July 27, 2017)]
[Senate]
[Pages S4538-S4539]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 575. Mr. NELSON submitted an amendment intended to be proposed by 
him to the bill H.R. 2810, to authorize appropriations for fiscal year 
2018 for military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the end of subtitle __ of title __, add the following:

     SEC. ___. PROTECTING CRITICAL INFRASTRUCTURE AGAINST CYBER 
                   ATTACKS FROM FOREIGN GOVERNMENTS.

       (a) Findings.--Congress finds the following:
       (1) Authoritative evidence and testimony to Congress 
     indicate that the United States Government cannot prevent 
     cyber attacks by determined and capable adversaries from 
     reaching critical infrastructure in the United States and 
     that, absent major efforts to identify and eliminate 
     vulnerabilities in the most critical nodes of the most 
     critical infrastructure, such attacks would succeed in 
     causing unacceptable damage to the United States.
       (2) To secure the United States against cyber attacks, it 
     is necessary to develop deterrence capabilities through a 
     combination of offensive cyber attack means and greater 
     survivability, resilience, and recovery capabilities in the 
     critical infrastructure of the United States.
       (3) Defense of the United States against cyber attacks from 
     foreign adversaries, including foreign governments, is a 
     responsibility of the Federal Government.
       (b) Sense of Congress.--It is the sense of Congress that--
       (1) the Federal Government should provide funding in a 
     collaborative effort with the owners of the most critical 
     infrastructure to identify vulnerabilities to cyber attacks 
     in the most critical nodes and develop solutions either 
     through alternative equipment and practices, or by assured 
     redundancy and recovery capabilities; and
       (2) Government funding should also help cover the cost of 
     any inefficiencies caused by changes in equipment, practices, 
     or recovery capabilities to protect critical infrastructure 
     against cyber attacks from foreign governments.
       (c) Analysis and Solution Designs.--The President shall--
       (1) conduct an analysis of cyber vulnerabilities in the 
     most critical nodes of the most critical infrastructure; and
       (2) design solutions to eliminate such vulnerabilities.
       (d) Report.--
       (1) In general.--Not later than one year after the date of 
     the enactment of this Act, the President shall submit to 
     Congress a report on the vulnerabilities identified under 
     paragraph (1) of subsection (c) and the solutions designed 
     under paragraph (2) of such subsection.

[[Page S4539]]

       (2) Contents.--The report required by paragraph (1) shall 
     include the following:
       (A) A description of the vulnerabilities identified under 
     paragraph (1) of subsection (c).
       (B) A description of the solutions designed under paragraph 
     (2) of such subsection.
       (C) A strategy for working with owners of relevant critical 
     infrastructure to eliminate vulnerabilities identified under 
     subsection (c)(1).
       (D) An estimate of the cost of carrying out the strategy 
     included under subparagraph (C) and a schedule to implement 
     such strategy.
       (e) Consideration of Investments Required.--The President 
     shall consider the investments required to correct the 
     vulnerabilities identified under subsection (c)(1) whenever 
     developing plans and proposals for national infrastructure 
     investment that the President submits to Congress.
                                 ______