[Congressional Record Volume 163, Number 127 (Thursday, July 27, 2017)]
[Senate]
[Page S4587]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 686. Ms. WARREN submitted an amendment intended to be proposed by
her to the bill H.R. 2810, to authorize appropriations for fiscal year
2018 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. __. REPORT ON SIGNIFICANT SECURITY VULNERABILITIES OF
THE NATIONAL ELECTRIC GRID.
(a) Report Required.--Not later than 90 days after the date
of the enactment of this Act, the Secretary of Defense shall,
in consultation with the Director of National Intelligence
and the Secretary of Energy, submit to the congressional
defense committees a report setting forth the following:
(1) Identification of the significant security
vulnerabilities of the national electric grid that are
susceptible to significant malicious cyber-enabled
activities.
(2) An assessment of the effect of the security
vulnerabilities identified in paragraph (1) on the readiness
of the United States Armed Forces.
(3) An assessment of the strategic benefits derived from,
and the challenges associated with, isolating military
infrastructure from the national electric grid and the use of
microgrids by the Armed Forces.
(4) Recommendations on actions to be taken--
(A) to eliminate or mitigate the security vulnerabilities
identified pursuant to paragraph (1); and
(B) to address the effect of those security vulnerabilities
on the readiness of the Armed Forces identified pursuant to
paragraph (2).
(b) Form of Report.--The report required by subsection (a)
shall be submitted in unclassified form, but may include a
classified annex.
(c) Definitions.--In this section:
(1) The term ``security vulnerability'' has the meaning
given such term in section 102 of the Cybersecurity
Information Sharing Act of 2015 (6 U.S.C. 1501).
(2) The term ``significant malicious cyber-enabled
activities'' include--
(A) significant efforts--
(i) to deny access to or degrade, disrupt, or destroy an
information and communications technology system or network;
or
(ii) to exfiltrate, degrade, corrupt, destroy, or release
information from such a system or network without
authorization for purposes of--
(I) conducting influence operations; or
(II) causing a significant misappropriation of funds,
economic resources, trade secrets, personal identifications,
or financial information for commercial or competitive
advantage or private financial gain;
(B) significant destructive malware attacks; and
(C) significant denial of service activities.
______