[Congressional Record Volume 163, Number 127 (Thursday, July 27, 2017)]
[Senate]
[Page S4587]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 686. Ms. WARREN submitted an amendment intended to be proposed by 
her to the bill H.R. 2810, to authorize appropriations for fiscal year 
2018 for military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. __. REPORT ON SIGNIFICANT SECURITY VULNERABILITIES OF 
                   THE NATIONAL ELECTRIC GRID.

       (a) Report Required.--Not later than 90 days after the date 
     of the enactment of this Act, the Secretary of Defense shall, 
     in consultation with the Director of National Intelligence 
     and the Secretary of Energy, submit to the congressional 
     defense committees a report setting forth the following:
       (1) Identification of the significant security 
     vulnerabilities of the national electric grid that are 
     susceptible to significant malicious cyber-enabled 
     activities.
       (2) An assessment of the effect of the security 
     vulnerabilities identified in paragraph (1) on the readiness 
     of the United States Armed Forces.
       (3) An assessment of the strategic benefits derived from, 
     and the challenges associated with, isolating military 
     infrastructure from the national electric grid and the use of 
     microgrids by the Armed Forces.
       (4) Recommendations on actions to be taken--
       (A) to eliminate or mitigate the security vulnerabilities 
     identified pursuant to paragraph (1); and
       (B) to address the effect of those security vulnerabilities 
     on the readiness of the Armed Forces identified pursuant to 
     paragraph (2).
       (b) Form of Report.--The report required by subsection (a) 
     shall be submitted in unclassified form, but may include a 
     classified annex.
       (c) Definitions.--In this section:
       (1) The term ``security vulnerability'' has the meaning 
     given such term in section 102 of the Cybersecurity 
     Information Sharing Act of 2015 (6 U.S.C. 1501).
       (2) The term ``significant malicious cyber-enabled 
     activities'' include--
       (A) significant efforts--
       (i) to deny access to or degrade, disrupt, or destroy an 
     information and communications technology system or network; 
     or
       (ii) to exfiltrate, degrade, corrupt, destroy, or release 
     information from such a system or network without 
     authorization for purposes of--

       (I) conducting influence operations; or
       (II) causing a significant misappropriation of funds, 
     economic resources, trade secrets, personal identifications, 
     or financial information for commercial or competitive 
     advantage or private financial gain;

       (B) significant destructive malware attacks; and
       (C) significant denial of service activities.
                                 ______