[Congressional Record Volume 163, Number 143 (Wednesday, September 6, 2017)]
[Senate]
[Page S5008]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 794. Ms. WARREN (for herself and Mr. Tillis) submitted an 
amendment intended to be proposed by her to the bill H.R. 2810, to 
authorize appropriations for fiscal year 2018 for military activities 
of the Department of Defense, for military construction, and for 
defense activities of the Department of Energy, to prescribe military 
personnel strengths for such fiscal year, and for other purposes; which 
was ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. __. REPORT ON SIGNIFICANT SECURITY RISKS OF THE NATIONAL 
                   ELECTRIC GRID.

       (a) Report Required.--Not later than 90 days after the date 
     of the enactment of this Act, the Secretary of Defense shall, 
     in coordination with the Director of National Intelligence 
     and the Secretary of Energy, submit to the congressional 
     defense committees a report setting forth the following:
       (1) Identification of significant security risks to defense 
     critical electric infrastructure posed by significant 
     malicious cyber-enabled activities.
       (2) An assessment of the potential effect of the security 
     risks identified pursuant to paragraph (1) on the readiness 
     of the Armed Forces.
       (3) An assessment of the strategic benefits derived from, 
     and the challenges associated with, isolating military 
     infrastructure from the national electric grid and the use of 
     microgrids by the Armed Forces.
       (4) Recommendations on actions to be taken--
       (A) to eliminate or mitigate the security risks identified 
     pursuant to paragraph (1); and
       (B) to address the effect of those security risks on the 
     readiness of the Armed Forces identified pursuant to 
     paragraph (2).
       (b) Form of Report.--The report required by subsection (a) 
     shall be submitted in unclassified form, but may include a 
     classified annex.
       (c) Definitions.--In this section:
       (1) The term ``defense critical electric infrastructure''--
       (A) has the meaning given such term in section 215A(a) of 
     the Federal Power Act (16 U.S.C. 824o-1(a)); and
       (B) shall include any electric infrastructure located in 
     any of the 48 contiguous States or the District of Columbia 
     that serves a facility--
       (i) designated by the Secretary of Defense as--

       (I) critical to the defense of the United States; and
       (II) vulnerable to a disruption of the supply of electric 
     energy provided to such facility by an external provider; and

       (ii) that is not owned or operated by the owner or operator 
     of such facility.
       (2) The term ``security risk'' shall have such meaning as 
     the Secretary of Defense shall determine, in coordination 
     with the Director of National Intelligence and the Secretary 
     of Energy, for purposes of the report required by subsection 
     (a).
       (3) The term ``significant malicious cyber-enabled 
     activities'' include--
       (A) significant efforts--
       (i) to deny access to or degrade, disrupt, or destroy an 
     information and communications technology system or network; 
     or
       (ii) to exfiltrate, degrade, corrupt, destroy, or release 
     information from such a system or network without 
     authorization for purposes of--

       (I) conducting influence operations; or
       (II) causing a significant misappropriation of funds, 
     economic resources, trade secrets, personal identifications, 
     or financial information for commercial or competitive 
     advantage or private financial gain;

       (B) significant destructive malware attacks; and
       (C) significant denial of service activities.
                                 ______