[Congressional Record Volume 164, Number 96 (Monday, June 11, 2018)]
[Senate]
[Page S3638]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2664. Mr. WARNER (for himself and Mr. Kaine) submitted an
amendment intended to be proposed to amendment SA 2282 submitted by Mr.
Inhofe (for himself and Mr. McCain) and intended to be proposed to the
bill H.R. 5515, to authorize appropriations for fiscal year 2019 for
military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the end of part I of subtitle C of title XVI, add the
following:
SEC. ___. OVERSIGHT OF CYBER VULNERABILITY EVALUATIONS AND
MITIGATION STRATEGIES FOR MAJOR WEAPON SYSTEMS
OF THE DEPARTMENT OF DEFENSE.
(a) Budget Statement Required.--Beginning with fiscal year
2020 and for each fiscal year thereafter, the President shall
include in the supporting information submitted along with
the budget under section 1105 of title 31, United States
Code, for each major weapon system of the Department of
Defense for which funding is included in such budget, a
statement regarding the cyber vulnerabilities of the major
weapon system and matters regarding the mitigation of such
vulnerabilities.
(b) Contents.--Each statement for a major weapon system
required by subsection (a) shall include, for the major
weapon system, the following:
(1) Vulnerability evaluations.--
(A) Status.--A statement expressing whether the cyber
vulnerability evaluation required by section 1647(a) of the
National Defense Authorization Act for Fiscal Year 2016
(Public Law 114-92) of such major weapon system is pending,
in progress, complete, or waived in accordance with
subsection (a)(2) of such section 1647.
(B) Funding.--The seven-year funding profile needed to
complete the pending or in progress cyber vulnerability
evaluation.
(C) Description.--A description of the activities planned
in each fiscal year to complete the required evaluation.
(D) Risk analysis.--An assessment of the operational and
security risks associated with any cyber vulnerabilities
identified in the evaluation.
(2) Mitigation measures.--
(A) Status.--Whether--
(i) development of a strategy pursuant to subsection (d) of
such section is pending, in progress, or complete; and
(ii) activities to carry out such strategy are pending, in
progress, or complete.
(B) Funding.--The seven-year funding profile needed to
complete the pending or in progress mitigation strategy for
such major weapon system.
(C) Description.--A description of the activities planned
in each fiscal year to complete the mitigation strategy.
(c) Form.--The statement required by subsection (a) shall
be submitted in an unclassified form, but may include a
classified annex if necessary.
______