[Congressional Record Volume 164, Number 97 (Tuesday, June 12, 2018)]
[Senate]
[Pages S3845-S3846]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2813. Mr. PERDUE submitted an amendment intended to be proposed to
amendment SA 2282 proposed by Mr. Inhofe (for himself and Mr. McCain)
to the bill H.R. 5515, to authorize appropriations for fiscal year 2019
for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the end of part I of subtitle C of title XVI, add the
following:
SEC. __. UNITED STATES CYBER STRATEGY.
(a) Strategy Required.--
(1) In general.--Not later than one year after the date of
the enactment of this Act, the President shall submit to the
appropriate congressional committees and make available to
the public a comprehensive, interagency national strategy for
cyberspace.
(2) Elements.--The comprehensive, interagency national
strategy required by paragraph (1) shall include the
following elements:
(A) A government-wide and accepted glossary of definitions
and terms for cyberspace and cyber-related activities.
(B) Criteria for the types of malicious cyber activities,
including cyber-enabled information warfare, that the United
States Government will seek to deter and will respond to.
(C) Processes, mechanisms, and authorities for attribution
of malicious cyber activities.
(D) Menu of options, and criteria for use of each, for
deterrence, denial, and response to malicious cyber
activities, including cyber-enabled information warfare,
using the range of national power to conduct.
(E) Tasks, roles, and responsibilities of the following
entities in regards to cyberspace:
(i) The Department of Homeland Security for domestic cyber
security concerns and defense of critical infrastructure.
(ii) The Department of Defense for military cyber
activities and offensive cyber operations.
(iii) The Department of State for cyber diplomacy and
promotion of United States values on fair use of cyberspace
and related activities.
(iv) The Department of Commerce for cybersecurity matters
relating to industry and economic needs, including standards,
research, innovation, and competitiveness.
(v) The Federal Bureau of Investigation for law enforcement
and intelligence relating to criminal behavior of persons,
individuals, and States, in cyberspace.
(vi) The intelligence community (as defined in section 3 of
the National Security Act of 1947 (50 U.S.C. 3003)).
(vii) Any other agency deemed appropriate by the President
to be a primary stakeholder for a cyber activity or related
policy.
(F) Specific tasks, roles, and responsibilities of the
above entities in regards to cybersecurity incidents
involving critical infrastructure, cybersecurity incidents
involving the .gov Internet domain, and other cybersecurity
incidents of significant consequence.
(G) A specific description of the communication,
cooperation, and deconfliction mechanisms used in the
interagency, especially in an incident response capacity.
(H) The specific priorities of the President in incident
response and generalized order of operations in the event of
a cyber attack to which the Federal Government is responding.
(I) Use of, coordination with, or liaison to international
partners, nongovernmental organizations, or commercial
entities that support United States policy goals in
cyberspace.
(J) The establishment of a permanent interagency working
group to continually implement, study, and revise the cyber
strategy for the whole of Government to meet emerging threats
and trends.
[[Page S3846]]
(K) Mechanisms for continuous information sharing among
Government agencies relating to cyber-enabled information
warfare, cyber threats, cyber attacks, cybersecurity
vulnerabilities, and cybersecurity technology.
(L) The development of a semiannual or biennial war game
involving all Federal agencies to determine best practices
for domestic and global responses to cyber events.
(M) Research and development priorities for the Federal
Government and the United States.
(N) Cooperative enterprises with the private sector and
State and local governments.
(O) Such other matters as the President considers
appropriate.
(b) Assessment.--Not later than one year after the date of
the submission of the strategy required by subsection (a),
and annually after that, the President shall submit to the
appropriate committees of Congress an assessment of the
strategy, including--
(1) the status of implementation of the strategy;
(2) any organizational realignment necessary for
implementation of the strategy, including consolidation of
responsibility and directive authorities under a single
entity at the Federal level;
(3) any insufficient capabilities of the entities listed in
subsection (a)(2)(E);
(4) plans for corrective action for such insufficiencies;
(5) brief and results of semiannual or biennial war games
prescribed in subsection (a)(2)(L); and
(6) any changes to the strategy since such submission.
(c) Form.--The strategy and assessment required by this
section shall each be submitted in unclassified form, but may
include a classified annex.
(d) Definitions.--In this section:
(1) The term ``appropriate congressional committees''
means--
(A) the congressional defense committees;
(B) the congressional intelligence committees (as defined
in section 3 of the National Security Act of 1947 (50 U.S.C.
3003));
(C) the Committee on Foreign Relations, the Committee on
Homeland Security and Governmental Affairs, the Committee on
the Judiciary, and the Committee on Commerce, Science, and
Transportation of the Senate; and
(D) the Committee on Foreign Affairs, the Committee on
Homeland Security, the Committee on Oversight and
Governmental Reform, the Committee on the Judiciary, and the
Committee on Energy and Commerce of the House of
Representatives.
(2) The term ``critical infrastructure'' has the meaning
given such term in section 2 of Executive Order 13696 of
February 12, 2013 (78 Fed. Reg. 11739), or successor order.
(3) The term ``incident''--
(A) means an occurrence that actually or imminently
jeopardizes, without lawful authority an information system
or the integrity, confidentiality, or availability of
information on an information system; and
(B) includes attacks carried out with intent, occurrences
that were the result of attacks, and occurrences with the
effect of attacks.
(4) The term ``of significant consequence'', with respect
to an incident, means the incident that occurred caused--
(A) casualties among United States persons or persons of
allies of the United States;
(B) significant damage to private or public property;
(C) significant economic disruption;
(D) an effect, whether individually or in aggregate,
comparable to that of an armed attack or one that imperils a
vital national security interest of the United States; or
(E) significant disruption of the normal functioning of
United States democratic society or government, including
attacks against or incidents involving critical
infrastructure that could damage systems used to provide key
services to the public or government.
______