[Congressional Record Volume 164, Number 140 (Wednesday, August 22, 2018)]
[Senate]
[Pages S5855-S5859]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 3983. Ms. KLOBUCHAR submitted an amendment intended to be proposed 
by her to the bill H.R. 6157, making appropriations for the Department 
of Defense for the fiscal year ending September 30, 2019, and for other 
purposes; which was ordered to lie on the table; as follows:

       At the end, add the following:

                    DIVISION C--SECURE ELECTIONS ACT

     SEC. _01. SHORT TITLE.

       This division may be cited as the ``Secure Elections Act''.

     SEC. _02. DEFINITIONS.

       In this division:
       (1) Appropriate congressional committees.--The term 
     ``appropriate congressional committees'' means--
       (A) the Committee on Rules and Administration, the 
     Committee on Armed Services, the Committee on Homeland 
     Security and Governmental Affairs, the Committee on 
     Appropriations, the Select Committee on Intelligence, the 
     majority leader, and the minority leader of the Senate; and
       (B) the Committee on House Administration, the Committee on 
     Armed Services, the Committee on Homeland Security, the 
     Committee on Appropriations, the Permanent Select Committee 
     on Intelligence, the Speaker, and the minority leader of the 
     House of Representatives.
       (2) Appropriate federal entities.--The term ``appropriate 
     Federal entities'' means--
       (A) the Department of Commerce, including the National 
     Institute of Standards and Technology;
       (B) the Department of Defense;
       (C) the Department, including the component of the 
     Department that reports to the Under Secretary responsible 
     for overseeing critical infrastructure protection, 
     cybersecurity, and other related programs of the Department;
       (D) the Department of Justice, including the Federal Bureau 
     of Investigation;
       (E) the Commission; and
       (F) the Office of the Director of National Intelligence, 
     the National Security Agency, and such other elements of the 
     intelligence community (as defined in section 3 of the 
     National Security Act of 1947 (50 U.S.C. 3003)) as the 
     Director of National Intelligence determines are appropriate.
       (3) Commission.--The term ``Commission'' means the Election 
     Assistance Commission.
       (4) Cybersecurity incident.--The term ``cybersecurity 
     incident'' has the meaning given the term ``incident'' in 
     section 227 of the Homeland Security Act of 2002 (6 U.S.C. 
     148).
       (5) Department.--The term ``Department'' means the 
     Department of Homeland Security.
       (6) Election agency.--The term ``election agency'' means 
     any component of a State or any component of a county, 
     municipality, or other subdivision of a State that is 
     responsible for administering Federal elections.
       (7) Election cybersecurity incident.--The term ``election 
     cybersecurity incident'' means any cybersecurity incident 
     involving an election system.
       (8) Election cybersecurity threat.--The term ``election 
     cybersecurity threat'' means any cybersecurity threat (as 
     defined in section 102 of the Cybersecurity Information 
     Sharing Act of 2015 (6 U.S.C. 1501)) to an election system.
       (9) Election cybersecurity vulnerability.--The term 
     ``election cybersecurity vulnerability'' means any security 
     vulnerability (as defined in section 102 of the Cybersecurity 
     Information Sharing Act of 2015 (6 U.S.C. 1501)) that affects 
     an election system.
       (10) Election service provider.--The term ``election 
     service provider'' means any person providing, supporting, or 
     maintaining an election system on behalf of an election 
     agency, such as a contractor or vendor.
       (11) Election system.--The term ``election system'' means 
     the following:
       (A) Information technology infrastructure and systems used 
     to maintain voter registration databases.

[[Page S5856]]

       (B) Voting systems and associated infrastructure, which are 
     generally held in storage but are located at polling places 
     during early voting and on election day.
       (C) Information technology infrastructure and systems used 
     to manage elections, which may include systems that count, 
     audit, and display election results on election night on 
     behalf of State governments as well as for post-election 
     reporting used to certify and validate election results.
       (D) Such other systems the Secretary, in consultation with 
     the Commission, may identify as central to the management, 
     support, or administration of a Federal election.
       (12) Federal election.--The term ``Federal election'' means 
     a general, special, primary, or runoff election for the 
     office of President or Vice President, or of a Senator or 
     Representative in, or Delegate or Resident Commissioner to, 
     the Congress that is conducted by an election agency.
       (13) Federal entity.--The term ``Federal entity'' means any 
     agency (as defined in section 551 of title 5, United States 
     Code).
       (14) Secretary.--The term ``Secretary'' means the Secretary 
     of Homeland Security.
       (15) Significant cybersecurity incident.--The term 
     ``significant cybersecurity incident'' is a cybersecurity 
     incident that is, or a group of related cybersecurity 
     incidents that together are, likely to result in demonstrable 
     harm to the national security interests, foreign relations, 
     or economy of the United States or to the public confidence, 
     civil liberties, or public health and safety of the American 
     people.
       (16) Significant election cybersecurity incident.--The term 
     ``significant election cybersecurity incident'' means any 
     significant cybersecurity incident involving an election 
     system.
       (17) State.--The term ``State'' means each of the several 
     States of the United States, the District of Columbia, the 
     Commonwealth of Puerto Rico, Guam, American Samoa, the 
     Commonwealth of Northern Mariana Islands, and the United 
     States Virgin Islands.
       (18) State election official.--The term ``State election 
     official'' means--
       (A) the chief State election official of a State designated 
     under section 10 of the National Voter Registration Act of 
     1993 (52 U.S.C. 20509); or
       (B) in the Commonwealth of Puerto Rico, Guam, American 
     Samoa, the Commonwealth of Northern Mariana Islands, and the 
     United States Virgin Islands, a chief State election official 
     designated by the State for purposes of this division.
       (19) Voting system.--The term ``voting system'' has the 
     meaning given the term in section 301(b) of the Help America 
     Vote Act of 2002 (52 U.S.C. 21081(b)).

     SEC. _03. INFORMATION SHARING.

       (a) Designation of Responsible Federal Entity.--The 
     Secretary shall have primary responsibility within the 
     Federal Government for sharing information about election 
     cybersecurity incidents, threats, and vulnerabilities with 
     Federal entities and with election agencies.
       (b) Presumption of Federal Information Sharing to the 
     Department.--If a Federal entity receives information about 
     an election cybersecurity incident, threat, or vulnerability, 
     the Federal entity shall promptly share that information with 
     the Department, unless the head of the entity (or a Senate-
     confirmed official designated by the head) makes a specific 
     determination in writing that there is good cause to withhold 
     the particular information.
       (c) Establishment of Information Sharing Plans and 
     Protocols.--
       (1) In general.--The Secretary shall establish and maintain 
     a communication plan and protocols to promptly share 
     information related to election cybersecurity incidents, 
     threats, and vulnerabilities.
       (2) Contents.--The communication plan and protocols 
     required to be established under paragraph (1) shall require 
     that the Department promptly share appropriate information 
     with--
       (A) the appropriate Federal entities;
       (B) all State election officials;
       (C) to the maximum extent practicable, all election 
     agencies that have requested ongoing updates on election 
     cybersecurity incidents, threats, or vulnerabilities; and
       (D) to the maximum extent practicable, all election 
     agencies that may be affected by the risks associated with 
     the particular election cybersecurity incident, threat, or 
     vulnerability.
       (d) Development of State Election Cybersecurity Incident 
     Response and Communication Plan Template.--The Secretary 
     shall, in coordination with the Commission and the Election 
     Infrastructure Government Coordinating Council, establish a 
     template that a State may use when establishing a State 
     election cybersecurity incident response and communication 
     plan.
       (e) Technical Resources for Election Agencies.--In sharing 
     information about election cybersecurity incidents, threats, 
     and vulnerabilities with election agencies under this 
     section, the Department shall, to the maximum extent 
     practicable--
       (1) provide cyber threat indicators and defensive measures 
     (as such terms are defined in section 102 of the 
     Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 
     1501)), such as recommended technical instructions, that 
     assist with preventing, mitigating, and detecting threats or 
     vulnerabilities;
       (2) identify resources available for protecting against, 
     detecting, responding to, and recovering from associated 
     risks, including technical capabilities of the Department; 
     and
       (3) provide guidance about further sharing of the 
     information.
       (f) Declassification Review.--If the Department receives 
     classified information about an election cybersecurity 
     incident, threat, or vulnerability--
       (1) the Secretary shall promptly submit a request for 
     expedited declassification review to the head of a Federal 
     entity with authority to conduct the review, consistent with 
     Executive Order 13526 or any successor order, unless the 
     Secretary determines that such a request would be harmful to 
     national security; and
       (2) the head of the Federal entity described in paragraph 
     (1) shall promptly conduct the review.
       (g) Role of Non-Federal Entities.--The Department may share 
     information about election cybersecurity incidents, threats, 
     and vulnerabilities through a non-Federal entity.
       (h) Protection of Personal and Confidential Information.--
       (1) In general.--If a Federal entity shares or receives 
     information relating to an election cybersecurity incident, 
     threat, or vulnerability, the Federal entity shall, within 
     Federal information systems (as defined in section 3502 of 
     title 44, United States Code) of the entity--
       (A) minimize the acquisition, use, and disclosure of 
     personal information of voters, except as necessary to 
     identify, protect against, detect, respond to, or recover 
     from election cybersecurity incidents, threats, and 
     vulnerabilities;
       (B) notwithstanding any other provision of law, prohibit 
     the retention of personal information of voters, such as--
       (i) voter registration information, including physical 
     address, email address, and telephone number;
       (ii) political party affiliation or registration 
     information; and
       (iii) voter history, including registration status or 
     election participation; and
       (C) protect confidential Federal and State information from 
     unauthorized disclosure.
       (2) Exemption from disclosure.--Information relating to an 
     election cybersecurity incident, threat, or vulnerability, 
     such as personally identifiable information of reporting 
     persons or individuals affected by such incident, threat, or 
     vulnerability, shared by or with the Federal Government shall 
     be--
       (A) deemed voluntarily shared information and exempt from 
     disclosure under section 552 of title 5, United States Code, 
     and any State, tribal, or local provision of law requiring 
     disclosure of information or records; and
       (B) withheld, without discretion, from the public under 
     section 552(b)(3)(B) of title 5, United States Code, and any 
     State, tribal, or local provision of law requiring disclosure 
     of information or records.
       (i) Duty To Assess Possible Cybersecurity Incidents.--
       (1) Election agencies.--If an election agency becomes aware 
     of the possibility of an election cybersecurity incident, the 
     election agency shall promptly--
       (A) assess whether an election cybersecurity incident 
     occurred;
       (B) notify the State election official in accordance with 
     any notification process established by the State election 
     official; and
       (C) notify the Department in accordance with subsection 
     (j).
       (2) Election service providers.--If an election service 
     provider becomes aware of the possibility of an election 
     cybersecurity incident, the election service provider shall 
     promptly--
       (A) assess whether an election cybersecurity incident 
     occurred; and
       (B) notify the relevant election agencies in accordance 
     with subsection (k).
       (j) Information Sharing About Cybersecurity Incidents by 
     Election Agencies.--If an election agency has reason to 
     believe that an election cybersecurity incident has occurred 
     with respect to an election system owned, operated, or 
     maintained by or on behalf of the election agency, the 
     election agency shall, in the most expedient time possible 
     and without unreasonable delay, provide notification of the 
     election cybersecurity incident to the Department in 
     accordance with any notification process established by the 
     Secretary.
       (k) Information Sharing About Cybersecurity Incidents by 
     Election Service Providers.--If an election service provider 
     has reason to believe that an election cybersecurity incident 
     may have occurred, or that an incident related to the role of 
     the provider as an election service provider may have 
     occurred, the election service provider shall--
       (1) notify the relevant election agencies in the most 
     expedient time possible and without unreasonable delay; and
       (2) cooperate with the election agencies in providing the 
     notifications required under subsections (i)(1) and (j).
       (l) Content of Notification by Election Agencies.--The 
     notifications required under subsections (i)(1) and (j)--
       (1) shall include an initial assessment of--
       (A) the date, time, and time zone when the election 
     cybersecurity incident began, if known;
       (B) the date, time, and time zone when the election 
     cybersecurity incident was detected;
       (C) the date, time, and duration of the election 
     cybersecurity incident;
       (D) the circumstances of the election cybersecurity 
     incident, including the specific election systems believed to 
     have been accessed and information acquired; and

[[Page S5857]]

       (E) planned and implemented technical measures to respond 
     to and recover from the incident; and
       (2) shall be updated with additional material information, 
     including technical data, as it becomes available.
       (m) Security Clearance.--Not later than 30 days after the 
     date of enactment of this Act, the Secretary--
       (1) shall establish an expedited process for providing 
     appropriate security clearance to State election officials 
     and designated technical personnel employed by State election 
     agencies;
       (2) shall establish an expedited process for providing 
     appropriate security clearance to members of the Commission 
     and designated technical personnel employed by the 
     Commission; and
       (3) shall establish a process for providing appropriate 
     security clearance to personnel at other election agencies.
       (n) Protection From Liability.--Nothing in this division 
     may be construed to provide a cause of action against a 
     State, unit of local government, or an election service 
     provider.
       (o) Assessment of Inter-state Information Sharing About 
     Election Cybersecurity.--
       (1) In general.--The Secretary and the Commission, in 
     coordination with the heads of the appropriate Federal 
     entities and appropriate officials of State and local 
     governments, shall conduct an assessment of--
       (A) the structure and functioning of the Elections 
     Infrastructure Information Sharing and Analysis Center for 
     purposes of election cybersecurity; and
       (B) other mechanisms for inter-state information sharing 
     about election cybersecurity.
       (2) Comment from election agencies.--In carrying out the 
     assessment required under paragraph (1), the Secretary and 
     the Commission shall solicit and consider comments from all 
     State election agencies.
       (3) Distribution.--The Secretary and the Commission shall 
     jointly issue the assessment required under paragraph (1) 
     to--
       (A) all election agencies known to the Department and the 
     Commission; and
       (B) the appropriate congressional committees.
       (p) Congressional Notification.--If an appropriate Federal 
     entity has reason to believe that a significant election 
     cybersecurity incident has occurred, the entity shall--
       (1) not later than 7 calendar days after the date on which 
     there is a reasonable basis to conclude that the significant 
     election cybersecurity incident has occurred, provide 
     notification of the significant election cybersecurity 
     incident to the appropriate congressional committees; and
       (2) update the initial notification under paragraph (1) 
     within a reasonable period of time after additional 
     information relating to the significant election 
     cybersecurity incident is discovered.

     SEC. _04. REQUIREMENT FOR THE ESTABLISHMENT OF CYBERSECURITY 
                   INCIDENT RESPONSE PLANS.

       (a) In General.--Subtitle D of title II of the Help America 
     Vote Act of 2002 (52 U.S.C. 20901 et seq.) is amended by 
     adding at the end the following new part:

             ``PART 7--REQUIREMENTS FOR ELECTION ASSISTANCE

     ``SEC. 297. ELECTION CYBERSECURITY INCIDENT RESPONSE AND 
                   COMMUNICATION PLANS.

       ``No State may receive any grant awarded under this Act 
     after the date of the enactment of this section unless such 
     State has established a response and communication plan with 
     respect to election cybersecurity incidents (as defined in 
     section 2(7) of the Secure Elections Act). Nothing in this 
     section shall prohibit a State from using funds awarded 
     before the date of the enactment of this section for any use 
     otherwise authorized by law.''.
       (b) Conforming Amendment.--The table of contents in section 
     1(b) of the Help America Vote Act of 2002 is amended by 
     inserting after the item relating to section 296 the 
     following:

             ``PART 7--Requirements for Election Assistance

``Sec. 297. Election cybersecurity incident response and communication 
              plans.''.

     SEC. _05. ELECTION CYBERSECURITY AND ELECTION AUDIT 
                   GUIDELINES.

       (a) Development by Technical Advisory Board.--
       (1) In general.--
       (A) Additional duties.--Section 221(b)(1) of the Help 
     America Vote Act of 2002 (52 U.S.C. 20961(b)(2)) is amended 
     by striking ``in the development of the voluntary voting 
     system guidelines'' and inserting ``in the development of--
       ``(A) the voluntary voting system guidelines;
       ``(B) the voluntary election cybersecurity guidelines 
     (referred to in this part as the `election cybersecurity 
     guidelines') in accordance with paragraph (3); and
       ``(C) the voluntary election audit guidelines (referred to 
     in this part as the `election audit guidelines') in 
     accordance with paragraph (4).''.
       (B) Conforming amendments.--Sections 202(1) and 207(3) of 
     the Help America Vote Act of 2002 (52 U.S.C. 20922(1) and 
     20927(3)) are each amended by striking ``voluntary voting 
     system''.
       (2) Membership and renaming of technical guidelines 
     development committee.--
       (A) Membership.--Section 221(c)(1) of the Help America Vote 
     Act of 2002 (52 U.S.C. 20961(c)(1)) is amended--
       (i) by striking ``14'' and inserting ``19''; and
       (ii) by striking subparagraphs (A) through (E) and 
     inserting the following:
       ``(A) 2 Members of the Standards Board who are not 
     affiliated with the same political party--
       ``(i) 1 of whom is a local election official; and
       ``(ii) 1 of whom is a State election official.
       ``(B) 2 Members of the Board of Advisors who are not 
     affiliated with the same political party.
       ``(C) 2 Members of the Architectural and Transportation 
     Barrier Compliance Board under section 502 of the 
     Rehabilitation Act of 1972 (29 U.S.C. 792).
       ``(D) A representative of the Institute of Electrical and 
     Electronics Engineers.
       ``(E) 2 representatives of the National Association of 
     Secretaries of State selected by such Association who are not 
     members of the Standards Board or Board of Advisors, and who 
     are not of the same political party.
       ``(F) 2 representatives of the National Association of 
     State Election Directors selected by such Association who are 
     not members of the Standards Board or Board of Advisors, and 
     who are not of the same political party.
       ``(G) A representative of the Department of Homeland 
     Security who possesses technical and scientific expertise 
     relating to cybersecurity and the administration of 
     elections.
       ``(H) A representative of the Election Infrastructure 
     Information Sharing and Analysis Center who possesses 
     technical and scientific expertise relating to cybersecurity.
       ``(I) A representative of the National Association of State 
     Chief Information Officers.
       ``(J) A representative of State election information 
     technology directors selected by the National Association of 
     State Election Directors.
       ``(K) A representative of a manufacturer of voting system 
     hardware and software who possesses technical and scientific 
     expertise relating to cybersecurity and the administration of 
     elections.
       ``(L) A representative of a laboratory accredited under 
     section 231(b) who possesses technical and scientific 
     expertise relating to cybersecurity and the administration of 
     elections.
       ``(M) A representative that is an academic or scientific 
     researcher who possesses technical and scientific expertise 
     relating to cybersecurity.
       ``(N) A representative who possesses technical and 
     scientific expertise relating to the accessibility and 
     usability of voting systems.''.
       (B) Renaming of committee.--
       (i) In general.--Section 221(a) of the Help America Vote 
     Act of 2002 (52 U.S.C. 20961(a)) is amended by striking 
     ``Technical Guidelines Development Committee (hereafter in 
     this part referred to as the `Development Committee')'' and 
     inserting ``Technical Advisory Board''.
       (ii) Conforming amendments.--

       (I) Section 201 of such Act (52 U.S.C. 20921) is amended by 
     striking ``Technical Guidelines Development Committee'' and 
     inserting ``Technical Advisory Board''.
       (II) Section 221 of such Act (52 U.S.C. 20921) is amended 
     by striking ``Development Committee'' each place it appears 
     and inserting ``Technical Advisory Board''.
       (III) Section 222(b) of such Act (52 U.S.C. 20962(b)) is 
     amended--

       (aa) by striking ``Technical Guidelines Development 
     Committee'' in paragraph (1) and inserting ``Technical 
     Advisory Board'',
       (bb) by striking ``Development Committee'' in the heading 
     and inserting ``Technical Advisory Board'', and

       (IV) Section 271(e) of such Act (52 U.S.C. 21041(e)) is 
     amended by striking ``Technical Guidelines Development 
     Committee'' and inserting ``Technical Advisory Board''.
       (V) Section 281(d) of such Act (52 U.S.C. 21051(d)) is 
     amended by striking ``Technical Guidelines Development 
     Committee'' and inserting ``Technical Advisory Board''.
       (VI) The heading for section 221of such Act (52 U.S.C. 
     20961) is amended by striking ``technical guidelines 
     development committee'' and inserting ``technical advisory 
     board''.
       (VII) The heading for part 3 of subtitle A of title II of 
     such Act is amended by striking ``technical guidelines 
     development committee'' and inserting ``technical advisory 
     board''.
       (VIII) The items relating to section 221 and part 3 of 
     title II in the table of contents of such Act are each 
     amended by striking ``Technical Guidelines Development 
     Committee'' and inserting ``Technical Advisory Board''.

       (b) Guidelines.--
       (1) Election cybersecurity guidelines.--Section 221(b) of 
     the Help America Vote Act of 2002 (52 U.S.C. 20961(b)) is 
     amended by adding at the end the following new paragraph:
       ``(3) Election cybersecurity guidelines.--
       ``(A) In general.--The election cybersecurity guidelines 
     shall contain guidelines for election cybersecurity, 
     including standards for procuring, maintaining, testing, 
     operating, and updating election systems.
       ``(B) Requirements.--In developing the guidelines, the 
     Technical Advisory Board shall--
       ``(i) identify the top risks to election systems;
       ``(ii) describe how specific technology choices can 
     increase or decrease those risks; and

[[Page S5858]]

       ``(iii) provide recommended policies, best practices, and 
     overall security strategies for identifying, protecting 
     against, detecting, responding to, and recovering from the 
     risks identified under subparagraph (A).
       ``(C) Issues considered.--
       ``(i) In general.--In developing the election cybersecurity 
     guidelines, the Technical Advisory Board shall consider--

       ``(I) applying established cybersecurity best practices to 
     Federal election administration by States and local 
     governments, including appropriate technologies, procedures, 
     and personnel for identifying, protecting against, detecting, 
     responding to, and recovering from election cybersecurity 
     incidents, threats, and vulnerabilities;
       ``(II) providing actionable guidance to election agencies 
     that seek to implement additional cybersecurity protections; 
     and
       ``(III) any other factors that the Technical Advisory Board 
     determines to be relevant.

       ``(D) Relationship to voluntary voting system guidelines 
     and national institute of standards and technology 
     cybersecurity guidance.--In developing the election 
     cybersecurity guidelines, the Technical Advisory Board shall 
     consider--
       ``(i) the voluntary voting system guidelines; and
       ``(ii) cybersecurity standards and best practices developed 
     by the National Institute of Standards and Technology, 
     including frameworks, consistent with section 2(c) of the 
     National Institute of Standards and Technology Act (15 U.S.C. 
     272(c)).''.
       (2) Audit guidelines.--Section 221(b) of such Act (52 
     U.S.C. 20961(b)), as amended by paragraph (1), is amended by 
     adding at the end the following new paragraph:
       ``(4) Election audit guidelines.--
       ``(A) In general.--The election audit guidelines shall 
     include provisions regarding voting systems and statistical 
     audits for Federal elections, including that--
       ``(i) each vote is cast using a voting system that allows 
     the voter an opportunity to inspect and confirm the marked 
     ballot before casting it (consistent with accessibility 
     requirements); and
       ``(ii) each election result is determined by tabulating 
     marked ballots, and prior to the date on which the winning 
     Federal candidate in the election is sworn into office, 
     election agencies within the State inspect a random sample of 
     the marked ballots and thereby establish high statistical 
     confidence in the election result.
       ``(B) Issues considered.--In developing the election audit 
     guidelines, the Technical Advisory Board shall consider--
       ``(i) specific types of election audits, including 
     procedures and shortcomings for such audits;
       ``(ii) mechanisms to verify that election systems 
     accurately tabulate ballots, report results, and identify a 
     winner for each election for Federal office, even if there is 
     an error or fault in the voting system;
       ``(iii) durational requirements needed to facilitate 
     election audits in a timely manner that allows for confidence 
     in the outcome of the election prior to the swearing-in of a 
     Federal candidate, including variations in the acceptance of 
     postal ballots, time allowed to cure provisional ballots, and 
     election certification deadlines;
       ``(iv) the importance of manual (by hand, not device) 
     inspections of original marked paper ballots to provide 
     audits without serious vulnerabilities; and
       ``(v) any other factors that the Technical Advisory Board 
     considers to be relevant.''.
       (3) Deadlines.--Section 221(b)(2) of such Act (52 U.S.C. 
     20961(b)(2)), as amended by this Act, is amended--
       (A) by striking ``The Technical'' and inserting the 
     following:
       ``(A) Voluntary voting system guidelines.--The Technical'';
       (B) by striking ``this section'' and inserting ``paragraph 
     (1)(A)''; and
       (C) by adding at the end the following new subparagraph:
       ``(B) Election cybersecurity and election audit 
     guidelines.--
       ``(i) Initial guidelines.--The Technical Advisory Board 
     shall provide its initial set of recommendations under 
     subparagraphs (B) and (C) of paragraph (1) to the Executive 
     Director not later than 180 days after the date of the 
     enactment of the Secure Elections Act.
       ``(ii) Periodic review.--Not later than March 31, 2021, and 
     once every 2 years thereafter, the Technical Advisory Board 
     shall review and update the guidelines described in 
     subparagraphs (B) and (C) of paragraph (1).''.
       (c) Process for Adoption.--
       (1) Publication of recommendations.--Section 221(f) of the 
     Help America Vote Act of 2002 (52 U.S.C. 20961(f)) is 
     amended--
       (A) by striking ``At the time the Commission'' and 
     inserting the following:
       ``(1) Voluntary voting system guidelines.--At the time the 
     Commission''; and.
       (B) by adding at the end the following new paragraph:
       ``(2) Election cybersecurity and election audit 
     guidelines.--The Technical Advisory Board shall--
       ``(A) provide a reasonable opportunity for public comment, 
     including through Commission publication in the Federal 
     Register, on the guidelines required under subparagraphs (B) 
     and (C) of subsection (b)(1), including a 45-day opportunity 
     for public comment on a draft of the guidelines before they 
     are submitted to Congress under section 223(a), which shall, 
     to the extent practicable, occur concurrently with the other 
     activities of the Technical Advisory Board under this section 
     with respect to such guidelines; and
       ``(B) consider the public comments in developing the 
     guidelines.''.
       (2) Adoption.--
       (A) In general.--Part 3 of subtitle A of title II of the 
     Help America Vote Act of 2002 (52 U.S.C. 20961 et seq.) is 
     amended--
       (i) by inserting ``of voluntary voting guidelines'' after 
     ``adoption'' in the heading of section 222; and
       (ii) by adding at the end the following new section:

     ``SEC. 223. PROCESS FOR ADOPTION OF ELECTION CYBERSECURITY 
                   AND ELECTION AUDIT GUIDELINES.

       ``(a) Submission to Congress.--
       ``(1) In general.--Not later than 30 calendar days after 
     the date on which the Commission receives recommendations for 
     the guidelines described in subparagraphs (B) or (C) of 
     section 221(b)(1), the Commission shall consider the 
     guidelines and submit the guidelines to the appropriate 
     congressional committees.
       ``(2) Modification.--In considering the guidelines, the 
     Commission may modify the guidelines if--
       ``(A) the Commission determines that there is good cause to 
     modify the guidelines, consistent with the considerations 
     established in paragraphs (3) or (4) of section 221(b) (as 
     the case may be) and notwithstanding the recommendation of 
     the Technical Advisory Board; and
       ``(B) the Commission submits a written justification of the 
     modification to the Technical Advisory Board and the 
     appropriate congressional committees.
       ``(b) Distribution to Election Agencies.--The Commission 
     shall distribute the guidelines described in subparagraphs 
     (B) and (C) of section 221(b)(1) to all election agencies 
     known to the Commission.
       ``(c) Publication.--The Commission shall make the 
     guidelines described in subparagraphs (B) and (C) of section 
     221(b)(1) available on the public website of the Commission.
       ``(d) Appropriate Congressional Committees.--For purposes 
     of this section, the term `appropriate congressional 
     committees' means--
       ``(1) the Committee on Rules and Administration, the 
     Committee on Armed Services, the Committee on Homeland 
     Security and Governmental Affairs, the Committee on 
     Appropriations, the Select Committee on Intelligence, the 
     majority leader, and the minority leader of the Senate; and
       ``(2) the Committee on House Administration, the Committee 
     on Armed Services, the Committee on Homeland Security, the 
     Committee on Appropriations, the Permanent Select Committee 
     on Intelligence, the Speaker, and the minority leader of the 
     House of Representatives.
       ``(e) Rule of Construction.--Nothing in this section shall 
     be construed to subject the process for developing the 
     guidelines described in subparagraphs (B) and (C) of section 
     221(b)(1) to subchapter II of chapter 5, and chapter 7, of 
     title 5, United States Code (commonly known as the 
     `Administrative Procedure Act').''.
       (B) Clerical amendment.--The table of contents of such Act 
     is amended by inserting after the item relating to section 
     222 the following new item:

``Sec. 223. Process for adoption of election cybersecurity and election 
              audit guidelines.''.

     SEC. _06. REQUIREMENT TO CONDUCT POST-ELECTION AUDITS.

       (a) Requirement.--
       (1) In general.--Subtitle A of title III of the Help 
     America Vote Act of 2002 (52 U.S.C. 21081 et seq.) is 
     amended--
       (A) by redesignating sections 304 and 305 as sections 305 
     and 306, respectively; and
       (B) by inserting after section 303 the following new 
     section:

     ``SEC. 304. POST-ELECTION AUDITS.

       ``(a) In General.--Each State shall--
       ``(1) conduct a post-election audit of each Federal 
     election (as defined in section 2 of the Secure Elections 
     Act) through the inspection of a random sample of marked 
     ballots of sufficient quantity to establish high statistical 
     confidence in the election result;
       ``(2) provide a description of the planned audit, excluding 
     any information deemed to create a security risk, to be 
     conducted under paragraph (1) on a public website 
     administered by the chief State election official 90 days 
     prior to each such Federal election; and
       ``(3) provide results of the completed audit under 
     paragraph (1) on a public website administered by the chief 
     State election official within 10 days of the completion of 
     the audit.
       ``(b) Time for Completing Audit.--The audit required by 
     subsection (a) shall be completed in a timely manner to 
     ensure confidence in the outcome of the election and before--
       ``(1) in the case of a primary election, the date the 
     candidate is placed on the general election ballot; and
       ``(2) in the case of a general election, the date on which 
     the winning candidate in the election is sworn into office.
       ``(c) Effective Date.--
       ``(1) In general.--Except as provided in paragraph (2), 
     each State shall be required to comply with the requirements 
     of this section for the regularly scheduled general election 
     for Federal office held in November 2020, and each subsequent 
     election for Federal office.
       ``(2) Waiver.--If a State certifies to the Commission not 
     later than November 1, 2020,

[[Page S5859]]

     that the State will not meet the deadline described in 
     paragraph (1) for good cause and includes in the 
     certification the reasons for the failure to meet such 
     deadline, paragraph (1) shall apply to the State as if the 
     reference in such subparagraph to `November 2020' were a 
     reference to `November 2022'.''.
       (2) Enforcement.--Section 401 of such Act (52 U.S.C. 21111) 
     is amended by striking ``and 303'' and inserting ``303, and 
     304''.
       (3) Clerical amendment.--The table of contents of such Act 
     is amended--
       (A) by redesignating the items relating to sections 304 and 
     305 as relating to sections 305 and 306, respectively; and
       (B) by inserting after the item relating to section 303 the 
     following new item:

``Sec. 304. Post-election audits.''.

       (b) Reporting.--The Election Assistance Commission shall--
       (1) collect information regarding audits conducted by 
     States under section 304 of the Help America Vote Act of 2002 
     (as added by subsection (a)); and
       (2) submit reports to Congress on the information provided 
     by the States under section 304(a)(2) and 304(a)(3) of such 
     Act (as so added) and other information collected by the 
     Commission under paragraph (1).
     The reports under paragraph (2) shall be submitted 
     concurrently with the reports required under section 9(a)(3) 
     of the National Voter Registration Act of 1993.

     SEC. _07. REQUIREMENT FOR PAPER BALLOTS.

       (a) In General.--Part 7 of subtitle D of title II of the 
     Help America Vote Act of 2002, as added by section 4, is 
     amended by adding at the end the following new section:

     ``SEC. 298. PAPER BALLOTS.

       ``No State or jurisdiction may use any grant awarded under 
     this Act after the date of the enactment of this section to 
     obtain voting equipment unless such voting equipment records 
     each vote on a marked or printed, individualized, readable 
     paper ballot and allows the voter an opportunity to inspect 
     and confirm the marked or printed ballot (consistent with 
     accessibility requirements under Federal law) before the 
     ballot is cast and counted. Nothing in this section shall 
     prohibit a State from using funds awarded before the date of 
     the enactment of this section to obtain such equipment.''.
       (b) Conforming Amendment.--The table of contents in section 
     1(b) of the Help America Vote Act of 2002, as amended by 
     section 4, is amended by inserting after the item relating to 
     section 297 the following:

``Sec. 298. Paper ballots.''.

     SEC. _08. STREAMLINING THE COLLECTION OF ELECTION 
                   INFORMATION.

       Section 202 of the Help America Vote Act of 2002 (52 U.S.C. 
     20922) is amended by adding at the end the following flush 
     sentence:
     ``Subchapter I of chapter 35 of title 44, United States Code, 
     shall not apply to the collection of information for purposes 
     of maintaining any clearinghouse with respect to the 
     administration of Federal elections or the experiences of 
     State and local governments in implementing the guidelines 
     described in paragraph (1) or in operating voting systems in 
     general.''.

     SEC. _09. REPORTS TO CONGRESS ON FOREIGN THREATS TO 
                   ELECTIONS.

       (a) In General.--Not later than 30 days after the date of 
     enactment of this Act, and 90 days before the end of each 
     fiscal year thereafter, the Secretary and the Director of 
     National Intelligence, in coordination with the heads of the 
     appropriate Federal entities, shall submit a joint report to 
     the appropriate congressional committees on foreign threats 
     to elections in the United States, including physical and 
     cybersecurity threats.
       (b) Voluntary Participation by States.--The Secretary shall 
     solicit and consider comments from all State election 
     agencies. Participation by an election agency in the report 
     under this subsection shall be voluntary and at the 
     discretion of the State.

     SEC. _10. STATE ELECTION SYSTEM CYBERSECURITY MODERNIZATION 
                   AND MAINTENANCE GRANTS.

       (a) In General.--The Help America Vote Act of 2002 (52 
     U.S.C. 20901 et seq.) is amended by adding at the end the 
     following new title:

   ``TITLE X--PAYMENTS TO STATES FOR CYBERSECURITY MODERNIZATION AND 
                              MAINTENANCE

     ``SEC. 1001. DEFINITIONS.

       ``For purposes of this title:
       ``(1) Cyber navigator program.--The term `cyber navigator 
     program' means a program under which the State election 
     official employs election technology professionals to provide 
     practical cybersecurity knowledge, support, and services to 
     local election officials, including--
       ``(A) assessments of local election offices;
       ``(B) support to local information technology staff or 
     vendors in creating cyber security policies for voting 
     systems (as defined in section 301(b));
       ``(C) services to mitigate vulnerabilities discovered 
     during an assessment and to improve cybersecurity of a local 
     election office;
       ``(D) the establishment of best cyber hygiene practices 
     within an office; and
       ``(E) advice on the purchase of new election systems.
       ``(2) State.--The term `State' means each of the several 
     States of the United States and the District of Columbia.

     ``SEC. 1002. PAYMENTS TO STATES.

       ``(a) In General.--The Commission shall award annual grants 
     to States in accordance with this section.
       ``(b) Use of Funds.--A State receiving a grant under this 
     section shall use the funds received under the grant only 
     to--
       ``(1) upgrade election-related computer systems to address 
     cyber vulnerabilities consistent with best practices 
     recommended by the Department of Homeland Security, the 
     National Institute of Standards and Technology, and the 
     Commission;
       ``(2) implement a post-election audit system that provides 
     a high statistical confidence in the election result;
       ``(3) obtain or facilitate cybersecurity training for 
     officials in the office of the State election official and 
     for local election officials; and
       ``(4) establish or maintain a cyber navigator program.
       ``(c) Amount of Grants.--
       ``(1) In general.--Subject to paragraph (3), the amount of 
     funds provided to a State under a grant under this section 
     for any calendar year shall be equal to the product obtained 
     by multiplying--
       ``(A) the total amount appropriated for grants pursuant to 
     the authorization under section 1003(a); by
       ``(B) the State allocation percentage for the State (as 
     determined under paragraph (2)).
       ``(2) State allocation percentage.--The State allocation 
     percentage for a State is the amount (expressed as a 
     percentage) equal to the quotient obtained by dividing--
       ``(A) the total voting age population of all States (as 
     reported in the most recent decennial census); by
       ``(B) the voting age population of the State (as reported 
     in the most recent decennial census).
       ``(3) Minimum and maximum amount of payment.--The amount 
     determined under this subsection--
       ``(A) may not be less than $2,500,000 and
       ``(B) may not be greater than $10,000,000.
       ``(4) Pro rata adjustment.--The Commission shall make such 
     pro rata adjustments to the allocations determined under 
     paragraph (1) as are necessary to comply with the 
     requirements of paragraph (3).

     ``SEC. 1003. AUTHORIZATION OF APPROPRIATIONS.

       ``(a) In General.--There is authorized to be appropriated 
     to the Commission $250,000,000 to carry out this title for 
     each of fiscal years 2019 and 2020.
       ``(b) Availability.--Any amounts appropriated pursuant to 
     paragraph (1) shall remain available without fiscal year 
     limitation until expended.
       ``(c) Authorization of Appropriations for Commission.--In 
     addition to the amounts authorized under subsection (a), 
     there are authorized to be appropriated to the Commission 
     such sums as may be necessary to administer the programs 
     under this title.''.
       (b) Conforming Amendments.--
       (1) Section 202 of the Help America Vote Act of 2002 (52 
     U.S.C. 20922) is amended by striking ``and'' at the end of 
     paragraph (5), by striking the period at the end of paragraph 
     (6) and inserting ``; and'', and by adding at the end the 
     following new paragraph:
       ``(7) carrying out the grant program under title X.''.
       (2) The table of contents of such Act is amended by adding 
     at the end the following:

   ``TITLE X--PAYMENTS TO STATES FOR CYBERSECURITY MODERNIZATION AND 
                              MAINTENANCE

``Sec. 1001. Definitions.
``Sec. 1002. Payments to States.
``Sec. 1003. Authorization of appropriations.''.
                                 ______