[Congressional Record Volume 164, Number 140 (Wednesday, August 22, 2018)]
[Senate]
[Pages S5855-S5859]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 3983. Ms. KLOBUCHAR submitted an amendment intended to be proposed
by her to the bill H.R. 6157, making appropriations for the Department
of Defense for the fiscal year ending September 30, 2019, and for other
purposes; which was ordered to lie on the table; as follows:
At the end, add the following:
DIVISION C--SECURE ELECTIONS ACT
SEC. _01. SHORT TITLE.
This division may be cited as the ``Secure Elections Act''.
SEC. _02. DEFINITIONS.
In this division:
(1) Appropriate congressional committees.--The term
``appropriate congressional committees'' means--
(A) the Committee on Rules and Administration, the
Committee on Armed Services, the Committee on Homeland
Security and Governmental Affairs, the Committee on
Appropriations, the Select Committee on Intelligence, the
majority leader, and the minority leader of the Senate; and
(B) the Committee on House Administration, the Committee on
Armed Services, the Committee on Homeland Security, the
Committee on Appropriations, the Permanent Select Committee
on Intelligence, the Speaker, and the minority leader of the
House of Representatives.
(2) Appropriate federal entities.--The term ``appropriate
Federal entities'' means--
(A) the Department of Commerce, including the National
Institute of Standards and Technology;
(B) the Department of Defense;
(C) the Department, including the component of the
Department that reports to the Under Secretary responsible
for overseeing critical infrastructure protection,
cybersecurity, and other related programs of the Department;
(D) the Department of Justice, including the Federal Bureau
of Investigation;
(E) the Commission; and
(F) the Office of the Director of National Intelligence,
the National Security Agency, and such other elements of the
intelligence community (as defined in section 3 of the
National Security Act of 1947 (50 U.S.C. 3003)) as the
Director of National Intelligence determines are appropriate.
(3) Commission.--The term ``Commission'' means the Election
Assistance Commission.
(4) Cybersecurity incident.--The term ``cybersecurity
incident'' has the meaning given the term ``incident'' in
section 227 of the Homeland Security Act of 2002 (6 U.S.C.
148).
(5) Department.--The term ``Department'' means the
Department of Homeland Security.
(6) Election agency.--The term ``election agency'' means
any component of a State or any component of a county,
municipality, or other subdivision of a State that is
responsible for administering Federal elections.
(7) Election cybersecurity incident.--The term ``election
cybersecurity incident'' means any cybersecurity incident
involving an election system.
(8) Election cybersecurity threat.--The term ``election
cybersecurity threat'' means any cybersecurity threat (as
defined in section 102 of the Cybersecurity Information
Sharing Act of 2015 (6 U.S.C. 1501)) to an election system.
(9) Election cybersecurity vulnerability.--The term
``election cybersecurity vulnerability'' means any security
vulnerability (as defined in section 102 of the Cybersecurity
Information Sharing Act of 2015 (6 U.S.C. 1501)) that affects
an election system.
(10) Election service provider.--The term ``election
service provider'' means any person providing, supporting, or
maintaining an election system on behalf of an election
agency, such as a contractor or vendor.
(11) Election system.--The term ``election system'' means
the following:
(A) Information technology infrastructure and systems used
to maintain voter registration databases.
[[Page S5856]]
(B) Voting systems and associated infrastructure, which are
generally held in storage but are located at polling places
during early voting and on election day.
(C) Information technology infrastructure and systems used
to manage elections, which may include systems that count,
audit, and display election results on election night on
behalf of State governments as well as for post-election
reporting used to certify and validate election results.
(D) Such other systems the Secretary, in consultation with
the Commission, may identify as central to the management,
support, or administration of a Federal election.
(12) Federal election.--The term ``Federal election'' means
a general, special, primary, or runoff election for the
office of President or Vice President, or of a Senator or
Representative in, or Delegate or Resident Commissioner to,
the Congress that is conducted by an election agency.
(13) Federal entity.--The term ``Federal entity'' means any
agency (as defined in section 551 of title 5, United States
Code).
(14) Secretary.--The term ``Secretary'' means the Secretary
of Homeland Security.
(15) Significant cybersecurity incident.--The term
``significant cybersecurity incident'' is a cybersecurity
incident that is, or a group of related cybersecurity
incidents that together are, likely to result in demonstrable
harm to the national security interests, foreign relations,
or economy of the United States or to the public confidence,
civil liberties, or public health and safety of the American
people.
(16) Significant election cybersecurity incident.--The term
``significant election cybersecurity incident'' means any
significant cybersecurity incident involving an election
system.
(17) State.--The term ``State'' means each of the several
States of the United States, the District of Columbia, the
Commonwealth of Puerto Rico, Guam, American Samoa, the
Commonwealth of Northern Mariana Islands, and the United
States Virgin Islands.
(18) State election official.--The term ``State election
official'' means--
(A) the chief State election official of a State designated
under section 10 of the National Voter Registration Act of
1993 (52 U.S.C. 20509); or
(B) in the Commonwealth of Puerto Rico, Guam, American
Samoa, the Commonwealth of Northern Mariana Islands, and the
United States Virgin Islands, a chief State election official
designated by the State for purposes of this division.
(19) Voting system.--The term ``voting system'' has the
meaning given the term in section 301(b) of the Help America
Vote Act of 2002 (52 U.S.C. 21081(b)).
SEC. _03. INFORMATION SHARING.
(a) Designation of Responsible Federal Entity.--The
Secretary shall have primary responsibility within the
Federal Government for sharing information about election
cybersecurity incidents, threats, and vulnerabilities with
Federal entities and with election agencies.
(b) Presumption of Federal Information Sharing to the
Department.--If a Federal entity receives information about
an election cybersecurity incident, threat, or vulnerability,
the Federal entity shall promptly share that information with
the Department, unless the head of the entity (or a Senate-
confirmed official designated by the head) makes a specific
determination in writing that there is good cause to withhold
the particular information.
(c) Establishment of Information Sharing Plans and
Protocols.--
(1) In general.--The Secretary shall establish and maintain
a communication plan and protocols to promptly share
information related to election cybersecurity incidents,
threats, and vulnerabilities.
(2) Contents.--The communication plan and protocols
required to be established under paragraph (1) shall require
that the Department promptly share appropriate information
with--
(A) the appropriate Federal entities;
(B) all State election officials;
(C) to the maximum extent practicable, all election
agencies that have requested ongoing updates on election
cybersecurity incidents, threats, or vulnerabilities; and
(D) to the maximum extent practicable, all election
agencies that may be affected by the risks associated with
the particular election cybersecurity incident, threat, or
vulnerability.
(d) Development of State Election Cybersecurity Incident
Response and Communication Plan Template.--The Secretary
shall, in coordination with the Commission and the Election
Infrastructure Government Coordinating Council, establish a
template that a State may use when establishing a State
election cybersecurity incident response and communication
plan.
(e) Technical Resources for Election Agencies.--In sharing
information about election cybersecurity incidents, threats,
and vulnerabilities with election agencies under this
section, the Department shall, to the maximum extent
practicable--
(1) provide cyber threat indicators and defensive measures
(as such terms are defined in section 102 of the
Cybersecurity Information Sharing Act of 2015 (6 U.S.C.
1501)), such as recommended technical instructions, that
assist with preventing, mitigating, and detecting threats or
vulnerabilities;
(2) identify resources available for protecting against,
detecting, responding to, and recovering from associated
risks, including technical capabilities of the Department;
and
(3) provide guidance about further sharing of the
information.
(f) Declassification Review.--If the Department receives
classified information about an election cybersecurity
incident, threat, or vulnerability--
(1) the Secretary shall promptly submit a request for
expedited declassification review to the head of a Federal
entity with authority to conduct the review, consistent with
Executive Order 13526 or any successor order, unless the
Secretary determines that such a request would be harmful to
national security; and
(2) the head of the Federal entity described in paragraph
(1) shall promptly conduct the review.
(g) Role of Non-Federal Entities.--The Department may share
information about election cybersecurity incidents, threats,
and vulnerabilities through a non-Federal entity.
(h) Protection of Personal and Confidential Information.--
(1) In general.--If a Federal entity shares or receives
information relating to an election cybersecurity incident,
threat, or vulnerability, the Federal entity shall, within
Federal information systems (as defined in section 3502 of
title 44, United States Code) of the entity--
(A) minimize the acquisition, use, and disclosure of
personal information of voters, except as necessary to
identify, protect against, detect, respond to, or recover
from election cybersecurity incidents, threats, and
vulnerabilities;
(B) notwithstanding any other provision of law, prohibit
the retention of personal information of voters, such as--
(i) voter registration information, including physical
address, email address, and telephone number;
(ii) political party affiliation or registration
information; and
(iii) voter history, including registration status or
election participation; and
(C) protect confidential Federal and State information from
unauthorized disclosure.
(2) Exemption from disclosure.--Information relating to an
election cybersecurity incident, threat, or vulnerability,
such as personally identifiable information of reporting
persons or individuals affected by such incident, threat, or
vulnerability, shared by or with the Federal Government shall
be--
(A) deemed voluntarily shared information and exempt from
disclosure under section 552 of title 5, United States Code,
and any State, tribal, or local provision of law requiring
disclosure of information or records; and
(B) withheld, without discretion, from the public under
section 552(b)(3)(B) of title 5, United States Code, and any
State, tribal, or local provision of law requiring disclosure
of information or records.
(i) Duty To Assess Possible Cybersecurity Incidents.--
(1) Election agencies.--If an election agency becomes aware
of the possibility of an election cybersecurity incident, the
election agency shall promptly--
(A) assess whether an election cybersecurity incident
occurred;
(B) notify the State election official in accordance with
any notification process established by the State election
official; and
(C) notify the Department in accordance with subsection
(j).
(2) Election service providers.--If an election service
provider becomes aware of the possibility of an election
cybersecurity incident, the election service provider shall
promptly--
(A) assess whether an election cybersecurity incident
occurred; and
(B) notify the relevant election agencies in accordance
with subsection (k).
(j) Information Sharing About Cybersecurity Incidents by
Election Agencies.--If an election agency has reason to
believe that an election cybersecurity incident has occurred
with respect to an election system owned, operated, or
maintained by or on behalf of the election agency, the
election agency shall, in the most expedient time possible
and without unreasonable delay, provide notification of the
election cybersecurity incident to the Department in
accordance with any notification process established by the
Secretary.
(k) Information Sharing About Cybersecurity Incidents by
Election Service Providers.--If an election service provider
has reason to believe that an election cybersecurity incident
may have occurred, or that an incident related to the role of
the provider as an election service provider may have
occurred, the election service provider shall--
(1) notify the relevant election agencies in the most
expedient time possible and without unreasonable delay; and
(2) cooperate with the election agencies in providing the
notifications required under subsections (i)(1) and (j).
(l) Content of Notification by Election Agencies.--The
notifications required under subsections (i)(1) and (j)--
(1) shall include an initial assessment of--
(A) the date, time, and time zone when the election
cybersecurity incident began, if known;
(B) the date, time, and time zone when the election
cybersecurity incident was detected;
(C) the date, time, and duration of the election
cybersecurity incident;
(D) the circumstances of the election cybersecurity
incident, including the specific election systems believed to
have been accessed and information acquired; and
[[Page S5857]]
(E) planned and implemented technical measures to respond
to and recover from the incident; and
(2) shall be updated with additional material information,
including technical data, as it becomes available.
(m) Security Clearance.--Not later than 30 days after the
date of enactment of this Act, the Secretary--
(1) shall establish an expedited process for providing
appropriate security clearance to State election officials
and designated technical personnel employed by State election
agencies;
(2) shall establish an expedited process for providing
appropriate security clearance to members of the Commission
and designated technical personnel employed by the
Commission; and
(3) shall establish a process for providing appropriate
security clearance to personnel at other election agencies.
(n) Protection From Liability.--Nothing in this division
may be construed to provide a cause of action against a
State, unit of local government, or an election service
provider.
(o) Assessment of Inter-state Information Sharing About
Election Cybersecurity.--
(1) In general.--The Secretary and the Commission, in
coordination with the heads of the appropriate Federal
entities and appropriate officials of State and local
governments, shall conduct an assessment of--
(A) the structure and functioning of the Elections
Infrastructure Information Sharing and Analysis Center for
purposes of election cybersecurity; and
(B) other mechanisms for inter-state information sharing
about election cybersecurity.
(2) Comment from election agencies.--In carrying out the
assessment required under paragraph (1), the Secretary and
the Commission shall solicit and consider comments from all
State election agencies.
(3) Distribution.--The Secretary and the Commission shall
jointly issue the assessment required under paragraph (1)
to--
(A) all election agencies known to the Department and the
Commission; and
(B) the appropriate congressional committees.
(p) Congressional Notification.--If an appropriate Federal
entity has reason to believe that a significant election
cybersecurity incident has occurred, the entity shall--
(1) not later than 7 calendar days after the date on which
there is a reasonable basis to conclude that the significant
election cybersecurity incident has occurred, provide
notification of the significant election cybersecurity
incident to the appropriate congressional committees; and
(2) update the initial notification under paragraph (1)
within a reasonable period of time after additional
information relating to the significant election
cybersecurity incident is discovered.
SEC. _04. REQUIREMENT FOR THE ESTABLISHMENT OF CYBERSECURITY
INCIDENT RESPONSE PLANS.
(a) In General.--Subtitle D of title II of the Help America
Vote Act of 2002 (52 U.S.C. 20901 et seq.) is amended by
adding at the end the following new part:
``PART 7--REQUIREMENTS FOR ELECTION ASSISTANCE
``SEC. 297. ELECTION CYBERSECURITY INCIDENT RESPONSE AND
COMMUNICATION PLANS.
``No State may receive any grant awarded under this Act
after the date of the enactment of this section unless such
State has established a response and communication plan with
respect to election cybersecurity incidents (as defined in
section 2(7) of the Secure Elections Act). Nothing in this
section shall prohibit a State from using funds awarded
before the date of the enactment of this section for any use
otherwise authorized by law.''.
(b) Conforming Amendment.--The table of contents in section
1(b) of the Help America Vote Act of 2002 is amended by
inserting after the item relating to section 296 the
following:
``PART 7--Requirements for Election Assistance
``Sec. 297. Election cybersecurity incident response and communication
plans.''.
SEC. _05. ELECTION CYBERSECURITY AND ELECTION AUDIT
GUIDELINES.
(a) Development by Technical Advisory Board.--
(1) In general.--
(A) Additional duties.--Section 221(b)(1) of the Help
America Vote Act of 2002 (52 U.S.C. 20961(b)(2)) is amended
by striking ``in the development of the voluntary voting
system guidelines'' and inserting ``in the development of--
``(A) the voluntary voting system guidelines;
``(B) the voluntary election cybersecurity guidelines
(referred to in this part as the `election cybersecurity
guidelines') in accordance with paragraph (3); and
``(C) the voluntary election audit guidelines (referred to
in this part as the `election audit guidelines') in
accordance with paragraph (4).''.
(B) Conforming amendments.--Sections 202(1) and 207(3) of
the Help America Vote Act of 2002 (52 U.S.C. 20922(1) and
20927(3)) are each amended by striking ``voluntary voting
system''.
(2) Membership and renaming of technical guidelines
development committee.--
(A) Membership.--Section 221(c)(1) of the Help America Vote
Act of 2002 (52 U.S.C. 20961(c)(1)) is amended--
(i) by striking ``14'' and inserting ``19''; and
(ii) by striking subparagraphs (A) through (E) and
inserting the following:
``(A) 2 Members of the Standards Board who are not
affiliated with the same political party--
``(i) 1 of whom is a local election official; and
``(ii) 1 of whom is a State election official.
``(B) 2 Members of the Board of Advisors who are not
affiliated with the same political party.
``(C) 2 Members of the Architectural and Transportation
Barrier Compliance Board under section 502 of the
Rehabilitation Act of 1972 (29 U.S.C. 792).
``(D) A representative of the Institute of Electrical and
Electronics Engineers.
``(E) 2 representatives of the National Association of
Secretaries of State selected by such Association who are not
members of the Standards Board or Board of Advisors, and who
are not of the same political party.
``(F) 2 representatives of the National Association of
State Election Directors selected by such Association who are
not members of the Standards Board or Board of Advisors, and
who are not of the same political party.
``(G) A representative of the Department of Homeland
Security who possesses technical and scientific expertise
relating to cybersecurity and the administration of
elections.
``(H) A representative of the Election Infrastructure
Information Sharing and Analysis Center who possesses
technical and scientific expertise relating to cybersecurity.
``(I) A representative of the National Association of State
Chief Information Officers.
``(J) A representative of State election information
technology directors selected by the National Association of
State Election Directors.
``(K) A representative of a manufacturer of voting system
hardware and software who possesses technical and scientific
expertise relating to cybersecurity and the administration of
elections.
``(L) A representative of a laboratory accredited under
section 231(b) who possesses technical and scientific
expertise relating to cybersecurity and the administration of
elections.
``(M) A representative that is an academic or scientific
researcher who possesses technical and scientific expertise
relating to cybersecurity.
``(N) A representative who possesses technical and
scientific expertise relating to the accessibility and
usability of voting systems.''.
(B) Renaming of committee.--
(i) In general.--Section 221(a) of the Help America Vote
Act of 2002 (52 U.S.C. 20961(a)) is amended by striking
``Technical Guidelines Development Committee (hereafter in
this part referred to as the `Development Committee')'' and
inserting ``Technical Advisory Board''.
(ii) Conforming amendments.--
(I) Section 201 of such Act (52 U.S.C. 20921) is amended by
striking ``Technical Guidelines Development Committee'' and
inserting ``Technical Advisory Board''.
(II) Section 221 of such Act (52 U.S.C. 20921) is amended
by striking ``Development Committee'' each place it appears
and inserting ``Technical Advisory Board''.
(III) Section 222(b) of such Act (52 U.S.C. 20962(b)) is
amended--
(aa) by striking ``Technical Guidelines Development
Committee'' in paragraph (1) and inserting ``Technical
Advisory Board'',
(bb) by striking ``Development Committee'' in the heading
and inserting ``Technical Advisory Board'', and
(IV) Section 271(e) of such Act (52 U.S.C. 21041(e)) is
amended by striking ``Technical Guidelines Development
Committee'' and inserting ``Technical Advisory Board''.
(V) Section 281(d) of such Act (52 U.S.C. 21051(d)) is
amended by striking ``Technical Guidelines Development
Committee'' and inserting ``Technical Advisory Board''.
(VI) The heading for section 221of such Act (52 U.S.C.
20961) is amended by striking ``technical guidelines
development committee'' and inserting ``technical advisory
board''.
(VII) The heading for part 3 of subtitle A of title II of
such Act is amended by striking ``technical guidelines
development committee'' and inserting ``technical advisory
board''.
(VIII) The items relating to section 221 and part 3 of
title II in the table of contents of such Act are each
amended by striking ``Technical Guidelines Development
Committee'' and inserting ``Technical Advisory Board''.
(b) Guidelines.--
(1) Election cybersecurity guidelines.--Section 221(b) of
the Help America Vote Act of 2002 (52 U.S.C. 20961(b)) is
amended by adding at the end the following new paragraph:
``(3) Election cybersecurity guidelines.--
``(A) In general.--The election cybersecurity guidelines
shall contain guidelines for election cybersecurity,
including standards for procuring, maintaining, testing,
operating, and updating election systems.
``(B) Requirements.--In developing the guidelines, the
Technical Advisory Board shall--
``(i) identify the top risks to election systems;
``(ii) describe how specific technology choices can
increase or decrease those risks; and
[[Page S5858]]
``(iii) provide recommended policies, best practices, and
overall security strategies for identifying, protecting
against, detecting, responding to, and recovering from the
risks identified under subparagraph (A).
``(C) Issues considered.--
``(i) In general.--In developing the election cybersecurity
guidelines, the Technical Advisory Board shall consider--
``(I) applying established cybersecurity best practices to
Federal election administration by States and local
governments, including appropriate technologies, procedures,
and personnel for identifying, protecting against, detecting,
responding to, and recovering from election cybersecurity
incidents, threats, and vulnerabilities;
``(II) providing actionable guidance to election agencies
that seek to implement additional cybersecurity protections;
and
``(III) any other factors that the Technical Advisory Board
determines to be relevant.
``(D) Relationship to voluntary voting system guidelines
and national institute of standards and technology
cybersecurity guidance.--In developing the election
cybersecurity guidelines, the Technical Advisory Board shall
consider--
``(i) the voluntary voting system guidelines; and
``(ii) cybersecurity standards and best practices developed
by the National Institute of Standards and Technology,
including frameworks, consistent with section 2(c) of the
National Institute of Standards and Technology Act (15 U.S.C.
272(c)).''.
(2) Audit guidelines.--Section 221(b) of such Act (52
U.S.C. 20961(b)), as amended by paragraph (1), is amended by
adding at the end the following new paragraph:
``(4) Election audit guidelines.--
``(A) In general.--The election audit guidelines shall
include provisions regarding voting systems and statistical
audits for Federal elections, including that--
``(i) each vote is cast using a voting system that allows
the voter an opportunity to inspect and confirm the marked
ballot before casting it (consistent with accessibility
requirements); and
``(ii) each election result is determined by tabulating
marked ballots, and prior to the date on which the winning
Federal candidate in the election is sworn into office,
election agencies within the State inspect a random sample of
the marked ballots and thereby establish high statistical
confidence in the election result.
``(B) Issues considered.--In developing the election audit
guidelines, the Technical Advisory Board shall consider--
``(i) specific types of election audits, including
procedures and shortcomings for such audits;
``(ii) mechanisms to verify that election systems
accurately tabulate ballots, report results, and identify a
winner for each election for Federal office, even if there is
an error or fault in the voting system;
``(iii) durational requirements needed to facilitate
election audits in a timely manner that allows for confidence
in the outcome of the election prior to the swearing-in of a
Federal candidate, including variations in the acceptance of
postal ballots, time allowed to cure provisional ballots, and
election certification deadlines;
``(iv) the importance of manual (by hand, not device)
inspections of original marked paper ballots to provide
audits without serious vulnerabilities; and
``(v) any other factors that the Technical Advisory Board
considers to be relevant.''.
(3) Deadlines.--Section 221(b)(2) of such Act (52 U.S.C.
20961(b)(2)), as amended by this Act, is amended--
(A) by striking ``The Technical'' and inserting the
following:
``(A) Voluntary voting system guidelines.--The Technical'';
(B) by striking ``this section'' and inserting ``paragraph
(1)(A)''; and
(C) by adding at the end the following new subparagraph:
``(B) Election cybersecurity and election audit
guidelines.--
``(i) Initial guidelines.--The Technical Advisory Board
shall provide its initial set of recommendations under
subparagraphs (B) and (C) of paragraph (1) to the Executive
Director not later than 180 days after the date of the
enactment of the Secure Elections Act.
``(ii) Periodic review.--Not later than March 31, 2021, and
once every 2 years thereafter, the Technical Advisory Board
shall review and update the guidelines described in
subparagraphs (B) and (C) of paragraph (1).''.
(c) Process for Adoption.--
(1) Publication of recommendations.--Section 221(f) of the
Help America Vote Act of 2002 (52 U.S.C. 20961(f)) is
amended--
(A) by striking ``At the time the Commission'' and
inserting the following:
``(1) Voluntary voting system guidelines.--At the time the
Commission''; and.
(B) by adding at the end the following new paragraph:
``(2) Election cybersecurity and election audit
guidelines.--The Technical Advisory Board shall--
``(A) provide a reasonable opportunity for public comment,
including through Commission publication in the Federal
Register, on the guidelines required under subparagraphs (B)
and (C) of subsection (b)(1), including a 45-day opportunity
for public comment on a draft of the guidelines before they
are submitted to Congress under section 223(a), which shall,
to the extent practicable, occur concurrently with the other
activities of the Technical Advisory Board under this section
with respect to such guidelines; and
``(B) consider the public comments in developing the
guidelines.''.
(2) Adoption.--
(A) In general.--Part 3 of subtitle A of title II of the
Help America Vote Act of 2002 (52 U.S.C. 20961 et seq.) is
amended--
(i) by inserting ``of voluntary voting guidelines'' after
``adoption'' in the heading of section 222; and
(ii) by adding at the end the following new section:
``SEC. 223. PROCESS FOR ADOPTION OF ELECTION CYBERSECURITY
AND ELECTION AUDIT GUIDELINES.
``(a) Submission to Congress.--
``(1) In general.--Not later than 30 calendar days after
the date on which the Commission receives recommendations for
the guidelines described in subparagraphs (B) or (C) of
section 221(b)(1), the Commission shall consider the
guidelines and submit the guidelines to the appropriate
congressional committees.
``(2) Modification.--In considering the guidelines, the
Commission may modify the guidelines if--
``(A) the Commission determines that there is good cause to
modify the guidelines, consistent with the considerations
established in paragraphs (3) or (4) of section 221(b) (as
the case may be) and notwithstanding the recommendation of
the Technical Advisory Board; and
``(B) the Commission submits a written justification of the
modification to the Technical Advisory Board and the
appropriate congressional committees.
``(b) Distribution to Election Agencies.--The Commission
shall distribute the guidelines described in subparagraphs
(B) and (C) of section 221(b)(1) to all election agencies
known to the Commission.
``(c) Publication.--The Commission shall make the
guidelines described in subparagraphs (B) and (C) of section
221(b)(1) available on the public website of the Commission.
``(d) Appropriate Congressional Committees.--For purposes
of this section, the term `appropriate congressional
committees' means--
``(1) the Committee on Rules and Administration, the
Committee on Armed Services, the Committee on Homeland
Security and Governmental Affairs, the Committee on
Appropriations, the Select Committee on Intelligence, the
majority leader, and the minority leader of the Senate; and
``(2) the Committee on House Administration, the Committee
on Armed Services, the Committee on Homeland Security, the
Committee on Appropriations, the Permanent Select Committee
on Intelligence, the Speaker, and the minority leader of the
House of Representatives.
``(e) Rule of Construction.--Nothing in this section shall
be construed to subject the process for developing the
guidelines described in subparagraphs (B) and (C) of section
221(b)(1) to subchapter II of chapter 5, and chapter 7, of
title 5, United States Code (commonly known as the
`Administrative Procedure Act').''.
(B) Clerical amendment.--The table of contents of such Act
is amended by inserting after the item relating to section
222 the following new item:
``Sec. 223. Process for adoption of election cybersecurity and election
audit guidelines.''.
SEC. _06. REQUIREMENT TO CONDUCT POST-ELECTION AUDITS.
(a) Requirement.--
(1) In general.--Subtitle A of title III of the Help
America Vote Act of 2002 (52 U.S.C. 21081 et seq.) is
amended--
(A) by redesignating sections 304 and 305 as sections 305
and 306, respectively; and
(B) by inserting after section 303 the following new
section:
``SEC. 304. POST-ELECTION AUDITS.
``(a) In General.--Each State shall--
``(1) conduct a post-election audit of each Federal
election (as defined in section 2 of the Secure Elections
Act) through the inspection of a random sample of marked
ballots of sufficient quantity to establish high statistical
confidence in the election result;
``(2) provide a description of the planned audit, excluding
any information deemed to create a security risk, to be
conducted under paragraph (1) on a public website
administered by the chief State election official 90 days
prior to each such Federal election; and
``(3) provide results of the completed audit under
paragraph (1) on a public website administered by the chief
State election official within 10 days of the completion of
the audit.
``(b) Time for Completing Audit.--The audit required by
subsection (a) shall be completed in a timely manner to
ensure confidence in the outcome of the election and before--
``(1) in the case of a primary election, the date the
candidate is placed on the general election ballot; and
``(2) in the case of a general election, the date on which
the winning candidate in the election is sworn into office.
``(c) Effective Date.--
``(1) In general.--Except as provided in paragraph (2),
each State shall be required to comply with the requirements
of this section for the regularly scheduled general election
for Federal office held in November 2020, and each subsequent
election for Federal office.
``(2) Waiver.--If a State certifies to the Commission not
later than November 1, 2020,
[[Page S5859]]
that the State will not meet the deadline described in
paragraph (1) for good cause and includes in the
certification the reasons for the failure to meet such
deadline, paragraph (1) shall apply to the State as if the
reference in such subparagraph to `November 2020' were a
reference to `November 2022'.''.
(2) Enforcement.--Section 401 of such Act (52 U.S.C. 21111)
is amended by striking ``and 303'' and inserting ``303, and
304''.
(3) Clerical amendment.--The table of contents of such Act
is amended--
(A) by redesignating the items relating to sections 304 and
305 as relating to sections 305 and 306, respectively; and
(B) by inserting after the item relating to section 303 the
following new item:
``Sec. 304. Post-election audits.''.
(b) Reporting.--The Election Assistance Commission shall--
(1) collect information regarding audits conducted by
States under section 304 of the Help America Vote Act of 2002
(as added by subsection (a)); and
(2) submit reports to Congress on the information provided
by the States under section 304(a)(2) and 304(a)(3) of such
Act (as so added) and other information collected by the
Commission under paragraph (1).
The reports under paragraph (2) shall be submitted
concurrently with the reports required under section 9(a)(3)
of the National Voter Registration Act of 1993.
SEC. _07. REQUIREMENT FOR PAPER BALLOTS.
(a) In General.--Part 7 of subtitle D of title II of the
Help America Vote Act of 2002, as added by section 4, is
amended by adding at the end the following new section:
``SEC. 298. PAPER BALLOTS.
``No State or jurisdiction may use any grant awarded under
this Act after the date of the enactment of this section to
obtain voting equipment unless such voting equipment records
each vote on a marked or printed, individualized, readable
paper ballot and allows the voter an opportunity to inspect
and confirm the marked or printed ballot (consistent with
accessibility requirements under Federal law) before the
ballot is cast and counted. Nothing in this section shall
prohibit a State from using funds awarded before the date of
the enactment of this section to obtain such equipment.''.
(b) Conforming Amendment.--The table of contents in section
1(b) of the Help America Vote Act of 2002, as amended by
section 4, is amended by inserting after the item relating to
section 297 the following:
``Sec. 298. Paper ballots.''.
SEC. _08. STREAMLINING THE COLLECTION OF ELECTION
INFORMATION.
Section 202 of the Help America Vote Act of 2002 (52 U.S.C.
20922) is amended by adding at the end the following flush
sentence:
``Subchapter I of chapter 35 of title 44, United States Code,
shall not apply to the collection of information for purposes
of maintaining any clearinghouse with respect to the
administration of Federal elections or the experiences of
State and local governments in implementing the guidelines
described in paragraph (1) or in operating voting systems in
general.''.
SEC. _09. REPORTS TO CONGRESS ON FOREIGN THREATS TO
ELECTIONS.
(a) In General.--Not later than 30 days after the date of
enactment of this Act, and 90 days before the end of each
fiscal year thereafter, the Secretary and the Director of
National Intelligence, in coordination with the heads of the
appropriate Federal entities, shall submit a joint report to
the appropriate congressional committees on foreign threats
to elections in the United States, including physical and
cybersecurity threats.
(b) Voluntary Participation by States.--The Secretary shall
solicit and consider comments from all State election
agencies. Participation by an election agency in the report
under this subsection shall be voluntary and at the
discretion of the State.
SEC. _10. STATE ELECTION SYSTEM CYBERSECURITY MODERNIZATION
AND MAINTENANCE GRANTS.
(a) In General.--The Help America Vote Act of 2002 (52
U.S.C. 20901 et seq.) is amended by adding at the end the
following new title:
``TITLE X--PAYMENTS TO STATES FOR CYBERSECURITY MODERNIZATION AND
MAINTENANCE
``SEC. 1001. DEFINITIONS.
``For purposes of this title:
``(1) Cyber navigator program.--The term `cyber navigator
program' means a program under which the State election
official employs election technology professionals to provide
practical cybersecurity knowledge, support, and services to
local election officials, including--
``(A) assessments of local election offices;
``(B) support to local information technology staff or
vendors in creating cyber security policies for voting
systems (as defined in section 301(b));
``(C) services to mitigate vulnerabilities discovered
during an assessment and to improve cybersecurity of a local
election office;
``(D) the establishment of best cyber hygiene practices
within an office; and
``(E) advice on the purchase of new election systems.
``(2) State.--The term `State' means each of the several
States of the United States and the District of Columbia.
``SEC. 1002. PAYMENTS TO STATES.
``(a) In General.--The Commission shall award annual grants
to States in accordance with this section.
``(b) Use of Funds.--A State receiving a grant under this
section shall use the funds received under the grant only
to--
``(1) upgrade election-related computer systems to address
cyber vulnerabilities consistent with best practices
recommended by the Department of Homeland Security, the
National Institute of Standards and Technology, and the
Commission;
``(2) implement a post-election audit system that provides
a high statistical confidence in the election result;
``(3) obtain or facilitate cybersecurity training for
officials in the office of the State election official and
for local election officials; and
``(4) establish or maintain a cyber navigator program.
``(c) Amount of Grants.--
``(1) In general.--Subject to paragraph (3), the amount of
funds provided to a State under a grant under this section
for any calendar year shall be equal to the product obtained
by multiplying--
``(A) the total amount appropriated for grants pursuant to
the authorization under section 1003(a); by
``(B) the State allocation percentage for the State (as
determined under paragraph (2)).
``(2) State allocation percentage.--The State allocation
percentage for a State is the amount (expressed as a
percentage) equal to the quotient obtained by dividing--
``(A) the total voting age population of all States (as
reported in the most recent decennial census); by
``(B) the voting age population of the State (as reported
in the most recent decennial census).
``(3) Minimum and maximum amount of payment.--The amount
determined under this subsection--
``(A) may not be less than $2,500,000 and
``(B) may not be greater than $10,000,000.
``(4) Pro rata adjustment.--The Commission shall make such
pro rata adjustments to the allocations determined under
paragraph (1) as are necessary to comply with the
requirements of paragraph (3).
``SEC. 1003. AUTHORIZATION OF APPROPRIATIONS.
``(a) In General.--There is authorized to be appropriated
to the Commission $250,000,000 to carry out this title for
each of fiscal years 2019 and 2020.
``(b) Availability.--Any amounts appropriated pursuant to
paragraph (1) shall remain available without fiscal year
limitation until expended.
``(c) Authorization of Appropriations for Commission.--In
addition to the amounts authorized under subsection (a),
there are authorized to be appropriated to the Commission
such sums as may be necessary to administer the programs
under this title.''.
(b) Conforming Amendments.--
(1) Section 202 of the Help America Vote Act of 2002 (52
U.S.C. 20922) is amended by striking ``and'' at the end of
paragraph (5), by striking the period at the end of paragraph
(6) and inserting ``; and'', and by adding at the end the
following new paragraph:
``(7) carrying out the grant program under title X.''.
(2) The table of contents of such Act is amended by adding
at the end the following:
``TITLE X--PAYMENTS TO STATES FOR CYBERSECURITY MODERNIZATION AND
MAINTENANCE
``Sec. 1001. Definitions.
``Sec. 1002. Payments to States.
``Sec. 1003. Authorization of appropriations.''.
______