[Congressional Record Volume 165, Number 99 (Thursday, June 13, 2019)]
[Senate]
[Pages S3595-S3596]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 596. Mr. PETERS submitted an amendment intended to be proposed by
him to the bill S. 1790, to authorize appropriations for fiscal year
2020 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. PILOT PROGRAM TO IMPROVE PUBLIC-PRIVATE
CYBERSECURITY OPERATIONAL COLLABORATION.
(a) Definitions.--In this section--
(1) the term ``appropriate congressional committees''
means--
(A) the Committee on Homeland Security and Governmental
Affairs of the Senate; and
[[Page S3596]]
(B) the Committee on Homeland Security of the House of
Representatives;
(2) the term ``appropriate Federal agencies'' means--
(A) the Department of Homeland Security; and
(B) any other agency, as determined by the Secretary;
(3) the term ``collaboration effort'' means an effort
undertaken by the appropriate Federal agencies and 1 or more
non-Federal entities under the pilot program in order to
carry out the purpose of the pilot program;
(4) the term ``critical infrastructure'' has the meaning
given that term in section 1016(e) of the USA PATRIOT Act (42
U.S.C. 5195c(e));
(5) the term ``cybersecurity provider'' means a non-Federal
entity that provides cybersecurity services to another non-
Federal entity;
(6) the term ``cybersecurity threat'' means a cybersecurity
threat, as defined in section 102 of the Cybersecurity
Information Sharing Act of 2015 (6 U.S.C. 1501), that
affects--
(A) the national security of the United States; or
(B) critical infrastructure in the United States;
(7) the term ``malicious cyber actor'' means an entity that
poses a cybersecurity threat;
(8) the term ``non-Federal entity'' has the meaning given
the term in section 102 of the Cybersecurity Information
Sharing Act of 2015 (6 U.S.C. 1501); and
(9) the term ``Secretary'' means the Secretary of Homeland
Security.
(b) Establishment; Purpose.--Not later than 60 days after
the date of enactment of this Act, the Secretary, in
consultation with the heads of the appropriate Federal
agencies, may establish a pilot program under which the
appropriate Federal agencies, at the direction of the
Secretary, may collaborate with non-Federal entities in order
to coordinate and magnify Federal and non-Federal efforts to
prevent or disrupt cybersecurity threats or malicious cyber
actors.
(c) Partnership.--In carrying out the pilot program, the
Secretary may identify and partner with nonprofit
cybersecurity organizations capable of enabling near real-
time information sharing relating to cybersecurity threats
among cybersecurity providers in order to facilitate, as
appropriate--
(1) sharing of information relating to potential actions by
the Federal Government against cybersecurity threats or
malicious cyber actors with non-Federal entities;
(2) joint planning between the appropriate Federal agencies
and non-Federal entities relating to cybersecurity threats or
malicious cyber actors; and
(3) the synchronization of actions against cybersecurity
threats or malicious cyber actors by--
(A) the Federal Government;
(B) the non-Federal entities with which information is
shared under paragraph (1); and
(C) the non-Federal entities with which joint planning is
carried out under paragraph (2).
(d) Roles and Responsibilities.--
(1) In general.--The non-Federal entities involved in the
partnership described in subsection (c) shall facilitate all
non-Federal coordination, planning, and action relating to
the pilot program.
(2) Responsibilities of the secretary.--The Secretary shall
facilitate all Federal coordination, planning, and action
relating to the pilot program.
(e) Annual Reports to Appropriate Congressional
Committees.--
(1) In general.--Not later than 1 year after the date of
enactment of this Act, and each year thereafter, the
Secretary shall submit to the appropriate congressional
committees a report on the collaboration efforts carried out
during the year for which the report is submitted, which
shall include--
(A) a statement of the total number collaboration efforts
carried out during the year;
(B) with respect to each collaboration effort carried out
during the year--
(i) a statement of--
(I) the identity of any malicious cyber actor that, as a
result of a cybersecurity threat that the malicious cyber
actor engaged in or was likely to engage in, was a subject of
the collaboration effort;
(II) the responsibilities under the collaboration effort of
each appropriate Federal agency and each non-Federal entity
that participated in the collaboration effort; and
(III) whether the goal of the collaboration effort was
achieved; and
(ii) a description of how each appropriate Federal agency
and each non-Federal entity that participated in the
collaboration effort collaborated in carrying out the
collaboration effort; and
(C) a description of--
(i) the ways in which the collaboration efforts carried out
during the year--
(I) were successful; and
(II) could have been improved; and
(ii) how the Secretary will improve collaboration efforts
carried out on or after the date on which the report is
submitted.
(2) Form.--Any report submitted under paragraph (1) shall
be submitted in unclassified form, but may include a
classified annex.
(f) Termination.--The pilot program shall terminate on the
date that is 3 years after the date of enactment of this Act.
(g) Rule of Construction.--Nothing in this section shall be
construed to--
(1) authorize a non-Federal entity to engage in any
activity in violation of section 1030(a) of title 18, United
States Code; or
(2) limit an appropriate Federal agency or a non-Federal
entity from engaging in a lawful activity.
______