[Congressional Record Volume 165, Number 102 (Tuesday, June 18, 2019)]
[Senate]
[Pages S3681-S3682]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 654. Mr. CORNYN (for himself and Ms. Rosen) submitted an amendment
intended to be proposed by him to the bill S. 1790, to authorize
appropriations for fiscal year 2020 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the end of subtitle C of title II, add the following:
SEC. 243. FEDERAL CYBERSECURITY AND RESEARCH PROTECTION
POLICY.
(a) Definitions.--In this section--
(1) the term ``covered applicant'' means an applicant for
funding from a Federal agency to carry out research under a
covered program;
(2) the term ``covered program'' means a research program
of a Federal agency for which the Director determines
compliance with the Framework is required;
(3) the term ``Director'' means the Director of the Office
of Science and Technology Policy;
(4) the term ``Federal agency'' means an Executive agency,
as defined in section 105 of title 5, United States Code;
(5) the term ``Framework'' means the framework developed by
the working group under subsection (b)(3)(A);
(6) the term ``institution of higher education'' has the
meaning given the term in section 101 of the Higher Education
Act of 1965 (20 U.S.C. 1001); and
(7) the term ``working group'' means the interagency
working group established under subsection (b).
(b) Interagency Working Group for Coordination and
Development of Federal Cybersecurity and Research Protection
Framework.--
(1) In general.--The Director, acting through the National
Science and Technology Council and in coordination with the
National Security Advisor, shall establish an interagency
working group to--
(A) coordinate Federal science and technology agency and
Federal intelligence and security activities; and
(B) develop a Federal agency framework for compliance and
best practices, which shall be aimed at enhancing
cybersecurity protocols and protecting federally funded
research and development activities from foreign
interference, espionage, and exfiltration.
(2) Membership.--The working group shall, at a minimum, be
composed of the following members:
(A) The Director, who shall serve as chair of the working
group.
(B) A representative from the National Science and
Technology Council.
(C) Not more than 2 representatives from each of the
following entities:
(i) The Department of State.
(ii) The Department of the Treasury.
(iii) The Department of Defense.
(iv) The Department of Justice.
(v) The Department of Education.
(vi) The Department of Energy.
(vii) The Department of Agriculture.
(viii) The Department of Homeland Security.
(ix) The National Institutes of Health.
(x) The National Science Foundation.
(xi) The National Aeronautics and Space Administration.
(xii) The National Institute of Standards and Technology.
(xiii) The Federal Bureau of Investigation.
(xiv) The Central Intelligence Agency.
(xv) The Office of Management and Budget.
(xvi) The National Economic Council.
(xvii) The Office of the Director of National Intelligence.
(xviii) Such other Federal agencies as the Director
considers appropriate.
(3) Responsibilities.--Not later than 1 year after the date
of enactment of this Act, the working group shall--
(A) develop a framework for compliance across Federal
agencies to apply to applications submitted by covered
applicants for covered programs, which shall include--
(i) establishing a clear, unified cybersecurity policy
across Federal agencies for the protection of Federal
research from foreign interference, while accounting for the
importance of the open exchange of ideas and international
talent required for scientific progress and leadership of the
United States in science and technology;
(ii) identifying how existing mechanisms for control of
science and technology can be used to help protect federally
funded research and development from foreign interference,
cyber attacks, espionage, intellectual property theft, and
other attempts by foreign governments or representatives
thereof that attempt to compromise the integrity of the
United States scientific and technological enterprise;
(iii) recommending additional mechanisms for control to
help protect federally funded research and development from
foreign interference, cyber attacks, espionage, and
intellectual property theft, including--
(I) disclosing foreign interests, investments, or
involvement relating to Federal research; and
(II) creating and providing to each Federal agency a list,
which shall not be made available to the public, of
researchers found to be knowingly fraudulent in disclosure
and the institution of higher education where the fraudulence
occurred; and
(iv) developing a clear, unified metric across Federal
agencies that covered applicants will use to determine
compliance with the Framework for purposes of subsection
(c)(2); and
(B) coordinate activities to protect federally funded
research and development from foreign interference, cyber
attacks, theft, and espionage and develop common definitions
and best practices for Federal science agencies, grantees,
and covered applicants, including by--
(i) developing common definitions and aligning terms across
Federal agencies, including sensitive technologies, critical
technologies, emerging technologies, genomic data, and
foundational technologies;
(ii) coordinating efforts among Federal agencies to share
important information, suspicious foreign actors, specific
examples or attempts at foreign interference, cyber attacks,
theft, or espionage with key stakeholders, including
institutions of higher education, federally funded research
and development centers, and nonprofit research institutions,
to help them better understand and defend against those
threats;
(iii) identifying potential cyber threats and
vulnerabilities within the United States scientific and
technological enterprise and working with Federal agencies
and other stakeholders to develop and implement strategies
and best practices to defend and protect against potential
cyber attacks that may compromise research being conducted on
behalf of the Federal Government;
(iv) developing and periodically updating unclassified
policy guidance to assist Federal science agencies,
institutions of higher education, and grantees in defending
against threats to federally funded research and the
development and integrity of the United States scientific
enterprise that shall include--
(I) common definitions and terminology for classification
of research and technologies that are covered programs;
(II) identified areas of research or technology that may
require additional controls; and
(III) a classified addendum as necessary to further inform
Federal science agency decision-making; and
(v) determining how current Federal efforts, as described
in the memorandum issued by the Office of Science and
Technology Policy on February 22, 2013 entitled ``Increasing
Access to the Results of Federally Funded Scientific
Research'', can be appropriately balanced with concerns about
the need to protect certain research data, information, and
resulting technologies from foreign actors seeking to utilize
that information for the express interest of advancing their
scientific, technological, economic, and
[[Page S3682]]
military interests and which are directly counter to United
States interests.
(4) Engagement.--In developing the Framework and the
compliance metric described in paragraph (3)(A)(iv), the
working group shall solicit and incorporate input from
representatives of institutions of higher education
conducting federally funded research and development,
including--
(A) facility security officers;
(B) chief information officers;
(C) vice presidents for research;
(D) chief technology officers; and
(E) other relevant officers as determined by the Director.
(5) Reporting requirements.--The Director shall--
(A) not later than 60 days after the date of enactment of
this Act, report to Congress on the progress of establishing
the working group; and
(B) not later than 270 days after the date of enactment of
this Act, report to Congress on the activities of the working
group, including the progress of the working group in meeting
the responsibilities described in paragraphs (3) and (4).
(c) Application of and Compliance With Framework.--
(1) Application.--The Framework shall apply to--
(A) each grant by a Federal agency providing funds to be
used to carry out research under a covered program; and
(B) any researcher that applies for funds under a covered
program.
(2) Compliance.--Each covered applicant shall disclose in
the application for funding for a covered program whether the
applicant is in compliance with the Framework.
(d) OSTP Report.--Not later than 1 year after the date on
which the Framework is developed under subsection (b)(3)(A),
and biennially thereafter, the Director shall submit to the
Committee on Commerce, Science, and Transportation, the
Committee on Homeland Security and Governmental Affairs, and
the Committee on Foreign Relations of the Senate and the
Committee on Science, Space, and Technology, the Committee on
Oversight and Reform, and the Committee on Foreign Affairs of
the House of Representatives a report discussing--
(1) the research programs of Federal agencies that are
covered programs;
(2) the research programs of Federal agencies that the
Director determines are not covered programs, and the basis
for the determination; and
(3) analysis of enforcement mechanisms and penalties for
fraudulently disclosing foreign interests, investments, or
involvement relating to federally funded research and
potential recommendations for future legislation to address
unmet needs to protect federally funded research from foreign
interference, cyber attacks, theft, or espionage.
(e) GAO Report.--Not later than 3 years after the date of
enactment of this Act, the Comptroller General of the United
States shall submit to the Committee on Homeland Security and
Governmental Affairs of the Senate and the Committee on
Oversight and Reform of the House of Representatives a report
that--
(1) includes an analysis of the implementation of the
Framework by Federal agencies; and
(2) examines compliance by institutions of higher
education, federally funded research and development centers,
and nonprofit research institutions with the Framework.
(f) Rule of Construction.--Nothing in this section or
resulting framework shall be construed to affect or otherwise
disrupt research activities occurring before, on, or after
the date of enactment of this Act, unless as determined by a
majority of the working group.
______