[Congressional Record Volume 165, Number 102 (Tuesday, June 18, 2019)]
[Senate]
[Pages S3681-S3682]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 654. Mr. CORNYN (for himself and Ms. Rosen) submitted an amendment 
intended to be proposed by him to the bill S. 1790, to authorize 
appropriations for fiscal year 2020 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the end of subtitle C of title II, add the following:

     SEC. 243. FEDERAL CYBERSECURITY AND RESEARCH PROTECTION 
                   POLICY.

       (a) Definitions.--In this section--
       (1) the term ``covered applicant'' means an applicant for 
     funding from a Federal agency to carry out research under a 
     covered program;
       (2) the term ``covered program'' means a research program 
     of a Federal agency for which the Director determines 
     compliance with the Framework is required;
       (3) the term ``Director'' means the Director of the Office 
     of Science and Technology Policy;
       (4) the term ``Federal agency'' means an Executive agency, 
     as defined in section 105 of title 5, United States Code;
       (5) the term ``Framework'' means the framework developed by 
     the working group under subsection (b)(3)(A);
       (6) the term ``institution of higher education'' has the 
     meaning given the term in section 101 of the Higher Education 
     Act of 1965 (20 U.S.C. 1001); and
       (7) the term ``working group'' means the interagency 
     working group established under subsection (b).
       (b) Interagency Working Group for Coordination and 
     Development of Federal Cybersecurity and Research Protection 
     Framework.--
       (1) In general.--The Director, acting through the National 
     Science and Technology Council and in coordination with the 
     National Security Advisor, shall establish an interagency 
     working group to--
       (A) coordinate Federal science and technology agency and 
     Federal intelligence and security activities; and
       (B) develop a Federal agency framework for compliance and 
     best practices, which shall be aimed at enhancing 
     cybersecurity protocols and protecting federally funded 
     research and development activities from foreign 
     interference, espionage, and exfiltration.
       (2) Membership.--The working group shall, at a minimum, be 
     composed of the following members:
       (A) The Director, who shall serve as chair of the working 
     group.
       (B) A representative from the National Science and 
     Technology Council.
       (C) Not more than 2 representatives from each of the 
     following entities:
       (i) The Department of State.
       (ii) The Department of the Treasury.
       (iii) The Department of Defense.
       (iv) The Department of Justice.
       (v) The Department of Education.
       (vi) The Department of Energy.
       (vii) The Department of Agriculture.
       (viii) The Department of Homeland Security.
       (ix) The National Institutes of Health.
       (x) The National Science Foundation.
       (xi) The National Aeronautics and Space Administration.
       (xii) The National Institute of Standards and Technology.
       (xiii) The Federal Bureau of Investigation.
       (xiv) The Central Intelligence Agency.
       (xv) The Office of Management and Budget.
       (xvi) The National Economic Council.
       (xvii) The Office of the Director of National Intelligence.
       (xviii) Such other Federal agencies as the Director 
     considers appropriate.
       (3) Responsibilities.--Not later than 1 year after the date 
     of enactment of this Act, the working group shall--
       (A) develop a framework for compliance across Federal 
     agencies to apply to applications submitted by covered 
     applicants for covered programs, which shall include--
       (i) establishing a clear, unified cybersecurity policy 
     across Federal agencies for the protection of Federal 
     research from foreign interference, while accounting for the 
     importance of the open exchange of ideas and international 
     talent required for scientific progress and leadership of the 
     United States in science and technology;
       (ii) identifying how existing mechanisms for control of 
     science and technology can be used to help protect federally 
     funded research and development from foreign interference, 
     cyber attacks, espionage, intellectual property theft, and 
     other attempts by foreign governments or representatives 
     thereof that attempt to compromise the integrity of the 
     United States scientific and technological enterprise;
       (iii) recommending additional mechanisms for control to 
     help protect federally funded research and development from 
     foreign interference, cyber attacks, espionage, and 
     intellectual property theft, including--

       (I) disclosing foreign interests, investments, or 
     involvement relating to Federal research; and
       (II) creating and providing to each Federal agency a list, 
     which shall not be made available to the public, of 
     researchers found to be knowingly fraudulent in disclosure 
     and the institution of higher education where the fraudulence 
     occurred; and

       (iv) developing a clear, unified metric across Federal 
     agencies that covered applicants will use to determine 
     compliance with the Framework for purposes of subsection 
     (c)(2); and
       (B) coordinate activities to protect federally funded 
     research and development from foreign interference, cyber 
     attacks, theft, and espionage and develop common definitions 
     and best practices for Federal science agencies, grantees, 
     and covered applicants, including by--
       (i) developing common definitions and aligning terms across 
     Federal agencies, including sensitive technologies, critical 
     technologies, emerging technologies, genomic data, and 
     foundational technologies;
       (ii) coordinating efforts among Federal agencies to share 
     important information, suspicious foreign actors, specific 
     examples or attempts at foreign interference, cyber attacks, 
     theft, or espionage with key stakeholders, including 
     institutions of higher education, federally funded research 
     and development centers, and nonprofit research institutions, 
     to help them better understand and defend against those 
     threats;
       (iii) identifying potential cyber threats and 
     vulnerabilities within the United States scientific and 
     technological enterprise and working with Federal agencies 
     and other stakeholders to develop and implement strategies 
     and best practices to defend and protect against potential 
     cyber attacks that may compromise research being conducted on 
     behalf of the Federal Government;
       (iv) developing and periodically updating unclassified 
     policy guidance to assist Federal science agencies, 
     institutions of higher education, and grantees in defending 
     against threats to federally funded research and the 
     development and integrity of the United States scientific 
     enterprise that shall include--

       (I) common definitions and terminology for classification 
     of research and technologies that are covered programs;
       (II) identified areas of research or technology that may 
     require additional controls; and
       (III) a classified addendum as necessary to further inform 
     Federal science agency decision-making; and

       (v) determining how current Federal efforts, as described 
     in the memorandum issued by the Office of Science and 
     Technology Policy on February 22, 2013 entitled ``Increasing 
     Access to the Results of Federally Funded Scientific 
     Research'', can be appropriately balanced with concerns about 
     the need to protect certain research data, information, and 
     resulting technologies from foreign actors seeking to utilize 
     that information for the express interest of advancing their 
     scientific, technological, economic, and

[[Page S3682]]

     military interests and which are directly counter to United 
     States interests.
       (4) Engagement.--In developing the Framework and the 
     compliance metric described in paragraph (3)(A)(iv), the 
     working group shall solicit and incorporate input from 
     representatives of institutions of higher education 
     conducting federally funded research and development, 
     including--
       (A) facility security officers;
       (B) chief information officers;
       (C) vice presidents for research;
       (D) chief technology officers; and
       (E) other relevant officers as determined by the Director.
       (5) Reporting requirements.--The Director shall--
       (A) not later than 60 days after the date of enactment of 
     this Act, report to Congress on the progress of establishing 
     the working group; and
       (B) not later than 270 days after the date of enactment of 
     this Act, report to Congress on the activities of the working 
     group, including the progress of the working group in meeting 
     the responsibilities described in paragraphs (3) and (4).
       (c) Application of and Compliance With Framework.--
       (1) Application.--The Framework shall apply to--
       (A) each grant by a Federal agency providing funds to be 
     used to carry out research under a covered program; and
       (B) any researcher that applies for funds under a covered 
     program.
       (2) Compliance.--Each covered applicant shall disclose in 
     the application for funding for a covered program whether the 
     applicant is in compliance with the Framework.
       (d) OSTP Report.--Not later than 1 year after the date on 
     which the Framework is developed under subsection (b)(3)(A), 
     and biennially thereafter, the Director shall submit to the 
     Committee on Commerce, Science, and Transportation, the 
     Committee on Homeland Security and Governmental Affairs, and 
     the Committee on Foreign Relations of the Senate and the 
     Committee on Science, Space, and Technology, the Committee on 
     Oversight and Reform, and the Committee on Foreign Affairs of 
     the House of Representatives a report discussing--
       (1) the research programs of Federal agencies that are 
     covered programs;
       (2) the research programs of Federal agencies that the 
     Director determines are not covered programs, and the basis 
     for the determination; and
       (3) analysis of enforcement mechanisms and penalties for 
     fraudulently disclosing foreign interests, investments, or 
     involvement relating to federally funded research and 
     potential recommendations for future legislation to address 
     unmet needs to protect federally funded research from foreign 
     interference, cyber attacks, theft, or espionage.
       (e) GAO Report.--Not later than 3 years after the date of 
     enactment of this Act, the Comptroller General of the United 
     States shall submit to the Committee on Homeland Security and 
     Governmental Affairs of the Senate and the Committee on 
     Oversight and Reform of the House of Representatives a report 
     that--
       (1) includes an analysis of the implementation of the 
     Framework by Federal agencies; and
       (2) examines compliance by institutions of higher 
     education, federally funded research and development centers, 
     and nonprofit research institutions with the Framework.
       (f) Rule of Construction.--Nothing in this section or 
     resulting framework shall be construed to affect or otherwise 
     disrupt research activities occurring before, on, or after 
     the date of enactment of this Act, unless as determined by a 
     majority of the working group.
                                 ______