[Congressional Record Volume 165, Number 102 (Tuesday, June 18, 2019)]
[Senate]
[Pages S3695-S3696]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 686. Mr. PETERS submitted an amendment intended to be proposed by
him to the bill S. 1790, to authorize appropriations for fiscal year
2020 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. PILOT PROGRAM TO IMPROVE PUBLIC-PRIVATE
CYBERSECURITY OPERATIONAL COLLABORATION.
(a) Definitions.--In this section--
(1) the term ``appropriate congressional committees and
leadership'' means--
(A) the Committee on Homeland Security and Governmental
Affairs of the Senate, the Committee on the Judiciary, the
Committee on Armed Services, the Select Committee on
Intelligence, the Committee on Foreign Relations, the
majority leader, and the minority leader of the Senate; and
(B) the Committee on Homeland Security of the House of
Representatives, the Committee on the Judiciary, the
Committee on Armed Services, the Permanent Select Committee
on Intelligence, the Committee on Foreign Affairs, the
Speaker, and the minority leader of the House of
Representatives;
(2) the term ``appropriate Federal agencies'' means--
(A) the Department of Homeland Security; and
(B) any other agency, as determined by the Secretary;
(3) the term ``collaboration effort'' means an effort
undertaken by the appropriate Federal agencies and 1 or more
non-Federal entities under the pilot program in order to
carry out the purpose of the pilot program;
(4) the term ``critical infrastructure'' has the meaning
given that term in section 1016(e) of the USA PATRIOT Act (42
U.S.C. 5195c(e));
(5) the term ``cybersecurity provider'' means a non-Federal
entity that provides cybersecurity services to another non-
Federal entity;
(6) the term ``cybersecurity threat'' means a cybersecurity
threat, as defined in section 102 of the Cybersecurity
Information Sharing Act of 2015 (6 U.S.C. 1501), that
affects--
(A) the national security of the United States; or
(B) critical infrastructure in the United States;
(7) the term ``malicious cyber actor'' means an entity that
poses a cybersecurity threat;
(8) the term ``non-Federal entity'' has the meaning given
the term in section 102 of the Cybersecurity Information
Sharing Act of 2015 (6 U.S.C. 1501); and
(9) the term ``Secretary'' means the Secretary of Homeland
Security.
(b) Establishment; Purpose.--Not later than 60 days after
the date of enactment of this Act, the Secretary, in
consultation with the heads of the appropriate Federal
agencies, may establish a pilot program under which the
appropriate Federal agencies, as coordinated and facilitated
by the Secretary, may identify and partner with nonprofit
cybersecurity organizations capable of enabling near real-
time information sharing of cybersecurity threats among
cybersecurity providers in order to coordinate and magnify
Federal and non-Federal efforts to prevent or disrupt
cybersecurity threats or malicious cyber actors, by, as
appropriate--
(1) sharing information relating to potential actions by
the Federal Government against cybersecurity threats or
malicious cyber actors with non-Federal entities;
(2) facilitating joint planning between the appropriate
Federal agencies and non-Federal entities relating to
cybersecurity threats or malicious cyber actors; and
(3) synchronizing activities of the Federal Government
against cybersecurity threats or malicious cyber actors of--
(A) the non-Federal entities with which information is
shared under paragraph (1); and
(B) the non-Federal entities with which joint planning is
carried out under paragraph (2).
(c) Federal Coordination.--The Secretary shall facilitate
all Federal coordination, planning, and action relating to
the pilot program.
(d) Annual Reports to Appropriate Congressional Committees
and Leadership.--
(1) In general.--Not later than 1 year after the date of
enactment of this Act, and each year thereafter, the
Secretary shall submit to the appropriate congressional
committees and leadership a report on the collaboration
efforts carried out during the year for which the report is
submitted, which shall include--
(A) a statement of the total number collaboration efforts
carried out during the year;
(B) with respect to each collaboration effort carried out
during the year--
(i) a statement of--
(I) the identity of any malicious cyber actor that, as a
result of a cybersecurity threat that the malicious cyber
actor engaged in or was likely to engage in, was a subject of
the collaboration effort;
(II) the responsibilities under the collaboration effort of
each appropriate Federal agency and each non-Federal entity
that participated in the collaboration effort; and
(III) whether the goal of the collaboration effort was
achieved; and
(ii) a description of how each appropriate Federal agency
and each non-Federal entity that participated in the
collaboration effort collaborated in carrying out the
collaboration effort; and
(C) a description of--
(i) the ways in which the collaboration efforts carried out
during the year--
(I) were successful; and
(II) could have been improved; and
(ii) how the Secretary will improve collaboration efforts
carried out on or after the date on which the report is
submitted.
(2) Form.--Any report submitted under paragraph (1) shall
be submitted in unclassified form, but may include a
classified annex.
(e) Termination.--The pilot program shall terminate on the
date that is 3 years after the date of enactment of this Act.
(f) Rule of Construction.--Nothing in this section shall be
construed to--
[[Page S3696]]
(1) authorize a non-Federal entity to engage in any
activity in violation of section 1030(a) of title 18, United
States Code; or
(2) limit an appropriate Federal agency or a non-Federal
entity from engaging in a lawful activity.
______