[Congressional Record Volume 166, Number 42 (Tuesday, March 3, 2020)]
[Senate]
[Page S1426]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1455. Ms. ROSEN submitted an amendment intended to be proposed to 
amendment SA 1407 submitted by Ms. Murkowski and intended to be 
proposed to the bill S. 2657, to support innovation in advanced 
geothermal research and development, and for other purposes; which was 
ordered to lie on the table; as follows:

        At the end of part I of subtitle B of title II, add the 
     following:

     SEC. 220_. CYBER SENSE PROGRAM.

       (a) In General.--The Secretary shall establish a voluntary 
     Cyber Sense program (referred to in the section as the 
     ``program'') to test the cybersecurity of products and 
     technologies intended for use in the bulk-power system (as 
     defined in section 215(a) of the Federal Power Act (16 U.S.C. 
     824o(a)).
       (b) Program Requirements.--In carrying out subsection (a), 
     the Secretary shall--
       (1) establish a testing process under the program to test 
     the cybersecurity of products and technologies intended for 
     use in the bulk-power system, including products relating to 
     industrial control systems and operational technologies, such 
     as supervisory control and data acquisition systems;
       (2) for products and technologies tested under the program, 
     establish and maintain cybersecurity vulnerability reporting 
     processes and a related database;
       (3) provide technical assistance to electric utilities, 
     product manufacturers, and other electricity sector 
     stakeholders to develop solutions to mitigate identified 
     cybersecurity vulnerabilities in products and technologies 
     tested under the program;
       (4) biennially review products and technologies tested 
     under the program for cybersecurity vulnerabilities and 
     provide analysis with respect to how those products and 
     technologies respond to and mitigate cyber threats;
       (5) develop guidance that is informed by analysis and 
     testing results under the program for electric utilities for 
     the procurement of products and technologies;
       (6) provide reasonable notice to, and solicit comments 
     from, the public prior to establishing or revising the 
     testing process under the program;
       (7) oversee testing of products and technologies under the 
     program; and
       (8) consider incentives to encourage the use of analysis 
     and results of testing under the program in the design of 
     products and technologies for use in the bulk-power system.
       (c) Disclosure of Information.--Any cybersecurity 
     vulnerability reported pursuant to a process established 
     under subsection (b)(2), the disclosure of which the 
     Secretary reasonably foresees would cause harm to critical 
     electric infrastructure (as defined in section 215A(a) of the 
     Federal Power Act (16 U.S.C. 824o-1(a)), shall be considered 
     to be critical electric infrastructure information for 
     purposes of section 215A(d) of the Federal Power Act (16 
     U.S.C. 824o-1(d)).
       (d) Federal Government Liability.--Nothing in this section 
     authorizes the commencement of an action against the United 
     States with respect to the testing of a product or technology 
     under the program.
                                 ______