[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Pages S3233-S3235]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1712. Mr. KING (for himself and Mr. Sasse) submitted an amendment 
intended to be proposed by him to the bill S. 4049, to authorize 
appropriations for fiscal year 2021 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. __. JOINT COLLABORATIVE ENVIRONMENT.

       (a) In General.--In coordination with the Cyber Threat Data 
     Standards and Interoperability Council established pursuant 
     to subsection (e), the Director of the Cybersecurity and 
     Infrastructure Security Agency and the Director of the 
     National Security Agency shall establish a joint, cloud-
     based, information sharing environment to--
       (1) integrate the unclassified and classified cyber threat 
     intelligence, malware forensics, and data from network sensor 
     programs of the Federal Government;

[[Page S3234]]

       (2) enable cross-correlation of threat data at the speed 
     and scale necessary for rapid detection and identification of 
     cyber threats;
       (3) enable query and analysis by appropriate operators 
     across the Federal Government; and
       (4) facilitate a whole-of-government, comprehensive 
     understanding of the cyber threats facing the Federal 
     Government and critical infrastructure networks in the United 
     States.
       (b) Development.--
       (1) Initial evaluation.--Not later than 180 days after the 
     date of enactment of this Act, the Director of the 
     Cybersecurity and Infrastructure Security Agency and the 
     Director of the National Security Agency shall--
       (A) identify all existing Federal sources of classified and 
     unclassified cyber threat information; and
       (B) evaluate all programs, applications, or platforms of 
     the Federal Government that are intended to detect, identify, 
     analyze, and monitor cyber threats against the United States 
     or critical infrastructure.
       (2) Design.--Not later than 1 year after the evaluation 
     required under paragraph (1), the Director of the 
     Cybersecurity and Infrastructure Security Agency and the 
     Director of the National Security Agency shall design the 
     structure of a common platform for sharing and fusing 
     existing government information, insights, and data related 
     to cyber threats and threat actors, which shall, at a 
     minimum--
       (A) account for appropriate data standards and 
     interoperability requirements;
       (B) enable integration of current applications, platforms, 
     data, and information, to include classified information;
       (C) ensure accessibility by such Federal agencies as the 
     Director of the Cybersecurity and Infrastructure Security 
     Agency and the Director for the National Security Agency 
     determine necessary;
       (D) account for potential private sector participation and 
     partnerships;
       (E) enable unclassified data to be integrated with 
     classified data;
       (F) anticipate the deployment of analytic tools across 
     classification levels to leverage all relevant data sets, as 
     appropriate;
       (G) identify tools and analytical software that can be 
     applied and shared to manipulate, transform, and display data 
     and other identified needs; and
       (H) anticipate the integration of new technologies and data 
     streams, including data from Federal Government-sponsored 
     voluntary network sensors or network-monitoring programs for 
     the private sector or for State, local, Tribal, and 
     territorial governments.
       (c) Operation.--The information sharing environment 
     established pursuant to subsection (a) shall be jointly 
     managed by--
       (1) the Director of the Cybersecurity and Infrastructure 
     Security Agency, who shall have responsibility for 
     unclassified information and data streams; and
       (2) the Director of the National Security Agency, who shall 
     have responsibility for all classified information and data 
     streams.
       (d) Post-deployment Assessment.--Not later than 2 years 
     after the deployment of the information sharing environment 
     requirement under subsection (a), the Director of the 
     Cybersecurity and Infrastructure Security Agency and the 
     Director of the National Security Agency shall jointly assess 
     the means by which the sharing environment can be expanded to 
     include critical infrastructure information sharing 
     organizations and, to the maximum extent practicable, begin 
     the process of such expansion.
       (e) Cyber Threat Data Standards and Interoperability 
     Council.--
       (1) Establishment.--The President shall establish an 
     interagency council (in this subsection referred to as the 
     ``Council''), chaired by the Director of the Cybersecurity 
     and Infrastructure Security Agency and the Director of the 
     National Security Agency, to set data standards and 
     requirements for participation under this section.
       (2) Other membership.--The President shall identify and 
     appoint additional Council members from Federal agencies that 
     oversee programs that generate, collect, or disseminate data 
     or information related to the detection, identification, 
     analysis, and monitoring of cyber threats.
       (3) Data streams.--The Council shall identify, designate, 
     and periodically update Federal programs required to 
     participate in or be interoperable with the information 
     sharing environment described in subsection (a), including--
       (A) Federal Government network-monitoring and intrusion 
     detection programs;
       (B) cyber threat indicator-sharing programs;
       (C) Federal Government-sponsored network sensors or 
     network-monitoring programs for the private sector or for 
     State, local, Tribal, and territorial governments;
       (D) incident response and cybersecurity technical 
     assistance programs; and
       (E) malware forensics and reverse-engineering programs.
       (4) Data governance.--The Council shall establish 
     procedures and data governance structures, as necessary to 
     protect sensitive data, comply with Federal regulations and 
     statutes, and respect existing consent agreements with the 
     private sector and other non-Federal entities.
       (5) Recommendations.--As appropriate, the Council, or the 
     chairpersons thereof, shall recommend to the President budget 
     and authorization changes necessary to ensure sufficient 
     funding and authorities for the operation, expansion, 
     adaptation, and security of the information sharing 
     environment established pursuant to subsection (a).
       (f) Privacy and Civil Liberties.--
       (1) Guidelines of attorney general.--Not later than 60 days 
     after the date of enactment of this Act, the Attorney General 
     shall, in coordination with heads of the appropriate Federal 
     agencies and in consultation with officers designated under 
     section 1062 of the National Security Intelligence Reform Act 
     of 2004 (42 U.S.C. 2000ee-1), develop, submit to Congress, 
     and make available to the public interim guidelines relating 
     to privacy and civil liberties which shall govern the 
     receipt, retention, use, and dissemination of cyber threat 
     indicators by a Federal agency obtained in connection with 
     activities authorized under this section.
       (2) Final guidelines.--
       (A) In general.--Not later than 180 days after the date of 
     enactment of this Act, the Attorney General shall, in 
     coordination with heads of the appropriate Federal agencies 
     and in consultation with officers designated under section 
     1062 of the National Security Intelligence Reform Act of 2004 
     (42 U.S.C. 2000ee-1) and such private entities with industry 
     expertise as the Attorney General considers relevant, 
     promulgate final guidelines relating to privacy and civil 
     liberties which shall govern the receipt, retention, use, and 
     dissemination of cyber threat indicators by a Federal entity 
     obtained in connection with activities authorized under this 
     section.
       (B) Periodic review.--The Attorney General shall, in 
     coordination with heads of the appropriate Federal agencies 
     and in consultation with the officers and private entities 
     described in subparagraph (A), periodically, but not less 
     frequently than once every 2 years, review the guidelines 
     promulgated under subparagraph (A).
       (3) Content.--The guidelines required under paragraphs (1) 
     and (2) shall, consistent with the need to protect 
     information systems from cybersecurity threats and mitigate 
     cybersecurity threats--
       (A) limit the effect on privacy and civil liberties of 
     activities by the Federal Government under this section;
       (B) limit the receipt, retention, use, and dissemination of 
     cyber threat indicators containing personal information or 
     information that identifies specific persons, including by 
     establishing--
       (i) a process for the timely destruction of such 
     information that is known not to be directly related to uses 
     authorized under this title; and
       (ii) specific limitations on the length of any period in 
     which a cyber threat indicator may be retained;
       (C) include requirements to safeguard cyber threat 
     indicators containing personal information or information 
     that identifies specific persons from unauthorized access or 
     acquisition, including appropriate sanctions for activities 
     by officers, employees, or agents of the Federal Government 
     in contravention of such guidelines;
       (D) include procedures for notifying entities and Federal 
     agencies if information received pursuant to this section is 
     known or determined by a Federal agency receiving such 
     information not to constitute a cyber threat indicator;
       (E) protect the confidentiality of cyber threat indicators 
     containing personal information or information that 
     identifies specific persons to the greatest extent 
     practicable and require recipients to be informed that such 
     indicators may only be used for purposes authorized under 
     this section; and
       (F) include steps that may be needed so that dissemination 
     of cyber threat indicators is consistent with the protection 
     of classified and other sensitive national security 
     information.
       (g) Oversight of Government Activities.--
       (1) Biennial report on privacy and civil liberties.--Not 
     later than 2 years after the date of enactment of this Act 
     and not less frequently than once every year thereafter, the 
     Privacy and Civil Liberties Oversight Board shall submit to 
     Congress and the President a report providing--
       (A) an assessment of the effect on privacy and civil 
     liberties by the type of activities carried out under this 
     section; and
       (B) an assessment of the sufficiency of the policies, 
     procedures, and guidelines established pursuant to subsection 
     (f) in addressing concerns relating to privacy and civil 
     liberties.
       (2) Biennial report by inspectors general.--
       (A) In general.--Not later than 2 years after the date of 
     enactment of this Act and not less frequently than once every 
     2 years thereafter, the Inspector General of the Department 
     of Homeland Security, the Inspector General of the 
     Intelligence Community, the Inspector General of the 
     Department of Justice, the Inspector General of the 
     Department of Defense, and the Inspector General of the 
     Department of Energy shall, in consultation with the Council 
     of Inspectors General on Financial Oversight, jointly submit 
     to Congress a report on the receipt, use, and dissemination 
     of cyber threat indicators and defensive measures that have 
     been shared with Federal agencies under this section.
       (B) Contents.--Each report submitted under subparagraph (A) 
     shall include the following:
       (i) A review of the types of cyber threat indicators shared 
     with Federal agencies.

[[Page S3235]]

       (ii) A review of the actions taken by Federal agencies as a 
     result of the receipt of such cyber threat indicators.
       (iii) A list of Federal entities receiving such cyber 
     threat indicators.
       (iv) A review of the sharing of such cyber threat 
     indicators among Federal agencies to identify inappropriate 
     barriers to sharing information.
       (3) Recommendations.--Each report submitted under this 
     subsection may include such recommendations as the Privacy 
     and Civil Liberties Oversight Board, with respect to a report 
     submitted under paragraph (1), or the Inspectors General 
     referred to in paragraph (2)(A), with respect to a report 
     submitted under paragraph (2), may have for improvements or 
     modifications to the authorities under this section.
       (4) Form.--Each report required under this subsection shall 
     be submitted in unclassified form, but may include a 
     classified annex.
       (h) Critical Infrastructure.--In this section, the term 
     ``critical infrastructure'' has the meaning given that term 
     in section 1016(e) of the Critical Infrastructures Protection 
     Act of 2001 (42 U.S.C. 5195c(e).
                                 ______