[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Pages S3233-S3235]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1712. Mr. KING (for himself and Mr. Sasse) submitted an amendment
intended to be proposed by him to the bill S. 4049, to authorize
appropriations for fiscal year 2021 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. __. JOINT COLLABORATIVE ENVIRONMENT.
(a) In General.--In coordination with the Cyber Threat Data
Standards and Interoperability Council established pursuant
to subsection (e), the Director of the Cybersecurity and
Infrastructure Security Agency and the Director of the
National Security Agency shall establish a joint, cloud-
based, information sharing environment to--
(1) integrate the unclassified and classified cyber threat
intelligence, malware forensics, and data from network sensor
programs of the Federal Government;
[[Page S3234]]
(2) enable cross-correlation of threat data at the speed
and scale necessary for rapid detection and identification of
cyber threats;
(3) enable query and analysis by appropriate operators
across the Federal Government; and
(4) facilitate a whole-of-government, comprehensive
understanding of the cyber threats facing the Federal
Government and critical infrastructure networks in the United
States.
(b) Development.--
(1) Initial evaluation.--Not later than 180 days after the
date of enactment of this Act, the Director of the
Cybersecurity and Infrastructure Security Agency and the
Director of the National Security Agency shall--
(A) identify all existing Federal sources of classified and
unclassified cyber threat information; and
(B) evaluate all programs, applications, or platforms of
the Federal Government that are intended to detect, identify,
analyze, and monitor cyber threats against the United States
or critical infrastructure.
(2) Design.--Not later than 1 year after the evaluation
required under paragraph (1), the Director of the
Cybersecurity and Infrastructure Security Agency and the
Director of the National Security Agency shall design the
structure of a common platform for sharing and fusing
existing government information, insights, and data related
to cyber threats and threat actors, which shall, at a
minimum--
(A) account for appropriate data standards and
interoperability requirements;
(B) enable integration of current applications, platforms,
data, and information, to include classified information;
(C) ensure accessibility by such Federal agencies as the
Director of the Cybersecurity and Infrastructure Security
Agency and the Director for the National Security Agency
determine necessary;
(D) account for potential private sector participation and
partnerships;
(E) enable unclassified data to be integrated with
classified data;
(F) anticipate the deployment of analytic tools across
classification levels to leverage all relevant data sets, as
appropriate;
(G) identify tools and analytical software that can be
applied and shared to manipulate, transform, and display data
and other identified needs; and
(H) anticipate the integration of new technologies and data
streams, including data from Federal Government-sponsored
voluntary network sensors or network-monitoring programs for
the private sector or for State, local, Tribal, and
territorial governments.
(c) Operation.--The information sharing environment
established pursuant to subsection (a) shall be jointly
managed by--
(1) the Director of the Cybersecurity and Infrastructure
Security Agency, who shall have responsibility for
unclassified information and data streams; and
(2) the Director of the National Security Agency, who shall
have responsibility for all classified information and data
streams.
(d) Post-deployment Assessment.--Not later than 2 years
after the deployment of the information sharing environment
requirement under subsection (a), the Director of the
Cybersecurity and Infrastructure Security Agency and the
Director of the National Security Agency shall jointly assess
the means by which the sharing environment can be expanded to
include critical infrastructure information sharing
organizations and, to the maximum extent practicable, begin
the process of such expansion.
(e) Cyber Threat Data Standards and Interoperability
Council.--
(1) Establishment.--The President shall establish an
interagency council (in this subsection referred to as the
``Council''), chaired by the Director of the Cybersecurity
and Infrastructure Security Agency and the Director of the
National Security Agency, to set data standards and
requirements for participation under this section.
(2) Other membership.--The President shall identify and
appoint additional Council members from Federal agencies that
oversee programs that generate, collect, or disseminate data
or information related to the detection, identification,
analysis, and monitoring of cyber threats.
(3) Data streams.--The Council shall identify, designate,
and periodically update Federal programs required to
participate in or be interoperable with the information
sharing environment described in subsection (a), including--
(A) Federal Government network-monitoring and intrusion
detection programs;
(B) cyber threat indicator-sharing programs;
(C) Federal Government-sponsored network sensors or
network-monitoring programs for the private sector or for
State, local, Tribal, and territorial governments;
(D) incident response and cybersecurity technical
assistance programs; and
(E) malware forensics and reverse-engineering programs.
(4) Data governance.--The Council shall establish
procedures and data governance structures, as necessary to
protect sensitive data, comply with Federal regulations and
statutes, and respect existing consent agreements with the
private sector and other non-Federal entities.
(5) Recommendations.--As appropriate, the Council, or the
chairpersons thereof, shall recommend to the President budget
and authorization changes necessary to ensure sufficient
funding and authorities for the operation, expansion,
adaptation, and security of the information sharing
environment established pursuant to subsection (a).
(f) Privacy and Civil Liberties.--
(1) Guidelines of attorney general.--Not later than 60 days
after the date of enactment of this Act, the Attorney General
shall, in coordination with heads of the appropriate Federal
agencies and in consultation with officers designated under
section 1062 of the National Security Intelligence Reform Act
of 2004 (42 U.S.C. 2000ee-1), develop, submit to Congress,
and make available to the public interim guidelines relating
to privacy and civil liberties which shall govern the
receipt, retention, use, and dissemination of cyber threat
indicators by a Federal agency obtained in connection with
activities authorized under this section.
(2) Final guidelines.--
(A) In general.--Not later than 180 days after the date of
enactment of this Act, the Attorney General shall, in
coordination with heads of the appropriate Federal agencies
and in consultation with officers designated under section
1062 of the National Security Intelligence Reform Act of 2004
(42 U.S.C. 2000ee-1) and such private entities with industry
expertise as the Attorney General considers relevant,
promulgate final guidelines relating to privacy and civil
liberties which shall govern the receipt, retention, use, and
dissemination of cyber threat indicators by a Federal entity
obtained in connection with activities authorized under this
section.
(B) Periodic review.--The Attorney General shall, in
coordination with heads of the appropriate Federal agencies
and in consultation with the officers and private entities
described in subparagraph (A), periodically, but not less
frequently than once every 2 years, review the guidelines
promulgated under subparagraph (A).
(3) Content.--The guidelines required under paragraphs (1)
and (2) shall, consistent with the need to protect
information systems from cybersecurity threats and mitigate
cybersecurity threats--
(A) limit the effect on privacy and civil liberties of
activities by the Federal Government under this section;
(B) limit the receipt, retention, use, and dissemination of
cyber threat indicators containing personal information or
information that identifies specific persons, including by
establishing--
(i) a process for the timely destruction of such
information that is known not to be directly related to uses
authorized under this title; and
(ii) specific limitations on the length of any period in
which a cyber threat indicator may be retained;
(C) include requirements to safeguard cyber threat
indicators containing personal information or information
that identifies specific persons from unauthorized access or
acquisition, including appropriate sanctions for activities
by officers, employees, or agents of the Federal Government
in contravention of such guidelines;
(D) include procedures for notifying entities and Federal
agencies if information received pursuant to this section is
known or determined by a Federal agency receiving such
information not to constitute a cyber threat indicator;
(E) protect the confidentiality of cyber threat indicators
containing personal information or information that
identifies specific persons to the greatest extent
practicable and require recipients to be informed that such
indicators may only be used for purposes authorized under
this section; and
(F) include steps that may be needed so that dissemination
of cyber threat indicators is consistent with the protection
of classified and other sensitive national security
information.
(g) Oversight of Government Activities.--
(1) Biennial report on privacy and civil liberties.--Not
later than 2 years after the date of enactment of this Act
and not less frequently than once every year thereafter, the
Privacy and Civil Liberties Oversight Board shall submit to
Congress and the President a report providing--
(A) an assessment of the effect on privacy and civil
liberties by the type of activities carried out under this
section; and
(B) an assessment of the sufficiency of the policies,
procedures, and guidelines established pursuant to subsection
(f) in addressing concerns relating to privacy and civil
liberties.
(2) Biennial report by inspectors general.--
(A) In general.--Not later than 2 years after the date of
enactment of this Act and not less frequently than once every
2 years thereafter, the Inspector General of the Department
of Homeland Security, the Inspector General of the
Intelligence Community, the Inspector General of the
Department of Justice, the Inspector General of the
Department of Defense, and the Inspector General of the
Department of Energy shall, in consultation with the Council
of Inspectors General on Financial Oversight, jointly submit
to Congress a report on the receipt, use, and dissemination
of cyber threat indicators and defensive measures that have
been shared with Federal agencies under this section.
(B) Contents.--Each report submitted under subparagraph (A)
shall include the following:
(i) A review of the types of cyber threat indicators shared
with Federal agencies.
[[Page S3235]]
(ii) A review of the actions taken by Federal agencies as a
result of the receipt of such cyber threat indicators.
(iii) A list of Federal entities receiving such cyber
threat indicators.
(iv) A review of the sharing of such cyber threat
indicators among Federal agencies to identify inappropriate
barriers to sharing information.
(3) Recommendations.--Each report submitted under this
subsection may include such recommendations as the Privacy
and Civil Liberties Oversight Board, with respect to a report
submitted under paragraph (1), or the Inspectors General
referred to in paragraph (2)(A), with respect to a report
submitted under paragraph (2), may have for improvements or
modifications to the authorities under this section.
(4) Form.--Each report required under this subsection shall
be submitted in unclassified form, but may include a
classified annex.
(h) Critical Infrastructure.--In this section, the term
``critical infrastructure'' has the meaning given that term
in section 1016(e) of the Critical Infrastructures Protection
Act of 2001 (42 U.S.C. 5195c(e).
______