[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Pages S3235-S3236]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1714. Mr. KING (for himself and Mr. Sasse) submitted an amendment
intended to be proposed by him to the bill S. 4049, to authorize
appropriations for fiscal year 2021 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. __. NATIONAL RISK MANAGEMENT ACT.
(a) Short Title.--This section may be cited as the
``National Risk Management Act''.
(b) Definitions.--In this section:
(1) Critical infrastructure.--The term ``critical
infrastructure'' has the meaning given that term in section
1016 of the Uniting and Strengthening America by Providing
Appropriate Tools Required to Intercept and Obstruct
Terrorism Act of 2001 (42 U.S.C. 5195c).
(2) Department.--The term ``Department'' means the
Department of Homeland Security.
(3) Director.--The term ``Director'' means the Director of
the Cybersecurity and Infrastructure Security Agency of the
Department.
(4) National critical function.--The term ``national
critical function'' means a function of the government or the
private sector that is so vital to the United States that the
disruption, corruption, or dysfunction of the function would
have a debilitating effect on security, national economic
security, national public health or safety, or any
combination thereof.
(5) Secretary.--The term ``Secretary'' means the Secretary
of Homeland Security.
(6) Sector risk management agency.--The term ``Sector Risk
Management Agency'' means an agency designated under
subsection (e).
(c) National Risk Management Cycle.--
(1) Risk identification and assessment.--
(A) In general.--The Secretary, acting through the
Director, shall establish a process by which to identify,
assess, and prioritize risks to critical infrastructure,
considering both cyber and physical threats, vulnerabilities,
and consequences.
(B) Consultation.--In developing the process required under
subparagraph (A), the Secretary shall consult with Sector
Risk Management Agencies and critical infrastructure owners
and operators.
(C) Publication.--Not later than 180 days after the date of
enactment of this Act, the Secretary shall publish procedures
for process developed pursuant to subparagraph (A) in the
Federal Register.
(D) Report.--Not later than 1 year after the date of
enactment of this Act, and once every 4 years thereafter, the
Secretary shall submit to the President a report on the risks
identified by the process established pursuant to
subparagraph (A).
(2) National critical infrastructure resilience strategy.--
(A) In general.--Not later than 1 year after the Secretary
submits each report required under paragraph (1), the
President shall submit to majority and minority leaders of
the Senate and the Speaker and the minority leader of the
House of Representatives a National Critical Infrastructure
Resilience Strategy designed to address the risks identified
by the Secretary.
(B) Elements.--In each strategy submitted under this
paragraph, the President shall:
(i) Identify, assess, and prioritize areas of risk to
critical infrastructure that would compromise, disrupt, or
impede their ability to support the national critical
functions of national security, economic security, or public
health and safety.
(ii) Assess the implementation of the previous National
Critical Infrastructure Resilience Strategy, as applicable.
[[Page S3236]]
(iii) Identify and outline current and proposed national-
level actions, programs, and efforts to be taken to address
the risks identified.
(iv) Identify the Federal departments or agencies
responsible for leading each national-level action, program,
or effort and the relevant critical infrastructure sectors
for each.
(v) Outline the budget plan required to provide sufficient
resources to successfully execute the full range of
activities proposed or described by the National Critical
Infrastructure Resilience Strategy.
(vi) Request any additional authorities or resources
necessary to successfully execute the National Critical
Infrastructure Resilience Strategy.
(C) Form.--The strategy required under subparagraph (A)
shall be submitted in unclassified form, but may contain a
classified annex.
(3) Congressional briefing.--Not later than 1 year after
the date on which the President submits a National Critical
Infrastructure Resilience Strategy under this subsection, and
once every year thereafter, the Secretary, in coordination
with Sector Risk Management Agencies, shall brief the
appropriate committees of Congress on the national risk
management cycle activities undertaken pursuant to this
section.
(d) Critical Infrastructure Sector Designation.--
(1) Initial review.--Not later than 180 days after the date
of enactment of this section, the Secretary shall--
(A) review the critical infrastructure sector model and
corresponding designations for Sector Risk Management
Agencies in effect on the date of enactment of this Act; and
(B) submit a report to the President containing
recommendations for--
(i) any additions or deletions to the list of critical
infrastructure sectors set forth in Presidential Policy
Directive-21; and
(ii) any new assignment or alternative assignment of a
Federal department or agency to serve as the Sector Risk
Management Agency for a sector.
(2) Periodic review.--Not later than 1 year before the
submission of each strategy required under subsection (c)(2),
the Secretary, in consultation with the Director, shall--
(A) review the current list of critical infrastructure
sectors and the assignment of Sector Risk Management
Agencies, as set forth in Presidential Policy Directive-21,
or any successor document; and
(B) recommend to the President--
(i) any additions or deletions to the list of critical
infrastructure sectors; and
(ii) any new assignment or alternative assignment of a
Federal agency to serve as the Sector Risk Management Agency
for each sector.
(3) Update.--
(A) In general.--Not later than 180 days after the date on
which the Secretary makes a recommendation under paragraph
(2), the President shall--
(i) review the recommendation and update, as appropriate,
the designation of critical infrastructure sectors and each
sector's corresponding Sector Risk Management Agency; or
(ii) submit a report to the majority and minority leaders
of the Senate and the Speaker and minority leader of the
House of Representatives explaining the basis for rejecting
the recommendations of the Secretary.
(B) Limitation.--The President--
(i) may not designate more than 1 department or agency as
the Sector Risk Management Agency for each critical
infrastructure sector; and
(ii) may only designate an agency under this subsection if
the agency is referenced in section 205 of the Chief
Financial Officers Act of 1990 (42 U.S.C. 901).
(4) Publication.--Any designation of critical
infrastructure sectors shall be published in the Federal
Register.
(e) Sector Risk Management Agencies.--
(1) In general.--Any reference to a Sector-Specific Agency
in any law, regulation, map, document, record, or other paper
of the United States shall be deemed to be a reference to the
Sector Risk Management Agency of the relevant critical
infrastructure sector.
(2) Coordination.--In carrying out this section, the head
of each Sector Risk Management Agency shall--
(A) coordinate with the Secretary and the head of other
relevant Federal departments and agencies;
(B) collaborate with critical infrastructure owners and
operators; and
(C) as appropriate, coordinate with independent regulatory
agencies, and State, local, Tribal, and territorial entities.
(3) Responsibilities.--The head of each Sector Risk
Management Agency shall utilize the specialized expertise of
the agency about the assigned critical infrastructure sector
and authorities of the agency under applicable law to support
and carry out activities for its assigned sector related to--
(A) sector risk management, including--
(i) establishing and carrying out programs to assist
critical infrastructure owners and operators within their
assigned sector in identifying, understanding, and mitigating
threats, vulnerabilities, and risks to their region, sector,
systems or assets; and
(ii) recommending resilience measures to mitigate the
consequences of destruction, compromise, and disruption of
their systems and assets;
(B) sector risk identification and assessment, including--
(i) identifying, assessing, and prioritizing risks to
critical infrastructure within their sector, considering
physical and cyber threats, vulnerabilities, and
consequences; and
(ii) supporting national risk assessment efforts led by the
Department, including identifying, assessing, and
prioritizing cross-sector and national-level risks;
(C) sector coordination, including--
(i) serving as a day-to-day Federal interface for the
dynamic prioritization and coordination of sector-specific
activities and their responsibilities under this section;
(ii) serving as the government coordinating council chair
for their assigned sector; and
(iii) participating in cross-sector coordinating councils,
as appropriate;
(D) threat and vulnerability information sharing,
including--
(i) facilitating access to, and exchange of, information
and intelligence necessary to strengthen the resilience of
critical infrastructure, including through the sector's
information sharing and analysis center;
(ii) facilitating the identification of intelligence needs
and priorities of critical infrastructure in coordination
with the Director of National Intelligence and the heads of
other Federal departments and agencies, as appropriate;
(iii) providing the Director ongoing, and where
practicable, real-time awareness of identified threats,
vulnerabilities, mitigations, and other actions related to
the security of critical infrastructure; and
(iv) supporting the reporting requirements of the
Department under applicable law by providing, on an annual
basis, sector-specific critical infrastructure information;
(E) incident management, including--
(i) supporting incident management and restoration efforts
during or following a security incident;
(ii) supporting the Cybersecurity and Infrastructure
Security Agency, as requested, in conducting vulnerability
assessments and asset response activities for critical
infrastructure; and
(iii) supporting the Attorney General and law enforcement
agencies with efforts to detect and prosecute threats to and
attacks against critical infrastructure;
(F) emergency preparedness, including--
(i) coordinating with critical infrastructure owners and
operators in the development of planning documents for
coordinated action in response to an incident or emergency;
(ii) conducting exercises and simulations of potential
incidents or emergencies; and
(iii) supporting the Department and other Federal
departments or agencies in developing planning documents or
conducting exercises or simulations relevant to their
assigned sector;
(G) participation in national risk management efforts,
including--
(i) supporting the Secretary in the risk identification and
assessment activities carried out pursuant to subsection (c);
(ii) supporting the President in the development of the
National Critical Infrastructure Resilience Strategy pursuant
to subsection (c); and
(iii) implementing the National Critical Infrastructure
Resilience Strategy pursuant to subsection (c).
(4) Status of information.--Information shared with a
Sector Risk Management Agency in furtherance of the
responsibilities outlined in paragraph (3)(B)(ii) shall be
treated as protected critical infrastructure information
under section 214 of the Homeland Security Act of 2002 (6
U.S.C. 673).
(f) Reporting and Auditing.--Not later than 2 years after
the date of enactment of this Act, and once every 4 years
thereafter, the Comptroller General of the United States
shall submit a report to appropriate Committees of Congress
on the effectiveness of Sector Risk Management Agencies in
carrying out their responsibilities under subsection (e).
______