[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Pages S3235-S3236]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1714. Mr. KING (for himself and Mr. Sasse) submitted an amendment 
intended to be proposed by him to the bill S. 4049, to authorize 
appropriations for fiscal year 2021 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. __. NATIONAL RISK MANAGEMENT ACT.

       (a) Short Title.--This section may be cited as the 
     ``National Risk Management Act''.
       (b) Definitions.--In this section:
       (1) Critical infrastructure.--The term ``critical 
     infrastructure'' has the meaning given that term in section 
     1016 of the Uniting and Strengthening America by Providing 
     Appropriate Tools Required to Intercept and Obstruct 
     Terrorism Act of 2001 (42 U.S.C. 5195c).
       (2) Department.--The term ``Department'' means the 
     Department of Homeland Security.
       (3) Director.--The term ``Director'' means the Director of 
     the Cybersecurity and Infrastructure Security Agency of the 
     Department.
       (4) National critical function.--The term ``national 
     critical function'' means a function of the government or the 
     private sector that is so vital to the United States that the 
     disruption, corruption, or dysfunction of the function would 
     have a debilitating effect on security, national economic 
     security, national public health or safety, or any 
     combination thereof.
       (5) Secretary.--The term ``Secretary'' means the Secretary 
     of Homeland Security.
       (6) Sector risk management agency.--The term ``Sector Risk 
     Management Agency'' means an agency designated under 
     subsection (e).
       (c) National Risk Management Cycle.--
       (1) Risk identification and assessment.--
       (A) In general.--The Secretary, acting through the 
     Director, shall establish a process by which to identify, 
     assess, and prioritize risks to critical infrastructure, 
     considering both cyber and physical threats, vulnerabilities, 
     and consequences.
       (B) Consultation.--In developing the process required under 
     subparagraph (A), the Secretary shall consult with Sector 
     Risk Management Agencies and critical infrastructure owners 
     and operators.
       (C) Publication.--Not later than 180 days after the date of 
     enactment of this Act, the Secretary shall publish procedures 
     for process developed pursuant to subparagraph (A) in the 
     Federal Register.
       (D) Report.--Not later than 1 year after the date of 
     enactment of this Act, and once every 4 years thereafter, the 
     Secretary shall submit to the President a report on the risks 
     identified by the process established pursuant to 
     subparagraph (A).
       (2) National critical infrastructure resilience strategy.--
       (A) In general.--Not later than 1 year after the Secretary 
     submits each report required under paragraph (1), the 
     President shall submit to majority and minority leaders of 
     the Senate and the Speaker and the minority leader of the 
     House of Representatives a National Critical Infrastructure 
     Resilience Strategy designed to address the risks identified 
     by the Secretary.
       (B) Elements.--In each strategy submitted under this 
     paragraph, the President shall:
       (i) Identify, assess, and prioritize areas of risk to 
     critical infrastructure that would compromise, disrupt, or 
     impede their ability to support the national critical 
     functions of national security, economic security, or public 
     health and safety.
       (ii) Assess the implementation of the previous National 
     Critical Infrastructure Resilience Strategy, as applicable.

[[Page S3236]]

       (iii) Identify and outline current and proposed national-
     level actions, programs, and efforts to be taken to address 
     the risks identified.
       (iv) Identify the Federal departments or agencies 
     responsible for leading each national-level action, program, 
     or effort and the relevant critical infrastructure sectors 
     for each.
       (v) Outline the budget plan required to provide sufficient 
     resources to successfully execute the full range of 
     activities proposed or described by the National Critical 
     Infrastructure Resilience Strategy.
       (vi) Request any additional authorities or resources 
     necessary to successfully execute the National Critical 
     Infrastructure Resilience Strategy.
       (C) Form.--The strategy required under subparagraph (A) 
     shall be submitted in unclassified form, but may contain a 
     classified annex.
       (3) Congressional briefing.--Not later than 1 year after 
     the date on which the President submits a National Critical 
     Infrastructure Resilience Strategy under this subsection, and 
     once every year thereafter, the Secretary, in coordination 
     with Sector Risk Management Agencies, shall brief the 
     appropriate committees of Congress on the national risk 
     management cycle activities undertaken pursuant to this 
     section.
       (d) Critical Infrastructure Sector Designation.--
       (1) Initial review.--Not later than 180 days after the date 
     of enactment of this section, the Secretary shall--
       (A) review the critical infrastructure sector model and 
     corresponding designations for Sector Risk Management 
     Agencies in effect on the date of enactment of this Act; and
       (B) submit a report to the President containing 
     recommendations for--
       (i) any additions or deletions to the list of critical 
     infrastructure sectors set forth in Presidential Policy 
     Directive-21; and
       (ii) any new assignment or alternative assignment of a 
     Federal department or agency to serve as the Sector Risk 
     Management Agency for a sector.
       (2) Periodic review.--Not later than 1 year before the 
     submission of each strategy required under subsection (c)(2), 
     the Secretary, in consultation with the Director, shall--
       (A) review the current list of critical infrastructure 
     sectors and the assignment of Sector Risk Management 
     Agencies, as set forth in Presidential Policy Directive-21, 
     or any successor document; and
       (B) recommend to the President--
       (i) any additions or deletions to the list of critical 
     infrastructure sectors; and
       (ii) any new assignment or alternative assignment of a 
     Federal agency to serve as the Sector Risk Management Agency 
     for each sector.
       (3) Update.--
       (A) In general.--Not later than 180 days after the date on 
     which the Secretary makes a recommendation under paragraph 
     (2), the President shall--
       (i) review the recommendation and update, as appropriate, 
     the designation of critical infrastructure sectors and each 
     sector's corresponding Sector Risk Management Agency; or
       (ii) submit a report to the majority and minority leaders 
     of the Senate and the Speaker and minority leader of the 
     House of Representatives explaining the basis for rejecting 
     the recommendations of the Secretary.
       (B) Limitation.--The President--
       (i) may not designate more than 1 department or agency as 
     the Sector Risk Management Agency for each critical 
     infrastructure sector; and
       (ii) may only designate an agency under this subsection if 
     the agency is referenced in section 205 of the Chief 
     Financial Officers Act of 1990 (42 U.S.C. 901).
       (4) Publication.--Any designation of critical 
     infrastructure sectors shall be published in the Federal 
     Register.
       (e) Sector Risk Management Agencies.--
       (1) In general.--Any reference to a Sector-Specific Agency 
     in any law, regulation, map, document, record, or other paper 
     of the United States shall be deemed to be a reference to the 
     Sector Risk Management Agency of the relevant critical 
     infrastructure sector.
       (2) Coordination.--In carrying out this section, the head 
     of each Sector Risk Management Agency shall--
       (A) coordinate with the Secretary and the head of other 
     relevant Federal departments and agencies;
       (B) collaborate with critical infrastructure owners and 
     operators; and
       (C) as appropriate, coordinate with independent regulatory 
     agencies, and State, local, Tribal, and territorial entities.
       (3) Responsibilities.--The head of each Sector Risk 
     Management Agency shall utilize the specialized expertise of 
     the agency about the assigned critical infrastructure sector 
     and authorities of the agency under applicable law to support 
     and carry out activities for its assigned sector related to--
       (A) sector risk management, including--
       (i) establishing and carrying out programs to assist 
     critical infrastructure owners and operators within their 
     assigned sector in identifying, understanding, and mitigating 
     threats, vulnerabilities, and risks to their region, sector, 
     systems or assets; and
       (ii) recommending resilience measures to mitigate the 
     consequences of destruction, compromise, and disruption of 
     their systems and assets;
       (B) sector risk identification and assessment, including--
       (i) identifying, assessing, and prioritizing risks to 
     critical infrastructure within their sector, considering 
     physical and cyber threats, vulnerabilities, and 
     consequences; and
       (ii) supporting national risk assessment efforts led by the 
     Department, including identifying, assessing, and 
     prioritizing cross-sector and national-level risks;
       (C) sector coordination, including--
       (i) serving as a day-to-day Federal interface for the 
     dynamic prioritization and coordination of sector-specific 
     activities and their responsibilities under this section;
       (ii) serving as the government coordinating council chair 
     for their assigned sector; and
       (iii) participating in cross-sector coordinating councils, 
     as appropriate;
       (D) threat and vulnerability information sharing, 
     including--
       (i) facilitating access to, and exchange of, information 
     and intelligence necessary to strengthen the resilience of 
     critical infrastructure, including through the sector's 
     information sharing and analysis center;
       (ii) facilitating the identification of intelligence needs 
     and priorities of critical infrastructure in coordination 
     with the Director of National Intelligence and the heads of 
     other Federal departments and agencies, as appropriate;
       (iii) providing the Director ongoing, and where 
     practicable, real-time awareness of identified threats, 
     vulnerabilities, mitigations, and other actions related to 
     the security of critical infrastructure; and
       (iv) supporting the reporting requirements of the 
     Department under applicable law by providing, on an annual 
     basis, sector-specific critical infrastructure information;
       (E) incident management, including--
       (i) supporting incident management and restoration efforts 
     during or following a security incident;
       (ii) supporting the Cybersecurity and Infrastructure 
     Security Agency, as requested, in conducting vulnerability 
     assessments and asset response activities for critical 
     infrastructure; and
       (iii) supporting the Attorney General and law enforcement 
     agencies with efforts to detect and prosecute threats to and 
     attacks against critical infrastructure;
       (F) emergency preparedness, including--
       (i) coordinating with critical infrastructure owners and 
     operators in the development of planning documents for 
     coordinated action in response to an incident or emergency;
       (ii) conducting exercises and simulations of potential 
     incidents or emergencies; and
       (iii) supporting the Department and other Federal 
     departments or agencies in developing planning documents or 
     conducting exercises or simulations relevant to their 
     assigned sector;
       (G) participation in national risk management efforts, 
     including--
       (i) supporting the Secretary in the risk identification and 
     assessment activities carried out pursuant to subsection (c);
       (ii) supporting the President in the development of the 
     National Critical Infrastructure Resilience Strategy pursuant 
     to subsection (c); and
       (iii) implementing the National Critical Infrastructure 
     Resilience Strategy pursuant to subsection (c).
       (4) Status of information.--Information shared with a 
     Sector Risk Management Agency in furtherance of the 
     responsibilities outlined in paragraph (3)(B)(ii) shall be 
     treated as protected critical infrastructure information 
     under section 214 of the Homeland Security Act of 2002 (6 
     U.S.C. 673).
       (f) Reporting and Auditing.--Not later than 2 years after 
     the date of enactment of this Act, and once every 4 years 
     thereafter, the Comptroller General of the United States 
     shall submit a report to appropriate Committees of Congress 
     on the effectiveness of Sector Risk Management Agencies in 
     carrying out their responsibilities under subsection (e).
                                 ______