[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Page S3238]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1717. Mr. KING (for himself and Mr. Sasse) submitted an amendment 
intended to be proposed by him to the bill S. 4049, to authorize 
appropriations for fiscal year 2021 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. ___. STRATEGY TO SECURE FOUNDATIONAL INTERNET PROTOCOLS 
                   AND E-MAIL.

       (a) Definitions.--In this section:
       (1) Border gateway protocol.--The term ``border gateway 
     protocol'' means a protocol designed to optimize routing of 
     information exchanged through the internet.
       (2) Domain name system.--The term ``domain name system'' 
     means a system that stores information associated with domain 
     names in a distributed database on networks.
       (3) Domain-based message authentication, reporting, and 
     conformance (dmarc).--The terms ``domain-based message 
     authentication, reporting, and conformance'' and ``DMARC'' 
     mean an e-mail authentication, policy, and reporting protocol 
     that verifies the authenticity of the sender of an e-mail and 
     blocks and reports fraudulent accounts.
       (4) Information and communications technology 
     infrastructure providers.--The term ``information and 
     communications technology infrastructure providers'' means 
     all systems that enable connectivity and operability of 
     internet service, backbone, cloud, web hosting, content 
     delivery, domain name system, and software-defined networks 
     and other systems and services.
       (b) Creation of a Strategy to Secure Foundational Internet 
     Protocols and e-mail.--
       (1) Protocol security strategy.--
       (A) In general.--Not later than December 31, 2020, the 
     National Telecommunications and Information Administration, 
     in coordination with the Secretary of Homeland Security, 
     shall submit to Congress a strategy to secure the border 
     gateway protocol and the domain name system.
       (B) Strategy requirements.--The strategy required under 
     subparagraph (A) shall--
       (i) articulate the security and privacy benefits of 
     implementing border gateway protocol and domain name system 
     security as well as the burdens of implementation and the 
     entities on whom those burdens will most likely fall;
       (ii) identify key United States and international 
     interested entities;
       (iii) outline identified security measures that could be 
     used to secure or provide authentication for the border 
     gateway protocol and domain name system;
       (iv) identify any barriers to implementing border gateway 
     protocol and domain name system security at scale;
       (v) propose a strategy to implement identified security 
     measures at scale, accounting for barriers to implementation 
     and balancing benefits and burdens, where feasible; and
       (vi) provide an initial estimate of the total cost to 
     government and implementing entities in the private sector of 
     implementing border gateway protocol and domain name system 
     security and propose recommendations for defraying these 
     costs, if applicable.
       (C) Consultation.--In developing the strategy under 
     subparagraph (A), the National Telecommunications and 
     Information Administration, in coordination with the 
     Secretary of Homeland Security, shall consult with 
     information and communications technology infrastructure 
     providers, civil society organizations, relevant non-profits, 
     and academic experts.
       (2) DMARC strategy.--
       (A) In general.--Not later than December 31, 2021, the 
     Secretary of Homeland Security shall submit to Congress a 
     strategy to implement a domain-based message authentication, 
     reporting, and conformance standard across all United States-
     based e-mail providers.
       (B) Report requirements.--The strategy required by 
     subparagraph (A) shall--
       (i) articulate the security and privacy benefits of 
     implementing the domain-based message authentication, 
     reporting, and conformance standard at scale, as well as the 
     burdens of implementation and the entities on whom those 
     burdens will most likely fall;
       (ii) identify key United States and international 
     interested entities;
       (iii) identify any barriers to implementing the domain-
     based message authentication, reporting, and conformance 
     standard at scale across all United States-based e-mail 
     providers; and
       (iv) propose a strategy to implement the domain-based 
     message authentication, reporting, and conformance standard 
     at scale across all United States-based e-mail providers, 
     accounting for barriers to implementation and balancing 
     benefits and burdens, where feasible.
       (C) Cost estimate.--The strategy required under 
     subparagraph (A) shall include--
       (i) an initial estimate of the total cost to the Federal 
     Government and private sector implementing entities of 
     implementing the domain-based message authentication, 
     reporting, and conformance standard at scale across all 
     United States-based e-mail providers; and
       (ii) recommendations for defraying the cost described in 
     clause (i), if applicable.
       (D) Consultation.--In developing the strategy pursuant to 
     subparagraph (A), the Secretary of Homeland Security shall 
     consult with the information technology sector.
                                 ______