[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Page S3238]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1717. Mr. KING (for himself and Mr. Sasse) submitted an amendment
intended to be proposed by him to the bill S. 4049, to authorize
appropriations for fiscal year 2021 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. STRATEGY TO SECURE FOUNDATIONAL INTERNET PROTOCOLS
AND E-MAIL.
(a) Definitions.--In this section:
(1) Border gateway protocol.--The term ``border gateway
protocol'' means a protocol designed to optimize routing of
information exchanged through the internet.
(2) Domain name system.--The term ``domain name system''
means a system that stores information associated with domain
names in a distributed database on networks.
(3) Domain-based message authentication, reporting, and
conformance (dmarc).--The terms ``domain-based message
authentication, reporting, and conformance'' and ``DMARC''
mean an e-mail authentication, policy, and reporting protocol
that verifies the authenticity of the sender of an e-mail and
blocks and reports fraudulent accounts.
(4) Information and communications technology
infrastructure providers.--The term ``information and
communications technology infrastructure providers'' means
all systems that enable connectivity and operability of
internet service, backbone, cloud, web hosting, content
delivery, domain name system, and software-defined networks
and other systems and services.
(b) Creation of a Strategy to Secure Foundational Internet
Protocols and e-mail.--
(1) Protocol security strategy.--
(A) In general.--Not later than December 31, 2020, the
National Telecommunications and Information Administration,
in coordination with the Secretary of Homeland Security,
shall submit to Congress a strategy to secure the border
gateway protocol and the domain name system.
(B) Strategy requirements.--The strategy required under
subparagraph (A) shall--
(i) articulate the security and privacy benefits of
implementing border gateway protocol and domain name system
security as well as the burdens of implementation and the
entities on whom those burdens will most likely fall;
(ii) identify key United States and international
interested entities;
(iii) outline identified security measures that could be
used to secure or provide authentication for the border
gateway protocol and domain name system;
(iv) identify any barriers to implementing border gateway
protocol and domain name system security at scale;
(v) propose a strategy to implement identified security
measures at scale, accounting for barriers to implementation
and balancing benefits and burdens, where feasible; and
(vi) provide an initial estimate of the total cost to
government and implementing entities in the private sector of
implementing border gateway protocol and domain name system
security and propose recommendations for defraying these
costs, if applicable.
(C) Consultation.--In developing the strategy under
subparagraph (A), the National Telecommunications and
Information Administration, in coordination with the
Secretary of Homeland Security, shall consult with
information and communications technology infrastructure
providers, civil society organizations, relevant non-profits,
and academic experts.
(2) DMARC strategy.--
(A) In general.--Not later than December 31, 2021, the
Secretary of Homeland Security shall submit to Congress a
strategy to implement a domain-based message authentication,
reporting, and conformance standard across all United States-
based e-mail providers.
(B) Report requirements.--The strategy required by
subparagraph (A) shall--
(i) articulate the security and privacy benefits of
implementing the domain-based message authentication,
reporting, and conformance standard at scale, as well as the
burdens of implementation and the entities on whom those
burdens will most likely fall;
(ii) identify key United States and international
interested entities;
(iii) identify any barriers to implementing the domain-
based message authentication, reporting, and conformance
standard at scale across all United States-based e-mail
providers; and
(iv) propose a strategy to implement the domain-based
message authentication, reporting, and conformance standard
at scale across all United States-based e-mail providers,
accounting for barriers to implementation and balancing
benefits and burdens, where feasible.
(C) Cost estimate.--The strategy required under
subparagraph (A) shall include--
(i) an initial estimate of the total cost to the Federal
Government and private sector implementing entities of
implementing the domain-based message authentication,
reporting, and conformance standard at scale across all
United States-based e-mail providers; and
(ii) recommendations for defraying the cost described in
clause (i), if applicable.
(D) Consultation.--In developing the strategy pursuant to
subparagraph (A), the Secretary of Homeland Security shall
consult with the information technology sector.
______