[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Pages S3240-S3241]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1721. Mr. KING (for himself and Mr. Sasse) submitted an amendment
intended to be proposed by him to the bill S. 4049, to authorize
appropriations for fiscal year 2021 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. ___. BIENNIAL NATIONAL CYBER EXERCISE.
(a) Requirement.--Not later than December 31, 2023, and not
less frequently than once every 2 years thereafter until a
date that is not less than 10 years after the date of
enactment of this Act, the Secretary, in consultation with
the President and the Secretary of Defense, shall conduct an
exercise to test the resilience, response, and recovery of
the United States in the case of a significant cyber incident
impacting critical infrastructure.
(b) Planning and Preparation.--
(1) In general.--Each exercise required under subsection
(a) shall be prepared by expert operational planners from--
(A) the Department of Homeland Security;
(B) the Department of Defense;
(C) the Federal Bureau of Investigation; and
(D) appropriate elements of the intelligence community, as
specified or designated under section 3(4) of the National
Security Act of 1947 (50 U.S.C. 3003(4)) identified by the
Director of National Intelligence.
(2) Assistance.--The Cybersecurity and Infrastructure
Security Agency of the Department of Homeland Security shall
provide assistance to the expert operational planners
described in paragraph (1) in the preparation of each
exercise required under subsection (a).
(c) Participants.--
(1) Federal government participants.--
(A) Relevant interagency partners, as determined by the
Secretary, shall participate in the exercise required under
subsection (a), including relevant interagency partners
from--
(i) law enforcement agencies;
(ii) elements of the intelligence community, as specified
or designated under section 3(4) of the National Security Act
of 1947 (50 U.S.C. 3003(4)); and
(iii) the Department of Defense.
(B) Senior leader representatives from sector-specific
agencies, as determined by the Secretary, shall participate
in the exercise required under subsection (a).
(C) Under subparagraph (B), the Secretary shall determine
that not less than 1 senior leader representative from each
sector-specific agency participates in an exercise required
under subsection (a) not less frequently than once every 4
years.
(2) State and local governments.--The Secretary shall
invite representatives from
[[Page S3241]]
State, local, and Tribal governments to participate in the
exercise required under subsection (a) if the Secretary
determines the participation of those representatives to be
appropriate.
(3) Private sector.--Depending on the nature of an exercise
being conducted under subsection (a), the Secretary, in
consultation with the senior leader representative of the
sector-specific agencies participating in the exercise under
paragraph (1)(B), shall invite the following individuals to
participate:
(A) Representatives from private entities.
(B) Other individuals that the Secretary determines will
best assist the United States in preparing for, and defending
against, a cyber attack.
(4) International partners.--Depending on the nature of an
exercise being conducted under subsection (a), the Secretary
shall invite allies and partners of the United States to
participate in the exercise.
(d) Observers.--The Secretary may invite representatives
from the executive and legislative branches of the Federal
Government to observe the exercise required under subsection
(a).
(e) Elements.--The exercise required under subsection (a)
shall include the following elements:
(1) Exercising of the orchestration of cybersecurity
response and the provision of cyber support to Federal,
State, local, and Tribal governments and private entities,
including exercising of the command, control, and
deconfliction of operational responses of--
(A) the National Security Council;
(B) interagency coordinating and response groups; and
(C) each Federal Government participant described in
subsection (c)(1).
(2) Testing of the information-sharing needs and
capabilities of exercise participants.
(3) Testing of the relevant policy, guidance, and doctrine,
including the National Cyber Incident Response Plan of the
Cybersecurity and Infrastructure Security Agency of the
Department of Homeland Security.
(4) A test of the interoperability of Federal, State,
local, and Tribal governments and private entities.
(5) Exercising of the integration of operational
capabilities of the Department of Homeland Security, the
Cyber Mission Force, Federal law enforcement agencies, and
elements of the intelligence community, as specified or
designated under section 3(4) of the National Security Act of
1947 (50 U.S.C. 3003(4)).
(6) Exercising of integrated operations, mutual support,
and shared situational awareness of the cybersecurity
operations centers of the Federal Government, including--
(A) the Cybersecurity and Infrastructure Security Agency of
the Department of Homeland Security;
(B) the Cyber Threat Operations Center of the National
Security Agency;
(C) the Joint Operations Center of Cyber Command;
(D) the Cyber Threat Intelligence Integration Center of the
Office of the Director of National Intelligence;
(E) the National Cyber Investigative Joint Task Force of
the Federal Bureau of Investigation;
(F) the Defense Cyber Crime Center of the Department of
Defense; and
(G) the Intelligence Community Security Coordination Center
of the Office of the Director of National Intelligence.
(f) Briefing.--
(1) In general.--Not later than 180 days after the date on
which each exercise required under subsection (a) is
conducted, the President shall submit to the appropriate
congressional committees a briefing on the participation of
the Federal Government participants described in subsection
(c)(1) in the exercise.
(2) Contents.--The briefing required under paragraph (1)
shall include--
(A) an assessment of the decision and response gaps
observed in the national level response exercise described in
paragraph (1);
(B) proposed recommendations to improve the resilience,
response, and recovery of the United States in the case of a
significant cyber attack against critical infrastructure;
(C) plans to implement the recommendations described in
subparagraph (B); and
(D) specific timelines for the implementation of the plans
described in subparagraph (C).
(g) Repeal.--Subsection (b) of section 1648 of the National
Defense Authorization Act for Fiscal Year 2016 (Public Law
114-92; 129 Stat. 1119) is repealed.
(h) Definitions.--In this section:
(1) Appropriate congressional committees.--The term
``appropriate congressional committees'' means--
(A) the Committee on Armed Services of the Senate;
(B) the Committee on Armed Services of the House of
Representatives;
(C) the Committee on Homeland Security and Governmental
Affairs of the Senate; and
(D) the Committee on Homeland Security of the House of
Representatives.
(2) Private entity.--The term ``private entity'' has the
meaning given the term in section 102 of the Cybersecurity
Information Sharing Act of 2015 (6 U.S.C. 1501).
(3) Secretary.--The term ``Secretary'' means the Secretary
of Homeland Security.
(4) Sector-specific agency.--The term ``sector-specific
agency'' has the meaning given the term ``Sector-Specific
Agency'' in section 2201 of the Homeland Security Act of 2002
(6 U.S.C. 651).
(5) State.--The term ``State'' means any State of the
United States, the District of Columbia, the Commonwealth of
Puerto Rico, the Northern Mariana Islands, the United States
Virgin Islands, Guam, American Samoa, and any other territory
or possession of the United States.
______