[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Page S3243]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1727. Mr. KING (for himself and Mr. Sasse) submitted an amendment
intended to be proposed by him to the bill S. 4049, to authorize
appropriations for fiscal year 2021 for military activities of the
Department of Defense, for military construction, and for defense
activities of the Department of Energy, to prescribe military personnel
strengths for such fiscal year, and for other purposes; which was
ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. __. ESTABLISHMENT OF JOINT CYBER PLANNING OFFICE.
(a) Amendment.--Subtitle A of title XXII of the Homeland
Security Act of 2002 (6 U.S.C. 651 et seq.) is amended by
adding at the end the following:
``SEC. 2215. JOINT CYBER PLANNING OFFICE.
``(a) Establishment of Office.--There is established in the
Agency an office for joint cyber planning (referred to in
this section as the `Office') to carry out certain
responsibilities of the Secretary. The Office shall be headed
by a Director of Joint Cyber Planning.
``(b) Mission.--The Office shall lead Government-wide and
public-private planning for cyber defense campaigns,
including the development of a set of coordinated actions to
respond to and recover from significant cyber incidents or
limit, mitigate, or defend against coordinated, malicious
cyber campaigns that pose a potential risk to critical
infrastructure of the United States and broader national
interests.
``(c) Planning and Execution.--In leading the development
of Government-wide and public-private plans for cyber defense
campaigns pursuant to subsection (b), the Director of Joint
Cyber Planning shall--
``(1) establish coordinated and deliberate processes and
procedures across relevant Federal departments and agencies,
accounting for all participating Federal agency cyber
capabilities and authorities;
``(2) ensure that plans are, to the greatest extent
practicable, developed in collaboration with relevant public-
and private-sector entities, particularly in areas where such
entities have comparative advantages in limiting, mitigating,
or defending against a significant cyber incident or
coordinated, malicious cyber campaign;
``(3) ensure that plans are responsive to potential
adversary activity conducted in response to U.S. offensive
cyber operations.
``(4) in order to inform and facilitate exercises of such
plans, develop and model scenarios based on an understanding
of adversary threats, critical infrastructure vulnerability,
and potential consequences of disruption or compromise;
``(5) coordinate with and, as necessary, support relevant
Federal agencies in the establishment of procedures,
development of additional plans, including for offensive and
intelligence activities in support of cyber defense campaign
plans, and procurement of authorizations necessary for the
rapid execution of plans once a significant cyber incident or
malicious cyber campaign has been identified; and
``(6) support the Department and other Federal agencies, as
appropriate, in coordination and execution of plans developed
pursuant to this section.
``(d) Composition.--The Office shall be composed of--
``(1) a central planning staff;
``(2) appropriate representatives of Federal agencies,
including--
``(A) the United States Cyber Command;
``(B) the National Security Agency;
``(C) the Federal Bureau of Investigation;
``(D) the Federal Emergency Management Agency; and
``(E) the Office of the Director of National Intelligence;
``(3) appropriate representatives of non-Federal entities,
such as--
``(A) State, local, and tribal governments;
``(B) information sharing and analysis organizations,
including information sharing and analysis centers;
``(C) owners and operators of critical information systems;
and
``(D) private entities; and
``(4) other appropriate representatives or entities, as
determined by the Secretary.
``(e) Interagency Agreements.--The Secretary and the head
of a Federal agency described in subsection (d) may enter
into agreements for the purpose of detailing personnel on a
reimbursable or non-reimbursable basis.
``(f) Information Protection.--Information provided to the
Office by a private entity shall be considered to have been
shared pursuant to section 103(c) of the Cybersecurity
Information Sharing Act of 2015 (6 U.S.C. 1503(c)) and shall
receive the protections and exemptions provided in such Act.
``(g) Funds.--There are authorized to be appropriated
$15,000,000 to the Director of Joint Cyber Planning to carry
out this section.
``(h) Definitions.--In this section:
``(1) Critical infrastructure.--The term `critical
infrastructure' means a physical or cyber system or asset
that are so vital to the United States that the incapacity or
destruction of such system or asset would have a debilitating
impact on the physical or economic security of the United
States or on public health or safety.
``(2) Cyber defense campaign.--The term `cyber defense
campaign' means a set of coordinated actions to respond to
and recover from a significant cyber incident or limit,
mitigate, or defend against a coordinated, malicious cyber
campaign targeting critical infrastructure in the United
States.
``(3) Significant cyber incident.--The term `significant
cyber incident' means an incident that is, or group of
related cyber incidents that together are, reasonably likely
to result in significant harm to the national security,
foreign policy, or economic health or financial stability of
the United States.''.
(b) Technical and Conforming Amendment.--The table of
contents in section 1(b) of the Homeland Security Act of 2002
(Public Law 107-296; 116 Stat.2135) is amended by inserting
after the item relating to section 2214 the following:
``Sec. 2215. Joint Cyber Planning Office.''.
______