[Congressional Record Volume 166, Number 116 (Wednesday, June 24, 2020)]
[Senate]
[Page S3243]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1727. Mr. KING (for himself and Mr. Sasse) submitted an amendment 
intended to be proposed by him to the bill S. 4049, to authorize 
appropriations for fiscal year 2021 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. __. ESTABLISHMENT OF JOINT CYBER PLANNING OFFICE.

       (a) Amendment.--Subtitle A of title XXII of the Homeland 
     Security Act of 2002 (6 U.S.C. 651 et seq.) is amended by 
     adding at the end the following:

     ``SEC. 2215. JOINT CYBER PLANNING OFFICE.

       ``(a) Establishment of Office.--There is established in the 
     Agency an office for joint cyber planning (referred to in 
     this section as the `Office') to carry out certain 
     responsibilities of the Secretary. The Office shall be headed 
     by a Director of Joint Cyber Planning.
       ``(b) Mission.--The Office shall lead Government-wide and 
     public-private planning for cyber defense campaigns, 
     including the development of a set of coordinated actions to 
     respond to and recover from significant cyber incidents or 
     limit, mitigate, or defend against coordinated, malicious 
     cyber campaigns that pose a potential risk to critical 
     infrastructure of the United States and broader national 
     interests.
       ``(c) Planning and Execution.--In leading the development 
     of Government-wide and public-private plans for cyber defense 
     campaigns pursuant to subsection (b), the Director of Joint 
     Cyber Planning shall--
       ``(1) establish coordinated and deliberate processes and 
     procedures across relevant Federal departments and agencies, 
     accounting for all participating Federal agency cyber 
     capabilities and authorities;
       ``(2) ensure that plans are, to the greatest extent 
     practicable, developed in collaboration with relevant public- 
     and private-sector entities, particularly in areas where such 
     entities have comparative advantages in limiting, mitigating, 
     or defending against a significant cyber incident or 
     coordinated, malicious cyber campaign;
       ``(3) ensure that plans are responsive to potential 
     adversary activity conducted in response to U.S. offensive 
     cyber operations.
       ``(4) in order to inform and facilitate exercises of such 
     plans, develop and model scenarios based on an understanding 
     of adversary threats, critical infrastructure vulnerability, 
     and potential consequences of disruption or compromise;
       ``(5) coordinate with and, as necessary, support relevant 
     Federal agencies in the establishment of procedures, 
     development of additional plans, including for offensive and 
     intelligence activities in support of cyber defense campaign 
     plans, and procurement of authorizations necessary for the 
     rapid execution of plans once a significant cyber incident or 
     malicious cyber campaign has been identified; and
       ``(6) support the Department and other Federal agencies, as 
     appropriate, in coordination and execution of plans developed 
     pursuant to this section.
       ``(d) Composition.--The Office shall be composed of--
       ``(1) a central planning staff;
       ``(2) appropriate representatives of Federal agencies, 
     including--
       ``(A) the United States Cyber Command;
       ``(B) the National Security Agency;
       ``(C) the Federal Bureau of Investigation;
       ``(D) the Federal Emergency Management Agency; and
       ``(E) the Office of the Director of National Intelligence;
       ``(3) appropriate representatives of non-Federal entities, 
     such as--
       ``(A) State, local, and tribal governments;
       ``(B) information sharing and analysis organizations, 
     including information sharing and analysis centers;
       ``(C) owners and operators of critical information systems; 
     and
       ``(D) private entities; and
       ``(4) other appropriate representatives or entities, as 
     determined by the Secretary.
       ``(e) Interagency Agreements.--The Secretary and the head 
     of a Federal agency described in subsection (d) may enter 
     into agreements for the purpose of detailing personnel on a 
     reimbursable or non-reimbursable basis.
       ``(f) Information Protection.--Information provided to the 
     Office by a private entity shall be considered to have been 
     shared pursuant to section 103(c) of the Cybersecurity 
     Information Sharing Act of 2015 (6 U.S.C. 1503(c)) and shall 
     receive the protections and exemptions provided in such Act.
       ``(g) Funds.--There are authorized to be appropriated 
     $15,000,000 to the Director of Joint Cyber Planning to carry 
     out this section.
       ``(h) Definitions.--In this section:
       ``(1) Critical infrastructure.--The term `critical 
     infrastructure' means a physical or cyber system or asset 
     that are so vital to the United States that the incapacity or 
     destruction of such system or asset would have a debilitating 
     impact on the physical or economic security of the United 
     States or on public health or safety.
       ``(2) Cyber defense campaign.--The term `cyber defense 
     campaign' means a set of coordinated actions to respond to 
     and recover from a significant cyber incident or limit, 
     mitigate, or defend against a coordinated, malicious cyber 
     campaign targeting critical infrastructure in the United 
     States.
       ``(3) Significant cyber incident.--The term `significant 
     cyber incident' means an incident that is, or group of 
     related cyber incidents that together are, reasonably likely 
     to result in significant harm to the national security, 
     foreign policy, or economic health or financial stability of 
     the United States.''.
       (b) Technical and Conforming Amendment.--The table of 
     contents in section 1(b) of the Homeland Security Act of 2002 
     (Public Law 107-296; 116 Stat.2135) is amended by inserting 
     after the item relating to section 2214 the following:

``Sec. 2215. Joint Cyber Planning Office.''.
                                 ______