[Congressional Record Volume 166, Number 117 (Thursday, June 25, 2020)]
[Senate]
[Pages S3407-S3408]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 1910. Mr. WARNER submitted an amendment intended to be proposed by 
him to the bill S. 4049, to authorize appropriations for fiscal year 
2021 for military activities of the Department of Defense, for military 
construction, and for defense activities of the Department of Energy, 
to prescribe military personnel strengths for such fiscal year, and for 
other purposes; which was ordered to lie on the table; as follows:

       At the appropriate place in subtitle B of title XVI, insert 
     the following:

     SEC. ___. STUDY ON ALTERNATIVES AND RECOMMENDATIONS FOR 
                   PROVIDING A CYBER PROTECTION PROGRAM FOR THE 
                   DEFENSE INDUSTRIAL BASE.

       (a) Study Required.--The Secretary of Defense shall conduct 
     a study to explore alternatives and recommendations for 
     providing a cyber protection program for the defense 
     industrial base.
       (b) Assessment.--The study conducted under subsection (a) 
     shall include an assessment of the viability and 
     affordability of various options for securing Department of 
     Defense information and defense industrial base development 
     environments, including the roles of the Department members 
     of the defense industrial base, and commercial cybersecurity 
     industry in providing the following effective security 
     capabilities for the defense industrial base.
       (c) Elements.--At a minimum, the study required by 
     subsection (a) shall include the following:
       (1) Global security operations center.--Consideration of a 
     global security operations center, including the following:
       (A) Assessment of the feasibility (technical, policy, cost, 
     and etcetera) of offering voluntary defense industrial base 
     protection via a managed global security operations center 
     model. Options considered shall include Department management 
     and provision of [SOC] services or contracting to private 
     industry for managed security services devoted exclusively to 
     the defense industrial base.
       (B) Determination of minimum functions to be provided and 
     whether those functions are either met by existing defense 
     industrial base entities or not. Possible functions 
     considered shall include dissemination of cyber threat 
     intelligence, cyber situation monitoring, development and 
     testing of advanced analytics, alerting and incident 
     response, and coordination with other [SOC]s and computer 
     security incident response teams (CSIRTS).
       (C) Definition and analysis of options for global security 
     operations center management and oversight (such as public 
     entity, private entity, cleared defense contractor, 
     Department entity, or joint venture), operations and support 
     to defense industrial base entities, staffing, and funding.
       (D) Evaluation of the current state of managed security 
     services to determine their suitability for this role.
       (2) Reduced-rate licensing for commercial cyber security 
     products that meet minimum compliance with nist 800-171.--
     Consideration of a reduced-rate licensing for commercial 
     cyber security products that meet minimum compliance with 
     National Institute of Standards and Technology special 
     publication 800-171, including the following:
       (A) Estimation of the cost and identification of the 
     advantages and disadvantages of having the Department 
     subsidize the cost of advanced cybersecurity tools to protect 
     the unclassified networks of defense industrial base 
     contractors. Such estimation and identification shall include 
     tools that are configured to provide sanitized threat data to 
     the global security operations center considered under 
     paragraph (1).
       (B) Analysis of any economies of scale cost benefits and 
     reduced compliance barriers for the defense industrial base 
     by using reduced-rate licensing to improve cybersecurity 
     postures.
       (3) Secure hosting and access to development environments 
     and data.--Consideration of secure hosting and access to 
     development environments and data, including secure cloud 
     environments and software development offerings, including 
     the following:
       (A) Requiring contractors to provide secure systems and 
     connectivity to all subcontractors.

[[Page S3408]]

       (B) Department development and provision of secure systems 
     and connectivity to eligible defense industrial base 
     contractors, including secure cloud services.
       (C) Providing secure development environments as a service 
     by negotiating with commercial providers to offer consistent, 
     low-priced options to eligible defense industrial base 
     contractors (with possible incentives to commercial 
     providers).
       (D) Such other options as may be worthy.
       (4) Department develop secure cloud computing 
     environment.--Consideration of a Department developed secure 
     cloud computing environment providing secure cloud services 
     to eligible Department contractors at reduced and affordable 
     rates.
       (d) Additional Requirements.--In carrying out the study, 
     the Secretary shall--
       (1) define the trade-space for options, the evaluation of 
     cyber risk for each proposed capability and option, and 
     determination of Department member eligibility for 
     participating in any program and receiving benefit;
       (2) assess legal matters (such as protections for 
     participating defense industrial base companies) and 
     contractual (such as Defense Acquisition Regulations System) 
     ramifications; and
       (3) use experts from across the Department, the defense 
     industrial base, and commercial sectors as part of the study 
     team.
                                 ______