[Congressional Record Volume 166, Number 117 (Thursday, June 25, 2020)]
[Senate]
[Page S3409]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 1917. Ms. HASSAN (for herself, Mr. Cornyn, Mr. Portman, and Mr.
Peters) submitted an amendment intended to be proposed by her to the
bill S. 4049, to authorize appropriations for fiscal year 2021 for
military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the appropriate place, insert the following:
SEC. __. CYBERSECURITY STATE COORDINATOR ACT.
(a) Short Title.--This section may be cited as the
``Cybersecurity State Coordinator Act of 2020''.
(b) Cybersecurity State Coordinator.--
(1) In general.--Subtitle A of title XXII of the Homeland
Security Act of 2002 (6 U.S.C. 651 et seq.) is amended--
(A) in section 2202(c) (6 U.S.C. 652(c))--
(i) in paragraph (10), by striking ``and'' at the end;
(ii) by redesignating paragraph (11) as paragraph (12); and
(iii) by inserting after paragraph (10) the following:
``(11) appoint a Cybersecurity State Coordinator in each
State, as described in section 2215; and''; and
(B) by adding at the end the following:
``SEC. 2215. CYBERSECURITY STATE COORDINATOR.
``(a) Appointment.--The Director shall appoint an employee
of the Agency in each State, with the appropriate
cybersecurity qualifications and expertise, who shall serve
as the Cybersecurity State Coordinator.
``(b) Duties.--The duties of a Cybersecurity State
Coordinator appointed under subsection (a) shall include--
``(1) building strategic relationships across Federal and,
on a voluntary basis, non-Federal entities by advising on
establishing governance structures to facilitate the
development and maintenance of secure and resilient
infrastructure;
``(2) serving as a Federal cybersecurity risk advisor and
coordinating between Federal and, on a voluntary basis, non-
Federal entities to support preparation, response, and
remediation efforts relating to cybersecurity risks and
incidents;
``(3) facilitating the sharing of cyber threat information
between Federal and, on a voluntary basis, non-Federal
entities to improve understanding of cybersecurity risks and
situational awareness of cybersecurity incidents;
``(4) raising awareness of the financial, technical, and
operational resources available from the Federal Government
to non-Federal entities to increase resilience against cyber
threats;
``(5) supporting training, exercises, and planning for
continuity of operations to expedite recovery from
cybersecurity incidents, including ransomware;
``(6) serving as a principal point of contact for non-
Federal entities to engage, on a voluntary basis, with the
Federal Government on preparing, managing, and responding to
cybersecurity incidents;
``(7) assisting non-Federal entities in developing and
coordinating vulnerability disclosure programs consistent
with Federal and information security industry standards; and
``(8) performing such other duties as determined necessary
by the Director to achieve the goal of managing cybersecurity
risks in the United States and reducing the impact of cyber
threats to non-Federal entities.
``(c) Feedback.--The Director shall consult with relevant
State and local officials regarding the appointment, and
State and local officials and other non-Federal entities
regarding the performance, of the Cybersecurity State
Coordinator of a State.''.
(2) Oversight.--The Director of the Cybersecurity and
Infrastructure Security Agency shall provide to the Committee
on Homeland Security and Governmental Affairs of the Senate
and the Committee on Homeland Security of the House of
Representatives a briefing on the placement and efficacy of
the Cybersecurity State Coordinators appointed under section
2215 of the Homeland Security Act of 2002, as added by
paragraph (1)--
(A) not later than 1 year after the date of enactment of
this Act; and
(B) not later than 2 years after providing the first
briefing under this paragraph.
(3) Rule of construction.--Nothing in this subsection or
the amendments made by this subsection shall be construed to
affect or otherwise modify the authority of Federal law
enforcement agencies with respect to investigations relating
to cybersecurity incidents.
(4) Technical and conforming amendment.--The table of
contents in section 1(b) of the Homeland Security Act of 2002
(Public Law 107-296; 116 Stat. 2135) is amended by inserting
after the item relating to section 2214 the following:
``Sec. 2215. Cybersecurity State Coordinator.''.
______