[Congressional Record Volume 166, Number 119 (Monday, June 29, 2020)]
[Senate]
[Pages S3658-S3659]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]
SA 2214. Mr. KING submitted an amendment intended to be proposed by
him to the bill S. 4049, to authorize appropriations for fiscal year
2021 for military activities of the Department of Defense, for military
construction, and for defense activities of the Department of Energy,
to prescribe military personnel strengths for such fiscal year, and for
other purposes; which was ordered to lie on the table; as follows:
At the title X, add the following:
Subtitle _--National Cybersecurity Certification and Labeling
SEC. _01. DEFINITIONS.
In this subtitle:
(1) Accredited certifying agent.--The term ``accredited
certifying agent'' means any person who is accredited by the
National Cybersecurity Certification and Labeling Authority
as a certifying agent for the purposes of certifying a
specific class of critical information and communications
technology.
(2) Certification.--The term ``certification'' means a seal
or symbol provided by the National Cybersecurity
Certification and Labeling Authority or an accredited
certifying agent, that results from passage of a
comprehensive evaluation of an information and communications
technology that establishes the extent to which a particular
design and implementation meets a set of specified security
standards.
(3) Critical information and communications technology.--
The term ``critical information and communications
technology'' means information and communications
[[Page S3659]]
technology that is in use in critical infrastructure sectors
and that underpins national critical functions as determined
by the Secretary of Homeland Security.
(4) Label.--The term ``label'' means a clear, visual, and
easy to understand symbol or list that conveys specific
information about a product's security attributes,
characteristics, functionality, components, or other features
SEC. _02. NATIONAL CYBERSECURITY CERTIFICATION AND LABELING
AUTHORITY AND PROGRAM.
(a) Establishment.--There is established a National
Cybersecurity Certification and Labeling Authority
(hereinafter referred to as the ``Authority'') for the
purpose of administering a voluntary program, which the
Authority shall establish, for the certification and labeling
of critical information and communications technologies.
(b) Accreditation of Certifying Agents.--As part of the
program established and administered under subsection (a),
the Authority shall define and publish a process whereby
nongovernmental entities may apply to become accredited
agents for the certification of specific critical information
and communications technologies.
(c) Identification of Standards, Frameworks, and
Benchmarks.--As part of the program established and
administered under subsection (a), the Authority shall work
in close coordination with the Secretary of Commerce, the
Secretary of Homeland Security, and subject matter experts
from the Federal Government, academia, nongovernmental
organizations, and the private sector to identify and
harmonize common security standards, frameworks, and
benchmarks against which the security of critical information
and communications technologies may be measured.
(d) Product Certification.--As part of the program
established and administered under subsection (a), the
Authority, in consultation with the Secretary of Commerce,
the Secretary of Homeland Security, and other experts from
the Federal Government, academia, nongovernmental
organizations, and the private sector, shall--
(1) develop, and disseminate to accredited certifying
agents, guidelines to standardize the presentation of
certifications to communicate the level of security for
critical information and communications technologies;
(2) develop, or permit agents accredited under subsection
(b) to develop, certification criteria for critical
information and communications technologies based on
identified security standards, frameworks, and benchmarks,
through the work conducted pursuant to subsection (c);
(3) issue, or permit agents accredited under subsection (b)
to issue, certifications for products and services that meet
and comply with security standards, frameworks, and
benchmarks the standards, frameworks, and benchmarks
identified under subsection (c);
(4) permit a manufacturer or distributor of a critical
information and communication technology to display a
certificate reflecting the extent to which the covered
product meets the standards, frameworks, and benchmarks
identified under subsection (c);
(5) remove the certification of a critical information and
communication technology as a critical information and
communication technology certified under the program if the
manufacturer of the certified critical information and
communication technology falls out of conformity with the
standards, frameworks, and benchmarks identified under
subsection (c);
(6) work to enhance public awareness of the Authority's
certificates and labeling, including through public outreach,
education, research and development, and other means; and
(7) publicly display a list of certified critical
information and communication technology, along with their
respective certification information.
(e) Certifications.--
(1) In general.--Certifications issued under the program
established and administered under subsection (a) shall
remain valid for one year from the date of issuance.
(2) Classes of certification.--In identifying and
harmonizing the standards, frameworks, and benchmarks under
subsection (c), the Authority shall designate at least three
classes of certifications, including--
(A) for products and services that product manufacturers
and service providers of critical information and
communications attest meet the criteria for certification
under the program established and administered under
subsection (a), attestation-based certification;
(B) for products that have undergone a security evaluation
and testing process by a qualifying third party,
accreditation-based certification; and
(C) for products that have undergone a security evaluation
and testing process by a qualifying third party, test-based
certification.
(f) Product Labeling.--The Authority, in consultation with
the Secretary of Commerce, the Secretary of Homeland
Security, and other experts from the Federal Government,
academia, nongovernmental organizations, and the private
sector, shall--
(1) collaborate with the private sector to standardize
language and define a labeling schema to provide transparent
information on the security characteristics and constituent
components of a software or hardware product that includes
critical information and communication technology; and
(2) establish a mechanism by which product developers can
provide this information for both product labeling and public
posting.
(g) Enforcement.--
(1) Prohibition.--It shall be unlawful for a person--
(A) to falsely attested to, or falsify an audit or test
for, a security standard, framework, or benchmark for
certification;
(B) to intentionally mislabel a product; or
(C) to failed to maintain a security standard, framework,
or benchmark to which the person has attested for a security
standard, framework, or benchmark for certification.
(2) Enforcement by federal trade commission.--
(A) Unfair or deceptive acts or practices.--A violation of
paragraph (1) shall be treated as an unfair and deceptive act
or practice in violation of a regulation under section
18(a)(1)(B) of the Federal Trade Commission Act (15 U.S.C.
57a(a)(1)(B)) regarding unfair or deceptive acts or
practices.
(B) Powers of commission.--
(i) In general.--The Federal Trade Commission shall enforce
this subsection in the same manner, by the same means, and
with the same jurisdiction, powers, and duties as though all
applicable terms and provisions of the Federal Trade
Commission Act (15 U.S.C. 41 et seq.) were incorporated into
and made a part of this subsection.
(ii) Privileges and immunities.--Any person who violates
this subsection shall be subject to the penalties and
entitled to the privileges and immunities provided in the
Federal Trade Commission Act (15 U.S.C. 41 et seq.).
SEC. _03. SELECTION OF THE AUTHORITY.
(a) Selection.--The Secretary of Commerce, in coordination
with the Secretary of Homeland Security, shall issue a notice
of funding opportunity and select, on a competitive basis, a
nonprofit, nongovernmental organization to serve as the
National Cybersecurity Certification and Labeling Authority
(in this section referred to as the ``Authority'') for period
of five years.
(b) Eligibility for Selection.--The Secretary of Commerce
may only select an organization to serve as the Authority if
such organization--
(1) is a nongovernmental, not-for-profit that is--
(A) exempt from taxation under section 501(a) of the
Internal Revenue Code of 1986; and
(B) described in sections 501(c)(3) and 170(b)(1)(A)(vi) of
that Code;
(2) has a demonstrable track record of work on
cybersecurity and information security standards, frameworks,
and benchmarks; and
(3) possesses requisite staffing and expertise, with
demonstrable prior experience in technology security or
safety standards, frameworks, and benchmarks, as well as
certification.
(c) Application.--The Secretary shall establish a process
by which a nonprofit, nongovernmental organization that seeks
to be selected as the Authority may apply for consideration.
(d) Program Evaluation.--Not later than the date that is
four years after the initial selection pursuant subsection
(a), and every four years thereafter, the Secretary of
Commerce, in consultation with the Secretary of Homeland
Security, shall--
(1) assess the effectiveness of the labels and certificates
produced by the Authority, including--
(A) assessing the costs to businesses that manufacture
critical information and communication technologies
participating in the Authority's program;
(B) evaluating the level of participation in the
Authority's program by businesses that manufacture critical
information and communication technologies; and
(C) assessing the level of public awareness and consumer
awareness of the labels under the Authority's program;
(2) audit the impartiality and fairness of the activities
of the Authority;
(3) issue a public report on the assessment most recently
carried out under paragraph (1) and the audit most recently
carried out under paragraph (2); and
(4) brief Congress on the findings of the Secretary of
Commerce with respect to the most recent assessment under
paragraph (1) and the most recent audit under paragraph (2).
(e) Renewal.--After the initial selection pursuant to
subsection (a), the Secretary of Commerce, in consultation
with the Secretary of Homeland Security, shall, every five
years--
(1) accept applications from nonprofit, nongovernmental
organizations seeking selection as the Authority; and
(2) following competitive consideration of all
applications--
(A) renew the selection of the existing Authority; or
(B) select another applicant organization to serve as the
Authority.
SEC. _04. AUTHORIZATION OF APPROPRIATIONS.
There is authorized to be appropriated such sums as may be
necessary to carry out this subtitle. Such funds shall remain
available until expended.
______