[Congressional Record Volume 166, Number 121 (Wednesday, July 1, 2020)]
[Senate]
[Pages S4150-S4151]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2392. Mr. KING (for himself and Mr. Sasse) submitted an amendment 
intended to be proposed by him to the bill S. 4049, to authorize 
appropriations for fiscal year 2021 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. ___. CISA DIRECTOR.

       Subchapter II of chapter 53 of title 5, United States Code, 
     is amended--
       (1) in section 5313, by inserting after the item relating 
     to ``Administrator of the Transportation Security 
     Administration'' the following:
     ``Director, Cybersecurity and Infrastructure Security 
     Agency.''; and
       (2) in section 5314, by striking the item relating to 
     ``Director, Cybersecurity and Infrastructure Security 
     Agency.''.

     SEC. __. AGENCY REVIEW.

       (a) Requirement of Comprehensive Review.--In order to 
     strengthen the Cybersecurity and Infrastructure Security 
     Agency, the Secretary of Homeland Security shall conduct a 
     comprehensive review of the ability of the Cybersecurity and 
     Infrastructure Security Agency to fulfill--
       (1) the missions of the Cybersecurity and Infrastructure 
     Security Agency; and
       (2) the recommendations detailed in the report issued by 
     the Cyberspace Solarium Commission under section 1652(k) of 
     the John S. McCain National Defense Authorization Act for 
     Fiscal Year 2019 (Public Law 115-232).
       (b) Elements of Review.--The review conducted under 
     subsection (a) shall include the following elements:
       (1) An assessment of how additional budget resources could 
     be used by the Cybersecurity and Infrastructure Security 
     Agency for projects and programs that--
       (A) support the national risk management mission;
       (B) promote public-private integration; and
       (C) provide situational awareness of cybersecurity threats.
       (2) A comprehensive force structure assessment of the 
     Cybersecurity and Infrastructure Security Agency including--
       (A) a determination of the appropriate size and composition 
     of personnel to accomplish the mission of the Cybersecurity 
     and Infrastructure Security Agency, as well as the 
     recommendations detailed in the report issued by the 
     Cyberspace Solarium Commission under section 1652(k) of the 
     John S. McCain National Defense Authorization Act for Fiscal 
     Year 2019 (Public Law 115-232);
       (B) an assessment of whether existing personnel are 
     appropriately matched to the

[[Page S4151]]

     prioritization of threats in the cyber domain and risks in 
     critical infrastructure;
       (C) an assessment of whether the Cybersecurity and 
     Infrastructure Security Agency has the appropriate personnel 
     and resources to--
       (i) perform risk assessments, threat hunting, incident 
     response to support both private and public cybersecurity;
       (ii) carry out the responsibilities of the Cybersecurity 
     and Infrastructure Security Agency related to the security of 
     Federal information and Federal information systems; and
       (iii) carry out the critical infrastructure 
     responsibilities of the Cybersecurity and Infrastructure 
     Security Agency, including national risk management; and
       (D) an assessment of whether current structure, personnel, 
     and resources of regional field offices are sufficient in 
     fulfilling agency responsibilities and mission requirements.
       (c) Submission of Review.--Not later than 1 year after the 
     date of the enactment of this Act, the Secretary of Homeland 
     Security shall submit a report to Congress detailing the 
     results of the assessments required under subsection (b), 
     including recommendations to address any identified gaps.

     SEC. __. GENERAL SERVICES ADMINISTRATION REVIEW.

       (a) Review.--The Administrator of the General Services 
     Administration shall--
       (1) conduct a review of current Cybersecurity and 
     Infrastructure Security Agency facilities and assess the 
     suitability of such facilities to fully support current and 
     projected mission requirements nationally and regionally; and
       (2) make recommendations regarding resources needed to 
     procure or build a new facility or augment existing 
     facilities to ensure sufficient size and accommodations to 
     fully support current and projected mission requirements, 
     including the integration of personnel from the private 
     sector and other departments and agencies.
       (b) Submission of Review.--Not later than 1 year after the 
     date of the enactment of this Act, the Administrator of the 
     General Services Administration shall submit the review 
     required under subsection (a) to--
       (1) the President;
       (2) the Secretary of Homeland Security; and
       (3) to the Committee on Homeland Security and Governmental 
     Affairs of the Senate and the Committee on Homeland Security 
     of the House of Representatives.
                                 ______