[Congressional Record Volume 166, Number 127 (Monday, July 20, 2020)]
[Senate]
[Page S4272]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2438. Mr. KING (for himself and Mr. Sasse) submitted an amendment 
intended to be proposed by him to the bill S. 4049, to authorize 
appropriations for fiscal year 2021 for military activities of the 
Department of Defense, for military construction, and for defense 
activities of the Department of Energy, to prescribe military personnel 
strengths for such fiscal year, and for other purposes; which was 
ordered to lie on the table; as follows:

       At the appropriate place, insert the following:

     SEC. __. REPORT ON THE INTEGRATION OF UNITED STATES CYBER 
                   CENTERS.

       (a) Review Required.--The Comptroller General of the United 
     States shall conduct a comprehensive review of the Federal 
     cyber and cybersecurity centers in operation on the date of 
     enactment of this Act.
       (b) Elements of Review.--The review required under 
     subsection (a) shall--
       (1) with respect to each Federal cyber center--
       (A) assess where the missions and operations, or portions 
     of the mission, of the Federal cyber center are unique, 
     overlap, are inefficient, or are in conflict in some way with 
     the mission of the authorizing agency of the Federal cyber 
     center;
       (B) assess aspects of the operations of the Federal cyber 
     center that would benefit from greater integration, 
     collaboration, or collocation to support a unified 
     cybersecurity strategy within the Federal government,
       (C) assess shortcomings in the capacity, structure, and 
     funding of the Federal cyber center and in the integration of 
     the work of the Federal cyber center with sector-specific 
     agencies; and
       (D) assess whether the Federal cyber center has distinct 
     statutory authorities best kept within the authorizing agency 
     of the Federal cyber center;
       (2) assess any shortcomings in the Federal cyber centers 
     that inhibit the ability of the Federal cyber centers to 
     support the Cybersecurity and Infrastructure Security Agency 
     in the role of Cybersecurity and Infrastructure Security 
     Agency as the primary interface between the Federal 
     Government and critical infrastructure for cybersecurity;
       (3) assess whether an integrated national cybersecurity 
     model, such as the National Cybersecurity Center of the 
     United Kingdom, is an effective model for the United States;
       (4) recommend procedures and criteria for expanding the 
     integration of public- and private-sector personnel into 
     Federal Government cyber defense and security efforts, 
     including any limitations posed by the security clearance 
     program for private sector expertise; and
       (5) recommend a cyber center structure that strengthens a 
     public-private, integrated cyber center within the 
     Cybersecurity and Infrastructure Security Agency that 
     optimizes efficiency, minimizes redundancy, and increases 
     information and expertise sharing in support of the critical 
     infrastructure security and resilience mission.
       (c) Federal Cyber Centers Described.--The review required 
     to be conducted under subsection (a) shall include in the 
     review, at a minimum, the following Federal cyber centers:
       (1) The Cybersecurity and Infrastructure Security Agency of 
     the Department of Homeland Security.
       (2) The Cyber Threat Operations Center of the National 
     Security Agency.
       (3) The Joint Operations Center of Cyber Command.
       (4) The Cyber Threat Intelligence Integration Center of the 
     Office of the Director of National Intelligence.
       (5) The National Cyber Investigative Joint Task Force of 
     the Federal Bureau of Investigation.
       (6) The Defense Cyber Crime Center of the Department of 
     Defense.
       (7) The Intelligence Community Security Coordination Center 
     of the Office of the Director of National Intelligence.
       (8) Any other sector-specific or agency centers proposed or 
     under consideration by the Comptroller General of the United 
     States.
       (d) Report.--
       (1) In general.--Not later than 1 year after the date of 
     enactment of this Act, the Comptroller General of the United 
     States shall submit a report on the review required under 
     subsection (a) to--
       (A) the Committee on Armed Services, the Committee on 
     Committee on Homeland Security and Governmental Affairs, the 
     Committee on the Judiciary, and the Select Committee on 
     Intelligence of the Senate; and
       (B) the Committee on Armed Services, the Committee on 
     Homeland Security, the Committee on the Judiciary, and the 
     Permanent Select Committee on Intelligence of the House of 
     Representatives.
       (2) Form of report.--The report required under paragraph 
     (1) may be submitted in unclassified form, and may contain a 
     classified annex, if necessary.
       (e) Sense of the Senate.--It is the sense of the Senate 
     that, after submission of the report under subsection (d), 
     the Secretary of Homeland Security, in coordination with the 
     intelligence community, should conduct a regular review 
     regarding--
       (1) the status of Federal cyber center integration efforts;
       (2) whether any findings of the review conducted under 
     subsection (a) should be updated;
       (3) whether additional resources or authorities required to 
     support Federal cyber centers; and
       (4) the progress of Federal agencies in addressing the 
     areas identified through the review conducted under 
     subsection (a).
                                 ______