US Codex
Bill
Notes

Title II — Public-Private Collaboration on Cybersecurity

H.R. 3696 · 113th Congress · Jul 29, 2014 · Lineage

II Public-Private Collaboration on Cybersecurity

Sec. 201 Public-private collaboration on cybersecurity

(a)
National Institute of Standards and Technology—
(1)
In general— The Director of the National Institute of Standards and Technology, in coordination with the Secretary of Homeland Security, shall, on an ongoing basis, facilitate and support the development of a voluntary, industry-led set of standards, guidelines, best practices, methodologies, procedures, and processes to reduce cyber risks to critical infrastructure. The Director, in coordination with the Secretary—
(A)
shall—
(i)
coordinate closely and continuously with relevant private entities, critical infrastructure owners and critical infrastructure operators, Sector Coordinating Councils, Information Sharing and Analysis Centers, and other relevant industry organizations, and incorporate industry expertise to the fullest extent possible;
(ii)
consult with the Sector Specific Agencies, Federal, State and local governments, the governments of other countries, and international organizations;
(iii)
utilize a prioritized, flexible, repeatable, performance-based, and cost-effective approach, including information security measures and controls, that may be voluntarily adopted by critical infrastructure owners and critical infrastructure operators to help them identify, assess, and manage cyber risks;
(iv)
include methodologies to—
(I)
identify and mitigate impacts of the cybersecurity measures or controls on business confidentiality; and
(II)
protect individual privacy and civil liberties;
(v)
incorporate voluntary consensus standards and industry best practices, and align with voluntary international standards to the fullest extent possible;
(vi)
prevent duplication of regulatory processes and prevent conflict with or superseding of regulatory requirements, mandatory standards, and processes; and
(vii)
include such other similar and consistent elements as determined necessary; and
(B)
shall not prescribe or otherwise require—
(i)
the use of specific solutions;
(ii)
the use of specific information technology products or services; or
(iii)
that information technology products or services be designed, developed, or manufactured in a particular manner.
(2)
Limitation— Information shared with or provided to the Director of the National Institute of Standards and Technology or the Secretary of Homeland Security for the purpose of the activities under paragraph (1) may not be used by any Federal, State, or local government department or agency to regulate the activity of any private entity.
(b)
Amendment—
(1)
In general— Subtitle C of title II of the Homeland Security Act of 2002, as amended by sections 102, 103, 104, and 105, is further amended by adding at the end the following new section:

“230. Public-private collaboration on cybersecurity

“(a) Meetings—The Secretary shall meet with the Sector Coordinating Council for each critical infrastructure sector designated under section 227(b) on a biannual basis to discuss the cybersecurity threat to critical infrastructure, voluntary activities to address cybersecurity, and ideas to improve the public-private partnership to enhance cybersecurity, in which the Secretary shall—

“(1) provide each Sector Coordinating Council an assessment of the cybersecurity threat to each critical infrastructure sector designated under section 227(b), including information relating to—

“(A) any actual or assessed cyber threat, including a consideration of adversary capability and intent, preparedness, target attractiveness, and deterrence capabilities;

“(B) the extent and likelihood of death, injury, or serious adverse effects to human health and safety caused by an act of terrorism or other disruption, destruction, or unauthorized use of critical infrastructure;

“(C) the threat to national security caused by an act of terrorism or other disruption, destruction, or unauthorized use of critical infrastructure; and

“(D) the harm to the economy that would result from an act of terrorism or other disruption, destruction, or unauthorized use of critical infrastructure; and

“(2) provide recommendations, which may be voluntarily adopted, on ways to improve cybersecurity of critical infrastructure.

“(b) Report

“(1) In general—Starting 30 days after the end of the fiscal year in which the National Cybersecurity and Critical Infrastructure Protection Act of 2013 is enacted and annually thereafter, the Secretary shall submit to the appropriate congressional committees a report on the state of cybersecurity for each critical infrastructure sector designated under section 227(b) based on discussions between the Department and the Sector Coordinating Council in accordance with subsection (a) of this section. The Secretary shall maintain a public copy of each report, and each report may include a non-public annex for proprietary, business-sensitive information, or other sensitive information. Each report shall include, at a minimum information relating to—

“(A) the risk to each critical infrastructure sector, including known cyber threats, vulnerabilities, and potential consequences;

“(B) the extent and nature of any cybersecurity incidents during the previous year, including the extent to which cyber incidents jeopardized or imminently jeopardized information systems;

“(C) the current status of the voluntary, industry-led set of standards, guidelines, best practices, methodologies, procedures, and processes to reduce cyber risks within each critical infrastructure sector; and

“(D) the volume and range of voluntary technical assistance sought and provided by the Department to each critical infrastructure sector.

“(2) Sector Coordinating Council response—Before making public and submitting each report required under paragraph (1), the Secretary shall provide a draft of each report to the Sector Coordinating Council for the critical infrastructure sector covered by each such report. The Sector Coordinating Council at issue may provide to the Secretary a written response to such report within 45 days of receiving the draft. If such Sector Coordinating Council provides a written response, the Secretary shall include such written response in the final version of each report required under paragraph (1).

“(c) Limitation—Information shared with or provided to a Sector Coordinating Council, a critical infrastructure sector, or the Secretary for the purpose of the activities under subsections (a) and (b) may not be used by any Federal, State, or local government department or agency to regulate the activity of any private entity.”

(2)
Clerical amendment— The table of contents in section 1(b) of such Act is amended by adding after the item relating to section 229 (as added by section 105) the following new item:

Sec. 202 SAFETY Act and qualifying cyber incidents

(a)
In general— The Support Anti-Terrorism By Fostering Effective Technologies Act of 2002 (6 U.S.C. 441 et seq.) is amended—
(1)
in section 862(b) (6 U.S.C. 441(b))—
(A)
in the heading, by striking “Designation of Qualified Anti-Terrorism Technologies” and inserting “Designation of Anti-Terrorism and Cybersecurity Technologies”;
(B)
in the matter preceding paragraph (1), by inserting “and cybersecurity” after “anti-terrorism”;
(C)
in paragraphs (3), (4), and (5), by inserting “or cybersecurity” after “anti-terrorism” each place it appears; and
(D)
in paragraph (7)—
(i)
by inserting “or cybersecurity technology” after “Anti-terrorism technology”; and
(ii)
by inserting “or qualifying cyber incidents” after “acts of terrorism”;
(2)
in section 863 (6 U.S.C. 442)—
(A)
by inserting “or cybersecurity” after “anti-terrorism” each place it appears;
(B)
by inserting “or qualifying cyber incident” after “act of terrorism” each place it appears; and
(C)
by inserting “or qualifying cyber incidents” after “acts of terrorism” each place it appears;
(3)
in section 864 (6 U.S.C. 443)—
(A)
by inserting “or cybersecurity” after “anti-terrorism” each place it appears; and
(B)
by inserting “or qualifying cyber incident” after “act of terrorism” each place it appears; and
(4)
in section 865 (6 U.S.C. 444)—
(A)
in paragraph (1)—
(i)
in the heading, by inserting “or cybersecurity” after “anti-terrorism”;
(ii)
by inserting “or cybersecurity” after “anti-terrorism”;
(iii)
by inserting “or qualifying cyber incidents” after “acts of terrorism”; and
(iv)
by inserting “or incidents” after “such acts”; and
(B)
by adding at the end the following new paragraph:

“(7) Qualifying cyber incident

“(A) In general—The term qualifying cyber incident means any act that the Secretary determines meets the requirements under subparagraph (B), as such requirements are further defined and specified by the Secretary.

“(B) Requirements—A qualifying cyber incident meets the requirements of this subparagraph if—

“(i) the incident is unlawful or otherwise exceeds authorized access authority;

“(ii) the incident disrupts or imminently jeopardizes the integrity, operation, confidentiality, or availability of programmable electronic devices, communication networks, including hardware, software and data that are essential to their reliable operation, electronic storage devices, or any other information system, or the information that system controls, processes, stores, or transmits;

“(iii) the perpetrator of the incident gains access to an information system or a network of information systems resulting in—

“(I) misappropriation or theft of data, assets, information, or intellectual property;

“(II) corruption of data, assets, information, or intellectual property;

“(III) operational disruption; or

“(IV) an adverse effect on such system or network, or the data, assets, information, or intellectual property contained therein; and

“(iv) the incident causes harm inside or outside the United States that results in material levels of damage, disruption, or casualties severely affecting the United States population, infrastructure, economy, or national morale, or Federal, State, local, or tribal government functions.

“(C) Rule of construction—For purposes of clause (iv) of subparagraph (B), the term “severely” includes any qualifying cyber incident, whether at a local, regional, state, national, international, or tribal level, that affects—

“(i) the United States population, infrastructure, economy, or national morale, or

“(ii) Federal, State, local, or tribal government functions.”

(b)
Funding— Of the amounts authorized to be appropriated for each of fiscal years 2014, 2015, and 2016 for the Department of Homeland Security, the Secretary of Homeland Security is authorized to use not less than $20,000,000 for any such year for the Department’s SAFETY Act Office.

Sec. 203 Prohibition on new regulatory authority

This Act and the amendments made by this Act (except that this section shall not apply in the case of section 202 of this Act and the amendments made by such section 202) do not—
(1)
create or authorize the issuance of any new regulations or additional Federal Government regulatory authority; or
(2)
permit regulatory actions that would duplicate, conflict with, or supercede regulatory requirements, mandatory standards, or related processes.

Sec. 204 Prohibition on additional authorization of appropriations

No additional funds are authorized to be appropriated to carry out this Act and the amendments made by this Act. This Act and such amendments shall be carried out using amounts otherwise available for such purposes.

Sec. 205 Prohibition on collection activities to track individuals’ personally identifiable information

Nothing in this Act shall permit the Department of Homeland Security to engage in the monitoring, surveillance, exfiltration, or other collection activities for the purpose of tracking an individual’s personally identifiable information.

Sec. 206 Cybersecurity scholars

The Secretary of Homeland Security shall determine the feasibility and potential benefit of developing a visiting security researchers program from academia, including cybersecurity scholars at the Department of Homeland Security’s Centers of Excellence, as designated by the Secretary, to enhance knowledge with respect to the unique challenges of addressing cyber threats to critical infrastructure. Eligible candidates shall possess necessary security clearances and have a history of working with Federal agencies in matters of national or domestic security.

Sec. 207 National Research Council study on the resilience and reliability of the Nation’s power grid

(a)
Independent study— Not later than 60 days after the date of the enactment of this Act, the Secretary of Homeland Security, in coordination with the heads of other departments and agencies, as necessary, shall enter into an agreement with the National Research Council to conduct research of the future resilience and reliability of the Nation’s electric power transmission and distribution system. The research under this subsection shall be known as the Saving More American Resources Today Study or the SMART Study. In conducting such research, the National Research Council shall—
(1)
research the options for improving the Nation’s ability to expand and strengthen the capabilities of the Nation’s power grid, including estimation of the cost, time scale for implementation, and identification of the scale and scope of any potential significant health and environmental impacts;
(2)
consider the forces affecting the grid, including technical, economic, regulatory, environmental, and geopolitical factors, and how such forces are likely to affect—
(A)
the efficiency, control, reliability and robustness of operation;
(B)
the ability of the grid to recover from disruptions, including natural disasters and terrorist attacks;
(C)
the ability of the grid to incorporate greater reliance on distributed and intermittent power generation and electricity storage;
(D)
the ability of the grid to adapt to changing patterns of demand for electricity; and
(E)
the economic and regulatory factors affecting the evolution of the grid;
(3)
review Federal, State, industry, and academic research and development programs and identify technological options that could improve the future grid;
(4)
review studies and analyses prepared by the North American Electric Reliability Corporation (NERC) regarding the future resilience and reliability of the grid;
(5)
review the implications of increased reliance on digital information and control of the power grid for improving reliability, resilience, and congestion and for potentially increasing vulnerability to cyber attack;
(6)
review regulatory, industry, and institutional factors and programs affecting the future of the grid;
(7)
research the costs and benefits, as well as the strengths and weaknesses, of the options identified under paragraph (1) to address the emerging forces described in paragraph (2) that are shaping the grid;
(8)
identify the barriers to realizing the options identified and suggest strategies for overcoming those barriers including suggested actions, priorities, incentives, and possible legislative and executive actions; and
(9)
research the ability of the grid to integrate existing and future infrastructure, including utilities, telecommunications lines, highways, and other critical infrastructure.
(b)
Cooperation and access to information and personnel— The Secretary shall ensure that the National Research Council receives full and timely cooperation, including full access to information and personnel, from the Department of Homeland Security, the Department of Energy, including the management and operating components of the Departments, and other Federal departments and agencies, as necessary, for the purposes of conducting the study described in subsection (a).
(c)
Report—
(1)
In general— Not later than 18 months from the date on which the Secretary enters into the agreement with the National Research Council described in subsection (a), the National Research Council shall submit to the Secretary and the Committee on Homeland Security and the Committee on Energy and Commerce of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Energy and Natural Resources of the Senate a report containing the findings of the research required by that subsection.
(2)
Form of report— The report under paragraph (1) shall be submitted in unclassified form, but may include a classified annex.
(d)
Funding— Of the amounts authorized to be appropriated for 2014 for the Department of Homeland Security, the Secretary of Homeland Security is authorized to obligate and expend not more than $2,000,000 for the National Research Council report.