S. 2519 — what changed
National Cybersecurity Protection Act of 2014
From Reported in Senate to Engrossed in Senate. 3 sections amended and 5 added between Reported in Senate and Engrossed in Senate.
Section 1 Short title
changed
This Act may be cited as the “National Cybersecurity and Communications Integration Center Protection Act of 2014”.
Sec. 2 Definitions
added In this Act—
removed
“210G. Operations center
removed
“(a) Functions—There is in the Department an operations center, which may carry out the responsibilities of the Under Secretary appointed under section 103(a)(1)(H) with respect to security and resilience, including by—
removed
“(1) serving as a Federal civilian information sharing interface for cybersecurity;
removed
“(2) providing shared situational awareness to enable real-time, integrated, and operational actions across the Federal Government;
removed
“(3) sharing cybersecurity threat, vulnerability, impact, and incident information and analysis by and among Federal, State, and local government entities and private sector entities;
removed
“(4) coordinating cybersecurity information sharing throughout the Federal Government;
removed
“(5) conducting analysis of cybersecurity risks and incidents;
removed
“(6) upon request, providing timely technical assistance to Federal and non-Federal entities with respect to cybersecurity threats and attribution, vulnerability mitigation, and incident response and remediation; and
removed
“(7) providing recommendations on security and resilience measures to Federal and non-Federal entities.
removed
“(b) Composition—The operations center shall be composed of—
removed
“(1) personnel or other representatives of Federal agencies, including civilian and law enforcement agencies and elements of the intelligence community, as such term is defined under section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)); and
removed
“(2) representatives from State and local governments and other non-Federal entities, including—
removed
“(A) representatives from information sharing and analysis organizations; and
removed
“(B) private sector owners and operators of critical information systems.
removed
“(c) Annual report—Not later than 1 year after the date of enactment of the National Cybersecurity and Communications Integration Center Act of 2014, and every year thereafter for 3 years, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the operations center, which shall include—
removed
“(1) an analysis of the performance of the operations center in carrying out the functions under subsection (a);
removed
“(2) information on the composition of the center, including—
removed
“(A) the number of representatives from non-Federal entities that are participating in the operations center, including the number of representatives from States, nonprofit organizations, and private sector entities, respectively; and
removed
“(B) the number of requests from non-Federal entities to participate in the operations center and the response to such requests, including—
removed
“(i) the average length of time to fulfill such identified requests by the Federal agency responsible for fulfilling such requests; and
removed
“(ii) a description of any obstacles or challenges to fulfilling such requests; and
removed
“(3) the policies and procedures established by the operations center to safeguard privacy and civil liberties.
removed
“(d) GAO report—Not later than 1 year after the date of enactment of the National Cybersecurity and Communications Integration Center Act of 2014, the Comptroller General of the United States shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the effectiveness of the operations center.
removed
“(e) No right or benefit—The provision of assistance or information to, and inclusion in the operations center of, governmental or private entities under this section shall be at the discretion of the Under Secretary appointed under section 103(a)(1)(H). The provision of certain assistance or information to, or inclusion in the operations center of, one governmental or private entity pursuant to this section shall not create a right or benefit, substantive or procedural, to similar assistance or information for any other governmental or private entity.”
Sec. 3 National cybersecurity and communications integration center
added “226. National cybersecurity and communications integration center
added “(a) Definitions—In this section—
added “(1) the term cybersecurity risk means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of information or information systems, including such related consequences caused by an act of terrorism;
added “(2) the term incident means an occurrence that—
added “(A) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system; or
added “(B) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies;
added “(3) the term information sharing and analysis organization has the meaning given that term in section 212(5); and
added “(4) the term information system has the meaning given that term in section 3502(8) of title 44, United States Code.
added “(b) Center—There is in the Department a national cybersecurity and communications integration center (referred to in this section as the Center) to carry out certain responsibilities of the Under Secretary appointed under section 103(a)(1)(H).
added “(c) Functions—The cybersecurity functions of the Center shall include—
added “(1) being a Federal civilian interface for the multi-directional and cross-sector sharing of information related to cybersecurity risks, incidents, analysis, and warnings for Federal and non-Federal entities;
added “(2) providing shared situational awareness to enable real-time, integrated, and operational actions across the Federal Government and non-Federal entities to address cybersecurity risks and incidents to Federal and non-Federal entities;
added “(3) coordinating the sharing of information related to cybersecurity risks and incidents across the Federal Government;
added “(4) facilitating cross-sector coordination to address cybersecurity risks and incidents, including cybersecurity risks and incidents that may be related or could have consequential impacts across multiple sectors;
added “(5)
added “(A) conducting integration and analysis, including cross-sector integration and analysis, of cybersecurity risks and incidents; and
added “(B) sharing the analysis conducted under subparagraph (A) with Federal and non-Federal entities;
added “(6) upon request, providing timely technical assistance, risk management support, and incident response capabilities to Federal and non-Federal entities with respect to cybersecurity risks and incidents, which may include attribution, mitigation, and remediation; and
added “(7) providing information and recommendations on security and resilience measures to Federal and non-Federal entities, including information and recommendations to—
added “(A) facilitate information security; and
added “(B) strengthen information systems against cybersecurity risks and incidents.
added “(d) Composition
added “(1) In general—The Center shall be composed of—
added “(A) appropriate representatives of Federal entities, such as—
added “(i) sector-specific agencies;
added “(ii) civilian and law enforcement agencies; and
added “(iii) elements of the intelligence community, as that term is defined under section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4));
added “(B) appropriate representatives of non-Federal entities, such as—
added “(i) State and local governments;
added “(ii) information sharing and analysis organizations; and
added “(iii) owners and operators of critical information systems;
added “(C) components within the Center that carry out cybersecurity and communications activities;
added “(D) a designated Federal official for operational coordination with and across each sector; and
added “(E) other appropriate representatives or entities, as determined by the Secretary.
added “(2) Incidents—In the event of an incident, during exigent circumstances the Secretary may grant a Federal or non-Federal entity immediate temporary access to the Center.
added “(e) Principles—In carrying out the functions under subsection (c), the Center shall ensure—
added “(1) to the extent practicable, that—
added “(A) timely, actionable, and relevant information related to cybersecurity risks, incidents, and analysis is shared;
added “(B) when appropriate, information related to cybersecurity risks, incidents, and analysis is integrated with other relevant information and tailored to the specific characteristics of a sector;
added “(C) activities are prioritized and conducted based on the level of risk;
added “(D) industry sector-specific, academic, and national laboratory expertise is sought and receives appropriate consideration;
added “(E) continuous, collaborative, and inclusive coordination occurs—
added “(i) across sectors; and
added “(ii) with—
added “(I) sector coordinating councils;
added “(II) information sharing and analysis organizations; and
added “(III) other appropriate non-Federal partners;
added “(F) as appropriate, the Center works to develop and use mechanisms for sharing information related to cybersecurity risks and incidents that are technology-neutral, interoperable, real-time, cost-effective, and resilient; and
added “(G) the Center works with other agencies to reduce unnecessarily duplicative sharing of information related to cybersecurity risks and incidents;
added “(2) that information related to cybersecurity risks and incidents is appropriately safeguarded against unauthorized access; and
added “(3) that activities conducted by the Center comply with all policies, regulations, and laws that protect the privacy and civil liberties of United States persons.
added “(f) No right or benefit
added “(1) In general—The provision of assistance or information to, and inclusion in the Center of, governmental or private entities under this section shall be at the sole and unreviewable discretion of the Under Secretary appointed under section 103(a)(1)(H).
added “(2) Certain assistance or information—The provision of certain assistance or information to, or inclusion in the Center of, one governmental or private entity pursuant to this section shall not create a right or benefit, substantive or procedural, to similar assistance or information for any other governmental or private entity.”
Sec. 4 Recommendations regarding new agreements
addedSec. 5 Annual report
addedadded Not later than 1 year after the date of enactment of this Act, and every year thereafter for 3 years, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on the Judiciary of the Senate, the Committee on Homeland Security and the Committee on the Judiciary of the House of Representatives, and the Comptroller General of the United States a report on the Center, which shall include—
Sec. 6 GAO report
addedadded Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the effectiveness of the Center in carrying out its cybersecurity mission.
Sec. 7 Cyber incident response plan; clearances; breaches
addedadded “227. Cyber incident response plan
added “The Under Secretary appointed under section 103(a)(1)(H) shall, in coordination with appropriate Federal departments and agencies, State and local governments, sector coordinating councils, information sharing and analysis organizations (as defined in section 212(5)), owners and operators of critical infrastructure, and other appropriate entities and individuals, develop, regularly update, maintain, and exercise adaptable cyber incident response plans to address cybersecurity risks (as defined in section 226) to critical infrastructure.
added “228. Clearances
added “The Secretary shall make available the process of application for security clearances under Executive Order 13549 (75 Fed. Reg. 162; relating to a classified national security information program) or any successor Executive Order to appropriate representatives of sector coordinating councils, sector information sharing and analysis organizations (as defined in section 212(5)), owners and operators of critical infrastructure, and any other person that the Secretary determines appropriate.”