US Codex
Bill
Notes

H.R. 5239 — what changed

Cyber Sense Act of 2018

From Introduced in House to Reported in House. 1 section amended between Introduced in House and Reported in House.

Sec. 2 Cyber Sense

(a)
changed In general— The Secretary of Energy shall establish a voluntary Cyber Sense program to identify and promote cyber-secure test the cybersecurity of products and technologies intended for use in the bulk-power system, as defined in section 215(a) of the Federal Power Act (16 U.S.C. 824o(a)).
(b)
Program requirements— In carrying out subsection (a), the Secretary of Energy shall—
(1)
changed establish a Cyber Sense testing process under the Cyber Sense program to identify test the cybersecurity of products and technologies intended for use in the bulk-power system that are cyber-secure, system, including products relating to industrial control systems, systems and operational technologies, such as supervisory control and data acquisition systems;
(2)
changed for products tested and identified as cyber-secure technologies tested under the Cyber Sense program, establish and maintain cybersecurity vulnerability reporting processes and a related database;
(3)
changed provide technical assistance to electric utilities, product manufacturers, and other electricity sector stakeholders to develop solutions to mitigate identified cybersecurity vulnerabilities in products tested and identified as cyber-secure technologies tested under the Cyber Sense program;
(4)
changed biennially review products tested and identified as cyber-secure technologies tested under the Cyber Sense program for cybersecurity vulnerabilities and provide analysis with respect to how such products and technologies respond to and mitigate cyber threats;
(5)
changed develop procurement guidance guidance, that is informed by analysis and testing results under the Cyber Sense program, for electric utilities for procurement of products tested and identified as cyber-secure under the Cyber Sense program;technologies;
(6)
changed provide reasonable notice to the public, and solicit comments from the public, prior to establishing or revising the testing process under the Cyber Sense testing process;program;
(7)
changed establish procedures for disqualifying oversee testing of products that were tested and identified as cyber-secure technologies under the Cyber Sense program but that no longer meet the qualifications to be identified cyber-secure products under such program;program; and
(8)
changed oversee consider incentives to encourage the use of analysis and results of testing under the Cyber Sense testing carried out by third parties; andprogram in the design of products and technologies for use in the bulk-power system.
(9)
removed consider incentives to encourage the use in the bulk-power system of products tested and identified as cyber-secure under the Cyber Sense program.
(c)
changed Disclosure of information— Any cybersecurity vulnerability reported pursuant to the a process established under subsection (b)(2), the disclosure of which the Secretary of Energy reasonably foresees would cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be deemed to be critical electric infrastructure information for purposes of section 215A(d) of the Federal Power Act.
(d)
changed Federal Government liability— Nothing in this section shall be construed to authorize the commencement of an action against the United States Government with respect to the testing and identification of a product or technology under the Cyber Sense program.