---
kind: "diff"
citation: "H.R. 5239"
bill: "115-hr-5239"
heading: "Cyber Sense Act of 2018"
from: "ih"
from_label: "Introduced in House"
to: "rh"
to_label: "Reported in House"
sections_amended: 1
sections_added: 0
sections_removed: 0
url: "https://uscodex.org/bills/115/hr/5239/changes/rh"
---

# H.R. 5239 — what changed

H.R. 5239, Cyber Sense Act of 2018 — 1 section amended between Introduced in House and Reported in House.

Edits are marked `<del>struck</del>` and `<ins>inserted</ins>`.

## Sec. 2 Cyber Sense

- (a) In general— The Secretary of Energy shall establish a voluntary Cyber Sense program to <del>identify and promote cyber-secure </del><ins>test the cybersecurity of </ins>products <ins>and technologies </ins>intended for use in the bulk-power system, as defined in section 215(a) of the Federal Power Act (16 U.S.C. 824o(a)).
- (b) Program requirements— In carrying out subsection (a), the Secretary of Energy shall—
  - (1) establish a <del>Cyber Sense </del>testing process <ins>under the Cyber Sense program </ins>to <del>identify </del><ins>test the cybersecurity of </ins>products and technologies intended for use in the bulk-power <del>system that are cyber-secure, </del><ins>system, </ins>including products relating to industrial control <del>systems, </del><ins>systems and operational technologies, </ins>such as supervisory control and data acquisition systems;
  - (2) for products <del>tested </del>and <del>identified as cyber-secure </del><ins>technologies tested </ins>under the Cyber Sense program, establish and maintain cybersecurity vulnerability reporting processes and a related database;
  - (3) provide technical assistance to electric utilities, product manufacturers, and other electricity sector stakeholders to develop solutions to mitigate identified cybersecurity vulnerabilities in products <del>tested </del>and <del>identified as cyber-secure </del><ins>technologies tested </ins>under the Cyber Sense program;
  - (4) biennially review products <del>tested </del>and <del>identified as cyber-secure </del><ins>technologies tested </ins>under the Cyber Sense program for cybersecurity vulnerabilities and provide analysis with respect to how such products <ins>and technologies </ins>respond to and mitigate cyber threats;
  - (5) develop <del>procurement guidance </del><ins>guidance, that is informed by analysis and testing results under the Cyber Sense program, </ins>for electric utilities for <ins>procurement of </ins>products <del>tested </del>and <del>identified as cyber-secure under the Cyber Sense program;</del><ins>technologies;</ins>
  - (6) provide reasonable notice to the public, and solicit comments from the public, prior to establishing or revising the <ins>testing process under the </ins>Cyber Sense <del>testing process;</del><ins>program;</ins>
  - (7) <del>establish procedures for disqualifying </del><ins>oversee testing of </ins>products <del>that were tested </del>and <del>identified as cyber-secure </del><ins>technologies </ins>under the Cyber Sense <del>program but that no longer meet the qualifications to be identified cyber-secure products under such program;</del><ins>program; and</ins>
  - (8) <del>oversee </del><ins>consider incentives to encourage the use of analysis and results of testing under the </ins>Cyber Sense <del>testing carried out by third parties; and</del><ins>program in the design of products and technologies for use in the bulk-power system.</ins>
  - (9) <del>consider incentives to encourage the use in the bulk-power system of products tested and identified as cyber-secure under the Cyber Sense program.</del>
- (c) Disclosure of information— Any cybersecurity vulnerability reported pursuant to <del>the </del><ins>a </ins>process established under subsection (b)(2), the disclosure of which the Secretary of Energy reasonably foresees would cause harm to critical electric infrastructure (as defined in section 215A of the Federal Power Act), shall be deemed to be critical electric infrastructure information for purposes of section 215A(d) of the Federal Power Act.
- (d) Federal Government liability— Nothing in this section shall be construed to authorize the commencement of an action against the United States Government with respect to the testing <del>and identification </del>of a product <ins>or technology </ins>under the Cyber Sense program.
