(a)
Designation of responsible Federal entity— The Secretary shall have primary responsibility within the Federal Government for sharing information about election cybersecurity incidents, threats, and vulnerabilities with Federal entities and with election agencies.
(b)
Presumption of Federal information sharing to the department— If a Federal entity receives information about an election cybersecurity incident, threat, or vulnerability, the Federal entity shall promptly share that information with the Department, unless the head of the entity (or a Senate-confirmed official designated by the head) makes a specific determination in writing that there is good cause to withhold the particular information.
(c)
Presumption of Federal and State information sharing from the department— If the Department receives information about an election cybersecurity incident, threat, or vulnerability, the Department shall promptly share that information with—
(1)
the appropriate Federal entities;
(2)
all State election agencies;
(3)
to the maximum extent practicable, all election agencies that have requested ongoing updates on election cybersecurity incidents, threats, or vulnerabilities; and
(4)
to the maximum extent practicable, all election agencies that may be affected by the risks associated with the particular election cybersecurity incident, threat, or vulnerability.
(d)
Technical resources for election agencies— In sharing information about election cybersecurity incidents, threats, and vulnerabilities with election agencies under this section, the Department shall, to the maximum extent practicable—
(1)
provide cyber threat indicators and defensive measures (as such terms are defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (
6 U.S.C. 1501)), such as recommended technical instructions, that assist with preventing, mitigating, and detecting threats or vulnerabilities;
(2)
identify resources available for protecting against, detecting, responding to, and recovering from associated risks, including technical capabilities of the Department; and
(3)
provide guidance about further sharing of the information.
(e)
Declassification review— If the Department receives classified information about an election cybersecurity incident, threat, or vulnerability—
(1)
the Secretary shall promptly submit a request for expedited declassification review to the head of a Federal entity with authority to conduct the review, consistent with Executive Order 13526 or any successor order, unless the Secretary determines that such a request would be inappropriate; and
(2)
the head of the Federal entity described in paragraph (1) shall promptly conduct the review.
(f)
Role of non-Federal entities— The Department may share information about election cybersecurity incidents, threats, and vulnerabilities through a non-Federal entity.
(g)
Protection of personal and confidential information—
(1)
In general— If a Federal entity shares information relating to an election cybersecurity incident, threat, or vulnerability, the Federal entity shall, within Federal information systems (as defined in section 3502 of title 44, United States Code) of the entity—
(A)
minimize the acquisition, use, and disclosure of personal information of voters, except as necessary to identify, protect against, detect, respond to, or recover from election cybersecurity incidents, threats, and vulnerabilities;
(B)
notwithstanding any other provision of law, prohibit the retention of personal information of voters, such as—
(i)
voter registration information, including physical address, email address, and telephone number;
(ii)
political party affiliation or registration information; and
(iii)
voter history, including registration status or election participation; and
(C)
protect confidential Federal and State information from unauthorized disclosure.
(2)
Exemption from disclosure— Information relating to an election cybersecurity incident, threat, or vulnerability, such as personally identifiable information of reporting persons or individuals affected by such incident, threat, or vulnerability, shared by or with the Federal Government shall be—
(A)
deemed voluntarily shared information and exempt from disclosure under section 552 of title 5, United States Code, and any State, tribal, or local provision of law requiring disclosure of information or records; and
(B)
withheld, without discretion, from the public under section 552(b)(3)(B) of title 5, United States Code, and any State, tribal, or local provision of law requiring disclosure of information or records.
(h)
Duty To assess possible cybersecurity incidents—
(1)
Election agencies— If an election agency becomes aware of the possibility of an election cybersecurity incident, the election agency shall promptly assess whether an election cybersecurity incident occurred and notify the State election official.
(2)
Election service providers— If an election service provider becomes aware of the possibility of an election cybersecurity incident, the election service provider shall promptly assess whether an election cybersecurity incident occurred and notify the relevant election agencies consistent with subsection (j).
(i)
Information sharing about cybersecurity incidents by election agencies— If an election agency has reason to believe that an election cybersecurity incident has occurred with respect to an election system owned, operated, or maintained by or on behalf of the election agency, the election agency shall, in the most expedient time possible and without unreasonable delay, provide notification of the election cybersecurity incident to the Department.
(j)
Information sharing about cybersecurity incidents by election service providers— If an election service provider has reason to believe that an election cybersecurity incident may have occurred, or that an incident related to the role of the provider as an election service provider may have occurred, the election service provider shall—
(1)
notify the relevant election agencies in the most expedient time possible and without unreasonable delay; and
(2)
cooperate with the election agencies in providing the notifications required under subsections (h)(1) and (i).
(k)
Content of notification by election agencies— The notifications required under subsections (h)(1) and (i)—
(1)
shall include an initial assessment of—
(A)
the date, time, and duration of the election cybersecurity incident;
(B)
the circumstances of the election cybersecurity incident, including the specific election systems believed to have been accessed and information acquired; and
(C)
planned and implemented technical measures to respond to and recover from the incident; and
(2)
shall be updated with additional material information, including technical data, as it becomes available.
(l)
Security clearance— Not later than 30 days after the date of enactment of this Act, the Secretary—
(1)
shall establish an expedited process for providing appropriate security clearance to State election officials and designated technical personnel employed by State election agencies;
(2)
shall establish an expedited process for providing appropriate security clearance to members of the Commission and designated technical personnel employed by the Commission; and
(3)
shall establish a process for providing appropriate security clearance to personnel at other election agencies.
(m)
Protection from liability— Nothing in this Act may be construed to provide a cause of action against a State, unit of local government, or an election service provider.
(n)
Assessment of inter-State information sharing about election cybersecurity—
(1)
In general— The Secretary and the Chairman, in coordination with the heads of the appropriate Federal entities and appropriate officials of State and local governments, shall conduct an assessment of—
(A)
the structure and functioning of the Multi-State Information Sharing and Analysis Center for purposes of election cybersecurity; and
(B)
other mechanisms for inter-state information sharing about election cybersecurity.
(2)
Comment from election agencies— In carrying out the assessment required under paragraph (1), the Secretary and the Chairman shall solicit and consider comments from all State election agencies.
(3)
Distribution— The Secretary and the Chairman shall jointly issue the assessment required under paragraph (1) to—
(A)
all election agencies known to the Department and the Commission; and
(B)
the appropriate congressional committees.
(o)
Congressional notification—
(1)
In general— If an appropriate Federal entity has reason to believe that a significant election cybersecurity incident has occurred, the entity shall—
(A)
not later than 7 calendar days after the date on which there is a reasonable basis to conclude that the significant incident has occurred, provide notification of the incident to the appropriate congressional committees; and
(B)
update the initial notification under paragraph (1) within a reasonable period of time after additional information relating to the incident is discovered.
(2)
Reporting threshold— The Secretary shall—
(A)
promulgate a uniform definition of a “significant election cybersecurity incident”; and
(B)
shall submit the definition promulgated under subparagraph (A) to the appropriate congressional committees.