(a)
Establishment— The Secretary, in consultation with State regulatory authorities, industry stakeholders, the Electric Reliability Organization, and any other Federal agencies that the Secretary determines to be appropriate, shall carry out a program—
(1)
to develop, and provide for voluntary implementation of, maturity models, self-assessments, and auditing methods for assessing the physical security and cybersecurity of electric utilities;
(2)
to assist with threat assessment and cybersecurity training for electric utilities;
(3)
to provide technical assistance for electric utilities subject to the program;
(4)
to provide training to electric utilities to address and mitigate cybersecurity supply chain management risks;
(5)
to advance the cybersecurity of third-party vendors in partnerships with electric utilities; and
(6)
to increase opportunities for sharing best practices and data collection within the electric sector.
(b)
Scope— In carrying out the program under subsection (a), the Secretary shall—
(1)
take into consideration—
(A)
the different sizes of electric utilities; and
(B)
the regions that electric utilities serve;
(2)
prioritize—
(A)
electric utilities with respect to which the Secretary has substantial concerns; and
(B)
electric utilities with fewer available resources due to size or region; and
(3)
to the maximum extent practicable, use and leverage—
(A)
existing Department of Energy programs; and
(B)
existing programs of the Federal agencies determined to be appropriate under subsection (a).
(c)
Protection of information— Information provided to, or collected by, the Federal Government pursuant to this section—
(1)
shall be exempt from disclosure under section 552(b)(3) of title 5, United States Code; and
(2)
shall not be made available by any Federal agency, State, political subdivision of a State, or Tribal authority pursuant to any Federal, State, political subdivision of a State, or Tribal law, respectively, requiring public disclosure of information or records.