US Codex
Bill
Notes

H.R. 3699 — what changed

Pipeline Security Act

From Introduced in House to Reported in House. 2 sections amended and 1 added between Introduced in House and Reported in House.

Sec. 3 Pipeline security section

(a)
changed In general— Title XII of the Implementing Recommendations of the 9/11 Commission Act of 2007 (Public Law 110–53) is amended by adding at the end the following new section:

“1209. Pipeline security section

“(a) Establishment—There is within the Transportation Security Administration a pipeline security section to carry out pipeline security programs in furtherance of section 114(f)(16) of title 49, United States Code.

“(b) Mission—The mission of the section referred to in subsection (a) is to oversee, in coordination with the the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, the security of pipeline transportation and pipeline facilities (as such terms are defined in section 60101 of title 49, United States Code) against cybersecurity threats (as such term is defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (Public Law 114–113; 6 U.S.C. 1501)), an act of terrorism (as such term is defined in section 3077 of title 18, United States Code), and other nefarious acts that jeopardize the physical security or cybersecurity of such transportation or facilities.

“(c) Leadership; staffing—The Administrator of the Transportation Security Administration shall appoint as the head of the section an individual with knowledge of the pipeline industry and security best practices, as determined appropriate by the Administrator. The section shall be staffed by a workforce that includes personnel with cybersecurity expertise.

“(d) Responsibilities—The section shall be responsible for carrying out the duties of the section as directed by the Administrator of the Transportation Security Administration, acting through the head appointed pursuant to subsection (c). Such duties shall include the following:

changed “(1) Developing, in consultation with relevant Federal, State, local, Tribal, territorial entities and public and private sector stakeholders, guidelines for improving the security of pipeline transportation and pipeline facilities against cybersecurity threats, an act of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of such transportation or facilities.facilities, consistent with the National Institute of Standards and Technology Framework for Improvement of Critical Infrastructure Cybersecurity and any update to such guidelines pursuant to section 2(c)(15) of the National Institute for Standards and Technology Act (15 U.S.C. 272(c)(15)).

“(2) Updating such guidelines as necessary based on intelligence and risk assessments, but not less frequently than every three years.

“(3) Sharing of such guidelines and, as appropriate, intelligence and information regarding such security threats to pipeline transportation and pipeline facilities, as appropriate, with relevant Federal, State, local, Tribal, and territorial entities and public and private sector stakeholders.

changed “(4) Conducting voluntary security assessments based on the guidelines developed pursuant to paragraph (1) to provide recommendations for the improvement of the security of pipeline transportation and pipeline facilities against cybersecurity threats, an act of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of such transportation or facilities, including the security policies, plans, practices, and training programs maintained by owners and operators of pipeline facilities.

changed “(5) Carrying out a program to inspect pipeline transportation through which the Administrator identifies and pipeline facilities, including inspections ranks the relative risk of pipelines and inspects pipeline facilities determined critical designated by the Administrator owners and operators of such facilities as critical based on a risk assessment conducted in consultation with relevant Federal, State, local, Tribal, and territorial entities and public and private sector stakeholders.the guidelines developed pursuant to paragraph (1).

“(6) Preparing notice and comment regulations for publication, if determined necessary by the Administrator.

changed “(e) Details—In furtherance of the section’s mission, as set forth in subsection (b), the Administrator and the Director of the Cybersecurity and Infrastructure Security Agency may detail personnel between their components to leverage expertise.”expertise. Personnel detailed from the Cybersecurity and Infrastructure Security Agency may be considered as fulfilling the cybersecurity expertise requirements in referred to in subsection (c).”

(b)
Updated guidelines— Not later than March 31, 2021, the section shall publish updated guidelines pursuant to section 1209 of the Implementing Recommendations of the 9/11 Commission Act of 2007, as added by subsection (a).
(c)
Clerical amendment— The table of contents for the Implementing Recommendations of the 9/11 Commission Act of 2007 is amended by inserting after the item relating to section 1208 the following new item:

Sec. 4 Personnel strategy

(a)
In general— Not later than 180 days after the date of the enactment of this Act, the Administrator of the Transportation Security Administration, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall develop a personnel strategy for enhancing operations within the pipeline security section of the Transportation Security Administration, as established pursuant to section 1209 of the Implementing Recommendations of the 9/11 Commission Act of 2007, as added by section 3.
(b)
Contents— The strategy required under subsection (a) shall take into consideration the most recently published versions of each of the following documents:
(1)
The Transportation Security Administration National Strategy for Transportation Security.
(2)
The Department of Homeland Security Cybersecurity Strategy.
(3)
The Transportation Security Administration Cybersecurity Roadmap.
(4)
The Department of Homeland Security Balanced Workforce Strategy.
(5)
The Department of Homeland Security Quadrennial Homeland Security Review.
(c)
changed Resources— The strategy shall include an assessment of additional resources determined necessary by the Administrator.
(d)
Submission to Congress— Upon development of the strategy, the Administrator of the Transportation Security Administration shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a copy of such strategy.

Sec. 6 Stakeholder engagement

added

added Not later than one year after the date of the enactment of this Act, the Administrator of the Transportation Security Administration shall convene not less than two industry days to engage with relevant pipeline transportation and pipeline facilities stakeholders on matters related to the security of pipeline transportation and pipeline facilities (as such terms are defined in section 60101 of title 49, United States Code).