H.R. 3243 — what changed
Pipeline Security Act
From Introduced in House to Reported in House. 3 sections amended between Introduced in House and Reported in House.
Sec. 3 Pipeline security section Pipeline security division
“D Pipeline Security
changed
“1631. Pipeline security sectionsection Pipeline security division
changed
“(a) Establishment—There is within the Administration a pipeline security section sectionpipeline security division to carry out pipeline security programs in furtherance of section 114(f)(16) of title 49, United States Code.
changed
“(b) Mission—The mission of the section sectiondivision referred to in subsection (a) is to oversee, in coordination with the Cybersecurity and Infrastructure Security Agency of the Department, the security of pipeline transportation and pipeline facilities (as such terms are defined in section 60101 of title 49, United States Code) against cybersecurity threats (as such term is defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (Public Law 114–113; 6 U.S.C. 1501)), an act of terrorism (as such term is defined in section 3077 of title 18, United States Code), and other nefarious acts that jeopardize the physical security or cybersecurity of such transportation or facilities.
changed
“(c) Leadership; staffing—The Administrator shall appoint as the head of the section an sectiondivisionan individual in the executive service of the Administration with knowledge of the pipeline industry and security best practices, as determined appropriate by the Administrator. The section sectiondivision shall be staffed by a workforce that includes personnel with cybersecurity expertise.
changed
“(d) Responsibilities—The section sectiondivision shall be responsible for carrying out the duties of the section sectiondivision as directed by the Administrator, acting through the head appointed pursuant to subsection (c). Such duties shall include the following:
“(1) Developing, in consultation with relevant Federal, State, local, Tribal, and territorial entities and public and private sector stakeholders, guidelines for improving the security of pipeline transportation and pipeline facilities against cybersecurity threats, an act of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of such transportation or facilities, consistent with the National Institute of Standards and Technology Framework for Improvement of Critical Infrastructure Cybersecurity and any update to such guidelines pursuant to section 2(c)(15) of the National Institute for Standards and Technology Act (15 U.S.C. 272(c)(15)).
changed
“(2) Updating such guidelines as necessary based on intelligence and risk assessments, but not less frequently than every three years.years, unless such guidelines are superseded by directives or regulations.
“(3) Sharing of such guidelines and, as appropriate, intelligence and information regarding such security threats to pipeline transportation and pipeline facilities, as appropriate, with relevant Federal, State, local, Tribal, and territorial entities and public and private sector stakeholders.
changed “(4) Conducting voluntary security assessments based on such guidelines to provide recommendations, or mandatory security assessments if required by superseding directives or regulations, to provide recommendations or requirements for the improvement of the security of pipeline transportation and pipeline facilities against cybersecurity threats, an act of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of such transportation or facilities, including the security policies, plans, practices, and training programs maintained by owners and operators of pipeline facilities.
changed
“(5) Carrying out a program through which the Administrator identifies and ranks the relative risk of pipelines and inspects pipeline facilities designated by owners and operators of such facilities as critical based on such guidelines.guidelines or superseding directives or regulations.
“(6) Preparing notice and comment regulations for publication, if determined necessary by the Administrator.
changed
“(e) Details—In furtherance of the section’s mission, as set forth in subsection (b), “(6) Supporting the Administrator development and the Director implementation of the Cybersecurity and Infrastructure Security Agency may detail personnel between their components to leverage expertise. Personnel detailed from the Cybersecurity and Infrastructure Security Agency may be considered as fulfilling a security directive or regulation when the cybersecurity expertise requirements in referred to in subsection (c).”Administrator issues such a directive or regulation.
added “(e) Details—In furtherance of the section’sdivision’s mission, as set forth in subsection (b), the Administrator and the Director of the Cybersecurity and Infrastructure Security Agency may detail personnel between their components to leverage expertise. Personnel detailed from the Cybersecurity and Infrastructure Security Agency may be considered as fulfilling the cybersecurity expertise requirements in referred to in subsection (c).”