US Codex
Bill
Notes

S. 2520 — what changed

State and Local Government Cybersecurity Act of 2021

From Reported in Senate to Engrossed in Senate. 1 section amended between Reported in Senate and Engrossed in Senate.

Sec. 2 Amendments to the Homeland Security Act of 2002

Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended—

(1)
changed in section 2201 (6 U.S.C. 651)—651), by adding at the end the following:

added “(7) SLTT entity—The term SLTT entity means a domestic government entity that is a State government, local government, Tribal government, territorial government, or any subdivision thereof.”

(A)
removed by redesignating paragraphs (4), (5), and (6) as paragraphs (5), (6), and (7), respectively; and
(B)
removed by inserting after paragraph (3) the following:

removed “(4) Entity—The term entity shall include—

removed “(A) an association, corporation, whether for-profit or nonprofit, partnership, proprietorship, organization, institution, establishment, or individual, whether domestic or foreign;

removed “(B) a governmental agency or other governmental entity, whether domestic or foreign, including State, local, Tribal, and territorial government entities; and

removed “(C) the general public.”

(2)
removed in section 2202 (6 U.S.C. 652)—
(A)
removed in subsection (c)—
(i)
removed in paragraph (11), by striking “and” at the end;
(ii)
removed in the first paragraph (12), by striking “and” at the end;
(iii)
removed by redesignating the second and third paragraphs (12) as paragraphs (13) and (15), respectively;
(iv)
removed in paragraph (13), as so redesignated, by striking “and” at the end; and
(v)
removed by inserting after paragraph (13), as so redesignated, the following:

removed “(14) carry out the authority of the Secretary under subsection (e)(1)(S); and”

(B)
removed in subsection (e)(1), by adding at the end the following:

removed “(S) To make grants to and enter into cooperative agreements or contracts with States, local, Tribal, and territorial governments, and other non-Federal entities as the Secretary determines necessary to carry out the responsibilities of the Secretary related to cybersecurity and infrastructure security under this Act and any other provision of law, including grants, cooperative agreements, and contracts that provide assistance and education related to cyber threat indicators, defensive measures and cybersecurity technologies, cybersecurity risks, incidents, analysis, and warnings.”

(2)
renumbered was (5) in section 2209 (6 U.S.C. 659)—
(A)
renumbered was (5)(2) in subsection (c)(6), by inserting “operational and” before “timely”;
(B)
renumbered was (5)(3) in subsection (d)(1)(E), by inserting “, including an entity that collaborates with election officials,” after “governments”; and
(C)
renumbered was (5)(4) by adding at the end the following:

added “(p) Coordination on cybersecurity for SLTT entities

added “(1) Coordination—The Center shall, upon request and to the extent practicable, and in coordination as appropriate with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center—

added “(A) conduct exercises with SLTT entities;

added “(B) provide operational and technical cybersecurity training to SLTT entities to address cybersecurity risks or incidents, with or without reimbursement, related to—

added “(i) cyber threat indicators;

added “(ii) defensive measures;

added “(iii) cybersecurity risks;

added “(iv) vulnerabilities; and

added “(v) incident response and management;

added “(C) in order to increase situational awareness and help prevent incidents, assist SLTT entities in sharing, in real time, with the Federal Government as well as among SLTT entities, actionable—

added “(i) cyber threat indicators;

added “(ii) defensive measures;

added “(iii) information about cybersecurity risks; and

added “(iv) information about incidents;

added “(D) provide SLTT entities notifications containing specific incident and malware information that may affect them or their residents;

added “(E) provide to, and periodically update, SLTT entities via an easily accessible platform and other means—

added “(i) information about tools;

added “(ii) information about products;

added “(iii) resources;

added “(iv) policies;

added “(v) guidelines;

added “(vi) controls; and

added “(vii) other cybersecurity standards and best practices and procedures related to information security, including, as appropriate, information produced by other Federal agencies;

added “(F) work with senior SLTT entity officials, including chief information officers and senior election officials and through national associations, to coordinate the effective implementation by SLTT entities of tools, products, resources, policies, guidelines, controls, and procedures related to information security to secure the information systems, including election systems, of SLTT entities;

added “(G) provide operational and technical assistance to SLTT entities to implement tools, products, resources, policies, guidelines, controls, and procedures on information security;

added “(H) assist SLTT entities in developing policies and procedures for coordinating vulnerability disclosures consistent with international and national standards in the information technology industry; and

added “(I) promote cybersecurity education and awareness through engagements with Federal agencies and non-Federal entities.

added “(q) Report—Not later than 1 year after the date of enactment of this subsection, and every 2 years thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on the services and capabilities that the Agency directly and indirectly provides to SLTT entities.”

removed “(p) Coordination on cybersecurity for Federal and non-Federal entities

removed “(1) Coordination—The Center shall, to the extent practicable, and in coordination as appropriate with Federal and non-Federal entities, such as the Multi-State Information Sharing and Analysis Center—

removed “(A) conduct exercises with Federal and non-Federal entities;

removed “(B) provide operational and technical cybersecurity training related to cyber threat indicators, proactive and defensive measures, cybersecurity risks and vulnerabilities, and incident response and management to Federal and non-Federal entities to address cybersecurity risks or incidents, with or without reimbursement;

removed “(C) assist Federal and non-Federal entities, upon request, in sharing actionable and real time cyber threat indicators, defensive measures, cybersecurity risks, and incidents from and to the Federal Government as well as among Federal and non-Federal entities, in order to increase situational awareness and help prevent incidents;

removed “(D) provide notifications containing specific incident and malware information that may affect them or their customers and residents;

removed “(E) provide and periodically update via an easily accessible platform and other means tools, products, resources, policies, guidelines, controls, and other cybersecurity standards and best practices and procedures related to information security;

removed “(F) work with senior Federal and non-Federal officials, including State, local, Tribal, and territorial Chief Information Officers, senior election officials, and through national associations, to coordinate a nationwide effort to ensure effective implementation of tools, products, resources, policies, guidelines, controls, and procedures related to information security to secure and ensure the resiliency of Federal and non-Federal information systems, including election systems;

removed “(G) provide, upon request, operational and technical assistance to Federal and non-Federal entities to implement tools, products, resources, policies, guidelines, controls, and procedures on information security, including by, as appropriate, deploying and sustaining cybersecurity technologies, such as an intrusion and threat detection capability, to assist those Federal and non-Federal entities in detecting cybersecurity risks and incidents;

removed “(H) assist Federal and non-Federal entities in developing policies and procedures for coordinating vulnerability disclosures, to the extent practicable, consistent with international and national standards in the information technology industry;

removed “(I) ensure that Federal and non-Federal entities, as appropriate, are made aware of the tools, products, resources, policies, guidelines, controls, and procedures on information security developed by the Department and other appropriate Federal departments and agencies for ensuring the security and resiliency of civilian information systems; and

removed “(J) promote cybersecurity education and awareness through engagements with Federal and non-Federal entities.

removed “(q) Report—Not later than 1 year after the date of enactment of this subsection, and every 2 years thereafter, the Secretary shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a report on—

removed “(1) the status of cybersecurity measures that are in place, and any gaps that exist, in each State and in the largest urban areas of the United States;

removed “(2) the services and capabilities that the Agency directly provides to governmental agencies or other governmental entities; and

removed “(3) the services and capabilities that the Agency indirectly provides to governmental agencies or other governmental entities through an entity described in section 2201(4)(B).”