Pipeline Security Act
A BILL
To amend the Homeland Security Act of 2002 to codify the Transportation Security Administration’s responsibility relating to securing pipeline transportation and pipeline facilities against cybersecurity threats, acts of terrorism, and other nefarious acts that jeopardize the physical security or cybersecurity of pipelines, and for other purposes.
Sec. 2 Pipeline transportation and pipeline facilities security responsibilities
“(16) maintain responsibility, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency, as appropriate, for securing pipeline transportation and pipeline facilities (as such terms are defined in section 60101 of this title) against cybersecurity threats (as such term is defined in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650)), acts of terrorism (as such term is defined in section 3077 of title 18), and other security threats; and”
“(v) ensuring the security of pipeline transportation and pipeline facilities (as such terms are defined in section 60101 of this title) against cybersecurity threats (as such term is defined in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650)), acts of terrorism (as such term is defined in section 3077 of title 18), and other security threats.”
“(y) Pipeline transportation and pipeline facilities responsibilities
“(1) In general—In carrying out responsibilities to secure pipeline transportation and pipeline facilities (as such terms are defined in section 60101 of this title) pursuant to subsection (f)(16), the Administrator of the Transportation Security Administration shall carry out the following:
“(A) Develop, in consultation with relevant Federal, State, local, Tribal, and territorial entities and public and private sector stakeholders, guidelines for improving the security of pipeline transportation and pipeline facilities against cybersecurity threats (as such term is defined in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650)), acts of terrorism (as such term is defined in section 3077 of title 18), and other security threats, consistent with the National Institute of Standards and Technology Framework for Improvement of Critical Infrastructure Cybersecurity, any update to such guidelines pursuant to section 2(c)(15) of the National Institute for Standards and Technology Act (15 U.S.C. 272(c)(15)), and any other standard the Administrator considers appropriate.
“(B) Promulgate a security directive or regulation that applies to pipeline transportation or pipeline facilities, as appropriate.
“(C) Share, as appropriate, with relevant Federal, State, local, Tribal, and territorial entities and public and private sector stakeholders, such guidelines, security directives, and regulations and, as appropriate, intelligence and information regarding such security threats to pipeline transportation and pipeline facilities.
“(D) Conduct security assessments, as appropriate, based on such guidelines, security directives, or regulations to provide recommendations or requirements for the improvement of the security of pipeline transportation and pipeline facilities against cybersecurity threats, acts of terrorism, and other security threats, including the security policies, plans, practices, and training programs maintained by owners and operators of pipeline transportation and pipeline facilities.
“(E) Carry out a program through which the Administrator identifies and ranks the relative security risks to certain pipeline transportation and pipeline facilities, and inspects pipeline transportation and pipeline facilities based in part on the designation by owners and operators of such facilities as critical based on such guidelines, security directives, or regulations.
“(2) Details—The Administrator of the Transportation Security Administration and the Director of the Cybersecurity and Infrastructure Security Agency may detail personnel between their components to leverage expertise.”