(a)
Study— The Comptroller General of the United States shall conduct a study on the actions the Federal Government has taken to support the cybersecurity of commercial satellite systems, including as part of any action to address the cybersecurity of critical infrastructure sectors.
(b)
Report— Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall report to the appropriate congressional committees on the study conducted under subsection (a), which shall include information—
(1)
on efforts of the Federal Government, and the effectiveness of those efforts, to—
(A)
address or improve the cybersecurity of commercial satellite systems; and
(B)
support related efforts with international entities or the private sector;
(2)
on the resources made available to the public by Federal agencies to address cybersecurity risks and threats to commercial satellite systems, including resources made available through the clearinghouse;
(3)
on the extent to which commercial satellite systems are reliant on, or relied on by, critical infrastructure;
(4)
that includes an analysis of how commercial satellite systems and the threats to those systems are integrated into Federal and non-Federal critical infrastructure risk analyses and protection plans;
(5)
on the extent to which Federal agencies are reliant on commercial satellite systems and how Federal agencies mitigate cybersecurity risks associated with those systems;
(6)
on the extent to which Federal agencies are reliant on commercial satellite systems that are owned wholly or in part or controlled by foreign entities, or that have infrastructure in foreign countries, and how Federal agencies mitigate associated cybersecurity risks;
(7)
on the extent to which Federal agencies coordinate or duplicate authorities and take other actions focused on the cybersecurity of commercial satellite systems; and
(8)
as determined appropriate by the Comptroller General of the United States, that includes recommendations for further Federal action to support the cybersecurity of commercial satellite systems, including recommendations on information that should be shared through the clearinghouse.
(c)
Consultation— In carrying out subsections (a) and (b), the Comptroller General of the United States shall coordinate with appropriate Federal agencies and organizations, including—
(1)
the Department of Commerce;
(2)
the Office of the National Cyber Director;
(3)
the Department of Homeland Security;
(4)
the Department of Defense;
(5)
the Department of Transportation;
(6)
the Federal Communications Commission;
(7)
the National Aeronautics and Space Administration;
(8)
the National Executive Committee for Space-Based Positioning, Navigation, and Timing;
(9)
the National Space Council;
(10)
the Department of Justice; and
(11)
the Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector.
(d)
Briefing— Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall provide a briefing to the appropriate congressional committees on the study conducted under subsection (a).
(e)
Classification— The report made under subsection (b) shall be unclassified but may include a classified annex.