US Codex
Pub. L.
Notes

Division G — Homeland Security

117th Congress · Approved Dec 23, 2022 · 136 Stat. 2395 · Lineage

DIVISION G Homeland Security

TITLE LXXI Homeland Security Matters

Subtitle A Strengthening Security in Our Communities

SEC. 7101. Enhancements to Funding and Administration of Nonprofit Security Grant Program of the Department of Homeland Security.

(a)
In General.— Section 2009 of the Homeland Security Act of 2002 (6 U.S.C. 609a) is amended—
(1)
in subsection (a), by inserting “ or other threats” before the period at the end;
(2)
in subsection (b)—
(A)
in the matter preceding paragraph (1), by striking “ (a)”; and
(B)
by amending paragraph (2) to read as follows:

“(2) determined by the Secretary to be at risk of terrorist attacks or other threats.”

(3)
in subsection (c)—
(A)
by redesignating paragraphs (1), (2), and (3) as subparagraphs (A), (B), and (E), respectively, and moving such subparagraphs, as so redesignated, two ems to the right;
(B)
in the matter preceding subparagraph (A), as so redesignated, by striking “ The recipient” and inserting the following:

“(1) In general.—The recipient”

(C)
in subparagraph (A), as so redesignated, by striking “ equipment and inspection and screening systems” and inserting “ equipment, inspection and screening systems, and alteration or remodeling of existing buildings or physical facilities”;
(D)
by inserting after subparagraph (B), as so redesignated, the following new subparagraphs:

“(C) Facility security personnel costs.

“(D) Expenses directly related to the administration of the grant, except that those expenses may not exceed 5 percent of the amount of the grant.”

; and

(E)
by adding at the end the following new paragraphs:

“(2) Retention.—Each State through which a recipient receives a grant under this section may retain not more than 5 percent of each grant for expenses directly related to the administration of the grant.

“(3) Outreach and technical assistance.—

“(A) In general.—If the Administrator establishes target allocations in determining award amounts under the Program, a State may request a project to use a portion of the target allocation for outreach and technical assistance if the State does not receive enough eligible applications from nonprofit organizations located outside high-risk urban areas.

“(B) Priority.—Any outreach or technical assistance described in subparagraph (A) should prioritize underserved communities and nonprofit organizations that are traditionally underrepresented in the Program.

“(C) Parameters.—In determining grant guidelines under subsection (g), the Administrator may determine the parameters for outreach and technical assistance.”

(4)
in subsection (e)—
(A)
by striking “ 2020 through 2024” and inserting “ 2022 through 2028”;
(B)
by striking “ on the expenditure” and inserting

“(1) The expenditure”

; and

(C)
by adding at the end the following new paragraphs:

“(2) The number of applications submitted by eligible nonprofit organizations to each State.

“(3) The number of applications submitted by each State to the Administrator.

“(4) The operations of the program office of the Program, including staffing resources and efforts with respect to subparagraphs (A) through (D) of subsection (c)(1).”

; and

(5)
by striking subsection (f) and inserting the following new subsections:

“(f) Administration.—Not later than 120 days after the date of enactment of this subsection, the Administrator shall ensure that within the Federal Emergency Management Agency a program office for the Program (in this subsection referred to as the ‘program office’) shall—

“(1) be headed by a senior official of the Agency; and

“(2) administer the Program (including, where appropriate, in coordination with States), including relating to—

“(A) outreach, engagement, education, and technical assistance and support to eligible nonprofit organizations described in subsection (b), with particular attention to those organizations in underserved communities, before, during, and after the awarding of grants, including web-based training videos for eligible nonprofit organizations that provide guidance on preparing an application and the environmental planning and historic preservation process;

“(B) the establishment of mechanisms to ensure program office processes are conducted in accordance with constitutional, statutory, and regulatory requirements that protect civil rights and civil liberties and advance equal access for members of underserved communities;

“(C) the establishment of mechanisms for the Administrator to provide feedback to eligible nonprofit organizations that do not receive grants;

“(D) the establishment of mechanisms to identify and collect data to measure the effectiveness of grants under the Program;

“(E) the establishment and enforcement of standardized baseline operational requirements for States, including requirements for States to eliminate or prevent any administrative or operational obstacles that may impact eligible nonprofit organizations described in subsection (b) from receiving grants under the Program;

“(F) carrying out efforts to prevent waste, fraud, and abuse, including through audits of grantees; and

“(G) promoting diversity in the types and locations of eligible nonprofit organizations that are applying for grants under the Program.

“(g) Grant Guidelines.—For each fiscal year, before awarding grants under this section, the Administrator—

“(1) shall publish guidelines, including a notice of funding opportunity or similar announcement, as the Administrator determines appropriate; and

“(2) may prohibit States from closing application processes before the publication of those guidelines.

“(h) Paperwork Reduction Act.—Chapter 35 of title 44, United States Code (commonly known as the ‘Paperwork Reduction Act’), shall not apply to any changes to the application materials, Program forms, or other core Program documentation intended to enhance participation by eligible nonprofit organizations in the Program.

“(i) Authorization of Appropriations.—

“(1) In general.—There is authorized to be appropriated $360,000,000 for each of fiscal years 2023 through 2028 for grants under this section, of which—

“(A) $180,000,000 each such fiscal year shall be for recipients in high-risk urban areas that receive funding under section 2003; and

“(B) $180,000,000 each such fiscal year shall be for recipients in jurisdictions that do not so receive such funding.

“(2) Operations and support.—There is authorized to be appropriated $18,000,000 for each of fiscal years 2023 through 2028 for Operations and Support at the Federal Emergency Management Agency for costs incurred for the management and administration (including evaluation) of this section.”

(b)
Report.—
(1)
In general.— Not later than 180 days after the date of the enactment of this Act, the Administrator shall seek to enter into a contract or other agreement with an independent research organization pursuant to which the organization will conduct a study that analyzes and reports on the following:
(A)
The effectiveness of the Nonprofit Security Grant Program established under section 2009(a) of the Homeland Security Act 2002 (6 U.S.C. 609a(a)), as amended by subsection (a), for preparedness against terrorist attacks or other threats.
(B)
The risk-based formula and allocations under such Program.
(C)
The risk profile of and any identifiable factors leading to the low participation of traditionally underrepresented groups and States under such Program.
(2)
Submission.— The report required under paragraph (1) shall be submitted to the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Homeland Security of the House of Representatives, and the Committees on Appropriations of the Senate and the House of Representatives.
(3)
Funding.— The Administrator may use funding authorized under subsection (j) of section 2009 of the Homeland Security Act of 2002 (6 U.S.C. 609a)), as amended by subsection (a), to carry out this subsection.
(c)
Technical and Conforming Amendments.— Section 2008 of the Homeland Security Act of 2002 (6 U.S.C. 609) is amended—
(1)
in subsection (c) by striking “ sections 2003 and 2004” and inserting “ sections 2003, 2004, and 2009”; and
(2)
in subsection (e), by striking “ section 2003 or 2004” and inserting “ section 2003, 2004, or 2009”.

SEC. 7102. Preservation of Homeland Security Capabilities.

(a)
Definitions.— In this section:
(1)
Administrator.— The term “Administrator” means the Administrator of the Federal Emergency Management Agency.
(2)
Appropriate congressional committees.— The term “appropriate congressional committees” means the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives.
(3)
Covered homeland security capability.— The term “covered homeland security capability” means a homeland security capability related to preventing, preparing for, protecting against, or responding to acts of terrorism that—
(A)
was developed or otherwise supported through grant funding under the UASI before the current fiscal year; and
(B)
is at risk of being reduced or eliminated without additional Federal financial assistance.
(4)
Covered urban area.— The term “covered urban area” means an urban area that—
(A)
during the current fiscal year did not receive grant funding under the UASI; and
(B)
requires continued Federal assistance for the purpose of preserving a covered homeland security capability.
(5)
Secretary.— The term “Secretary” means the Secretary of Homeland Security.
(6)
UASI.— The term “UASI” means the Urban Area Security Initiative under section 2003 of the Homeland Security Act of 2002 (6 U.S.C. 604).
(b)
Report and Proposal.—
(1)
Submission to congress.— Not later than 18 months after the date of the enactment of this Act, the Secretary, acting through the Administrator, shall submit to the appropriate congressional committees a report regarding covered homeland security capabilities, including a proposal relating to providing Federal assistance to covered urban areas to preserve such capabilities that is informed by the survey information collected pursuant to subsection (c)—
(A)
under which the Administrator would make Federal financial assistance available for at least three consecutive fiscal years to covered urban areas; and
(B)
that would allow covered urban areas to transition to other sources funding for such covered homeland security capabilities.
(2)
Requirements relating to uasi funds.— The proposal required under paragraph (1) shall contain the following:
(A)
A prohibition on a covered urban area that receives Federal financial assistance described in paragraph (1)(A) during a fiscal year from also receiving funds under the UASI during such fiscal year.
(B)
A requirement for a covered urban area to submit to the Administrator notice of whether such covered urban area would elect to receive—
(i)
Federal financial assistance under paragraph (1)(A); or
(ii)
funding under the UASI.
(3)
Analysis.— The report required under paragraph (1) shall include the following:
(A)
An analysis of whether providing additional Federal financial assistance, as described in paragraph (1)(A), would allow covered urban areas to preserve covered homeland security capabilities on a long-term basis.
(B)
An analysis of whether legislative changes to the UASI are necessary to ensure urban areas receiving funds under the UASI are able to preserve covered homeland security capabilities on a long-term basis.
(4)
Other contents of proposal.— The proposal required under paragraph (1) shall—
(A)
set forth eligibility criteria for covered urban areas to receive Federal assistance described in paragraph (1)(A);
(B)
identify annual funding levels that would be required to provide such Federal assistance, in accordance with the survey required under subsection (c); and
(C)
consider a range of approaches to make such Federal assistance available to covered urban areas, including—
(i)
modifications to the UASI in a manner that would not affect the availability of funding to urban areas under the UASI;
(ii)
the establishment of a competitive grant program;
(iii)
the establishment of a formula grant program; and
(iv)
a timeline for the implementation of any such approach and, if necessary, a legislative proposal to authorize any such approach.
(c)
Survey.— In developing the proposal required under subsection (b), the Administrator shall, to ascertain the scope of Federal financial assistance required, survey the following:
(1)
Urban areas that did not receive grant funding under the UASI during the current fiscal year concerning covered homeland security capabilities that are at risk of being reduced or eliminated without additional Federal financial assistance.
(2)
Urban areas that received grant funding under the UASI during the current fiscal year, but did not receive such funding during at least one fiscal year of the seven fiscal years immediately preceding the current fiscal year.
(3)
Any other urban areas the Secretary determines appropriate.
(d)
Exemption.— The Secretary may exempt the Administrator from the requirements of subchapter I of chapter 35 of title 44, United States Code (commonly referred to as the “Paperwork Reduction Act”), for purposes of carrying out subsection (c) if the Secretary determines that complying with such requirements would delay the development of the proposal required under subsection (b).
(e)
Rule of Construction.— Nothing in this section may be construed as directing or authorizing the Administrator to implement the proposal required under subsection (b).

SEC. 7103. School and Daycare Protection.

(a)
In General.— Not later than 180 days after the date of the enactment of this Act and annually thereafter, the Secretary of Homeland Security shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report regarding the following:
(1)
The Department of Homeland Security’s activities, policies, and plans to enhance the security of early childhood education programs, elementary schools, and secondary schools during the preceding year that includes information on the Department’s activities through the Federal School Safety Clearinghouse.
(2)
Information on all structures or efforts within the Department intended to bolster coordination among departmental components and offices involved in carrying out paragraph (1) and, with respect to each structure or effort, specificity on which components and offices are involved and which component or office leads such structure or effort.
(3)
A detailed description of the measures used to ensure privacy rights, civil rights, and civil liberties protections in carrying out these activities.
(b)
Briefing.— Not later than 30 days after the submission of each report required under subsection (a), the Secretary of Homeland Security shall provide to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a briefing regarding such report and the status of efforts to carry out plans included in such report for the preceding year.
(c)
Definitions.— In this section, the terms “early childhood education program”, “elementary school”, and “secondary school” have the meanings given such terms in section 8101 of the Elementary and Secondary Education Act of 1965 (20 U.S.C. 7801).

SEC. 7104. Cybersecurity Grants for Schools.

(a)
In General.— Section 2220 of the Homeland Security Act of 2002 (6 U.S.C. 665f) is amended by adding at the end the following new subsection:

“(e) Grants and Cooperative Agreements.—The Director may award financial assistance in the form of grants or cooperative agreements to States, local governments, institutions of higher education (as such term is defined in section 101 of the Higher Education Act of 1965 (20 U.S.C. 1001)), nonprofit organizations, and other non-Federal entities as determined appropriate by the Director for the purpose of funding cybersecurity and infrastructure security education and training programs and initiatives to—

“(1) carry out the purposes of CETAP; and

“(2) enhance CETAP to address the national shortfall of cybersecurity professionals.”

(b)
Briefings.— Paragraph (2) of subsection (c) of section 2220 of the Homeland Security Act of 2002 (6 U.S.C. 665f) is amended—
(1)
by redesignating subparagraphs (C) and (D) as subparagraphs (D) and (E) respectively; and
(2)
by inserting after subparagraph (B) the following new subparagraph:

“(C) information on any grants or cooperative agreements made pursuant to subsection (e), including how any such grants or cooperative agreements are being used to enhance cybersecurity education for underserved populations or communities;”

SEC. 7105. Transnational Criminal Investigative Unit Stipend.

(a)
Short Title.— This section may be cited as the “Transnational Criminal Investigative Unit Stipend Act”.
(b)
Stipends for Transnational Criminal Investigative Units.—
(1)
In general.— Subtitle H of title VIII of the Homeland Security Act of 2002 (6 U.S.C. 451 et seq.) is amended by adding at the end the following:

“SEC. 890C. TRANSNATIONAL CRIMINAL INVESTIGATIVE UNITS.

“(a) In General.—The Secretary, with the concurrence of the Secretary of State, shall operate Transnational Criminal Investigative Units within Homeland Security Investigations.

“(b) Composition.—Each Transnational Criminal Investigative Unit shall be composed of trained foreign law enforcement officials who shall collaborate with Homeland Security Investigations to investigate and prosecute individuals involved in transnational criminal activity.

“(c) Vetting Requirement.—

“(1) In general.—Before entry into a Transnational Criminal Investigative Unit, and at periodic intervals while serving in such a unit, foreign law enforcement officials shall be required to pass certain security evaluations, which may include a background check, a polygraph examination, a urinalysis test, or other measures that the Secretary determines to be appropriate.

“(2) Leahy vetting required.—No member of a foreign law enforcement unit may join a Transnational Criminal Investigative Unit if the Secretary, in coordination with the Secretary of State, has credible information that such foreign law enforcement unit has committed a gross violation of human rights, consistent with the limitations set forth in section 620M of the Foreign Assistance Act of 1961 (22 U.S.C. 2378d).

“(3) Approval and concurrence.—The establishment and continued support of the Transnational Criminal Investigative Units who are assigned under paragraph (1)—

“(A) shall be performed with the approval of the chief of mission to the foreign country to which the personnel are assigned;

“(B) shall be consistent with the duties and powers of the Secretary of State and the chief of mission for a foreign country under section 103 of the Omnibus Diplomatic Security and Antiterrorism Act of 1986 (22 U.S.C. 4802) and section 207 of the Foreign Service Act of 1980 (22 U.S.C. 3927), respectively; and

“(C) shall not be established without the concurrence of the Assistant Secretary of State for International Narcotics and Law Enforcement Affairs.

“(4) Report.—The Executive Associate Director of Homeland Security Investigations shall submit a report to the Committee on Foreign Relations of the Senate, the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on the Judiciary of the Senate, the Committee on Foreign Affairs of the House of Representatives, the Committee on Homeland Security of the House of Representatives, and the Committee on the Judiciary of the House of Representatives that describes—

“(A) the procedures used for vetting Transnational Criminal Investigative Unit members to include compliance with the vetting required under this subsection; and

“(B) any additional measures that should be implemented to prevent personnel in vetted units from being compromised by criminal organizations.

“(d) Monetary Stipend.—The Executive Associate Director of Homeland Security Investigations is authorized to pay vetted members of a Transnational Criminal Investigative Unit a monetary stipend in an amount associated with their duties dedicated to unit activities.

“(e) Annual Briefing.—The Executive Associate Director of Homeland Security Investigations, during the 5-year period beginning on the date of the enactment of this section, shall provide an annual unclassified briefing to the congressional committees referred to in subsection (c)(4), which may include a classified session, if necessary, that identifies—

“(1) the number of vetted members of Transnational Criminal Investigative Unit in each country;

“(2) the amount paid in stipends to such members, disaggregated by country;

“(3) relevant enforcement statistics, such as arrests and progress made on joint investigations, in each such country; and

“(4) whether any vetted members of the Transnational Criminal Investigative Unit in each country were involved in any unlawful activity, including human rights abuses or significant acts of corruption.”

(2)
Clerical amendment.— The table of contents for the Homeland Security Act of 2002 (Public Law 107–296) is amended by inserting after the item relating to section 890B the following:

“Sec. 890C. Transnational Criminal Investigative Units.”.

SEC. 7106. Chemical Security Analysis Center.

(a)
In General.— Title III of the Homeland Security Act of 2002 (6 U.S.C. 181 et seq.) is amended by adding at the end the following new section:

“SEC. 323. CHEMICAL SECURITY ANALYSIS CENTER.

“(a) In General.—The Secretary, acting through the Under Secretary for Science and Technology, shall designate the laboratory described in subsection (b) as an additional laboratory pursuant to the authority under section 308(c)(2), which shall be used to conduct studies, analyses, and research to assess and address domestic chemical security events.

“(b) Laboratory Described.—The laboratory described in this subsection is the laboratory known, as of the date of enactment of this section, as the Chemical Security Analysis Center.

“(c) Laboratory Activities.—Pursuant to the authority under section 302(4), the Chemical Security Analysis Center shall—

“(1) identify and develop approaches and mitigation strategies to domestic chemical security threats, including the development of comprehensive, research-based definable goals relating to such approaches and mitigation strategies;

“(2) provide an enduring science-based chemical threat and hazard analysis capability;

“(3) provide expertise regarding risk and consequence modeling, chemical sensing and detection, analytical chemistry, acute chemical toxicology, synthetic chemistry and reaction characterization, and nontraditional chemical agents and emerging chemical threats;

“(4) staff and operate a technical assistance program that provides operational support and subject matter expertise, design and execute laboratory and field tests, and provide a comprehensive knowledge repository of chemical threat information that is continuously updated with data from scientific, intelligence, operational, and private sector sources;

“(5) consult, as appropriate, with the Countering Weapons of Mass Destruction Office of the Department to mitigate, prepare, and respond to threats, hazards, and risks associated with domestic chemical security events; and

“(6) carry out such other activities authorized under this section as the Secretary determines appropriate.

“(d) Special Rule.—Nothing in this section amends, alters, or affects—

“(1) the responsibilities of the Countering Weapons of Mass Destruction Office of the Department; or

“(2) the activities or requirements authorized to other entities within the Federal Government, including the activities and requirements of the Environmental Protection Agency under section 112(r) of the Clean Air Act (42 U.S.C. 7412(r)), the Toxic Substances Control Act (15 U.S.C. 2601 et seq.), and the Comprehensive Environmental Response, Compensation, and Liability Act of 1980 (commonly referred to as ‘Superfund’; 42 U.S.C. 9601 et seq.).”

(b)
Technical and Conforming Amendment.— The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 322 the following new item:

“Sec. 323. Chemical Security Analysis Center.”.

Subtitle B Strengthening DHS Management, Policymaking, and Operations

SEC. 7111. Joint Task Forces of the Department of Homeland Security.

(a)
Short Title.— This section may be cited as the “DHS Joint Task Forces Reauthorization Act of 2022”.
(b)
Dhs Joint Task Forces.— Subsection (b) of section 708 of the Homeland Security Act of 2002 (6 U.S.C. 348) is amended—
(1)
by amending paragraph (8) to read as follows:

“(8) Joint task force staff.—

“(A) In general.—Each Joint Task Force shall have a staff, composed of personnel from relevant components and offices of the Department, to assist the Director of such Joint Task Force in carrying out the mission and responsibilities of such Joint Task Force.

“(B) Report.—The Secretary shall include in the report submitted under paragraph (6)(F)—

“(i) the number of personnel of each component or office permanently assigned to each Joint Task Force; and

“(ii) the number of personnel of each component or office assigned on a temporary basis to each Joint Task Force.”

(2)
in paragraph (9)—
(A)
in the heading, by striking “ establishment” and inserting “ mission; establishment”;
(B)
by amending subparagraph (A) to read as follows:

“(A) using leading practices in performance management and lessons learned by other law enforcement task forces and joint operations, establish—

“(i) the mission, strategic goals, and objectives of each Joint Task Force;

“(ii) the criteria for terminating each Joint Task Force; and

“(iii) outcome-based and other appropriate performance metrics for evaluating the effectiveness of each Joint Task Force with respect to the mission, strategic goals, and objectives established pursuant to clause (i), including—

“(I) targets for each Joint Task Force to achieve by not later than one and three years after such establishment; and

“(II) a description of the methodology used to establish such metrics;”

(C)
in subparagraph (B)—
(iii)
by striking “ date of the enactment of this section” and insert “ date of the enactment of the DHS Joint Task Forces Reauthorization Act of 2022”;
(iv)
by inserting “ mission, strategic goals, objectives, and” before “ metrics”; and
(v)
by striking the period at the end and inserting “ ; and”; and
(D)
by amending subparagraph (C) to read as follows:

“(C) not later than one year after the date of the enactment of the DHS Joint Task Forces Reauthorization Act of 2022 and annually thereafter, submit to the committees specified in subparagraph (B) a report that contains information on the progress in implementing the outcome-based and other appropriate performance metrics established pursuant to subparagraph (A)(iii).”

(3)
in paragraph (11)—
(A)
in the heading, by inserting “ or termination” after “ formation”; and
(B)
by amending subparagraph (A) to read as follows:

“(A) In general.—Not later than seven days after establishing or terminating a Joint Task Force under this subsection, the Secretary shall submit to the majority leader of the Senate, the minority leader of the Senate, the Speaker of the House of Representatives, the majority leader of the House of Representatives, the minority leader of the House of Representatives, and the Committee on Homeland Security and the Committee on Transportation and Infrastructure of the House of Representatives and the Committee on Homeland Security and Governmental Affairs and the Committee on Commerce, Science, and Transportation of the Senate a notification regarding such establishment or termination, as the case may be. The contents of any such notification shall include the following:

“(i) The criteria and conditions required to establish or terminate the Joint Task Force at issue.

“(ii) The primary mission, strategic goals, objectives, and plan of operations of such Joint Task Force.

“(iii) If such notification is a notification of termination, information on the effectiveness of such Joint Task Force as measured by the outcome-based performance metrics and other appropriate performance metrics established pursuant to paragraph (9)(A)(iii).

“(iv) The funding and resources required to establish or terminate such Joint Task Force.

“(v) The number of personnel of each component or office permanently assigned to such Joint Task Force.

“(vi) The number of personnel of each component and office assigned on a temporary basis to such Joint Task Force.

“(vii) If such notification is a notification of establishment, the anticipated costs of establishing and operating such Joint Task Force.

“(viii) If such notification is a notification of termination, funding allocated in the immediately preceding fiscal year to such Joint Task Force for—

“(I) operations, notwithstanding such termination; and

“(II) activities associated with such termination.

“(ix) The anticipated establishment or actual termination date of such Joint Task Force, as the case may be.”

(4)
in paragraph (12)—
(A)
in subparagraph (A)—
(i)
by striking “ January 31, 2018, and January 31, 2021, the Inspector General of the Department” and inserting “ one year after the date of the enactment of the DHS Joint Task Forces Reauthorization Act of 2022, the Comptroller General of the United States”; and
(ii)
by inserting “ an assessment of the effectiveness of the Secretary’s utilization of the authority provided under this section for the purposes specified in subsection (b)(2) as among the range of options available to the Secretary to conduct joint operations among departmental components and offices and” before “ a review of the Joint Task Forces”; and
(B)
in subparagraph (B)—
(i)
in the matter preceding clause (i), by striking “ reviews” and inserting “ review”; and
(ii)
by amending clauses (i) and (ii) to read as follows:

“(i) an assessment of methodology utilized to determine whether to establish or terminate each Joint Task Force; and

“(ii) an assessment of the effectiveness of oversight over each Joint Task Force, with specificity regarding the Secretary’s utilization of outcome-based or other appropriate performance metrics (established pursuant to paragraph (9)(A)(iii)) to evaluate the effectiveness of each Joint Task Force in measuring progress with respect to the mission, strategic goals, and objectives (established pursuant to paragraph (9)(A)(i)) of such Joint Task Force.”

; and

(5)
in paragraph (13), by striking “ 2022” and inserting “ 2024”.

SEC. 7112. Homeland Procurement Reform Act.

(a)
In General.— Subtitle D of title VIII of the Homeland Security Act of 2002 (6 U.S.C. 391 et seq.) is amended by adding at the end the following new section:

“SEC. 836. REQUIREMENTS TO BUY CERTAIN ITEMS RELATED TO NATIONAL SECURITY INTERESTS.

“(a) Definitions.—In this section:

“(1) Covered item.—The term ‘covered item’ means any of the following:

“(A) Footwear provided as part of a uniform.

“(B) Uniforms.

“(C) Holsters and tactical pouches.

“(D) Patches, insignia, and embellishments.

“(E) Chemical, biological, radiological, and nuclear protective gear.

“(F) Body armor components intended to provide ballistic protection for an individual, consisting of 1 or more of the following:

“(i) Soft ballistic panels.

“(ii) Hard ballistic plates.

“(iii) Concealed armor carriers worn under a uniform.

“(iv) External armor carriers worn over a uniform.

“(G) Any other item of clothing or protective equipment as determined appropriate by the Secretary.

“(2) Frontline operational component.—The term ‘frontline operational component’ means any of the following entities of the Department:

“(A) U.S. Customs and Border Protection.

“(B) U.S. Immigration and Customs Enforcement.

“(C) The United States Secret Service.

“(D) The Transportation Security Administration.

“(E) The Federal Protective Service.

“(F) The Federal Emergency Management Agency.

“(G) The Federal Law Enforcement Training Centers.

“(H) The Cybersecurity and Infrastructure Security Agency.

“(b) Requirements.—

“(1) In general.—The Secretary shall ensure that any procurement of a covered item for a frontline operational component meets the following criteria:

“(A)

(i) To the maximum extent possible, not less than one-third of funds obligated in a specific fiscal year for the procurement of such covered items shall be covered items that are manufactured or supplied in the United States by entities that qualify as small business concerns, as such term is described under section 3 of the Small Business Act (15 U.S.C. 632).

“(ii) Covered items may only be supplied pursuant to subparagraph (A) to the extent that United States entities that qualify as small business concerns—

“(I) are unable to manufacture covered items in the United States; and

“(II) meet the criteria identified in subparagraph (B).

“(B) Each contractor with respect to the procurement of such a covered item, including the end-item manufacturer of such a covered item—

“(i) is an entity registered with the System for Award Management (or successor system) administered by the General Services Administration; and

“(ii) is in compliance with ISO 9001:2015 of the International Organization for Standardization (or successor standard) or a standard determined appropriate by the Secretary to ensure the quality of products and adherence to applicable statutory and regulatory requirements.

“(C) Each supplier of such a covered item with an insignia (such as any patch, badge, or emblem) and each supplier of such an insignia, if such covered item with such insignia or such insignia, as the case may be, is not produced, applied, or assembled in the United States, shall—

“(i) store such covered item with such insignia or such insignia in a locked area;

“(ii) report any pilferage or theft of such covered item with such insignia or such insignia occurring at any stage before delivery of such covered item with such insignia or such insignia; and

“(iii) destroy any such defective or unusable covered item with insignia or insignia in a manner established by the Secretary, and maintain records, for three years after the creation of such records, of such destruction that include the date of such destruction, a description of the covered item with insignia or insignia destroyed, the quantity of the covered item with insignia or insignia destroyed, and the method of destruction.

“(2) Waiver.—

“(A) In general.—In the case of a national emergency declared by the President under the National Emergencies Act (50 U.S.C. 1601 et seq.) or a major disaster declared by the President under section 401 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5170), the Secretary may waive a requirement in subparagraph (A), (B) or (C) of paragraph (1) if the Secretary determines there is an insufficient supply of a covered item that meets such requirement.

“(B) Notice.—Not later than 60 days after the date on which the Secretary determines a waiver under subparagraph (A) is necessary, the Secretary shall provide to the Committee on Homeland Security and Governmental Affairs and the Committee on Appropriations of the Senate and the Committee on Homeland Security, the Committee on Oversight and Reform, and the Committee on Appropriations of the House of Representatives notice of such determination, which shall include the following:

“(i) Identification of the national emergency or major disaster declared by the President.

“(ii) Identification of the covered item for which the Secretary intends to issue the waiver.

“(iii) A description of the demand for the covered item and corresponding lack of supply from contractors able to meet the criteria described in subparagraph (B) or (C) of paragraph (1).

“(c) Pricing.—The Secretary shall ensure that covered items are purchased at a fair and reasonable price, consistent with the procedures and guidelines specified in the Federal Acquisition Regulation.

“(d) Report.—Not later than one year after the date of the enactment of this section and annually thereafter, the Secretary shall provide to the Committee on Homeland Security, the Committee on Oversight and Reform, the Committee on Small Business, and the Committee on Appropriations of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs, the Committee on Small Business and Entrepreneurship, and the Committee on Appropriations of the Senate a briefing on instances in which vendors have failed to meet deadlines for delivery of covered items and corrective actions taken by the Department in response to such instances.

“(e) Effective Date.—This section applies with respect to a contract entered into by the Department or any frontline operational component on or after the date that is 180 days after the date of the enactment of this section.”

(b)
Study.—
(1)
In general.— Not later than 18 months after the date of the enactment of this Act, the Secretary of Homeland Security shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate and the Committee on Homeland Security of the House of Representatives a study of the adequacy of uniform allowances provided to employees of frontline operational components (as such term is defined in section 836 of the Homeland Security Act of 2002, as added by subsection (a)).
(2)
Requirements.— The study conducted under paragraph (1) shall—
(A)
be informed by a Department-wide survey of employees from across the Department of Homeland Security who receive uniform allowances that seeks to ascertain what, if any, improvements could be made to the current uniform allowances and what, if any, impacts current allowances have had on employee morale and retention;
(B)
assess the adequacy of the most recent increase made to the uniform allowance for first year employees; and
(C)
consider increasing by 50 percent, at minimum, the annual allowance for all other employees.
(c)
Additional Report.—
(1)
In general.— Not later than 180 days after the date of the enactment of this Act, the Secretary of Homeland Security shall provide a report with recommendations on how the Department of Homeland Security could procure additional items from domestic sources and bolster the domestic supply chain for items related to national security to—
(A)
the Committee on Homeland Security and Governmental Affairs, the Committee on Small Business and Entrepreneurship, and the Committee on Appropriations of the Senate; and
(B)
the Committee on Homeland Security, the Committee on Oversight and Reform, the Committee on Small Business, and the Committee on Appropriations of the House of Representatives.
(2)
Contents.— The report required under paragraph (1) shall include the following:
(A)
A review of the compliance of the Department of Homeland Security with the requirements under section 604 of title VI of division A of the American Recovery and Reinvestment Act of 2009 (6 U.S.C. 453b) to buy certain items related to national security interests from sources in the United States.
(B)
An assessment of the capacity of the Department of Homeland Security to procure the following items from domestic sources:
(i)
Personal protective equipment and other items necessary to respond to a pandemic such as that caused by COVID–19.
(ii)
Helmets that provide ballistic protection and other head protection and components.
(iii)
Rain gear, cold weather gear, and other environmental and flame resistant clothing.
(d)
Clerical Amendment.— The table of contents in section 1(b) of the Homeland Security Act of 2002 (Public Law 107–296; 116 Stat. 2135) is amended by inserting after the item relating to section 835 the following:

“Sec. 836. Requirements to buy certain items related to national security interests.”.

SEC. 7113. Daily Public Report of Covered Contract Awards.

(a)
Daily Contract Reporting Requirements.—
(1)
Report.—
(A)
In general.— The Secretary shall post, maintain, and update in accordance with paragraph (2), on a publicly available website of the Department, a daily report of all covered contract awards.
(B)
Contents.— Each report under this paragraph shall include, for each covered contract award, information relating to the following:
(i)
The contract number, modification number, or delivery order number.
(ii)
The contract type.
(iii)
The amount obligated for the award.
(iv)
The total contract value for the award, including all options.
(v)
The description of the purpose for the award.
(vi)
The number of proposals or bids received.
(vii)
The name and address of the vendor, and whether the vendor is a small business.
(viii)
The period and primary place of performance for the award.
(ix)
Whether the award is multiyear.
(x)
The contracting office.
(2)
Update.— The Secretary shall make updates referred to in paragraph (1) not later than five business days after the date on which a covered contract is authorized or modified.
(3)
Effective date.— Paragraph (1) shall take effect on the date that is 180 days after the date of the enactment of this Act.
(b)
Undefinitized Contract Action or Definitized Amount.— If a covered contract award reported under subsection (a) includes an undefinitized contract action, the Secretary shall—
(1)
report the estimated total contract value for the award and the amount obligated upon award; and
(2)
once there is a definitized amount for the award, update the total contract value and amount obligated.
(c)
Exemption.— Each report required under subsection (a) shall not include covered contract awards for which synopsis was exempted under section 5.202(a)(1) of the Federal Acquisition Regulation, or any successor thereto.
(d)
Definitions.— In this section:
(1)
Covered contract award.— The term “covered contract award”—
(A)
means a contract action of the Department with a total contract value of not less than $4,000,000, including unexercised options; and
(B)
includes—
(i)
contract awards governed by the Federal Acquisition Regulation;
(ii)
modifications to a contract award that increase the total value, expand the scope of work, or extend the period of performance;
(iii)
orders placed on a multiple-award or multiple-agency contract that includes delivery or quantity terms that are indefinite;
(iv)
other transaction authority agreements; and
(v)
contract awards made with other than full and open competition.
(2)
Definitized amount.— The term “definitized amount” means the final amount of a covered contract award after agreement between the Department and the contractor at issue.
(3)
Department.— The term “Department” means the Department of Homeland Security.
(4)
Secretary.— The term “Secretary” means the Secretary of Homeland Security.
(5)
Small business.— The term “small business” means an entity that qualifies as a small business concern, as defined under section 3 of the Small Business Act (15 U.S.C. 632).
(6)
Total contract value.— The term “total contract value” means the total amount of funds expected to be provided to the contractor at issue under the terms of the contract through the full period of performance.
(7)
Undefinitized contract action.— The term “undefinitized contract action” means any contract action for which the contract terms, specifications, or price is not established prior to the start of the performance of the covered contract award.
(e)
Sunset.— This section shall cease to have force or effect on the date that is five years after the date of the enactment of this Act.

SEC. 7114. Preference for United States Industry.

Section 308 of the Homeland Security Act of 2002 (6 U.S.C. 188) is amended by adding at the end the following new subsection:

“(d) Preference for United States Industry.—

“(1) Definitions.—In this subsection:

“(A) Country of concern.—The term ‘country of concern’ means a country that—

“(i) is a covered nation, as such term is defined in section 4872(d) of title 10, United States Code; or

“(ii) the Secretary determines is engaged in conduct that is detrimental to the national security of the United States.

“(B) Nonprofit organization; small business firm; subject invention.—The terms ‘nonprofit organization’, ‘small business firm’, and ‘subject invention’ have the meanings given such terms in section 201 of title 35, United States Code.

“(C) Manufactured substantially in the united states.—The term ‘manufactured substantially in the United States’ means an item is a domestic end product.

“(D) Domestic end product.—The term ‘domestic end product’ has the meaning given such term in section 25.003 of title 48, Code of Federal Regulations, or any successor thereto.

“(3) Waivers.—

“(A) In general.—Subject to subparagraph (B), in individual cases, the requirements under section 204 of title 35, United States Code, may be waived by the Secretary upon a showing by the small business firm, nonprofit organization, or assignee that reasonable but unsuccessful efforts have been made to grant licenses on similar terms to potential licensees that would be likely to manufacture substantially in the United States or that under the circumstances domestic manufacture is not commercially feasible.

“(B) Conditions on waivers granted by department.—

“(i) Before grant of waiver.—Before granting a waiver under subparagraph (A), the Secretary shall comply with the procedures developed and implemented by the Department pursuant to section 70923(b)(2) of the Build America, Buy America Act (enacted as subtitle A of title IX of division G of Public Law 117–58).

“(ii) Prohibition on granting certain waivers.—The Secretary may not grant a waiver under subparagraph (A) if, as a result of such waiver, products embodying the applicable subject invention, or produced through the use of the applicable subject invention, would be manufactured substantially in a country of concern.”

SEC. 7115. Department of Homeland Security Mentor-Protégé Program.

(a)
In General.— Subtitle H of title VIII of the Homeland Security Act of 2002 (6 U.S.C. 451 et seq.), as amended by subtitle A, is further amended by adding at the end the following new section:

“SEC. 890D.

MENTOR-PROTÉGÉ PROGRAM.

“(a) Establishment.—There is established in the Department a mentor-protégé program (in this section referred to as the ‘Program’) under which a mentor firm enters into an agreement with a protégé firm for the purpose of assisting the protégé firm to compete for prime contracts and subcontracts of the Department.

“(b) Eligibility.—The Secretary shall establish criteria for mentor firms and protégé firms to be eligible to participate in the Program, including a requirement that a firm is not included on any list maintained by the Federal Government of contractors that have been suspended or debarred.

“(c) Program Application and Approval.—

“(1) Application.—The Secretary, acting through the Office of Small and Disadvantaged Business Utilization of the Department, shall establish a process for submission of an application jointly by a mentor firm and the protégé firm selected by the mentor firm. The application shall include each of the following:

“(A) A description of the assistance to be provided by the mentor firm, including, to the extent available, the number and a brief description of each anticipated subcontract to be awarded to the protégé firm.

“(B) A schedule with milestones for achieving the assistance to be provided over the period of participation in the Program.

“(C) An estimate of the costs to be incurred by the mentor firm for providing assistance under the Program.

“(D) Attestations that Program participants will submit to the Secretary reports at times specified by the Secretary to assist the Secretary in evaluating the protégé firm’s developmental progress.

“(E) Attestations that Program participants will inform the Secretary in the event of a change in eligibility or voluntary withdrawal from the Program.

“(2) Approval.—Not later than 60 days after receipt of an application pursuant to paragraph (1), the head of the Office of Small and Disadvantaged Business Utilization shall notify applicants of approval or, in the case of disapproval, the process for resubmitting an application for reconsideration.

“(3) Rescission.—The head of the Office of Small and Disadvantaged Business Utilization may rescind the approval of an application under this subsection if it determines that such action is in the best interest of the Department.

“(d) Program Duration.—A mentor firm and protégé firm approved under subsection (c) shall enter into an agreement to participate in the Program for a period of not less than 36 months.

“(e) Program Benefits.—A mentor firm and protégé firm that enter into an agreement under subsection (d) may receive the following Program benefits:

“(1) With respect to an award of a contract that requires a subcontracting plan, a mentor firm may receive evaluation credit for participating in the Program.

“(2) With respect to an award of a contract that requires a subcontracting plan, a mentor firm may receive credit for a protégé firm performing as a first tier subcontractor or a subcontractor at any tier in an amount equal to the total dollar value of any subcontracts awarded to such protégé firm.

“(3) A protégé firm may receive technical, managerial, financial, or any other mutually agreed upon benefit from a mentor firm, including a subcontract award.

“(f) Reporting.—Not later than one year after the date of the enactment of this section and annually thereafter, the head of the Office of Small and Disadvantaged Business Utilization shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Homeland Security and the Committee on Small Business of the House of Representatives a report that—

“(1) identifies each agreement between a mentor firm and a protégé firm entered into under this section, including the number of protégé firm participants that are—

“(A) small business concerns;

“(B) small business concerns owned and controlled by veterans;

“(C) small business concerns owned and controlled by service-disabled veterans;

“(D) qualified HUBZone small business concerns;

“(E) small business concerns owned and controlled by socially and economically disadvantaged individuals;

“(F) small business concerns owned and controlled by women;

“(G) historically Black colleges and universities; and

“(H) minority-serving institutions;

“(2) describes the type of assistance provided by mentor firms to protégé firms;

“(3) identifies contracts within the Department in which a mentor firm serving as the prime contractor provided subcontracts to a protégé firm under the Program; and

“(4) assesses the degree to which there has been—

“(A) an increase in the technical capabilities of protégé firms; and

“(B) an increase in the quantity and estimated value of prime contract and subcontract awards to protégé firms for the period covered by the report.

“(g) Rule of Construction.—Nothing in this section may be construed to limit, diminish, impair, or otherwise affect the authority of the Department to participate in any program carried out by or requiring approval of the Small Business Administration or adopt or follow any regulation or policy that the Administrator of the Small Business Administration may promulgate, except that, to the extent that any provision of this section (including subsection (h)) conflicts with any other provision of law, regulation, or policy, this section shall control.

“(h) Definitions.—In this section:

“(1) Historically black college or university.—The term ‘historically Black college or university’ has the meaning given the term ‘part B institution’ in section 322 of the Higher Education Act of 1965 (20 U.S.C. 1061).

“(2) Mentor firm.—The term ‘mentor firm’ means a for-profit business concern that is not a small business concern that—

“(A) has the ability to assist and commits to assisting a protégé to compete for Federal prime contracts and subcontracts; and

“(B) satisfies any other requirements imposed by the Secretary.

“(3) Minority-serving institution.—The term ‘minority-serving institution’ means an institution of higher education described in section 317 of the Higher Education Act of 1965 (20 U.S.C. 1067q(a)).

“(4) Protégé firm.—The term ‘protégé firm’ means a small business concern, a historically Black college or university, or a minority-serving institution that—

“(A) is eligible to enter into a prime contract or subcontract with the Department; and

“(B) satisfies any other requirements imposed by the Secretary.

“(5) Small business act definitions.—The terms ‘small business concern’, ‘small business concern owned and controlled by veterans’, ‘small business concern owned and controlled by service-disabled veterans’, ‘qualified HUBZone small business concern’, ‘and small business concern owned and controlled by women’ have the meanings given such terms, respectively, under section 3 of the Small Business Act (15 U.S.C. 632). The term ‘small business concern owned and controlled by socially and economically disadvantaged individuals’ has the meaning given such term in section 8(d)(3)(C) of the Small Business Act (15 U.S.C. 637(d)(3)(C)).”

(b)
Clerical Amendment.— The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 890C (as added by subtitle A) the following new item:

“Sec. 890D. Mentor-protégé program.”.

SEC. 7116. Dhs Economic Security Council.

(a)
Establishment of the Council.—
(1)
Definitions.— In this subsection:
(A)
Council.— The term “Council” means the council established under paragraph (2).
(B)
Department.— The term “Department” means the Department of Homeland Security.
(C)
Economic security.— The term “economic security” has the meaning given such term in section 890B(c)(2) of the Homeland Security Act of 2002 (6 U.S.C. 474(c)(2)).
(D)
Secretary.— The term “Secretary” means the Secretary of Homeland Security.
(2)
Establishment.— In accordance with the mission of the Department under section 101(b) of the Homeland Security Act of 2002 (6 U.S.C. 111(b)), and in particular paragraph (1)(F) of such section, the Secretary shall establish a standing council of Department component heads or their designees, to carry out the duties described in paragraph (3).
(3)
Duties of the council.— Pursuant to the scope of the mission of the Department as described in paragraph (2), the Council shall provide to the Secretary advice and recommendations on matters of economic security, including relating to the following:
(A)
Identifying concentrated risks for trade and economic security.
(B)
Setting priorities for securing the trade and economic security of the United States.
(C)
Coordinating Department-wide activity on trade and economic security matters.
(D)
With respect to the development of the continuity of the economy plan of the President under section 9603 of the William M. (Mac) Thornberry National Defense Authorization Act of Fiscal Year 2021 (6 U.S.C. 322).
(E)
Proposing statutory and regulatory changes impacting trade and economic security.
(F)
Any other matters the Secretary considers appropriate.
(4)
Chair and vice chair.— The Under Secretary for Strategy, Policy, and Plans of the Department—
(A)
shall serve as Chair of the Council; and
(B)
may designate a Council member as a Vice Chair.
(5)
Meetings.— The Council shall meet not less frequently than quarterly, as well as—
(A)
at the call of the Chair; or
(B)
at the direction of the Secretary.
(6)
Briefings.— Not later than 180 days after the date of the enactment of this Act and every 180 days thereafter for four years, the Council shall brief the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Homeland Security of the House of Representatives, the Committee on Finance of the Senate, the Committee on Ways and Means of the House of Representatives, the Committee on Commerce, Science, and Transportation of the Senate, and Committee on Energy and Commerce of the House of Representatives on the actions and activities of the Council.
(b)
Assistant Secretary.— Section 709 of the Homeland Security Act of 2002 (6 U.S.C. 349) is amended—
(1)
by redesignating subsection (g) as subsection (h); and
(2)
by inserting after subsection (f) the following new subsection:

“(g) Assistant Secretary.—

“(1) In general.—There is established within the Office of Strategy, Policy, and Plans an Assistant Secretary, who shall assist the Secretary in carrying out the duties under paragraph (2) and the responsibilities under paragraph (3). Notwithstanding section 103(a)(1), the Assistant Secretary established under this paragraph shall be appointed by the President without the advice and consent of the Senate.

“(2) Duties.—At the direction of the Secretary, the Assistant Secretary established under paragraph (1) shall be responsible for policy formulation regarding matters relating to economic security and trade, as such matters relate to the mission and the operations of the Department.

“(3) Additional responsibilities.—In addition to the duties specified in paragraph (2), the Assistant Secretary established under paragraph (1), at the direction of the Secretary, may—

“(A) oversee—

“(i) coordination of supply chain policy; and

“(ii) assessments and reports to Congress related to critical economic security domains;

“(B) coordinate with stakeholders in other Federal departments and agencies and nongovernmental entities with trade and economic security interests, authorities, and responsibilities; and

“(C) perform such additional duties as the Secretary or the Under Secretary of Strategy, Policy, and Plans may prescribe.

“(4) Definitions.—In this subsection:

“(A) Critical economic security domain.—The term ‘critical economic security domain’ means any infrastructure, industry, technology, or intellectual property (or combination thereof) that is essential for the economic security of the United States.

“(B) Economic security.—The term ‘economic security’ has the meaning given such term in section 890B(c)(2).”

(c)
Rule of Construction.— Nothing in this section or the amendments made by this section may be construed to affect or diminish the authority otherwise granted to any other officer of the Department of Homeland Security.

Subtitle C Enhancing Cybersecurity Training and Operations

SEC. 7121. President’s Cup Cybersecurity Competition.

(a)
In General.— The Director of the Cybersecurity and Infrastructure Security Agency (in this section referred to as the “Director”) of the Department of Homeland Security is authorized to hold an annual cybersecurity competition to be known as the “Department of Homeland Security Cybersecurity and Infrastructure Security Agency’s President’s Cup Cybersecurity Competition” (in this section referred to as the “competition”) for the purpose of identifying, challenging, and competitively awarding prizes, including cash prizes, to the United States Government’s best cybersecurity practitioners and teams across offensive and defensive cybersecurity disciplines.
(b)
Eligibility.— To be eligible to participate in the competition, an individual shall be a Federal civilian employee or member of the uniformed services (as such term is defined in section 2101(3) of title 5, United States Code) and shall comply with any rules promulgated by the Director regarding the competition.
(c)
Competition Administration.— The Director may enter into a grant, contract, cooperative agreement, or other agreement with a private sector for-profit or nonprofit entity or State or local government agency to administer the competition.
(d)
Competition Parameters.— Each competition shall incorporate the following elements:
(1)
Cybersecurity skills outlined in the National Initiative for Cybersecurity Education Framework, or any successor framework.
(2)
Individual and team events.
(3)
Categories demonstrating offensive and defensive cyber operations, such as software reverse engineering and exploitation, network operations, forensics, big data analysis, cyber analysis, cyber defense, cyber exploitation, secure programming, obfuscated coding, or cyber-physical systems.
(4)
Any other elements related to paragraphs (1), (2), or (3), as determined necessary by the Director.
(e)
Use of Funds.—
(1)
In general.— In order to further the goals and objectives of the competition, the Director may use amounts made available to the Director for the competition for reasonable expenses for the following:
(A)
Advertising, marketing, and promoting the competition.
(B)
Meals for participants and organizers of the competition if attendance at the meal during the competition is necessary to maintain the integrity of the competition.
(C)
Promotional items, including merchandise and apparel.
(D)
Consistent with section 4503 of title 5, United States Code, necessary expenses for the honorary recognition of competition participants, including members of the uniformed services.
(E)
Monetary and nonmonetary awards for competition participants, including members of the uniformed services, subject to subsection (f).
(2)
Application.— This subsection shall apply to amounts appropriated on or after the date of the enactment of this Act.
(f)
Prize Limitation.—
(1)
Awards by the director.— The Director may make one or more awards per competition, except that the amount or value of each shall not exceed $10,000.
(2)
Awards by the secretary of homeland security.— The Secretary of Homeland Security may make one or more awards per competition, except the amount or the value of each shall not exceed $25,000.
(3)
Regular pay.— A monetary award under this section shall be in addition to the regular pay of the recipient.
(4)
Overall yearly award limit.— The total amount or value of awards made under this Act during a fiscal year may not exceed $100,000.
(g)
Reporting Requirements.— The Director shall annually provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report that includes the following with respect to each competition conducted in the preceding year:
(1)
A description of available amounts.
(2)
A description of authorized expenditures.
(3)
Information relating to participation.
(4)
Information relating to lessons learned, and how such lessons may be applied to improve cybersecurity operations and recruitment of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security.

SEC. 7122. Industrial Control Systems Cybersecurity Training.

(a)
In General.— Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended by adding at the end the following new section:

“SEC. 2220E. INDUSTRIAL CONTROL SYSTEMS CYBERSECURITY TRAINING INITIATIVE.

“(a) Establishment.—

“(1) In general.—The Industrial Control Systems Cybersecurity Training Initiative (in this section referred to as the ‘Initiative’) is established within the Agency.

“(2) Purpose.—The purpose of the Initiative is to develop and strengthen the skills of the cybersecurity workforce related to securing industrial control systems.

“(b) Requirements.—In carrying out the Initiative, the Director shall—

“(1) ensure the Initiative includes—

“(A) virtual and in-person trainings and courses provided at no cost to participants;

“(B) trainings and courses available at different skill levels, including introductory level courses;

“(C) trainings and courses that cover cyber defense strategies for industrial control systems, including an understanding of the unique cyber threats facing industrial control systems and the mitigation of security vulnerabilities in industrial control systems technology; and

“(D) appropriate consideration regarding the availability of trainings and courses in different regions of the United States; and

“(2) engage in—

“(A) collaboration with the National Laboratories of the Department of Energy in accordance with section 309;

“(B) consultation with Sector Risk Management Agencies;

“(C) as appropriate, consultation with private sector entities with relevant expertise, such as vendors of industrial control systems technologies; and

“(3) consult, to the maximum extent practicable, with commercial training providers and academia to minimize the potential for duplication of other training opportunities.

“(c) Reports.—

“(1) In general.—Not later than one year after the date of the enactment of this section and annually thereafter, the Director shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the Initiative.

“(2) Contents.—Each report submitted under paragraph (1) shall include the following:

“(A) A description of the courses provided under the Initiative.

“(B) A description of outreach efforts to raise awareness of the availability of such courses.

“(C) The number of participants in each course.

“(D) Voluntarily provided information on the demographics of participants in such courses, including by sex, race, and place of residence.

“(E) Information on the participation in such courses of workers from each critical infrastructure sector.

“(F) Plans for expanding access to industrial control systems education and training, including expanding access to women and underrepresented populations, and expanding access to different regions of the United States.

“(G) Recommendations regarding how to strengthen the state of industrial control systems cybersecurity education and training.”

(b)
Clerical Amendment.— The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by inserting after the item relating to section 2220D the following new item:

“Sec. 2220E. Industrial Control Systems Cybersecurity Training Initiative.”.

SEC. 7123. National Computer Forensics Institute Reauthorization.

Section 822 of the Homeland Security Act of 2002 (6 U.S.C. 383) is amended—
(1)
in subsection (a)—
(A)
in the subsection heading, by striking “ In General” and inserting “ In General; Mission”;
(B)
by striking “ 2017 through 2022” and inserting “ 2023 through 2028”; and
(C)
by striking the second sentence and inserting “ The Institute’s mission shall be to educate, train, and equip State, local, territorial, and Tribal law enforcement officers, prosecutors, and judges, as well as participants in the United States Secret Service’s network of cyber fraud task forces who are Federal employees, members of the uniformed services, or State, local, Tribal, or territorial employees, regarding the investigation and prevention of cybersecurity incidents, electronic crimes, and related cybersecurity threats, including through the dissemination of homeland security information, in accordance with relevant Federal law regarding privacy, civil rights, and civil liberties protections.”;
(2)
by amending subsection (b) to read as follows:

“(b) Curriculum.—In furtherance of subsection (a), all education and training of the Institute shall be conducted in accordance with relevant Federal law regarding privacy, civil rights, and civil liberties protections. Education and training provided pursuant to subsection (a) shall relate to the following:

“(1) Investigating and preventing cybersecurity incidents, electronic crimes, and related cybersecurity threats, including relating to instances involving illicit use of digital assets and emerging trends in cybersecurity and electronic crime.

“(2) Conducting forensic examinations of computers, mobile devices, and other information systems.

“(3) Prosecutorial and judicial considerations related to cybersecurity incidents, electronic crimes, related cybersecurity threats, and forensic examinations of computers, mobile devices, and other information systems.

“(4) Methods to obtain, process, store, and admit digital evidence in court.”

(3)
in subsection (c)—
(A)
by striking “ cyber and electronic crime and related threats is shared with State, local, tribal, and territorial law enforcement officers and prosecutors” and inserting “ cybersecurity incidents, electronic crimes, and related cybersecurity threats is shared with recipients of education and training provided pursuant to subsection (a)”; and
(B)
by adding at the end the following new sentence: “ When selecting participants for such training, the Institute shall prioritize, to the extent reasonable and practicable, providing education and training to individuals from geographically-diverse jurisdictions throughout the United States, and the Institute shall prioritize, to the extent reasonable and practicable, State, local, tribal, and territorial law enforcement officers, prosecutors, judges, and other employees.”;
(4)
in subsection (d)—
(A)
by striking “ State, local, tribal, and territorial law enforcement officers” and inserting “ recipients of education and training provided pursuant to subsection (a)”; and
(B)
by striking “ necessary to conduct cyber and electronic crime and related threat investigations and computer and mobile device forensic examinations” and inserting “ for investigating and preventing cybersecurity incidents, electronic crimes, and related cybersecurity threats, and for forensic examinations of computers, mobile devices, and other information systems”;
(5)
in subsection (e)—
(A)
by amending the heading to read as follows: “ Cyber Fraud Task Forces”;
(B)
by striking “ Electronic Crime” and inserting “ Cyber Fraud”;
(C)
by striking “ State, local, tribal, and territorial law enforcement officers” and inserting “ recipients of education and training provided pursuant to subsection (a)”; and
(D)
by striking “ at” and inserting “ by”; and
(6)
by inserting after subsection (f) the following new subsections:

“(g) Expenses.—The Director of the United States Secret Service may pay for all or a part of the education, training, or equipment provided by the Institute, including relating to the travel, transportation, and subsistence expenses of recipients of education and training provided pursuant to subsection (a).

“(h) Annual Reports to Congress.—

“(1) In general.—The Secretary shall include in the annual report required under section 1116 of title 31, United States Code, information regarding the activities of the Institute, including, where possible, the following:

“(A) An identification of jurisdictions with recipients of the education and training provided pursuant to subsection (a) during such year.

“(B) Information relating to the costs associated with that education and training.

“(C) Any information regarding projected future demand for the education and training provided pursuant to subsection (a).

“(D) Impacts of the activities of the Institute on the capability of jurisdictions to investigate and prevent cybersecurity incidents, electronic crimes, and related cybersecurity threats.

“(E) A description of the nomination process for potential recipients of the information and training provided pursuant to subsection (a).

“(F) Any other issues determined relevant by the Secretary.

“(2) Exception.—Any information required under paragraph (1) that is submitted as part of the annual budget submitted by the President to Congress under section 1105 of title 31, United States Code, is not required to be included in the report required under paragraph (1).

“(i) Definitions.—In this section:

“(1) Cybersecurity threat.—The term ‘cybersecurity threat’ has the meaning given such term in section 102 of the Cybersecurity Act of 2015 (enacted as division N of the Consolidated Appropriations Act, 2016 (Public Law 114–113; 6 U.S.C. 1501)).

“(2) Incident.—The term ‘incident’ has the meaning given such term in section 2209(a).

“(3) Information system.—The term ‘information system’ has the meaning given such term in section 102 of the Cybersecurity Act of 2015 (enacted as division N of the Consolidated Appropriations Act, 2016 (Public Law 114–113; 6 U.S.C. 1501(9))).”

SEC. 7124. Report on Cybersecurity Roles and Responsibilities of the Department of Homeland Security.

(a)
In General.— Not later than one year after the date of the enactment of this Act, the Secretary of Homeland Security, in coordination with the Director of the Cybersecurity and Infrastructure Security Agency of the Department of Homeland Security, shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the roles and responsibilities of the Department and its components relating to cyber incident response.
(b)
Contents.— The report required under subsection (a) shall include the following:
(1)
A review of how the cyber incident response plans under section 2210(c) of the Homeland Security Act of 2002 (6 U.S.C. 660(c)) are utilized in the Federal Government’s response to a cyber incident.
(2)
An explanation of the roles and responsibilities of the Department of Homeland Security and its components with responsibility for, or in support of, the Federal Government’s response to a cyber incident, including primary responsibility for working with impacted private sector entities.
(3)
An explanation of which and how authorities of the Department and its components are utilized in the Federal Government’s response to a cyber incident.
(4)
Recommendations to provide further clarity for roles and responsibilities of the Department and its components relating to cyber incident response.

Subtitle D Enhancing Transportation and Border Security Operations

SEC. 7131. Tsa Reaching Across Nationalities, Societies, and Languages to Advance Traveler Education.

(a)
In General.— Not later than 180 days after the date of the enactment of this Act, the Administrator of the Transportation Security Administration (TSA) shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a plan to ensure that TSA material disseminated in major airports can be better understood by more people accessing such airports.
(b)
Contents.— The plan required under subsection (a) shall include the following:
(1)
An identification of the most common languages other than English that are the primary languages of individuals that travel through or work in each major airport.
(2)
A plan to improve—
(A)
TSA materials to communicate information in languages identified pursuant to paragraph (1); and
(B)
the communication of TSA material to individuals with vision or hearing impairments or other possible barriers to understanding such material.
(c)
Considerations.— In developing the plan required under subsection (a), the Administrator of the TSA, acting through the Office of Civil Rights and Liberties, Ombudsman, and Traveler Engagement of the TSA, shall take into consideration data regarding the following:
(1)
International enplanements.
(2)
Local populations surrounding major airports.
(3)
Languages spoken by members of Indian Tribes within each service area population in which a major airport is located.
(d)
Implementation.— Not later than 180 days after the submission of the plan required under subsection (a), the Administrator of the TSA, in consultation with the owner or operator of each major airport, shall implement such plan.
(e)
GAO Review.— Not later than one year after the implementation pursuant to subsection (d) of the plan required under subsection (a), the Comptroller General of the United States shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Commerce, Science, and Transportation of the Senate a review of such implementation.
(f)
Definitions.— In this section:
(1)
Airport.— The term “airport” has the meaning given such term in section 40102 of title 49, United States Code.
(2)
Indian tribe.— The term “Indian Tribe” has the meaning given the term “Indian tribe” in section 102 of the Federally Recognized Indian Tribe List Act of 1994 (25 U.S.C. 5130), individually identified (including parenthetically) in the list published most recently as of the date of the enactment of this Act pursuant to section 104 of that Act (25 U.S.C. 5131).
(3)
Major airports.— The term “major airports” means Category X and Category I airports.
(4)
Non-traveling individual.— The term “non-traveling individual” has the meaning given such term in section 1560.3 of title 49, Code of Federal Regulations.
(5)
TSA material.— The term “TSA material” means signs, videos, audio messages, websites, press releases, social media postings, and other communications published and disseminated by the Administrator of the TSA in Category X and Category I airports for use by both traveling and non-traveling individuals.

SEC. 7132. One-Stop Pilot Program.

(a)
Definitions.— In this section:
(1)
Administrator.— The term “Administrator” means the Administrator of the Transportation Security Administration.
(2)
Appropriate congressional committees.— The term “appropriate congressional committees” means—
(A)
the Committee on Homeland Security and Committee on Foreign Affairs of the House of Representatives; and
(B)
the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Committee on Foreign Relations of the Senate.
(3)
TSA.— The term “TSA” means the Transportation Security Administration of the Department of Homeland Security.
(b)
Implementation.— Notwithstanding 44901(a) of title 49, United States Code, the Administrator, in coordination with the Commissioner of U.S. Customs and Border Protection and the Secretary of State, may implement a pilot program at not more than six foreign last point of departure airports to permit passengers and their accessible property arriving on direct flights or flight segments originating at such participating foreign airports to continue on additional flights or flight segments originating in the United States without additional security re-screening if—
(1)
the initial screening was conducted in accordance with an aviation security screening agreement described in subsection (e);
(2)
passengers arriving from participating foreign airports are unable to access their checked baggage until the arrival at their final destination; and
(3)
upon arrival in the United States, passengers arriving from participating foreign airports do not come into contact with other arriving international passengers, those passengers’ property, or other persons who have not been screened or subjected to other appropriate security controls required for entry into the airport’s sterile area.
(c)
Requirements for Pilot Program.— In carrying out this section, the Administrator shall ensure that there is no reduction in the level of security or specific TSA aviation security standards or requirements for screening passengers and their property prior to boarding an international flight bound for the United States, including specific aviation security standards and requirements regarding the following:
(1)
High risk passengers and their property.
(2)
Weapons, explosives, and incendiaries.
(3)
Screening passengers and property transferring at a foreign last point of departure airport from another airport and bound for the United States, and addressing any commingling of such passengers and property with passengers and property screened under the pilot program described in subsection (b).
(4)
Insider risk at foreign last point of departure airports.
(d)
Re-screening of Checked Baggage.— Subject to subsection (f), the Administrator may determine whether checked baggage arriving from participating foreign airports referenced in subsection (b) that screen using an explosives detection system must be re-screened in the United States by an explosives detection system before such baggage continues on any additional flight or flight segment.
(e)
Aviation Security Screening Agreement.—
(1)
In general.— An aviation security screening agreement described in this subsection is a treaty, executive agreement, or non-binding instrument entered into with a foreign country that delineates and implements security standards and protocols utilized at a foreign last point of departure airport that are determined by the Administrator—
(A)
to be comparable to those of the United States; and
(B)
sufficiently effective to enable passengers and their accessible property to deplane into sterile areas of airports in the United States without the need for re-screening.
(2)
Non-delegation.— The authority to approve an aviation security screening agreement may not be delegated below the level of the Secretary of State, the Secretary of Homeland Security, or the Administrator.
(f)
Re-screening Requirement.—
(1)
In general.— If the Administrator determines that a foreign country participating in the aviation security screening agreement has not maintained and implemented security standards and protocols comparable to those of the United States at foreign last point of departure airports at which a pilot program has been established in accordance with this section, the Administrator shall ensure that passengers and their property arriving from such airports are re-screened in the United States, including by using explosives detection systems in accordance with section 44901(d)(1) of title 49, United States Code, and implementing regulations and directives, before such passengers and their property are permitted into sterile areas of airports in the United States.
(2)
Consultation.— If the Administrator has reasonable grounds to believe the other party to an aviation security screening agreement has not complied with such agreement, the Administrator shall request immediate consultation with such party.
(3)
Suspension or termination of agreement.— If a satisfactory resolution between TSA and a foreign country is not reached within 45 days after a consultation request under paragraph (2) or in the case of the foreign country’s continued or egregious failure to maintain the security standards and protocols described in paragraph (1), the President, or with the concurrence of the Secretary of State, the Secretary of Homeland Security or the Administrator, as appropriate, shall suspend or terminate the aviation security screening agreement with such country, as determined appropriate by the President, the Secretary of Homeland Security, or the Administrator. The Administrator shall notify the appropriate congressional committees of such consultation and suspension or termination, as the case may be, not later than seven days after such consultation and suspension or termination.
(g)
Briefings to Congress.— Not later than 45 days before an aviation security screening agreement described in subsection (e) enters into force, the Administrator, in coordination with the Secretary of State, shall submit to the appropriate congressional committees the following:
(1)
An aviation security threat assessment for the country in which such foreign last point of departure airport is located.
(2)
Information regarding any corresponding mitigation efforts to address any security issues identified in such threat assessment, including any plans for joint covert testing.
(3)
Information on potential security vulnerabilities associated with commencing a pilot program at such foreign last point of departure airport pursuant to subsection (b) and mitigation plans to address such potential security vulnerabilities.
(4)
An assessment of the impacts such pilot program will have on aviation security.
(5)
An assessment of the screening performed at such foreign last point of departure airport, including the feasibility of TSA personnel monitoring screening, security protocols, and standards.
(6)
Information regarding identifying the entity or entities responsible for screening passengers and property at such foreign last point of departure airport.
(7)
The name of the entity or local authority and any contractor or subcontractor.
(8)
Information regarding the screening requirements relating to such aviation security screening agreement.
(9)
Details regarding information sharing mechanisms between the TSA and such foreign last point of departure airport, screening authority, or entity responsible for screening provided for under such aviation security screening agreement.
(10)
A copy of the aviation security screening agreement, which shall identify the foreign last point of departure airport or airports at which a pilot program under this section is to be established.
(h)
Certifications Relating to the Pilot Program for One-stop Security.— For each aviation security screening agreement described in subsection (e), the Administrator, in coordination with the Secretary of State, shall submit to the appropriate congressional committees the following:
(1)
(A)
A certification that such agreement satisfies all of the requirements specified in subsection (c); or
(B)
in the event that one or more of such requirements are not so satisfied, a description of the unsatisfied requirement and information on what actions the Administrator will take to ensure that such remaining requirements are satisfied before such agreement enters into force.
(2)
A certification that TSA and U.S. Customs and Border Protection have ensured that any necessary physical modifications or appropriate mitigations exist in the domestic one- stop security pilot program airport prior to receiving international passengers from a last point of departure airport under the aviation security screening agreement.
(3)
A certification that a foreign last point of departure airport covered by an aviation security screening agreement has an operation to screen all checked bags as required by law, regulation, or international agreement, including the full utilization of explosives detection systems to the extent applicable.
(4)
A certification that the Administrator consulted with stakeholders, including air carriers, aviation nonprofit labor organizations, airport operators, relevant interagency partners, and other stakeholders that the Administrator determines appropriate.
(i)
Report to Congress.— Not later than five years after the date of the enactment of this Act, the Secretary of Homeland Security, in coordination with the Administrator, shall submit to the appropriate congressional committees a report regarding the implementation of the pilot program authorized under this section, including information relating to the following:
(1)
The impact of such program on homeland security and international aviation security, including any benefits and challenges of such program.
(2)
The impact of such program on passengers, airports, and air carriers, including any benefits and challenges of such program.
(3)
The impact and feasibility of continuing such program or expanding it into a more permanent program, including any benefits and challenges of such continuation or expansion.
(j)
Rule of Construction.— Nothing in this section may be construed as limiting the authority of U.S. Customs and Border Protection to inspect persons and baggage arriving in the United States in accordance with applicable law.
(k)
Sunset.— The pilot program authorized under this section shall terminate on the date that is six years after the date of the enactment of this Act.

SEC. 7133. Report on Efforts of the Department of Homeland Security to Deter Vehicular Terrorist Attacks (darren Drake).

(a)
In General.— Not later than one year after the date of the enactment of this Act, the Secretary of Homeland Security shall submit to Congress a report on the efforts of the Department of Homeland Security to deter vehicular terrorist attacks, including engagement with the private sector and other stakeholders. Such report shall include assessment of the following:
(1)
The impact of such engagement on efforts to protect the United States against terrorist attacks.
(2)
A description of the Department’s engagement with privacy, civil rights, and civil liberties stakeholders.
(3)
Ways to improve engagement among the following:
(A)
The Department.
(B)
Federal, State, local, and Tribal law enforcement agencies.
(C)
Other relevant stakeholders.
(b)
Format.— The report required under subsection (a) may be submitted in a classified or protected format, as determined appropriate by the Secretary of Homeland Security.

SEC. 7134. Dhs Illicit Cross-Border Tunnel Defense.

(a)
Counter Illicit Cross-border Tunnel Operations Strategic Plan.—
(1)
In general.— Not later than 180 days after the date of the enactment of this Act, the Commissioner of U.S. Customs and Border Protection, in coordination with the Under Secretary for Science and Technology, and, as appropriate, other officials of the Department of Homeland Security, shall develop a counter illicit cross-border tunnel operations strategic plan (in this section referred to as the “strategic plan”) to address the following:
(A)
Risk-based criteria to be used to prioritize the identification, breach, assessment, and remediation of illicit cross-border tunnels.
(B)
Promote the use of innovative technologies to identify, breach, assess, and remediate illicit cross-border tunnels in a manner that, among other considerations, reduces the impact of such activities on surrounding communities.
(C)
Processes to share relevant illicit cross-border tunnel location, operations, and technical information.
(D)
Indicators of specific types of illicit cross-border tunnels found in each U.S. Border Patrol sector identified through operations to be periodically disseminated to U.S. Border Patrol sector chiefs to educate field personnel.
(E)
A counter illicit cross-border tunnel operations resource needs assessment that includes consideration of the following:
(i)
Technology needs.
(ii)
Staffing needs, including the following:
(I)
A position description for counter illicit cross-border tunnel operations personnel.
(II)
Any specialized skills required of such personnel.
(III)
The number of such full time personnel, disaggregated by U.S. Border Patrol sector.
(2)
Report to congress on strategic plan.— Not later than one year after the development of the strategic plan, the Commissioner of U.S. Customs and Border Protection shall submit to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a report on the implementation of the strategic plan.
(b)
Authorization of Appropriations.— There is authorized to be appropriated to the Commissioner of U.S. Customs and Border Protection $1,000,000 for each of fiscal years 2023 and 2024 to carry out—
(1)
the development of the strategic plan; and
(2)
remediation operations of illicit cross-border tunnels in accordance with the strategic plan to the maximum extent practicable.

SEC. 7135. Providing Training for U.s. Customs and Border Protection Personnel on the Use of Containment Devices to Prevent Secondary Exposure to Fentanyl and Other Potentially Lethal Substances.

(a)
Training.— Paragraph (1) of section 416(b) of the Homeland Security Act of 2002 (6 U.S.C. 216(b)) is amended by adding at the end the following new subparagraph:

“(C) How to use containment devices to prevent potential synthetic opioid exposure.”

(b)
Availability of Containment Devices.— Section 416(c) of the Homeland Security Act of 2002 (6 U.S.C. 216(c)) is amended—
(1)
in the subsection heading, by inserting “ , Containment Devices,” after “ Equipment”; and
(2)
by striking “ and opioid receptor antagonists, including naloxone” and inserting “ , opioid receptor antagonists, including naloxone, and containment devices”.
(c)
Applicability to Other Components.— If the Secretary of Homeland Secretary determines that officers, agents, other personnel, or canines of a component of the Department of Homeland Security other than U.S. Customs and Border Protection are at risk of potential synthetic opioid exposure in the course of their duties, the head of such component shall carry out the responsibilities under section 416 of the Homeland Security Act of 2002 (6 U.S.C. 216) in the same manner and to the same degree as the Commissioner of U.S. Customs and Border Protection carries out such responsibilities.

SEC. 7136. Reports, Evaluations, and Research Regarding Drug Interdiction at and Between Ports of Entry.

(a)
Research on Additional Technologies to Detect Fentanyl.— Not later than one year after the date of the enactment of this Act, the Secretary of Homeland Security, in consultation with the Attorney General, the Secretary of Health and Human Services, and the Director of the Office of National Drug Control Policy, shall research additional technological solutions to—
(1)
target and detect illicit fentanyl, fentanyl analogs, and precursor chemicals, including low-purity fentanyl, especially in counterfeit pressed tablets, and illicit pill press molds; and
(2)
enhance detection of such counterfeit pressed tablets through nonintrusive, noninvasive, and other advanced screening technologies.
(b)
Evaluation of Current Technologies and Strategies in Illicit Drug Interdiction and Procurement Decisions.—
(1)
In general.— The Secretary of Homeland Security, in consultation with the Attorney General, the Secretary of Health and Human Services, and the Director of the Office of National Drug Control Policy, shall establish a program to collect available data and develop metrics to measure how technologies and strategies used by the Department of Homeland Security, U.S. Customs and Border Protection, U.S. Immigration and Customs Enforcement, and other relevant Federal agencies have helped detect trafficked illicit fentanyl, fentanyl analogs, and precursor chemicals or deter illicit fentanyl, fentanyl analogs, and precursor chemicals from being trafficked into the United States at and between land, air, and sea ports of entry.
(2)
Considerations.— The data and metrics program established pursuant to paragraph (1) may consider—
(A)
the rate of detection of illicit fentanyl, fentanyl analogs, and precursor chemicals at land, air, and sea ports of entry;
(B)
investigations and intelligence sharing into the origins of illicit fentanyl, fentanyl analogs, and precursor chemicals within the United States; and
(C)
other data or metrics considered appropriate by the Secretary of Homeland Security.
(3)
Updates.— The Secretary of Homeland Security, as appropriate and in the coordination with the officials referred to in paragraph (1), may update the data and metrics program established pursuant to paragraph (1).
(4)
Reports.—
(A)
Secretary of homeland security.— Not later than one year after the date of the enactment of this Act and biennially thereafter, the Secretary of Homeland Security, in consultation with the Attorney General, the Secretary of Health and Human Services, and the Director of the Office of National Drug Control Policy shall, based on the data collected and metrics developed pursuant to the program established pursuant to paragraph (1), submit to the Committee on Homeland Security, the Committee on Energy and Commerce, the Committee on Science, Space, and Technology, and the Committee on the Judiciary of the House of Representatives and the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Committee on the Judiciary of the Senate a report that—
(i)
examines and analyzes current technologies, including pilot technologies, deployed at land, air, and sea ports of entry to assess how well such technologies detect, deter, and address illicit fentanyl, fentanyl analogs, and precursor chemicals; and
(ii)
examines and analyzes current technologies, including pilot technologies, deployed between land ports of entry to assess how well and accurately such technologies detect, deter, interdict, and address illicit fentanyl, fentanyl analogs, and precursor chemicals;
(B)
Government accountability office.— Not later than one year after the submission of each of the first three reports required under subparagraph (A), the Comptroller General of the United States shall submit to the Committee on Homeland Security, the Committee on Energy and Commerce, the Committee on Science, Space, and Technology, and the Committee on the Judiciary of the House of Representatives and the Committee on Homeland Security and Governmental Affairs, the Committee on Commerce, Science, and Transportation, and the Committee on the Judiciary of the Senate a report that evaluates and, as appropriate, makes recommendations to improve, the collection of data under the program established pursuant to paragraph (1) and metrics used in the subsequent reports required under such subparagraph.

Subtitle E Technical Corrections, Conforming Changes, and Improvements

SEC. 7141. Quadrennial Homeland Security Review Technical Corrections.

(a)
In General.— Section 707 of the Homeland Security Act of 2002 (6 U.S.C. 347) is amended—
(1)
in subsection (a)(3)—
(A)
in subparagraph (B), by striking “ and” after the semicolon at the end;
(B)
by redesignating subparagraph (C) as subparagraph (D); and
(C)
by inserting after subparagraph (B) the following new subparagraph:

“(C) representatives from appropriate advisory committees established pursuant to section 871, including the Homeland Security Advisory Council and the Homeland Security Science and Technology Advisory Committee, or otherwise established, including the Aviation Security Advisory Committee established pursuant to section 44946 of title 49, United States Code; and”

(2)
in subsection (b)—
(A)
in paragraph (2), by inserting before the semicolon at the end the following: “ based on the risk assessment required pursuant to subsection (c)(2)(B)”;
(B)
in paragraph (3)—
(i)
by inserting “ , to the extent practicable,” after “ describe”; and
(ii)
by striking “ budget plan” and inserting “ resources required”;
(C)
in paragraph (4)—
(i)
by inserting “ , to the extent practicable,” after “ identify”;
(ii)
by striking “ budget plan required to provide sufficient resources to successfully” and inserting “ resources required to”; and
(iii)
by striking the semicolon at the end and inserting the following: “ , including any resources identified from redundant, wasteful, or unnecessary capabilities or capacities that may be redirected to better support other existing capabilities or capacities, as the case may be; and”;
(D)
in paragraph (5), by striking “ ; and” and inserting a period; and
(E)
by striking paragraph (6);
(3)
in subsection (c)—
(A)
in paragraph (1), by striking “ December 31 of the year” and inserting “ 60 days after the date of the submission of the President’s budget for the fiscal year after the fiscal year”;
(B)
in paragraph (2)—
(i)
in subparagraph (B), by striking “ description of the threats to” and inserting “ risk assessment of”;
(ii)
in subparagraph (C), by inserting “ , as required under subsection (b)(2)” before the semicolon at the end;
(iii)
in subparagraph (D)—
(I)
by inserting “ to the extent practicable,” before “ a description”; and
(II)
by striking “ budget plan” and inserting “ resources required”;
(iv)
in subparagraph (F)—
(I)
by inserting “ to the extent practicable,” before “ a discussion”; and
(II)
by striking “ the status of”;
(v)
in subparagraph (G)—
(I)
by inserting “ to the extent practicable,” before “ a discussion”;
(II)
by striking “ the status of”;
(III)
by inserting “ and risks” before “ to national homeland”; and
(IV)
by inserting “ and” after the semicolon at the end;
(vi)
by striking subparagraph (H); and
(vii)
by redesignating subparagraph (I) as subparagraph (H);
(C)
by redesignating paragraph (3) as paragraph (4); and
(D)
by inserting after paragraph (2) the following new paragraph:

“(3) Documentation.—The Secretary shall retain and, upon request, provide to Congress the following documentation regarding each quadrennial homeland security review:

“(A) Records regarding the consultation carried out pursuant to subsection (a)(3), including the following:

“(i) All written communications, including communications sent out by the Secretary and feedback submitted to the Secretary through technology, online communications tools, in-person discussions, and the interagency process.

“(ii) Information on how feedback received by the Secretary informed each such quadrennial homeland security review.

“(B) Information regarding the risk assessment required pursuant to subsection (c)(2)(B), including the following:

“(i) The risk model utilized to generate such risk assessment.

“(ii) Information, including data used in the risk model, utilized to generate such risk assessment.

“(iii) Sources of information, including other risk assessments, utilized to generate such risk assessment.

“(iv) Information on assumptions, weighing factors, and subjective judgments utilized to generate such risk assessment, together with information on the rationale or basis thereof.”

(4)
by redesignating subsection (d) as subsection (e); and
(5)
by inserting after subsection (c) the following new subsection:

“(d) Review.—Not later than 90 days after the submission of each report required under subsection (c)(1), the Secretary shall provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate information on the degree to which the findings and recommendations developed in the quadrennial homeland security review that is the subject of such report were integrated into the acquisition strategy and expenditure plans for the Department.”

(b)
Effective Date.— The amendments made by this Act shall apply with respect to a quadrennial homeland security review conducted after December 31, 2021.

SEC. 7142. Technical, Conforming, and Clerical Amendments.

The table of contents in section 1(b) of the Homeland Security Act of 2002 is amended by—
(1)
amending the items relating to sections 435 and 436 to read as follows:

“Sec. 435. Maritime operations coordination plan.

“Sec. 436. Maritime security capabilities assessments.”;

(2)
amending the item relating to section 1617 to read as follows:

“Sec. 1617. Diversified security technology industry marketplace.”;

(3)
amending the item relating to section 1621 to read as follows:

“Sec. 1621. Maintenance validation and oversight.”; and

(4)
amending the item relating to section 2103 to read as follows:

“Sec. 2103. Protection and sharing of information.”.

SEC. 7143. Cisa Technical Corrections and Improvements.

(a)
Technical Amendment Relating to DOTGOV Act of 2020.—
(1)
Amendment.— Section 904(b)(1) of the DOTGOV Act of 2020 (title IX of division U of Public Law 116–260) is amended, in the matter preceding subparagraph (A), by striking “ Homeland Security Act” and inserting “ Homeland Security Act of 2002”.
(2)
Effective date.— The amendment made by paragraph (1) shall take effect as if enacted as part of the DOTGOV Act of 2020 (title IX of division U of Public Law 116–260).
(b)
Consolidation of Definitions.—
(1)
In general.— Title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended by inserting before the subtitle A heading the following:

“SEC. 2200. DEFINITIONS.

“Except as otherwise specifically provided, in this title:

“(1) Agency.—The term ‘Agency’ means the Cybersecurity and Infrastructure Security Agency.

“(2) Appropriate congressional committees.—The term ‘appropriate congressional committees’ means—

“(A) the Committee on Homeland Security and Governmental Affairs of the Senate; and

“(B) the Committee on Homeland Security of the House of Representatives.

“(3) Cloud service provider.—The term ‘cloud service provider’ means an entity offering products or services related to cloud computing, as defined by the National Institute of Standards and Technology in NIST Special Publication 800– 145 and any amendatory or superseding document relating thereto.

“(4) Critical infrastructure information.—The term ‘critical infrastructure information’ means information not customarily in the public domain and related to the security of critical infrastructure or protected systems—

“(A) actual, potential, or threatened interference with, attack on, compromise of, or incapacitation of critical infrastructure or protected systems by either physical or computer-based attack or other similar conduct (including the misuse of or unauthorized access to all types of communications and data transmission systems) that violates Federal, State, or local law, harms interstate commerce of the United States, or threatens public health or safety;

“(B) the ability of any critical infrastructure or protected system to resist such interference, compromise, or incapacitation, including any planned or past assessment, projection, or estimate of the vulnerability of critical infrastructure or a protected system, including security testing, risk evaluation thereto, risk management planning, or risk audit; or

“(C) any planned or past operational problem or solution regarding critical infrastructure or protected systems, including repair, recovery, reconstruction, insurance, or continuity, to the extent it is related to such interference, compromise, or incapacitation.

“(5) Cyber threat indicator.—The term ‘cyber threat indicator’ means information that is necessary to describe or identify—

“(A) malicious reconnaissance, including anomalous patterns of communications that appear to be transmitted for the purpose of gathering technical information related to a cybersecurity threat or security vulnerability;

“(B) a method of defeating a security control or exploitation of a security vulnerability;

“(C) a security vulnerability, including anomalous activity that appears to indicate the existence of a security vulnerability;

“(D) a method of causing a user with legitimate access to an information system or information that is stored on, processed by, or transiting an information system to unwittingly enable the defeat of a security control or exploitation of a security vulnerability;

“(E) malicious cyber command and control;

“(F) the actual or potential harm caused by an incident, including a description of the information exfiltrated as a result of a particular cybersecurity threat;

“(G) any other attribute of a cybersecurity threat, if disclosure of such attribute is not otherwise prohibited by law; or

“(H) any combination thereof.

“(6) Cybersecurity purpose.—The term ‘cybersecurity purpose’ means the purpose of protecting an information system or information that is stored on, processed by, or transiting an information system from a cybersecurity threat or security vulnerability.

“(7) Cybersecurity risk.—The term ‘cybersecurity risk’—

“(A) means threats to and vulnerabilities of information or information systems and any related consequences caused by or resulting from unauthorized access, use, disclosure, degradation, disruption, modification, or destruction of such information or information systems, including such related consequences caused by an act of terrorism; and

“(B) does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.

“(8) Cybersecurity threat.—

“(A) In general.—Except as provided in subparagraph (B), the term ‘cybersecurity threat’ means an action, not protected by the First Amendment to the Constitution of the United States, on or through an information system that may result in an unauthorized effort to adversely impact the security, availability, confidentiality, or integrity of an information system or information that is stored on, processed by, or transiting an information system.

“(B) Exclusion.—The term ‘cybersecurity threat’ does not include any action that solely involves a violation of a consumer term of service or a consumer licensing agreement.

“(9) Defensive measure.—

“(A) In general.—Except as provided in subparagraph (B), the term ‘defensive measure’ means an action, device, procedure, signature, technique, or other measure applied to an information system or information that is stored on, processed by, or transiting an information system that detects, prevents, or mitigates a known or suspected cybersecurity threat or security vulnerability.

“(B) Exclusion.—The term ‘defensive measure’ does not include a measure that destroys, renders unusable, provides unauthorized access to, or substantially harms an information system or information stored on, processed by, or transiting such information system not owned by—

“(i) the private entity, as defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501), operating the measure; or

“(ii) another entity or Federal entity that is authorized to provide consent and has provided consent to that private entity for operation of such measure.

“(10) Director.—The term ‘Director’ means the Director of the Cybersecurity and Infrastructure Security Agency.

“(11) Homeland security enterprise.—The term ‘Homeland Security Enterprise’ means relevant governmental and nongovernmental entities involved in homeland security, including Federal, State, local, and Tribal government officials, private sector representatives, academics, and other policy experts.

“(12) Incident.—The term ‘incident’ means an occurrence that actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information on an information system, or actually or imminently jeopardizes, without lawful authority, an information system.

“(13) Information sharing and analysis organization.—The term ‘Information Sharing and Analysis Organization’ means any formal or informal entity or collaboration created or employed by public or private sector organizations, for purposes of—

“(A) gathering and analyzing critical infrastructure information, including information related to cybersecurity risks and incidents, in order to better understand security problems and interdependencies related to critical infrastructure, including cybersecurity risks and incidents, and protected systems, so as to ensure the availability, integrity, and reliability thereof;

“(B) communicating or disclosing critical infrastructure information, including cybersecurity risks and incidents, to help prevent, detect, mitigate, or recover from the effects of an interference, a compromise, or an incapacitation problem related to critical infrastructure, including cybersecurity risks and incidents, or protected systems; and

“(C) voluntarily disseminating critical infrastructure information, including cybersecurity risks and incidents, to its members, State, local, and Federal Governments, or any other entities that may be of assistance in carrying out the purposes specified in subparagraphs (A) and (B).

“(14) Information system.—The term ‘information system’—

“(A) has the meaning given the term in section 3502 of title 44, United States Code; and

“(B) includes industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers.

“(15) Intelligence community.—The term ‘intelligence community’ has the meaning given the term in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)).

“(16) Malicious cyber command and control.—The term ‘malicious cyber command and control’ means a method for unauthorized remote identification of, access to, or use of, an information system or information that is stored on, processed by, or transiting an information system.

“(17) Malicious reconnaissance.—The term ‘malicious reconnaissance’ a method for actively probing or passively monitoring an information system for the purpose of discerning security vulnerabilities of the information system, if such method is associated with a known or suspected cybersecurity threat.

“(18) Managed service provider.—The term ‘managed service provider’ means an entity that delivers services, such as network, application, infrastructure, or security services, via ongoing and regular support and active administration on the premises of a customer, in the data center of the entity (such as hosting), or in a third party data center.

“(19) Monitor.—The term ‘monitor’ means to acquire, identify, or scan, or to possess, information that is stored on, processed by, or transiting an information system.

“(20) National cybersecurity asset response activities.—The term ‘national cybersecurity asset response activities’ means—

“(A) furnishing cybersecurity technical assistance to entities affected by cybersecurity risks to protect assets, mitigate vulnerabilities, and reduce impacts of cyber incidents;

“(B) identifying other entities that may be at risk of an incident and assessing risk to the same or similar vulnerabilities;

“(C) assessing potential cybersecurity risks to a sector or region, including potential cascading effects, and developing courses of action to mitigate such risks;

“(D) facilitating information sharing and operational coordination with threat response; and

“(E) providing guidance on how best to utilize Federal resources and capabilities in a timely, effective manner to speed recovery from cybersecurity risks.

“(21) National security system.—The term ‘national security system’ has the meaning given the term in section 11103 of title 40, United States Code.

“(22) Ransomware attack.—The term ‘ransomware attack’—

“(A) means an incident that includes the use or threat of use of unauthorized or malicious code on an information system, or the use or threat of use of another digital mechanism such as a denial of service attack, to interrupt or disrupt the operations of an information system or compromise the confidentiality, availability, or integrity of electronic data stored on, processed by, or transiting an information system to extort a demand for a ransom payment; and

“(B) does not include any such event in which the demand for payment is—

“(i) not genuine; or

“(ii) made in good faith by an entity in response to a specific request by the owner or operator of the information system.

“(23) Sector risk management agency.—The term ‘Sector Risk Management Agency’ means a Federal department or agency, designated by law or Presidential directive, with responsibility for providing institutional knowledge and specialized expertise of a sector, as well as leading, facilitating, or supporting programs and associated activities of its designated critical infrastructure sector in the all hazards environment in coordination with the Department.

“(24) Security control.—The term ‘security control’ means the management, operational, and technical controls used to protect against an unauthorized effort to adversely affect the confidentiality, integrity, and availability of an information system or its information.

“(25) Security vulnerability.—The term ‘security vulnerability’ means any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control.

“(26) Sharing.—The term ‘sharing’ (including all conjugations thereof) means providing, receiving, and disseminating (including all conjugations of each such terms).

“(27) SLTT entity.—The term ‘SLTT entity’ means a domestic government entity that is a State government, local government, Tribal government, territorial government, or any subdivision thereof.

“(28) Supply chain compromise.—The term ‘supply chain compromise’ means an incident within the supply chain of an information system that an adversary can leverage, or does leverage, to jeopardize the confidentiality, integrity, or availability of the information system or the information the system processes, stores, or transmits, and can occur at any point during the life cycle.”

(2)
Technical and conforming amendments.— The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—
(A)
in section 320(d)(3)(C) (6 U.S.C. 195f(d)(3)(C)), by striking “ section 2201” and inserting “ section 2200”;
(B)
by amending section 2201 (6 U.S.C. 651) to read as follows:

“SEC. 2201. DEFINITION.

“In this subtitle, the term ‘Cybersecurity Advisory Committee’ means the advisory committee established under section 2219(a).”

(C)
in section 2202 (6 U.S.C. 652)—
(i)
in subsection (a)(1), by striking “ (in this subtitle referred to as the Agency)”;
(ii)
in subsection (b)(1), by striking “ a Director of Cybersecurity and Infrastructure Security (in this subtitle referred to as the ‘Director’)” and inserting “ the Director”; and
(iii)
in subsection (f)—
(I)
in paragraph (1), by inserting “ Executive” before “ Assistant Director”;
(II)
in paragraph (2), by inserting “ Executive” before “ Assistant Director”; and
(III)
in paragraph (3), by inserting “ Executive” before “ Assistant Director”;
(D)
in section 2209 (6 U.S.C. 659)—
(i)
by striking subsection (a) and inserting the following:

“(a) Definition.—The term ‘cybersecurity vulnerability’ has the meaning given the term ‘security vulnerability’ in section 2200.”

(ii)
in subsection (b), by inserting “ Executive” before “ Assistant Director for Cybersecurity”;
(iii)
in subsection (d)(1)—
(I)
in subparagraph (A)(iii), by striking “ , as that term is defined under section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4))”; and
(II)
in subparagraph (B)(ii), by striking “ information sharing and analysis organizations” and inserting “ Information Sharing and Analysis Organizations”;
(iv)
in subsection (e)(1)(E)(ii)(II), by striking “ information sharing and analysis organizations” and inserting “ Information Sharing and Analysis Organizations”;
(v)
in the second subsection (p), by striking “ (p) Coordination on Cybersecurity for SLTT Entities.—” and inserting “ (r) Coordination on Cybersecurity for SLTT Entities.—”; and
(vi)
in the second subsection (q), by striking “ (q) Report.—” and inserting “ (s) Report.—”;
(E)
in section 2210 (6 U.S.C. 660)—
(i)
in subsection (a), by striking “ section—” and all that follows and inserting “ section, the term ‘agency information system’ means an information system used or operated by an agency or by another entity on behalf of an agency.”;
(ii)
in subsection (c)—
(I)
by striking “ information sharing and analysis organizations (as defined in section 2222(5))” and inserting “ Information Sharing and Analysis Organizations”; and
(II)
by striking “ (as defined in section 2209)”; and
(iii)
in subsection (e)—
(I)
in paragraph (1)(B), by striking “ (as such term is defined in section 2209)”; and
(II)
in paragraph (3)(C), by striking “ (as such term is defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501))”;
(F)
in section 2211 (6 U.S.C. 661), by striking subsection (h);
(G)
in section 2212 (6 U.S.C. 662), by striking “ information sharing and analysis organizations (as defined in section 2222(5))” and inserting “ Information Sharing and Analysis Organizations”;
(H)
in section 2213(a) (6 U.S.C. 663(a)), by striking paragraph (4); and
(I)
in section 2216 (6 U.S.C. 665b)—
(i)
in subsection (d)(2), by striking “ information sharing and analysis organizations” and inserting “ Information Sharing and Analysis Organizations”; and
(ii)
in subsection (f), by striking “ section:” and all that follows and inserting “ section, the term ‘cyber defense operation’ means the defensive activities performed for a cybersecurity purpose.”;
(J)
in section 2218(c)(4)(A) (6 U.S.C. 665d(4)(A)), by striking “ information sharing and analysis organizations” and inserting “ Information Sharing and Analysis Organizations”;
(K)
in section 2220A (6 U.S.C. 665g)—
(i)
in subsection (a)—
(I)
by striking paragraphs (1), (2), (5), (6), and (7); and
(II)
by redesignating paragraphs (3), (4), (8), (9), (10), (11), and (12) as paragraphs (1) through (7), respectively;
(ii)
in subsection (e)(2)(B)(xiv)(II)(aa), by striking “ information sharing and analysis organization” and inserting “ Information Sharing and Analysis Organization”;
(iii)
in subsection (p), by striking “ appropriate committees of Congress” and inserting “ appropriate congressional committees”; and
(iv)
in subsection (q)(4), in the matter preceding clause (i), by striking “ appropriate committees of Congress” and inserting “ appropriate congressional committees”;
(L)
in section 2220C (6 U.S.C. 665i), by striking subsection (f) and inserting the following:

“(f) Definition.—In this section, the term ‘industrial control system’ means an information system used to monitor and/or control industrial processes such as manufacturing, product handling, production, and distribution, including supervisory control and data acquisition (SCADA) systems used to monitor and/or control geographically dispersed assets, distributed control systems (DCSs), Human-Machine Interfaces (HMIs), and programmable logic controllers that control localized processes.”

(M)
in section 2222 (6 U.S.C. 671)—
(i)
by striking paragraph (3) and inserting the following:

“(3) Critical infrastructure information.—The term ‘critical infrastructure information’ has the meaning given the term in section 2200.”

(ii)
by striking paragraphs (5) and (8); and
(iii)
by redesignating paragraphs (6) and (7) as paragraphs (5) and (6), respectively; and
(N)
in section 2240 (6 U.S.C. 681)—
(i)
by striking paragraph (2);
(ii)
by redesignating paragraphs (3) through (7) as paragraphs (2) through (6);
(iii)
in paragraph (6), as so redesignated, by striking “ section 2201” and inserting “ section 2200”;
(iv)
by striking paragraph (8), and inserting the following:

“(7) Federal entity.—The term ‘Federal entity’ has the meaning given the term in section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501).”

(v)
by striking paragraphs (9) through (12), (14), (15), and (17); and
(vi)
by redesignating paragraphs (13), (16), (18), and (19) as paragraphs (8), (9), (10), and (11), respectively.
(3)
Table of contents amendments.— The table of contents in section 1(b) of the Homeland Security Act of 2002 (Public Law 107–296; 116 Stat. 2135) is amended—
(A)
by inserting before the item relating to subtitle A of title XXII the following:

“Sec. 2200. Definitions.”;

(B)
by striking the item relating to section 2201 and insert the following:

“Sec. 2201. Definition.”; and

(C)
by moving the item relating to section 2220D to appear after the item relating to section 2220C.
(4)
Cybersecurity information sharing act of 2015 definitions.— Section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501) is amended—
(A)
by striking paragraphs (4) through (7) and inserting the following:

“(4) Cybersecurity purpose.—The term ‘cybersecurity purpose’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.

“(5) Cybersecurity threat.—The term ‘cybersecurity threat’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.

“(6) Cyber threat indicator.—The term ‘cyber threat indicator’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.

“(7) Defensive measure.—The term ‘defensive measure’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”

(B)
by striking paragraph (9) and inserting the following:

“(9) Information system.—The term ‘information system’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”

(C)
by striking paragraphs (11), (12), and (13) and inserting the following:

“(11) Malicious cyber command and control.—The term ‘malicious cyber command and control’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.

“(12) Malicious reconnaissance.—The term ‘malicious reconnaissance’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.

“(13) Monitor.—The term ‘monitor’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”

; and

(D)
by striking paragraphs (16) and (17) and inserting the following:

“(16) Security control.—The term ‘security control’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.

“(17) Security vulnerability.—The term ‘security vulnerability’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”

(c)
Correction to the Title of the Director of the Cybersecurity and Infrastructure Security Agency.— The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—
(1)
in section 523 (6 U.S.C. 3211)—
(A)
in subsection (a), in the matter preceding paragraph (1), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”; and
(B)
in subsection (c), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”;
(2)
in section 884(d)(4)(A)(ii) (6 U.S.C. 464(d)(4)(A)(ii)), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”;
(3)
in section 1801(b) (6 U.S.C. 571(b)), in the second and third sentences, by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”;
(4)
in section 2104(c)(2) (6 U.S.C. 624(c)(2)), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”;
(5)
in section 2202 (6 U.S.C. 652)—
(A)
in subsection (b)(3), by striking “ Director of Cybersecurity and Infrastructure Security of the Department” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”; and
(B)
in subsection (d), in the matter preceding paragraph (1), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”;
(6)
in section 2205, in the matter preceding paragraph (1), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”;
(7)
in section 2206, by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”; and
(8)
in section 2210(c), by striking “ Director of Cybersecurity and Infrastructure Security” and inserting “ Director of the Cybersecurity and Infrastructure Security Agency”.
(d)
Additional Technical and Conforming Amendments.—
(1)
Federal cybersecurity enhancement act of 2015.— The Federal Cybersecurity Enhancement Act of 2015 (6 U.S.C. 1521 et seq.) is amended—
(A)
in section 222(4) (6 U.S.C. 1521(4)), by striking “ section 2209” and inserting “ section 2200”; and
(B)
in section 226(a)(2) (6 U.S.C. 1524(a)(2)), by striking “ section 102” and inserting “ section 2200 of the Homeland Security Act of 2002”.
(2)
Federal power act.— Section 219A(a)(1) of the Federal Power Act (16 U.S.C. 824s–1(a)(1)) is amended by striking “ section 102 of the Cybersecurity Act of 2015 (6 U.S.C. 1501)” and inserting “ section 2200 of the Homeland Security Act of 2002”.
(3)
Infrastructure investment and jobs act.— Section 40124(a)(1) of the Infrastructure Investment and Jobs Act (42 U.S.C. 18723(a)(1)) is amended by striking “ section 102 of the Cybersecurity Act of 2015 (6 U.S.C. 1051)” and inserting “ section 2200 of the Homeland Security Act of 2002)”.
(4)
Public health service act.— Section 2811(b)(4)(D) of the Public Health Service Act (42 U.S.C. 300hh–10(b)(4)(D)) is amended by striking “ section 228(c) of the Homeland Security Act of 2002 (6 U.S.C. 149(c))” and inserting “ section 2210(b) of the Homeland Security Act of 2002 (6 U.S.C. 660(b))”.
(5)
William m. (mac) thornberry national defense authorization act of fiscal year 2021.— Section 9002 of the William M. (Mac) Thornberry National Defense Authorization Act for Fiscal Year 2021 (6 U.S.C. 652a) is amended—
(A)
in subsection (a)—
(i)
by striking paragraph (5);
(ii)
by redesignating paragraphs (6) and (7) as paragraphs (5) and (6), respectively; and
(iii)
by amending paragraph (7) to read as follows:

“(7) Sector risk management agency.—The term ‘Sector Risk Management Agency’ has the meaning given the term in section 2200 of the Homeland Security Act of 2002.”

(B)
in subsection (c)(3)(B), by striking “ given such term in section 2201(5) (6 U.S.C. 651(5))” and inserting “ given such term in section 2200”; and
(C)
in subsection (d), by striking “ section 2215 of the Homeland Security Act of 2002, as added by this section” and inserting “ section 2218 of the Homeland Security Act of 2002 (6 U.S.C. 665d)”.
(6)
National security act of 1947.— Section 113B(b)(4) of the National Security Act of 1947 (50 U.S.C. 3049a(b)(4)) is amended by striking section “ 226 of the Homeland Security Act of 2002 (6 U.S.C. 147)” and inserting “ section 2208 of the Homeland Security Act of 2002 (6 U.S.C. 658)”.
(7)
National defense authorization act for fiscal year 2020.— Section 6503(a)(3) of the National Defense Authorization Act for Fiscal Year 2020 (50 U.S.C. 3371a(a)(3)) is amended by striking “ section 102 of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501)” and inserting “ section 2200 of the Homeland Security Act of 2002”.
(8)
IoT cybersecurity improvement act of 2020.— Section 3(8) of the IoT Cybersecurity Improvement Act of 2020 (15 U.S.C. 278g-3a(8)) is amended by striking “ section 102(17) of the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501(17))” and inserting “ section 2200 of the Homeland Security Act of 2002”.
(9)
Small business act.— Section 21(a)(8)(B) of the Small Business Act (15 U.S.C. 648(a)(8)(B)) is amended by striking “ section 2209(a)” and inserting “ section 2200”.
(10)
Title 46.— Section 70101(2) of title 46, United States Code, is amended by striking “ section 227 of the Homeland Security Act of 2002 (6 U.S.C. 148)” and inserting “ section 2200 of the Homeland Security Act of 2002”.
(e)
Clarifying and Technical Amendments to the Cyber Incident Reporting for Critical Infrastructure Act of 2022.— The Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) is amended—
(1)
in section 2243(6 U.S.C. 681c), by striking subsection (c) and inserting the following:

“(c) Application of Section 2245.—Section 2245 shall apply in the same manner and to the same extent to reports and information submitted under subsections (a) and (b) as it applies to reports and information submitted under section 2242.”

; and

(2)
in section 2244(b)(2) (6 U.S.C. 681d(b)(2)), by inserting “ including that section 2245 shall apply to such information in the same manner and to the same extent to information submitted in response to requests under paragraph (1) as it applies to information submitted under section 2242”after “ section 2242”.
(f)
Rule of Construction.—
(1)
Interpretation of technical corrections.— Nothing in the amendments made by subsections (a) through (d) shall be construed to alter the authorities, responsibilities, functions, or activities of any agency (as such term is defined in section 3502 of title 44, United States Code) or officer or employee of the United States on or before the date of enactment of this Act.
(2)
Interpretation of references to definitions.— Any reference to a term defined in the Homeland Security Act of 2002 (6 U.S.C. 101 et seq.) on the day before the date of enactment of this Act that is defined in section 2200 of that Act pursuant to the amendments made under this Act shall be deemed to be a reference to that term as defined in section 2200 of the Homeland Security Act of 2002, as added by this Act.

TITLE LXXII Governmental Affairs

Subtitle A Improving Government for America’s Taxpayers

SEC. 7201. Requirement for Information Sharing Agreements.

(a)
Short Title.— This section may be cited as the “Intragovernmental Cybersecurity and Counterintelligence Information Sharing Act”.
(b)
Findings.— Congress finds the following:
(1)
The legislative branch, as a separate and equal branch of the United States Government, is a target of adversary cyber actors and intelligence services.
(2)
The legislative branch relies on the executive branch to provide timely and urgent tactical and operational information to ensure that Congress can protect the constitutional officers, personnel, and facilities of Congress and the institution of Congress more broadly.
(3)
The legislative branch currently is not receiving this information in a timely manner nor as a matter of course.
(c)
Definitions.— In this section—
(1)
the term “congressional leadership” means—
(A)
the Majority and Minority Leader of the Senate with respect to an agreement with the Sergeant at Arms and Doorkeeper of the Senate or the Secretary of the Senate; and
(B)
the Speaker and Minority Leader of the House of Representatives with respect to an agreement with the Chief Administrative Officer of the House of Representatives or the Sergeant at Arms of the House of Representatives; and
(2)
the terms “cybersecurity threat” and “security vulnerability” have the meanings given those terms in section 2200 of the Homeland Security Act of 2002, as added by section 5171 of this division.
(d)
Requirement.—
(1)
Designation.—
(A)
In general.— Not later than 30 days after the date of enactment of this Act, the President shall designate—
(i)
an individual appointed by the President, by and with the advice and consent of the Senate, to serve as a single point of contact to the legislative branch on matters related to tactical and operational cybersecurity threats and security vulnerabilities; and
(ii)
an individual appointed by the President, by and with the advice and consent of the Senate, to serve as a single point of contact to the legislative branch on matters related to tactical and operational counterintelligence.
(B)
Coordination.— The individuals designated by the President under subparagraph (A) shall coordinate with appropriate Executive agencies (as defined in section 105 of title 5, United States Code, including the Executive Office of the President) and appropriate officers in the executive branch in entering any agreement described in paragraph (2).
(2)
Information sharing agreements.—
(A)
In general.— Not later than 90 days after the date of enactment of this Act, the individuals designated by the President under paragraph (1)(A) shall enter into 1 or more information sharing agreements with—
(i)
the Sergeant at Arms and Doorkeeper of the Senate with respect to cybersecurity information sharing, subject to the approval of congressional leadership and in consultation with the chairman and the ranking minority member of the Committee on Rules and Administration of the Senate;
(ii)
the Secretary of the Senate with respect to counterintelligence information sharing, subject to the approval of congressional leadership and in consultation with the chairman and ranking minority member of the Committee on Rules and Administration of the Senate;
(iii)
the Chief Administrative Officer of the House of Representatives with respect to cybersecurity information sharing, subject to the approval of the chair of the Committee on House Administration of the House of Representatives and in consultation with the ranking minority member of the committee and congressional leadership; and
(iv)
the Sergeant at Arms of the House of Representatives with respect to counterintelligence information sharing, subject to the approval of the chair of the Committee on House Administration of the House of Representatives and in consultation with the ranking minority member of the committee and congressional leadership.
(B)
Purpose.— The agreements described in subparagraph (A) shall establish procedures for timely sharing of tactical and operational cybersecurity threat and security vulnerability information and planned or ongoing counterintelligence operations or targeted collection efforts with the legislative branch.
(3)
Implementation.— Not less frequently than semiannually during the 3-year period beginning on the date of enactment of this Act, the individuals designated by the President under paragraph (1)(A) shall meet with the officers referenced in clauses (i), (ii), (iii), and (iv) of paragraph (2)(A), the chairman and ranking minority member of the Committee on Homeland Security and Governmental Affairs of the Senate, with respect to an agreement with the Sergeant at Arms and Doorkeeper of the Senate, and the chair and ranking minority member of the Committee on Oversight and Reform of the House of Representatives, with respect to an agreement with the Chief Administrative Officer of the House of Representatives or the Sergeant at Arms of the House of Representatives, to ensure the agreements with such officers are being implemented in a manner consistent with applicable laws, including this Act.
(e)
Elements.—
(1)
In general.— The parties to an information sharing agreement under subsection (d)(2) shall jointly develop such elements of the agreement as the parties find appropriate, which—
(A)
with respect to an agreement covered by subsection (d)(2)(A)(i) or (ii), shall, at a minimum, include the applicable elements specified in paragraph (2); and
(B)
with respect to an agreement covered by subsection (d)(2)(A)(iii) or (iv), may include the applicable elements specified in paragraph (2).
(2)
Elements specified.— The elements specified in this paragraph are—
(A)
direct and timely sharing of technical indicators and contextual information on cyber threats and security vulnerabilities, and the means for such sharing;
(B)
direct and timely sharing of counterintelligence threats and vulnerabilities, including trends of counterintelligence activity, and the means for such sharing;
(C)
identification, by position, of the officials at the operational and tactical level responsible for daily management of the agreement;
(D)
the ability to seat cybersecurity personnel of the Office of the Sergeant at Arms and Doorkeeper of the Senate or the Office of the Chief Administrative Officer of the House of Representatives at cybersecurity operations centers within the executive branch; and
(E)
any other elements the parties find appropriate.

SEC. 7211. Government Accountability Office Unimplemented Priority Recommendations.

(a)
In General.— The Comptroller General of the United States shall, as part of the Comptroller General’s annual reporting to committees of Congress—
(1)
consolidate Matters for Congressional Consideration from the Government Accountability Office in one report organized by policy topic that includes the amount of time such Matters have been unimplemented and submit such report to congressional leadership and the oversight committees of each House;
(2)
with respect to the annual letters sent by the Comptroller General to individual agency heads and relevant congressional committees on the status of unimplemented priority recommendations, identify any additional congressional oversight actions that can help agencies implement such priority recommendations and address any underlying issues relating to such implementation;
(3)
make publicly available the information described in paragraphs (1) and (2); and
(4)
publish any known costs of unimplemented priority recommendations, if applicable.
(b)
Rule of Construction.— Nothing in this section shall be construed to require reporting relating to unimplemented priority recommendations or any other report, recommendation, information, or item relating to any element of the intelligence community, as defined in section 3 of the National Security Act of 1947 (50 U.S.C. 3003).

Subtitle B Advancing American AI Act

SEC. 7221. Short Title.

This subtitle may be cited as the “Advancing American AI Act”.

SEC. 7222. Purposes.

The purposes of this subtitle are to—
(1)
encourage agency artificial intelligence-related programs and initiatives that enhance the competitiveness of the United States and foster an approach to artificial intelligence that builds on the strengths of the United States in innovation and entrepreneurialism;
(2)
enhance the ability of the Federal Government to translate research advances into artificial intelligence applications to modernize systems and assist agency leaders in fulfilling their missions;
(3)
promote adoption of modernized business practices and advanced technologies across the Federal Government that align with the values of the United States, including the protection of privacy, civil rights, and civil liberties; and
(4)
test and harness applied artificial intelligence to enhance mission effectiveness, agency program integrity, and business practice efficiency.

SEC. 7223. Definitions.

In this subtitle:
(1)
Agency.— The term “agency” has the meaning given the term in section 3502 of title 44, United States Code.
(2)
Appropriate congressional committees.— The term “appropriate congressional committees” means—
(A)
the Committee on Homeland Security and Governmental Affairs of the Senate;
(B)
the Committee on Oversight and Reform of the House of Representatives; and
(C)
the Committee on Homeland Security of the House of Representatives.
(3)
Artificial intelligence.— The term “artificial intelligence” has the meaning given the term in section 238(g) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (10 U.S.C. 2358 note).
(4)
Artificial intelligence system.— The term “artificial intelligence system”—
(A)
means any data system, software, application, tool, or utility that operates in whole or in part using dynamic or static machine learning algorithms or other forms of artificial intelligence, whether—
(i)
the data system, software, application, tool, or utility is established primarily for the purpose of researching, developing, or implementing artificial intelligence technology; or
(ii)
artificial intelligence capability is integrated into another system or agency business process, operational activity, or technology system; and
(B)
does not include any common commercial product within which artificial intelligence is embedded, such as a word processor or map navigation system.
(5)
Department.— The term “Department” means the Department of Homeland Security.
(6)
Director.— The term “Director” means the Director of the Office of Management and Budget.

SEC. 7224. Principles and Policies for Use of Artificial Intelligence in Government.

(a)
Guidance.— The Director shall, when developing the guidance required under section 104(a) of the AI in Government Act of 2020 (title I of division U of Public Law 116–260), consider—
(1)
the considerations and recommended practices identified by the National Security Commission on Artificial Intelligence in the report entitled “Key Considerations for the Responsible Development and Fielding of AI”, as updated in April 2021;
(2)
the principles articulated in Executive Order 13960 (85 Fed. Reg. 78939; relating to promoting the use of trustworthy artificial intelligence in Government); and
(3)
the input of—
(A)
the Administrator of General Services;
(B)
relevant interagency councils, such as the Federal Privacy Council, the Chief Financial Officers Council, the Chief Information Officers Council, and the Chief Data Officers Council;
(C)
other governmental and nongovernmental privacy, civil rights, and civil liberties experts;
(D)
academia;
(E)
industry technology and data science experts; and
(F)
any other individual or entity the Director determines to be appropriate.
(b)
Department Policies and Processes for Procurement and Use of Artificial Intelligence-enabled Systems.— Not later than 180 days after the date of enactment of this Act—
(1)
the Secretary of Homeland Security, with the participation of the Chief Procurement Officer, the Chief Information Officer, the Chief Privacy Officer, and the Officer for Civil Rights and Civil Liberties of the Department and any other person determined to be relevant by the Secretary of Homeland Security, shall issue policies and procedures for the Department related to—
(A)
the acquisition and use of artificial intelligence; and
(B)
considerations for the risks and impacts related to artificial intelligence-enabled systems, including associated data of machine learning systems, to ensure that full consideration is given to—
(i)
the privacy, civil rights, and civil liberties impacts of artificial intelligence-enabled systems; and
(ii)
security against misuse, degradation, or rending inoperable of artificial intelligence-enabled systems; and
(2)
the Chief Privacy Officer and the Officer for Civil Rights and Civil Liberties of the Department shall report to Congress on any additional staffing or funding resources that may be required to carry out the requirements of this subsection.
(c)
Inspector General.— Not later than 180 days after the date of enactment of this Act, the Inspector General of the Department shall identify any training and investments needed to enable employees of the Office of the Inspector General to continually advance their understanding of—
(1)
artificial intelligence systems;
(2)
best practices for governance, oversight, and audits of the use of artificial intelligence systems; and
(3)
how the Office of the Inspector General is using artificial intelligence to enhance audit and investigative capabilities, including actions to—
(A)
ensure the integrity of audit and investigative results; and
(B)
guard against bias in the selection and conduct of audits and investigations.
(d)
Artificial Intelligence Hygiene and Protection of Government Information, Privacy, Civil Rights, and Civil Liberties.—
(1)
Establishment.— Not later than 1 year after the date of enactment of this Act, the Director, in consultation with a working group consisting of members selected by the Director from appropriate interagency councils, shall develop an initial means by which to—
(A)
ensure that contracts for the acquisition of an artificial intelligence system or service—
(i)
align with the guidance issued to the head of each agency under section 104(a) of the AI in Government Act of 2020 (title I of division U of Public Law 116–260);
(ii)
address protection of privacy, civil rights, and civil liberties;
(iii)
address the ownership and security of data and other information created, used, processed, stored, maintained, disseminated, disclosed, or disposed of by a contractor or subcontractor on behalf of the Federal Government; and
(iv)
include considerations for securing the training data, algorithms, and other components of any artificial intelligence system against misuse, unauthorized alteration, degradation, or rendering inoperable; and
(B)
address any other issue or concern determined to be relevant by the Director to ensure appropriate use and protection of privacy and Government data and other information.
(2)
Consultation.— In developing the considerations under paragraph (1)(A)(iv), the Director shall consult with the Secretary of Homeland Security, the Secretary of Energy, the Director of the National Institute of Standards and Technology, and the Director of National Intelligence.
(3)
Review.— The Director—
(A)
should continuously update the means developed under paragraph (1); and
(B)
not later than 2 years after the date of enactment of this Act and not less frequently than every 2 years thereafter, shall update the means developed under paragraph (1).
(4)
Briefing.— The Director shall brief the appropriate congressional committees—
(A)
not later than 90 days after the date of enactment of this Act and thereafter on a quarterly basis until the Director first implements the means developed under paragraph (1); and
(B)
annually thereafter on the implementation of this subsection.
(5)
Sunset.— This subsection shall cease to be effective on the date that is 5 years after the date of enactment of this Act.

SEC. 7225. Agency Inventories and Artificial Intelligence Use Cases.

(a)
Inventory.— Not later than 60 days after the date of enactment of this Act, and continuously thereafter for a period of 5 years, the Director, in consultation with the Chief Information Officers Council, the Chief Data Officers Council, and other interagency bodies as determined to be appropriate by the Director, shall require the head of each agency to—
(1)
prepare and maintain an inventory of the artificial intelligence use cases of the agency, including current and planned uses;
(2)
share agency inventories with other agencies, to the extent practicable and consistent with applicable law and policy, including those concerning protection of privacy and of sensitive law enforcement, national security, and other protected information; and
(3)
make agency inventories available to the public, in a manner determined by the Director, and to the extent practicable and in accordance with applicable law and policy, including those concerning the protection of privacy and of sensitive law enforcement, national security, and other protected information.
(b)
Central Inventory.— The Director is encouraged to designate a host entity and ensure the creation and maintenance of an online public directory to—
(1)
make agency artificial intelligence use case information available to the public and those wishing to do business with the Federal Government; and
(2)
identify common use cases across agencies.
(c)
Sharing.— The sharing of agency inventories described in subsection (a)(2) may be coordinated through the Chief Information Officers Council, the Chief Data Officers Council, the Chief Financial Officers Council, the Chief Acquisition Officers Council, or other interagency bodies to improve interagency coordination and information sharing for common use cases.
(d)
Department of Defense.— Nothing in this section shall apply to the Department of Defense.

SEC. 7226. Rapid Pilot, Deployment and Scale of Applied Artificial Intelligence Capabilities to Demonstrate Modernization Activities Related to Use Cases.

(a)
Identification of Use Cases.— Not later than 270 days after the date of enactment of this Act, the Director, in consultation with the Chief Information Officers Council, the Chief Data Officers Council, the Chief Financial Officers Council, and other interagency bodies as determined to be appropriate by the Director, shall identify 4 new use cases for the application of artificial intelligence-enabled systems to support interagency or intra-agency modernization initiatives that require linking multiple siloed internal and external data sources, consistent with applicable laws and policies, including those relating to the protection of privacy and of sensitive law enforcement, national security, and other protected information.
(b)
Pilot Program.—
(1)
Purposes.— The purposes of the pilot program under this subsection include—
(A)
to enable agencies to operate across organizational boundaries, coordinating between existing established programs and silos to improve delivery of the agency mission;
(B)
to demonstrate the circumstances under which artificial intelligence can be used to modernize or assist in modernizing legacy agency systems; and
(C)
to leverage commercially available artificial intelligence technologies that—
(i)
operate in secure cloud environments that can deploy rapidly without the need to replace existing systems; and
(ii)
do not require extensive staff or training to build.
(2)
Deployment and pilot.— Not later than 1 year after the date of enactment of this Act, the Director, in coordination with the heads of relevant agencies and Federal entities, including the Administrator of General Services, the Bureau of Fiscal Service of the Department of the Treasury, the Council of the Inspectors General on Integrity and Efficiency, and the Pandemic Response Accountability Committee, and other officials as the Director determines to be appropriate, shall ensure the initiation of the piloting of the 4 new artificial intelligence use case applications identified under subsection (a), leveraging commercially available technologies and systems to demonstrate scalable artificial intelligence-enabled capabilities to support the use cases identified under subsection (a).
(3)
Risk evaluation and mitigation plan.— In carrying out paragraph (2), the Director shall require the heads of agencies to—
(A)
evaluate risks in utilizing artificial intelligence systems; and
(B)
develop a risk mitigation plan to address those risks, including consideration of—
(i)
the artificial intelligence system not performing as expected or as designed;
(ii)
the quality and relevancy of the data resources used in the training of the algorithms used in an artificial intelligence system;
(iii)
the processes for training and testing, evaluating, validating, and modifying an artificial intelligence system; and
(iv)
the vulnerability of a utilized artificial intelligence system to unauthorized manipulation or misuse, including the use of data resources that substantially differ from the training data.
(4)
Prioritization.— In carrying out paragraph (2), the Director shall prioritize modernization projects that—
(A)
would benefit from commercially available privacy-preserving techniques, such as use of differential privacy, federated learning, and secure multiparty computing; and
(B)
otherwise take into account considerations of civil rights and civil liberties.
(5)
Privacy protections.— In carrying out paragraph (2), the Director shall require the heads of agencies to use privacy-preserving techniques when feasible, such as differential privacy, federated learning, and secure multiparty computing, to mitigate any risks to individual privacy or national security created by a project or data linkage.
(6)
Use case modernization application areas.— Use case modernization application areas described in paragraph (2) shall include not less than 1 from each of the following categories:
(A)
Applied artificial intelligence to drive agency productivity efficiencies in predictive supply chain and logistics, such as—
(i)
predictive food demand and optimized supply;
(ii)
predictive medical supplies and equipment demand and optimized supply; or
(iii)
predictive logistics to accelerate disaster preparedness, response, and recovery.
(B)
Applied artificial intelligence to accelerate agency investment return and address mission-oriented challenges, such as—
(i)
applied artificial intelligence portfolio management for agencies;
(ii)
workforce development and upskilling;
(iii)
redundant and laborious analyses;
(iv)
determining compliance with Government requirements, such as with Federal financial management and grants management, including implementation of chapter 64 of subtitle V of title 31, United States Code;
(v)
addressing fraud, waste, and abuse in agency programs and mitigating improper payments; or
(vi)
outcomes measurement to measure economic and social benefits.
(7)
Requirements.— Not later than 3 years after the date of enactment of this Act, the Director, in coordination with the heads of relevant agencies and other officials as the Director determines to be appropriate, shall establish an artificial intelligence capability within each of the 4 use case pilots under this subsection that—
(A)
solves data access and usability issues with automated technology and eliminates or minimizes the need for manual data cleansing and harmonization efforts;
(B)
continuously and automatically ingests data and updates domain models in near real-time to help identify new patterns and predict trends, to the extent possible, to help agency personnel to make better decisions and take faster actions;
(C)
organizes data for meaningful data visualization and analysis so the Government has predictive transparency for situational awareness to improve use case outcomes;
(D)
is rapidly configurable to support multiple applications and automatically adapts to dynamic conditions and evolving use case requirements, to the extent possible;
(E)
enables knowledge transfer and collaboration across agencies; and
(F)
preserves intellectual property rights to the data and output for benefit of the Federal Government and agencies and protects sensitive personally identifiable information.
(c)
Briefing.— Not earlier than 270 days but not later than 1 year after the date of enactment of this Act, and annually thereafter for 4 years, the Director shall brief the appropriate congressional committees on the activities carried out under this section and results of those activities.
(d)
Sunset.— The section shall cease to be effective on the date that is 5 years after the date of enactment of this Act.

SEC. 7227. Enabling Entrepreneurs and Agency Missions.

(a)
Innovative Commercial Items.— Section 880 of the National Defense Authorization Act for Fiscal Year 2017 (41 U.S.C. 3301 note) is amended—
(1)
in subsection (c), by striking $10,000,000” and inserting “ $25,000,000”;
(2)
by amending subsection (f) to read as follows:

“(f) Definitions.—In this section—

“(1) the term ‘commercial product’—

“(A) has the meaning given the term ‘commercial item’ in section 2.101 of the Federal Acquisition Regulation; and

“(B) includes a commercial product or a commercial service, as defined in sections 103 and 103a, respectively, of title 41, United States Code; and

“(2) the term ‘innovative’ means—

“(A) any new technology, process, or method, including research and development; or

“(B) any new application of an existing technology, process, or method.”

; and

(3)
in subsection (g), by striking “ 2022” and insert “ 2027”.
(b)
DHS Other Transaction Authority.— Section 831 of the Homeland Security Act of 2002 (6 U.S.C. 391) is amended—
(1)
in subsection (a)—
(A)
in the matter preceding paragraph (1), by striking “ September 30, 2017” and inserting “ September 30, 2024”; and
(B)
by amending paragraph (2) to read as follows:

“(2) Prototype projects.—The Secretary—

“(A) may, under the authority of paragraph (1), carry out prototype projects under section 4022 of title 10, United States Code; and

“(B) in applying the authorities of such section 4022, the Secretary shall perform the functions of the Secretary of Defense as prescribed in such section.”

(2)
in subsection (c)(1), by striking “ September 30, 2017” and inserting “ September 30, 2024”; and
(3)
in subsection (d), by striking “ section 845(e)” and all that follows and inserting “ section 4022(e) of title 10, United States Code.”.
(c)
Commercial Off the Shelf Supply Chain Risk Management Tools.—
(1)
In general.— The General Services Administration is encouraged to pilot commercial off the shelf supply chain risk management tools to improve the ability of the Federal Government to characterize, monitor, predict, and respond to specific supply chain threats and vulnerabilities that could inhibit future Federal acquisition operations.
(2)
Consultation.— In carrying out this subsection, the General Services Administration shall consult with the Federal Acquisition Security Council established under section 1322 of title 41, United States Code.

SEC. 7228. Intelligence Community Exception.

Nothing in this subtitle shall apply to any element of the intelligence community, as defined in section 3 of the National Security Act of 1947 (50 U.S.C. 3003).

Subtitle C Strategic EV Management

SEC. 7231. Short Title.

This subtitle may be cited as the “Strategic EV Management Act of 2022”.

SEC. 7232. Definitions.

In this subtitle:
(1)
Administrator.— The term “Administrator” means the Administrator of General Services.
(2)
Agency.— The term “agency” has the meaning given the term in section 551 of title 5, United States Code.
(3)
Appropriate congressional committees.— The term “appropriate congressional committees” means—
(A)
the Committee on Homeland Security and Governmental Affairs of the Senate;
(B)
the Committee on Oversight and Reform of the House of Representatives;
(C)
the Committee on Environment and Public Works of the Senate;
(D)
the Committee on Energy and Natural Resources of the Senate;
(E)
the Committee on Energy and Commerce of the House of Representatives;
(F)
the Committee on Appropriations of the Senate; and
(G)
the Committee on Appropriations of the House of Representatives.
(4)
Director.— The term “Director” means the Director of the Office of Management and Budget.

SEC. 7233. Strategic Guidance.

(a)
In General.— Not later than 2 years after the date of enactment of this Act, the Administrator, in consultation with the Director, shall coordinate with the heads of agencies to develop a comprehensive, strategic plan for Federal electric vehicle fleet battery management.
(b)
Contents.— The strategic plan required under subsection (a) shall—
(1)
maximize both cost and environmental efficiencies; and
(2)
incorporate—
(A)
guidelines for optimal charging practices that will maximize battery longevity and prevent premature degradation;
(B)
guidelines for reusing and recycling the batteries of retired vehicles;
(C)
guidelines for disposing electric vehicle batteries that cannot be reused or recycled; and
(D)
any other considerations determined appropriate by the Administrator and Director.
(c)
Modification.— The Administrator, in consultation with the Director, may periodically update the strategic plan required under subsection (a) as the Administrator and Director may determine necessary based on new information relating to electric vehicle batteries that becomes available.
(d)
Consultation.— In developing the strategic plan required under subsection (a) the Administrator, in consultation with the Director, may consult with appropriate entities, including—
(1)
the Secretary of Energy;
(2)
the Administrator of the Environmental Protection Agency;
(3)
the Chair of the Council on Environmental Quality;
(4)
scientists who are studying electric vehicle batteries and reuse and recycling solutions;
(5)
laboratories, companies, colleges, universities, or start-ups engaged in battery use, reuse, and recycling research;
(6)
industries interested in electric vehicle battery reuse and recycling;
(7)
electric vehicle equipment manufacturers and recyclers; and
(8)
any other relevant entities, as determined by the Administrator and Director.
(e)
Report.—
(1)
In general.— Not later than 3 years after the date of enactment of this Act, the Administrator and the Director shall submit to the appropriate congressional committees a report that describes the strategic plan required under subsection (a).
(2)
Briefing.— Not later than 4 years after the date of enactment of this Act, the Administrator and the Director shall brief the appropriate congressional committees on the implementation of the strategic plan required under subsection (a) across agencies.

SEC. 7234. Study of Federal Fleet Vehicles.

Not later than 2 years after the date of enactment of this Act, the Comptroller General of the United States shall submit to Congress a report on how the costs and benefits of operating and maintaining electric vehicles in the Federal fleet compare to the costs and benefits of operating and maintaining internal combustion engine vehicles.

Subtitle D Congressionally Mandated Reports

SEC. 7241. Short Title.

This subtitle may be cited as the “Access to Congressionally Mandated Reports Act”.

SEC. 7242. Definitions.

In this subtitle:
(1)
Congressional leadership.— The term “congressional leadership” means the Speaker, majority leader, and minority leader of the House of Representatives and the majority leader and minority leader of the Senate.
(2)
Congressionally mandated report.—
(A)
In general.— The term “congressionally mandated report” means a report of a Federal agency that is required by statute to be submitted to either House of Congress or any committee of Congress or subcommittee thereof.
(B)
Exclusions.—
(i)
Patriotic and national organizations.— The term “congressionally mandated report” does not include a report required under part B of subtitle II of title 36, United States Code.
(ii)
Inspectors general.— The term “congressionally mandated report” does not include a report by an office of an inspector general.
(iii)
National security exception.— The term “congressionally mandated report” does not include a report that is required to be submitted to one or more of the following committees:
(I)
The Select Committee on Intelligence, the Committee on Armed Services, the Committee on Appropriations, or the Committee on Foreign Relations of the Senate.
(II)
The Permanent Select Committee on Intelligence, the Committee on Armed Services, the Committee on Appropriations, or the Committee on Foreign Affairs of the House of Representatives.
(3)
Director.— The term “Director” means the Director of the Government Publishing Office.
(4)
Federal agency.— The term “Federal agency” has the meaning given the term “federal agency” under section 102 of title 40, United States Code, but does not include the Government Accountability Office or an element of the intelligence community.
(5)
Intelligence community.— The term “intelligence community” has the meaning given that term in section 3 of the National Security Act of 1947 (50 U.S.C. 3003).
(6)
Reports online portal.— The term “reports online portal” means the online portal established under section 5243(a).

SEC. 7243. Establishment of Online Portal for Congressionally Mandated Reports.

(a)
Requirement To Establish Online Portal.—
(1)
In general.— Not later than 1 year after the date of enactment of this Act, the Director shall establish and maintain an online portal accessible by the public that allows the public to obtain electronic copies of congressionally mandated reports in one place.
(2)
Existing functionality.— To the extent possible, the Director shall meet the requirements under paragraph (1) by using existing online portals and functionality under the authority of the Director in consultation with the Director of National Intelligence.
(3)
Consultation.— In carrying out this subtitle, the Director shall consult with congressional leadership, the Clerk of the House of Representatives, the Secretary of the Senate, and the Librarian of Congress regarding the requirements for and maintenance of congressionally mandated reports on the reports online portal.
(b)
Content and Function.— The Director shall ensure that the reports online portal includes the following:
(1)
Subject to subsection (c), with respect to each congressionally mandated report, each of the following:
(A)
A citation to the statute requiring the report.
(B)
An electronic copy of the report, including any transmittal letter associated with the report, that—
(i)
is based on an underlying open data standard that is maintained by a standards organization;
(ii)
allows the full text of the report to be searchable; and
(iii)
is not encumbered by any restrictions that would impede the reuse or searchability of the report.
(C)
The ability to retrieve a report, to the extent practicable, through searches based on each, and any combination, of the following:
(i)
The title of the report.
(ii)
The reporting Federal agency.
(iii)
The date of publication.
(iv)
Each congressional committee or subcommittee receiving the report, if applicable.
(v)
The statute requiring the report.
(vi)
Subject tags.
(vii)
A unique alphanumeric identifier for the report that is consistent across report editions.
(viii)
The serial number, Superintendent of Documents number, or other identification number for the report, if applicable.
(ix)
Key words.
(x)
Full text search.
(xi)
Any other relevant information specified by the Director.
(D)
The date on which the report was required to be submitted, and on which the report was submitted, to the reports online portal.
(E)
To the extent practicable, a permanent means of accessing the report electronically.
(2)
A means for bulk download of all congressionally mandated reports.
(3)
A means for downloading individual reports as the result of a search.
(4)
An electronic means for the head of each Federal agency to submit to the reports online portal each congressionally mandated report of the agency, as required by sections 5244 and 5246.
(5)
In tabular form, a list of all congressionally mandated reports that can be searched, sorted, and downloaded by—
(A)
reports submitted within the required time;
(B)
reports submitted after the date on which such reports were required to be submitted; and
(C)
to the extent practicable, reports not submitted.
(c)
Noncompliance by Federal Agencies.—
(1)
Reports not submitted.— If a Federal agency does not submit a congressionally mandated report to the Director, the Director shall to the extent practicable—
(A)
include on the reports online portal—
(i)
the information required under clauses (i), (ii), (iv), and (v) of subsection (b)(1)(C); and
(ii)
the date on which the report was required to be submitted; and
(B)
include the congressionally mandated report on the list described in subsection (b)(5)(C).
(2)
Reports not in open format.— If a Federal agency submits a congressionally mandated report that does not meet the criteria described in subsection (b)(1)(B), the Director shall still include the congressionally mandated report on the reports online portal.
(d)
Deadline.— The Director shall ensure that information required to be published on the reports online portal under this subtitle with respect to a congressionally mandated report or information required under subsection (c) of this section is published—
(1)
not later than 30 days after the information is received from the Federal agency involved; or
(2)
in the case of information required under subsection (c), not later than 30 days after the deadline under this subtitle for the Federal agency involved to submit information with respect to the congressionally mandated report involved.
(e)
Exception for Certain Reports.—
(1)
Exception described.— A congressionally mandated report which is required by statute to be submitted to a committee of Congress or a subcommittee thereof, including any transmittal letter associated with the report, shall not be submitted to or published on the reports online portal if the chair of a committee or subcommittee to which the report is submitted notifies the Director in writing that the report is to be withheld from submission and publication under this subtitle.
(2)
Notice on portal.— If a report is withheld from submission to or publication on the reports online portal under paragraph (1), the Director shall post on the portal—
(A)
a statement that the report is withheld at the request of a committee or subcommittee involved; and
(B)
the written notification provided by the chair of the committee or subcommittee specified in paragraph (1).
(f)
Free Access.— The Director may not charge a fee, require registration, or impose any other limitation in exchange for access to the reports online portal.
(g)
Upgrade Capability.— The reports online portal shall be enhanced and updated as necessary to carry out the purposes of this subtitle.
(h)
Submission to Congress.— The submission of a congressionally mandated report to the reports online portal pursuant to this subtitle shall not be construed to satisfy any requirement to submit the congressionally mandated report to Congress, or a committee or subcommittee thereof.

SEC. 7244. Federal Agency Responsibilities.

(a)
Submission of Electronic Copies of Reports.— Not earlier than 30 days or later than 60 days after the date on which a congressionally mandated report is submitted to either House of Congress or to any committee of Congress or subcommittee thereof, the head of the Federal agency submitting the congressionally mandated report shall submit to the Director the information required under subparagraphs (A) through (D) of section 5243(b)(1) with respect to the congressionally mandated report. Notwithstanding section 5246, nothing in this subtitle shall relieve a Federal agency of any other requirement to publish the congressionally mandated report on the online portal of the Federal agency or otherwise submit the congressionally mandated report to Congress or specific committees of Congress, or subcommittees thereof.
(b)
Guidance.— Not later than 180 days after the date of enactment of this Act, the Director of the Office of Management and Budget, in consultation with the Director, shall issue guidance to agencies on the implementation of this subtitle.
(c)
Structure of Submitted Report Data.— The head of each Federal agency shall ensure that each congressionally mandated report submitted to the Director complies with the guidance on the implementation of this subtitle issued by the Director of the Office of Management and Budget under subsection (b).
(d)
Point of Contact.— The head of each Federal agency shall designate a point of contact for congressionally mandated reports.
(e)
Requirement for Submission.— The Director shall not publish any report through the reports online portal that is received from anyone other than the head of the applicable Federal agency, or an officer or employee of the Federal agency specifically designated by the head of the Federal agency.

SEC. 7245. Changing or Removing Reports.

(a)
Limitation on Authority To Change or Remove Reports.— Except as provided in subsection (b), the head of the Federal agency concerned may change or remove a congressionally mandated report submitted to be published on the reports online portal only if—
(1)
the head of the Federal agency consults with each committee of Congress or subcommittee thereof to which the report is required to be submitted (or, in the case of a report which is not required to be submitted to a particular committee of Congress or subcommittee thereof, to each committee with jurisdiction over the agency, as determined by the head of the agency in consultation with the Speaker of the House of Representatives and the President pro tempore of the Senate) prior to changing or removing the report; and
(2)
a joint resolution is enacted to authorize the change in or removal of the report.
(b)
Exceptions.— Notwithstanding subsection (a), the head of the Federal agency concerned—
(1)
may make technical changes to a report submitted to or published on the reports online portal;
(2)
may remove a report from the reports online portal if the report was submitted to or published on the reports online portal in error; and
(3)
may withhold information, records, or reports from publication on the reports online portal in accordance with section 5246.

SEC. 7246. Withholding of Information.

(a)
In General.— Nothing in this subtitle shall be construed to—
(1)
require the disclosure of information, records, or reports that are exempt from public disclosure under section 552 of title 5, United States Code, or that are required to be withheld under section 552a of title 5, United States Code; or
(2)
impose any affirmative duty on the Director to review congressionally mandated reports submitted for publication to the reports online portal for the purpose of identifying and redacting such information or records.
(b)
Withholding of Information.—
(1)
In general.— Consistent with subsection (a)(1), the head of a Federal agency may withhold from the Director, and from publication on the reports online portal, any information, records, or reports that are exempt from public disclosure under section 552 of title 5, United States Code, or that are required to be withheld under section 552a of title 5, United States Code.
(2)
National security.— Nothing in this subtitle shall be construed to require the publication, on the reports online portal or otherwise, of any report containing information that is classified, the public release of which could have a harmful effect on national security, or that is otherwise prohibited.
(3)
Law enforcement sensitive.— Nothing in this subtitle shall be construed to require the publication on the reports online portal or otherwise of any congressionally mandated report—
(A)
containing information that is law enforcement sensitive; or
(B)
that describe information security policies, procedures, or activities of the executive branch.
(c)
Responsibility for Withholding of Information.— In publishing congressionally mandated reports to the reports online portal in accordance with this subtitle, the head of each Federal agency shall be responsible for withholding information pursuant to the requirements of this section.

SEC. 7247. Implementation.

(a)
Reports Submitted to Congress.—
(1)
In general.— This subtitle shall apply with respect to any congressionally mandated report which—
(A)
is required by statute to be submitted to the House of Representatives, or the Speaker thereof, or the Senate, or the President or President Pro Tempore thereof, at any time on or after the date of the enactment of this Act; or
(B)
is included by the Clerk of the House of Representatives or the Secretary of the Senate (as the case may be) on the list of reports received by the House of Representatives or the Senate (as the case may be) at any time on or after the date of the enactment of this Act.
(2)
Transition rule for previously submitted reports.— To the extent practicable, the Director shall ensure that any congressionally mandated report described in paragraph (1) which was required to be submitted to Congress by a statute enacted before the date of the enactment of this Act is published on the reports online portal under this subtitle.
(b)
Reports Submitted to Committees.— In the case of congressionally mandated reports which are required by statute to be submitted to a committee of Congress or a subcommittee thereof, this subtitle shall apply with respect to—
(1)
any such report which is first required to be submitted by a statute which is enacted on or after the date of the enactment of this Act; and
(2)
to the maximum extent practical, any congressionally mandated report which was required to be submitted by a statute enacted before the date of enactment of this Act unless—
(A)
the chair of the committee, or subcommittee thereof, to which the report was required to be submitted notifies the Director in writing that the report is to be withheld from publication; and
(B)
the Director publishes the notification on the reports online portal.
(c)
Access for Congressional Leadership.— Notwithstanding any provision of this subtitle or any other provision of law, congressional leadership shall have access to any congressionally mandated report.

SEC. 7248. Determination of Budgetary Effects.

The budgetary effects of this subtitle, for the purpose of complying with the Statutory Pay-As-You-Go-Act of 2010, shall be determined by reference to the latest statement titled “Budgetary Effects of PAYGO Legislation” for this subtitle, submitted for printing in the Congressional Record by the Chairman of the Senate Budget Committee, provided that such statement has been submitted prior to the vote on passage.

TITLE LXXIII Transportation and Infrastructure Matters

Subtitle A Global Catastrophic Risk Management Act of 2022

SEC. 7301. Short Title.

This subtitle may be cited as the “Global Catastrophic Risk Management Act of 2022”.

SEC. 7302. Definitions.

In this subtitle:
(1)
Administrator.— The term “Administrator” means the Administrator of the Federal Emergency Management Agency.
(2)
Basic need.— The term “basic need”—
(A)
means any good, service, or activity necessary to protect the health, safety, and general welfare of the civilian population of the United States; and
(B)
includes—
(i)
food;
(ii)
water;
(iii)
shelter;
(iv)
basic communication services;
(v)
basic sanitation and health services; and
(vi)
public safety.
(3)
Catastrophic incident.— The term “catastrophic incident”—
(A)
means any natural or man-made disaster that results in extraordinary levels of casualties or damage, mass evacuations, or disruption severely affecting the population, infrastructure, environment, economy, national morale, or government functions in an area; and
(B)
may include an incident—
(i)
with a sustained national impact over a prolonged period of time;
(ii)
that may rapidly exceed resources available to State and local government and private sector authorities in the impacted area; or
(iii)
that may significantly interrupt governmental operations and emergency services to such an extent that national security could be threatened.
(4)
Critical infrastructure.— The term “critical infrastructure” has the meaning given such term in section 1016(e) of the Critical Infrastructure Protection Act of 2001 (42 U.S.C. 5195c(e)).
(5)
Existential risk.— The term “existential risk” means the potential for an outcome that would result in human extinction.
(6)
Global catastrophic risk.— The term “global catastrophic risk” means the risk of events or incidents consequential enough to significantly harm or set back human civilization at the global scale.
(7)
Global catastrophic and existential threats.— The term “global catastrophic and existential threats” means threats that with varying likelihood may produce consequences severe enough to result in systemic failure or destruction of critical infrastructure or significant harm to human civilization. Examples of global catastrophic and existential threats include severe global pandemics, nuclear war, asteroid and comet impacts, supervolcanoes, sudden and severe changes to the climate, and intentional or accidental threats arising from the use and development of emerging technologies.
(8)
Indian tribal government.— The term “Indian Tribal government” has the meaning given the term “Indian tribal government” in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5122).
(9)
Local government; state.— The terms “local government” and “State” have the meanings given such terms in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5122).
(10)
National exercise program.— The term “national exercise program” means activities carried out to test and evaluate the national preparedness goal and related plans and strategies as described in section 648(b) of the Post-Katrina Emergency Management Reform Act of 2006 (6 U.S.C. 748(b)).
(11)
Secretary.— The term “Secretary” means the Secretary of Homeland Security.

SEC. 7303. Assessment of Global Catastrophic Risk.

(a)
In General.— The Secretary and the Administrator shall coordinate an assessment of global catastrophic risk.
(b)
Coordination.— When coordinating the assessment under subsection (a), the Secretary and the Administrator shall coordinate with senior designees of—
(1)
the Assistant to the President for National Security Affairs;
(2)
the Director of the Office of Science and Technology Policy;
(3)
the Secretary of State and the Under Secretary of State for Arms Control and International Security;
(4)
the Attorney General and the Director of the Federal Bureau of Investigation;
(5)
the Secretary of Energy, the Under Secretary of Energy for Nuclear Security, and the Director of Science;
(6)
the Secretary of Health and Human Services, the Assistant Secretary for Preparedness and Response, and the Assistant Secretary of Global Affairs;
(7)
the Secretary of Commerce, the Under Secretary of Commerce for Oceans and Atmosphere, and the Under Secretary of Commerce for Standards and Technology;
(8)
the Secretary of the Interior and the Director of the United States Geological Survey;
(9)
the Administrator of the Environmental Protection Agency and the Assistant Administrator for Water;
(10)
the Administrator of the National Aeronautics and Space Administration;
(11)
the Director of the National Science Foundation;
(12)
the Secretary of the Treasury;
(13)
the Secretary of Defense, the Assistant Secretary of the Army for Civil Works, and the Chief of Engineers and Commanding General of the Army Corps of Engineers;
(14)
the Chairman of the Joint Chiefs of Staff;
(15)
the Administrator of the United States Agency for International Development;
(16)
the Secretary of Transportation; and
(17)
other stakeholders the Secretary and the Administrator determine appropriate.

SEC. 7304. Report Required.

(a)
In General.— Not later than 1 year after the date of enactment of this Act, and every 10 years thereafter, the Secretary, in coordination with the Administrator, shall submit to the Committee on Homeland Security and Governmental Affairs and the Committee on Armed Services of the Senate and the Committee on Transportation and Infrastructure and the Committee on Armed Services of the House of Representatives a report containing a detailed assessment, based on the input and coordination required under section 7303, of global catastrophic and existential risk.
(b)
Matters Covered.— Each report required under subsection (a) shall include—
(1)
expert estimates of cumulative global catastrophic and existential risk in the next 30 years, including separate estimates for the likelihood of occurrence and potential consequences;
(2)
expert-informed analyses of the risk of the most concerning specific global catastrophic and existential threats, including separate estimates, where reasonably feasible and credible, of each threat for its likelihood of occurrence and its potential consequences, as well as associated uncertainties;
(3)
a comprehensive list of potential catastrophic or existential threats, including even those that may have very low likelihood;
(4)
technical assessments and lay explanations of the analyzed global catastrophic and existential risks, including their qualitative character and key factors affecting their likelihood of occurrence and potential consequences;
(5)
an explanation of any factors that limit the ability of the Secretary to assess the risk both cumulatively and for particular threats, and how those limitations may be overcome through future research or with additional resources, programs, or authorities;
(6)
a forecast of if and why global catastrophic and existential risk is likely to increase or decrease significantly in the next 10 years, both qualitatively and quantitatively, as well as a description of associated uncertainties;
(7)
proposals for how the Federal Government may more adequately assess global catastrophic and existential risk on an ongoing basis in future years;
(8)
recommendations for legislative actions, as appropriate, to support the evaluation and assessment of global catastrophic and existential risk; and
(9)
other matters deemed appropriate by the Secretary, in coordination with the Administrator, and based on the input and coordination required under section 7303.
(c)
Consultation Requirement.— In producing the report required under subsection (a), the Secretary shall—
(1)
regularly consult with experts on severe global pandemics, nuclear war, asteroid and comet impacts, supervolcanoes, sudden and severe changes to the climate, and intentional or accidental threats arising from the use and development of emerging technologies; and
(2)
share information gained through the consultation required under paragraph (1) with relevant Federal partners listed in section 7303(b).

SEC. 7305. Enhanced Catastrophic Incident Annex.

(a)
In General.— The Secretary, in coordination with the Administrator and the Federal partners listed in section 7303(b), shall supplement each Federal Interagency Operational Plan to include an annex containing a strategy to ensure the health, safety, and general welfare of the civilian population affected by catastrophic incidents by—
(1)
providing for the basic needs of the civilian population of the United States that is impacted by catastrophic incidents in the United States;
(2)
coordinating response efforts with State, local, and Indian Tribal governments, the private sector, and nonprofit relief organizations;
(3)
promoting personal and local readiness and non-reliance on government relief during periods of heightened tension or after catastrophic incidents; and
(4)
developing international partnerships with allied nations for the provision of relief services and goods.
(b)
Elements of the Strategy.— The strategy required under subsection (a) shall include a description of—
(1)
actions the Federal Government should take to ensure the basic needs of the civilian population of the United States in a catastrophic incident are met;
(2)
how the Federal Government should coordinate with non-Federal entities to multiply resources and enhance relief capabilities, including—
(A)
State and local governments;
(B)
Indian Tribal governments;
(C)
State disaster relief agencies;
(D)
State and local disaster relief managers;
(E)
State National Guards;
(F)
law enforcement and first response entities; and
(G)
nonprofit relief services;
(3)
actions the Federal Government should take to enhance individual resiliency to the effects of a catastrophic incident, which actions shall include—
(A)
readiness alerts to the public during periods of elevated threat;
(B)
efforts to enhance domestic supply and availability of critical goods and basic necessities; and
(C)
information campaigns to ensure the public is aware of response plans and services that will be activated when necessary;
(4)
efforts the Federal Government should undertake and agreements the Federal Government should seek with international allies to enhance the readiness of the United States to provide for the general welfare;
(5)
how the strategy will be implemented should multiple levels of critical infrastructure be destroyed or taken offline entirely for an extended period of time; and
(6)
the authorities the Federal Government should implicate in responding to a catastrophic incident.
(c)
Assumptions.— In designing the strategy under subsection (a), the Secretary, in coordination with the Administrator and the Federal partners listed in section 7303(b), shall account for certain factors to make the strategy operationally viable, including the assumption that—
(1)
multiple levels of critical infrastructure have been taken offline or destroyed by catastrophic incidents or the effects of catastrophic incidents;
(2)
impacted sectors may include—
(A)
the transportation sector;
(B)
the communication sector;
(C)
the energy sector;
(D)
the healthcare and public health sector; and
(E)
the water and wastewater sector;
(3)
State, local, Indian Tribal, and territorial governments have been equally affected or made largely inoperable by catastrophic incidents or the effects of catastrophic incidents;
(4)
the emergency has exceeded the response capabilities of State, local, and Indian Tribal governments under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) and other relevant disaster response laws; and
(5)
the United States military is sufficiently engaged in armed or cyber conflict with State or non-State adversaries, or is otherwise unable to augment domestic response capabilities in a significant manner due to a catastrophic incident.

SEC. 7306. Validation of the Strategy Through an Exercise.

Not later than 1 year after the addition of the annex required under section 7305, the Administrator shall lead an exercise as part of the national exercise program to test and enhance the operationalization of the strategy required under section 7305.

SEC. 7307. Recommendations.

(a)
In General.— The Secretary, in coordination with the Administrator and the Federal partners listed in section 7303(b) of this title, shall provide recommendations to Congress for—
(1)
actions that should be taken to prepare the United States to implement the strategy required under section 7305, increase readiness, and address preparedness gaps for responding to the impacts of catastrophic incidents on citizens of the United States; and
(2)
additional authorities that should be considered for Federal agencies to more effectively implement the strategy required under section 7305.
(b)
Inclusion in Reports.— The Secretary may include the recommendations required under subsection (a) in a report submitted under section 7308.

SEC. 7308. Reporting Requirements.

Not later than 1 year after the date on which the Administrator leads the exercise under section 7306, the Secretary, in coordination with the Administrator, shall submit to Congress a report that includes—
(1)
a description of the efforts of the Secretary and the Administrator to develop and update the strategy required under section 7305; and
(2)
an after-action report following the conduct of the exercise described in section 7306.

SEC. 7309. Rules of Construction.

(a)
Administrator.— Nothing in this subtitle shall be construed to supersede the civilian emergency management authority of the Administrator under the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.) or the Post Katrina Emergency Management Reform Act (6 U.S.C. 701 et seq.).
(b)
Secretary.— Nothing in this subtitle shall be construed as providing new authority to the Secretary, except to coordinate and facilitate the development of the assessments and reports required pursuant to this subtitle.

Subtitle B Technological Hazards Preparedness and Training

SEC. 7311. Short Title.

This subtitle may be cited as the “Technological Hazards Preparedness and Training Act of 2022”.

SEC. 7312. Definitions.

In this subtitle:
(1)
Administrator.— The term “Administrator” means the Administrator of the Federal Emergency Management Agency.
(2)
Indian tribal government.— The term “Indian Tribal government” has the meaning given the term “Indian tribal government” in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5122).
(3)
Local government; state.— The terms “local government” and “State” have the meanings given such terms in section 102 of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5122).
(4)
Technological hazard and related emerging threat.— The term “technological hazard and related emerging threat”—
(A)
means a hazard that involves materials created by humans that pose a unique hazard to the general public and environment and which may result from—
(i)
an accident;
(ii)
an emergency caused by another hazard; or
(iii)
intentional use of the hazardous materials; and
(B)
includes a chemical, radiological, biological, and nuclear hazard.

SEC. 7313. Assistance and Training for Communities with Technological Hazards and Related Emerging Threats.

(a)
In General.— The Administrator shall maintain the capacity to provide States, local, and Indian Tribal governments with technological hazards and related emerging threats technical assistance, training, and other preparedness programming to build community resilience to technological hazards and related emerging threats.
(b)
Authorities.— The Administrator shall carry out subsection (a) in accordance with—
(1)
the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5121 et seq.);
(2)
section 1236 of the Disaster Recovery Reform Act of 2018 (42 U.S.C. 5196g); and
(3)
the Post-Katrina Emergency Management Reform Act of 2006 (Public Law 109–295; 120 Stat. 1394).
(c)
Assessment and Notification.— In carrying out subsection (a), the Administrator shall—
(1)
use any available and appropriate multi-hazard risk assessment and mapping tools and capabilities to identify the communities that have the highest risk of and vulnerability to a technological hazard in each State; and
(2)
ensure each State and Indian Tribal government is aware of—
(A)
the communities identified under paragraph (1); and
(B)
the availability of programming under this section for—
(i)
technological hazards and related emerging threats preparedness; and
(ii)
building community capability.
(d)
Report.— Not later than 1 year after the date of enactment of this Act, and annually thereafter, the Administrator shall submit to the Committee on Homeland Security and Governmental Affairs of the Senate, the Committee on Appropriations of the Senate, the Committee on Energy and Natural Resources of the Senate, the Committee on Health, Education, Labor, and Pensions of the Senate, the Committee on Energy and Commerce of the House of Representatives, the Committee on Homeland Security of the House of Representatives, the Committee on Appropriations of the House of Representatives, and the Committee on Transportation and Infrastructure of the House of Representatives a report relating to—
(1)
actions taken to implement this section; and
(2)
technological hazards and related emerging threats preparedness programming provided under this section during the 1-year period preceding the date of submission of the report.
(e)
Consultation.— The Secretary of Homeland Security may seek continuing input relating to technological hazards and related emerging threats preparedness needs by consulting State, Tribal, territorial, and local emergency services organizations and private sector stakeholders.
(f)
Coordination.— The Secretary of Homeland Security shall coordinate with the Secretary of Energy relating to technological hazard preparedness and training for a hazard that could result from activities or facilities authorized or licensed by the Department of Energy.
(g)
Non-duplication of Effort.— In carrying out activities under subsection (a), the Administrator shall ensure that such activities do not unnecessarily duplicate efforts of other Federal departments or agencies, including programs within the Department of Health and Human Services.

SEC. 7314. Authorization of Appropriations.

There are authorized to be appropriated to carry out this subtitle $20,000,000 for each of fiscal years 2023 through 2024.

SEC. 7315. Savings Provision.

Nothing in this subtitle shall diminish or divert resources from—
(1)
the full completion of federally-led chemical surety material storage missions or chemical demilitarization missions that are underway as of the date of enactment of this Act; or
(2)
any transitional activities or other community assistance incidental to the completion of the missions described in paragraph (1).

Subtitle C Other Matters

SEC. 7321. Crisis Counseling Assistance and Training.

(a)
Federal Emergency Assistance.— Section 502(a)(6) of the Robert T. Stafford Disaster Relief and Emergency Assistance Act (42 U.S.C. 5192(a)(6)) is amended by inserting “ and section 416” after “ section 408”.
(b)
Applicability.— The amendment made by subsection (a) shall only apply to amounts appropriated on or after the date of enactment of this Act.