Federal
Cybersecurity Vulnerability Identification and Notification Act of 2020
Source: Congress.gov ·
4,908 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
Calendar No. 500
116TH CONGRESS
2D SESSION
S. 3045
[Report No. 116–242]
To amend the Homeland Security Act of 2002 to protect United States
critical infrastructure by ensuring that the Cybersecurity and Infrastruc-
ture Security Agency has the legal tools it needs to notify private and
public sector entities put at risk by cybersecurity vulnerabilities in the
networks and systems that control critical assets of the United States.
IN THE SENATE OF THE UNITED STATES
DECEMBER 12, 2019
Mr. JOHNSON (for himself, Ms. HASSAN, Mr. WYDEN, and Mr. KING) intro-
duced the following bill; which was read twice and referred to the Com-
mittee on Homeland Security and Governmental Affairs
JULY 29, 2020
Reported by Mr. JOHNSON, with an amendment
[Strike out all after the enacting clause and insert the part printed in italic]
A BILL
To amend the Homeland Security Act of 2002 to protect
United States critical infrastructure by ensuring that
the Cybersecurity and Infrastructure Security Agency
has the legal tools it needs to notify private and public
sector entities put at risk by cybersecurity vulnerabilities
in the networks and systems that control critical assets
of the United States.
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6652
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
2
•S 3045 RS
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Cybersecurity Vulner-
4
ability Identification and Notification Act of 2019’’.
5
SEC. 2. SUBPOENA AUTHORITY.
6
(a) IN GENERAL.—Section 2209 of the Homeland
7
Security Act of 2002 (6 U.S.C. 659) is amended—
8
(1) in subsection (a)—
9
(A) by redesignating paragraph (6) as
10
paragraph (7); and
11
(B) by inserting after paragraph (5) the
12
following:
13
‘‘(6) the term ‘security vulnerability’ has the
14
meaning given that term in section 102(17) of the
15
Cybersecurity Information Sharing Act of 2015 (6
16
U.S.C. 1501(17));’’;
17
(2) in subsection (c)—
18
(A) in paragraph (10), by striking ‘‘and’’
19
at the end;
20
(B) in paragraph (11), by striking the pe-
21
riod at the end and inserting ‘‘; and’’; and
22
(C) by adding at the end the following:
23
‘‘(12) detecting, identifying, and receiving infor-
24
mation about security vulnerabilities relating to crit-
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
3
•S 3045 RS
ical infrastructure in the information systems and
1
devices of Federal and non-Federal entities for a cy-
2
bersecurity purpose, as defined in section 102 of the
3
Cybersecurity Information Sharing Act of 2015 (6
4
U.S.C. 1501).’’; and
5
(3) by adding at the end the following:
6
‘‘(n) SUBPOENA AUTHORITY.—
7
‘‘(1) DEFINITION.—In this subsection, the term
8
‘enterprise device or system’—
9
‘‘(A) means a device or system commonly
10
used to perform industrial, commercial, sci-
11
entific, or governmental functions or processes
12
that relate to critical infrastructure, including
13
operational and industrial control systems, dis-
14
tributed control systems, and programmable
15
logic controllers; and
16
‘‘(B) does not include personal devices and
17
systems, such as consumer mobile devices, home
18
computers, residential wireless routers, or resi-
19
dential internet-enabled consumer devices.
20
‘‘(2) AUTHORITY.—
21
‘‘(A) IN GENERAL.—If the Director identi-
22
fies a system connected to the internet with a
23
specific security vulnerability and has reason to
24
believe that the security vulnerability relates to
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
4
•S 3045 RS
critical infrastructure and affects an enterprise
1
device or system owned or operated by a Fed-
2
eral or non-Federal entity, and the Director is
3
unable to identify the entity at risk, the Direc-
4
tor may issue a subpoena for the production of
5
information necessary to identify and notify the
6
entity at risk, in order to carry out a function
7
authorized under subsection (c)(12).
8
‘‘(B) LIMIT
ON
INFORMATION.—A sub-
9
poena issued under the authority under sub-
10
paragraph (A) may only seek information in the
11
categories set forth in subparagraphs (A), (B),
12
(D), and (E) of section 2703(c)(2) of title 18,
13
United States Code.
14
‘‘(C) LIABILITY
PROTECTIONS
FOR
DIS-
15
CLOSING PROVIDERS.—The provisions of section
16
2703(e) of title 18, United States Code, shall
17
apply to any subpoena issued under the author-
18
ity under subparagraph (A).
19
‘‘(3) COORDINATION.—
20
‘‘(A) IN GENERAL.—If the Director decides
21
to exercise the subpoena authority under this
22
subsection, and in the interest of avoiding inter-
23
ference with ongoing law enforcement investiga-
24
tions, the Director shall coordinate the issuance
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
5
•S 3045 RS
of any such subpoena with the Department of
1
Justice, including the Federal Bureau of Inves-
2
tigation, pursuant to inter-agency procedures
3
which the Director, in coordination with the At-
4
torney General, shall develop not later than 60
5
days after the date of enactment of this sub-
6
section.
7
‘‘(B) CONTENTS.—The inter-agency proce-
8
dures developed under this paragraph shall pro-
9
vide that a subpoena issued by the Director
10
under this subsection shall be—
11
‘‘(i) issued in order to carry out a
12
function described in subsection (c)(12);
13
and
14
‘‘(ii) subject to the limitations under
15
this subsection.
16
‘‘(4) NONCOMPLIANCE.—If any person, part-
17
nership, corporation, association, or entity fails to
18
comply with any duly served subpoena issued under
19
this subsection, the Director may request that the
20
Attorney General seek enforcement of the subpoena
21
in any judicial district in which such person, part-
22
nership, corporation, association, or entity resides, is
23
found, or transacts business.
24
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
6
•S 3045 RS
‘‘(5) NOTICE.—Not later than 7 days after the
1
date on which the Director receives information ob-
2
tained through a subpoena issued under this sub-
3
section, the Director shall notify the entity at risk
4
identified by information obtained under the sub-
5
poena regarding the subpoena and the identified vul-
6
nerability.
7
‘‘(6) AUTHENTICATION.—Any subpoena issued
8
by the Director under this subsection shall be au-
9
thenticated by the electronic signature of an author-
10
ized representative of the Agency or other com-
11
parable symbol or process identifying the Agency as
12
the source of the subpoena.
13
‘‘(7) PROCEDURES.—Not later than 90 days
14
after the date of enactment of this subsection, the
15
Director shall establish internal procedures and as-
16
sociated training, applicable to employees and oper-
17
ations of the Agency, regarding subpoenas issued
18
under this subsection, which shall address—
19
‘‘(A) the protection of and restriction on
20
dissemination of nonpublic information obtained
21
through a subpoena issued under this sub-
22
section, including a requirement that the Agen-
23
cy shall not disseminate nonpublic information
24
obtained through a subpoena issued under this
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
7
•S 3045 RS
subsection that identifies the party that is sub-
1
ject to the subpoena or the entity at risk identi-
2
fied by information obtained, unless—
3
‘‘(i) the party or entity consents; or
4
‘‘(ii) the Agency identifies or is noti-
5
fied of a cybersecurity incident involving
6
the party or entity, which relates to the
7
vulnerability which led to the issuance of
8
the subpoena;
9
‘‘(B) the restriction on the use of informa-
10
tion obtained through the subpoena for a cyber-
11
security purpose, as defined in section 102 of
12
the Cybersecurity Information Sharing Act of
13
2015 (6 U.S.C. 1501);
14
‘‘(C) the retention and destruction of non-
15
public information obtained through a subpoena
16
issued under this subsection, including—
17
‘‘(i) immediate destruction of informa-
18
tion obtained through the subpoena that
19
the Director determines is unrelated to
20
critical infrastructure; and
21
‘‘(ii)
destruction
of
any
personally
22
identifiable information not later than 6
23
months after the date on which the Direc-
24
tor receives information obtained through
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
8
•S 3045 RS
the subpoena, unless otherwise agreed to
1
by the individual identified by the sub-
2
poena respondent;
3
‘‘(D) the processes for providing notice to
4
each party that is subject to the subpoena and
5
each entity at risk identified by information ob-
6
tained pursuant to a subpoena issued under
7
this subsection; and
8
‘‘(E) the processes and criteria for con-
9
ducting critical infrastructure security risk as-
10
sessments to determine whether a subpoena is
11
necessary prior to being issued under this sub-
12
section.
13
‘‘(8) REVIEW OF PROCEDURES.—Not later than
14
1 year after the date of enactment of this sub-
15
section, the Privacy Officer of the Agency shall—
16
‘‘(A) review the procedures developed by
17
the Director under paragraph (7) to ensure
18
that—
19
‘‘(i) the procedures are consistent with
20
fair information practices; and
21
‘‘(ii) the operations of the Agency
22
comply with the procedures; and
23
‘‘(B) notify the Committee on Homeland
24
Security and Governmental Affairs of the Sen-
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
9
•S 3045 RS
ate and the Committee on Homeland Security
1
of the House of Representatives of the results
2
of the review.
3
‘‘(9)
PUBLICATION
OF
INFORMATION.—Not
4
later than 120 days after establishing the internal
5
procedures under paragraph (7), the Director shall
6
make publicly available information regarding the
7
subpoena process under this subsection, including
8
regarding—
9
‘‘(A) the purpose for subpoenas issued
10
under this subsection;
11
‘‘(B) the subpoena process;
12
‘‘(C) the criteria for the critical infrastruc-
13
ture security risk assessment conducted prior to
14
issuing a subpoena;
15
‘‘(D) policies and procedures on retention
16
and sharing of data obtained by subpoena;
17
‘‘(E) guidelines on how entities contacted
18
by the Director may respond to notice of a sub-
19
poena; and
20
‘‘(F) the procedures and policies of the
21
Agency developed under paragraph (7).
22
‘‘(10) ANNUAL REPORTS.—The Director shall
23
annually submit to the Committee on Homeland Se-
24
curity and Governmental Affairs of the Senate and
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
10
•S 3045 RS
the Committee on Homeland Security of the House
1
of Representatives a report (which may include a
2
classified annex but with the presumption of declas-
3
sification) on the use of subpoenas under this sub-
4
section by the Director, which shall include—
5
‘‘(A) a discussion of—
6
‘‘(i) the effectiveness of the use of
7
subpoenas to mitigate critical infrastruc-
8
ture security vulnerabilities;
9
‘‘(ii) the critical infrastructure secu-
10
rity risk assessment process conducted for
11
subpoenas issued under this subsection;
12
‘‘(iii) the number of subpoenas issued
13
under this subsection by the Director dur-
14
ing the preceding year;
15
‘‘(iv) to the extent practicable, the
16
number of vulnerable enterprise devices or
17
systems mitigated under this subsection by
18
the Agency during the preceding year; and
19
‘‘(v) the number of entities notified by
20
the Director under this subsection, and
21
their response, during the previous year;
22
and
23
‘‘(B) for each subpoena issued under this
24
subsection—
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6401
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
11
•S 3045 RS
‘‘(i) the source of the security vulner-
1
ability detected, identified, or received by
2
the Director;
3
‘‘(ii) the steps taken to identify the
4
entity at risk prior to issuing the sub-
5
poena; and
6
‘‘(iii) a description of the outcome of
7
the subpoena, including discussion on the
8
resolution or mitigation of the critical in-
9
frastructure security vulnerability.
10
‘‘(11)
PUBLICATION
OF
THE
ANNUAL
RE-
11
PORTS.—The Director shall make a version of the
12
annual report required by paragraph (10) publicly
13
available, which shall, at a minimum, include the
14
findings described in clause (iii), (iv) and (v) of sub-
15
paragraph (A).’’.
16
SECTION 1. SHORT TITLE.
17
This Act may be cited as the ‘‘Cybersecurity Vulner-
18
ability Identification and Notification Act of 2020’’.
19
SEC. 2. SUBPOENA AUTHORITY.
20
(a) IN GENERAL.—Section 2209 of the Homeland Se-
21
curity Act of 2002 (6 U.S.C. 659) is amended—
22
(1) in subsection (a)—
23
(A) in paragraph (5), by striking ‘‘and’’ at
24
the end;
25
VerDate Sep 11 2014
23:26 Jul 29, 2020
Jkt 099200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6203
E:\BILLS\S3045.RS
S3045
pamtmann on DSKBC07HB2PROD with BILLS
12
•S 3045 RS
(B) by redesignating paragraph (6) as
1
paragraph (7); and
2
(C) by inserting after paragraph (5) the fol-
3
lowing:
4
‘‘(6) the term ‘security vulnerability’ has the
5
meaning given that term in section 102(17) of the Cy-
6
bersecurity Information Sharing Act of 2015 (6
7
U.S.C. 1501(17)); and’’;
8
(2) in subsection (c)—
9
(A) in paragraph (10), by striking ‘‘and’’
10
at the end;
11
(B) in paragraph (11), by striking the pe-
12
riod at the end and inserting ‘‘; and’’; and
13
(C) by adding at the end the following:
14
‘‘(12) detecting, identifying, and receiving infor-
15
mation about security vulnerabilities relating to crit-
16
ical infrastructure in the information systems and de-
17
vices of Federal and non-Federal entities for a cyber-
18
security purpose, as defined in section 102 of the Cy-
19
bersecurity Information Sharing Act of 2015 (6
20
U.S.C. 1501).’’; and
21
(3) by adding at the end the following:
22
‘‘(o) SUBPOENA AUTHORITY.—
23
‘‘(1) DEFINITION.—In this subsection, the term
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.