Federal
State and Local Cybersecurity Improvement Act
Source: Congress.gov ·
8,492 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
IIB
117TH CONGRESS
1ST SESSION H. R. 3138
IN THE SENATE OF THE UNITED STATES
JULY 21, 2021
Received; read twice and referred to the Committee on Homeland Security and
Governmental Affairs
AN ACT
To amend the Homeland Security Act of 2002 to authorize
a grant program relating to the cybersecurity of State
and local governments, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
2
HR 3138 RFS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘State and Local Cyber-
2
security Improvement Act’’.
3
SEC. 2. STATE AND LOCAL CYBERSECURITY GRANT PRO-
4
GRAM.
5
(a) IN GENERAL.—Subtitle A of title XXII of the
6
Homeland Security Act of 2002 (6 U.S.C. 651 et seq.)
7
is amended by adding at the end the following new sec-
8
tions:
9
‘‘SEC. 2220A. STATE AND LOCAL CYBERSECURITY GRANT
10
PROGRAM.
11
‘‘(a) DEFINITIONS.—In this section:
12
‘‘(1) CYBER
THREAT
INDICATOR.—The term
13
‘cyber threat indicator’ has the meaning given the
14
term in section 102 of the Cybersecurity Act of 2015
15
(6 U.S.C. 1501).
16
‘‘(2) CYBERSECURITY PLAN.—The term ‘Cyber-
17
security Plan’ means a plan submitted by an eligible
18
entity under subsection (e)(1).
19
‘‘(3) ELIGIBLE ENTITY.—The term ‘eligible en-
20
tity’ means—
21
‘‘(A) a State; or
22
‘‘(B) an Indian tribe that, not later than
23
120 days after the date of the enactment of this
24
section or not later than 120 days before the
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
3
HR 3138 RFS
start of any fiscal year in which a grant under
1
this section is awarded—
2
‘‘(i) notifies the Secretary that the In-
3
dian tribe intends to develop a Cybersecu-
4
rity Plan; and
5
‘‘(ii) agrees to forfeit any distribution
6
under subsection (n)(2).
7
‘‘(4) INCIDENT.—The term ‘incident’ has the
8
meaning given the term in section 2209.
9
‘‘(5) INDIAN TRIBE; TRIBAL ORGANIZATION.—
10
The term ‘Indian tribe’ or ‘Tribal organization’ has
11
the meaning given that term in section 4(e) of the
12
of the Indian Self-Determination and Education As-
13
sistance Act (25 U.S.C. 5304(e)).
14
‘‘(6) INFORMATION SHARING AND ANALYSIS OR-
15
GANIZATION.—The term ‘information sharing and
16
analysis organization’ has the meaning given the
17
term in section 2222.
18
‘‘(7) INFORMATION SYSTEM.—The term ‘infor-
19
mation system’ has the meaning given the term in
20
section 102 of the Cybersecurity Act of 2015 (6
21
U.S.C. 1501).
22
‘‘(8) ONLINE SERVICE.—The term ‘online serv-
23
ice’ means any internet-facing service, including a
24
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
4
HR 3138 RFS
website, email, virtual private network, or custom
1
application.
2
‘‘(9)
RANSOMWARE
INCIDENT.—The
term
3
‘ransomware incident’ means an incident that actu-
4
ally or imminently jeopardizes, without lawful au-
5
thority, the integrity, confidentiality, or availability
6
of information on an information system, or actually
7
or imminently jeopardizes, without lawful authority,
8
an information system for the purpose of coercing
9
the information system’s owner, operator, or another
10
person.
11
‘‘(10) STATE
AND
LOCAL
CYBERSECURITY
12
GRANT PROGRAM.—The term ‘State and Local Cy-
13
bersecurity Grant Program’ means the program es-
14
tablished under subsection (b).
15
‘‘(11) STATE AND LOCAL CYBERSECURITY RE-
16
SILIENCE COMMITTEE.—The term ‘State and Local
17
Cybersecurity Resilience Committee’ means the com-
18
mittee established under subsection (o)(1).
19
‘‘(b) ESTABLISHMENT.—
20
‘‘(1) IN
GENERAL.—The Secretary, acting
21
through the Director, shall establish a program, to
22
be known as the ‘the State and Local Cybersecurity
23
Grant Program’, to award grants to eligible entities
24
to address cybersecurity risks and cybersecurity
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
5
HR 3138 RFS
threats to information systems of State, local, or
1
Tribal organizations.
2
‘‘(2) APPLICATION.—An eligible entity seeking
3
a grant under the State and Local Cybersecurity
4
Grant Program shall submit to the Secretary an ap-
5
plication at such time, in such manner, and con-
6
taining such information as the Secretary may re-
7
quire.
8
‘‘(c) BASELINE REQUIREMENTS.—An eligible entity
9
or multistate group that receives a grant under this sec-
10
tion shall use the grant in compliance with—
11
‘‘(1)(A) the Cybersecurity Plan of the eligible
12
entity or the Cybersecurity Plans of the eligible enti-
13
ties that comprise the multistate group; and
14
‘‘(B) the Homeland Security Strategy to Im-
15
prove the Cybersecurity of State, Local, Tribal, and
16
Territorial Governments developed under section
17
2210(e)(1); or
18
‘‘(2) activities carried out under paragraphs
19
(3), (4), and (5) of subsection (h).
20
‘‘(d) ADMINISTRATION.—The State and Local Cyber-
21
security Grant Program shall be administered in the same
22
office of the Department that administers grants made
23
under sections 2003 and 2004.
24
‘‘(e) CYBERSECURITY PLANS.—
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
6
HR 3138 RFS
‘‘(1) IN GENERAL.—An eligible entity applying
1
for a grant under this section shall submit to the
2
Secretary a Cybersecurity Plan for approval.
3
‘‘(2) REQUIRED ELEMENTS.—A Cybersecurity
4
Plan of an eligible entity shall—
5
‘‘(A) incorporate, to the extent practicable,
6
any existing plans of the eligible entity to pro-
7
tect against cybersecurity risks and cybersecu-
8
rity threats to information systems of State,
9
local, or Tribal organizations;
10
‘‘(B) describe, to the extent practicable,
11
how the eligible entity will—
12
‘‘(i) manage, monitor, and track infor-
13
mation systems, applications, and user ac-
14
counts owned or operated by or on behalf
15
of the eligible entity or by local or Tribal
16
organizations within the jurisdiction of the
17
eligible entity and the information tech-
18
nology deployed on those information sys-
19
tems, including legacy information systems
20
and information technology that are no
21
longer supported by the manufacturer of
22
the systems or technology;
23
‘‘(ii) monitor, audit, and track activity
24
between information systems, applications,
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
7
HR 3138 RFS
and user accounts owned or operated by or
1
on behalf of the eligible entity or by local
2
or Tribal organizations within the jurisdic-
3
tion of the eligible entity and between
4
those information systems and information
5
systems not owned or operated by the eligi-
6
ble entity or by local or Tribal organiza-
7
tions within the jurisdiction of the eligible
8
entity;
9
‘‘(iii) enhance the preparation, re-
10
sponse, and resilience of information sys-
11
tems, applications, and user accounts
12
owned or operated by or on behalf of the
13
eligible entity or local or Tribal organiza-
14
tions against cybersecurity risks and cyber-
15
security threats;
16
‘‘(iv) implement a process of contin-
17
uous cybersecurity vulnerability assess-
18
ments and threat mitigation practices
19
prioritized by degree of risk to address cy-
20
bersecurity risks and cybersecurity threats
21
on information systems of the eligible enti-
22
ty or local or Tribal organizations;
23
‘‘(v) ensure that State, local, and
24
Tribal organizations that own or operate
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
8
HR 3138 RFS
information systems that are located with-
1
in the jurisdiction of the eligible entity—
2
‘‘(I) adopt best practices and
3
methodologies to enhance cybersecu-
4
rity, such as the practices set forth in
5
the cybersecurity framework developed
6
by, and the cyber supply chain risk
7
management best practices identified
8
by, the National Institute of Stand-
9
ards and Technology; and
10
‘‘(II) utilize knowledge bases of
11
adversary tools and tactics to assess
12
risk;
13
‘‘(vi) promote the delivery of safe, rec-
14
ognizable, and trustworthy online services
15
by State, local, and Tribal organizations,
16
including through the use of the .gov inter-
17
net domain;
18
‘‘(vii) ensure continuity of operations
19
of the eligible entity and local, and Tribal
20
organizations in the event of a cybersecu-
21
rity incident (including a ransomware inci-
22
dent), including by conducting exercises to
23
practice responding to such an incident;
24
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
9
HR 3138 RFS
‘‘(viii) use the National Initiative for
1
Cybersecurity
Education
Cybersecurity
2
Workforce Framework developed by the
3
National Institute of Standards and Tech-
4
nology to identify and mitigate any gaps in
5
the cybersecurity workforces of State,
6
local, or Tribal organizations, enhance re-
7
cruitment and retention efforts for such
8
workforces, and bolster the knowledge,
9
skills, and abilities of State, local, and
10
Tribal organization personnel to address
11
cybersecurity
risks
and
cybersecurity
12
threats, such as through cybersecurity hy-
13
giene training;
14
‘‘(ix) ensure continuity of communica-
15
tions and data networks within the juris-
16
diction of the eligible entity between the el-
17
igible entity and local and Tribal organiza-
18
tions that own or operate information sys-
19
tems within the jurisdiction of the eligible
20
entity in the event of an incident involving
21
such communications or data networks
22
within the jurisdiction of the eligible entity;
23
‘‘(x) assess and mitigate, to the great-
24
est degree possible, cybersecurity risks and
25
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
10
HR 3138 RFS
cybersecurity threats related to critical in-
1
frastructure and key resources, the deg-
2
radation of which may impact the perform-
3
ance of information systems within the ju-
4
risdiction of the eligible entity;
5
‘‘(xi) enhance capabilities to share
6
cyber threat indicators and related infor-
7
mation between the eligible entity and local
8
and Tribal organizations that own or oper-
9
ate information systems within the juris-
10
diction of the eligible entity, including by
11
expanding existing information sharing
12
agreements with the Department;
13
‘‘(xii) enhance the capability of the el-
14
igible entity to share cyber threat indictors
15
and related information with the Depart-
16
ment;
17
‘‘(xiii) leverage cybersecurity services
18
offered by the Department;
19
‘‘(xiv) develop and coordinate strate-
20
gies to address cybersecurity risks and cy-
21
bersecurity threats to information systems
22
of the eligible entity in consultation with—
23
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
11
HR 3138 RFS
‘‘(I) local and Tribal organiza-
1
tions within the jurisdiction of the eli-
2
gible entity; and
3
‘‘(II) as applicable—
4
‘‘(aa) States that neighbor
5
the jurisdiction of the eligible en-
6
tity or, as appropriate, members
7
of an information sharing and
8
analysis organization; and
9
‘‘(bb) countries that neigh-
10
bor the jurisdiction of the eligible
11
entity; and
12
‘‘(xv) implement an information tech-
13
nology and operational technology mod-
14
ernization cybersecurity review process
15
that ensures alignment between informa-
16
tion technology and operational technology
17
cybersecurity objectives;
18
‘‘(C) describe, to the extent practicable, the
19
individual responsibilities of the eligible entity
20
and local and Tribal organizations within the
21
jurisdiction of the eligible entity in imple-
22
menting the plan;
23
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
12
HR 3138 RFS
‘‘(D) outline, to the extent practicable, the
1
necessary resources and a timeline for imple-
2
menting the plan; and
3
‘‘(E) describe how the eligible entity will
4
measure progress towards implementing the
5
plan.
6
‘‘(3) DISCRETIONARY ELEMENTS.—A Cyberse-
7
curity Plan of an eligible entity may include a de-
8
scription of—
9
‘‘(A) cooperative programs developed by
10
groups of local and Tribal organizations within
11
the jurisdiction of the eligible entity to address
12
cybersecurity risks and cybersecurity threats;
13
and
14
‘‘(B) programs provided by the eligible en-
15
tity to support local and Tribal organizations
16
and owners and operators of critical infrastruc-
17
ture to address cybersecurity risks and cyberse-
18
curity threats.
19
‘‘(4) MANAGEMENT OF FUNDS.—An eligible en-
20
tity applying for a grant under this section shall
21
agree to designate the Chief Information Officer, the
22
Chief Information Security Officer, or an equivalent
23
official of the eligible entity as the primary official
24
VerDate Sep 11 2014
02:19 Jul 22, 2021
Jkt 019200
PO 00000
Frm 00012
Fmt 6652
Sfmt 6201
E:\BILLS\H3138.RFS
H3138
kjohnson on DSK79L0C42PROD with BILLS
13
HR 3138 RFS
for the management and allocation of funds awarded
1
under this section.
2
‘‘(f) MULTISTATE GRANTS.—
3
‘‘(1) IN
GENERAL.—The Secretary, acting
4
through the Director, may award grants under this
5
section to a group of two or more eligible entities to
6
support multistate efforts to address cybersecurity
7
risks and cybersecurity threats to information sys-
8
tems within the jurisdictions of the eligible entities.
9
‘‘(2)
SATISFACTION
OF
OTHER
REQUIRE-
10
MENTS.—In order to be eligible for a multistate
11
grant under this subsection, each eligible entity that
12
comprises a multistate group shall submit to the
13
Secretary—
14
‘‘(A) a Cybersecurity Plan for approval in
15
accordance with subsection (i); and
16
‘‘(B) a plan for establishing a cybersecu-
17
rity planning committee under subsection (g).
18
‘‘(3) APPLICATION.—
19
‘‘(A) IN
GENERAL.—A multistate group
20
applying for a multistate grant under para-
21
graph (1) sh
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.