Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
116TH CONGRESS
1ST SESSION
S. 890
To authorize the Sergeant at Arms to protect the personal technology devices
and accounts of Senators and covered employees from cyber attacks
and hostile information collection activities, and for other purposes.
IN THE SENATE OF THE UNITED STATES
MARCH 27, 2019
Mr. WYDEN (for himself and Mr. COTTON) introduced the following bill; which
was read twice and referred to the Committee on Rules and Administration
A BILL
To authorize the Sergeant at Arms to protect the personal
technology devices and accounts of Senators and covered
employees from cyber attacks and hostile information
collection activities, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Senate Cybersecurity
4
Protection Act’’.
5
SEC. 2. DEFINITIONS.
6
In this Act—
7
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
2
•S 890 IS
(1) the term ‘‘covered employing office’’
1
means—
2
(A) the personal office of a Senator;
3
(B) the office of a committee of the Sen-
4
ate;
5
(C) any other office of the Senate not de-
6
scribed in subparagraph (A) or (B); or
7
(D) the office of a joint committee or joint
8
commission;
9
(2) the term ‘‘covered employee’’ means an indi-
10
vidual—
11
(A) who is employed or serving in a posi-
12
tion as—
13
(i) an officer or employee of a covered
14
employing office;
15
(ii) a detailee in a covered employing
16
office, without regard to whether the serv-
17
ice is on a reimbursable basis; or
18
(iii) a fellow in a covered employing
19
office, without regard to whether the posi-
20
tion is compensated or the source of the
21
compensation;
22
(B) who is not a Senate authorizer; and
23
(C) whom the covered employing office has
24
determined is highly vulnerable to cyber attacks
25
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
3
•S 890 IS
and hostile information collection activities be-
1
cause of the position of the individual;
2
(3) the term ‘‘personal account’’ means an ac-
3
count for online or telecommunications services (in-
4
cluding telephone, residential internet access, email,
5
text and multimedia messaging, cloud computing, so-
6
cial media, health care, and financial services)—
7
(A) used by a Senate authorizer or covered
8
employee;
9
(B) that is not administered or operated
10
by the Sergeant at Arms; and
11
(C) with respect to which the parties sign-
12
ing the security memorandum of understanding
13
as described in paragraph (6)(A) jointly agree
14
that the Sergeant at Arms will provide security,
15
in accordance with this Act;
16
(4) the term ‘‘personal technology device’’—
17
(A) means a handheld communications de-
18
vice, laptop computer, desktop computer, or
19
other internet-connected device—
20
(i) used by a Senate authorizer or cov-
21
ered employee;
22
(ii) that is not provided to the Senate
23
authorizer or covered employee, or admin-
24
istered, by the Sergeant at Arms; and
25
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
4
•S 890 IS
(iii) with respect to which the parties
1
signing the security memorandum of un-
2
derstanding as described in paragraph
3
(6)(A) jointly agree that the Sergeant at
4
Arms will provide security, in accordance
5
with this Act; and
6
(B) may, if agreed to by the parties pursu-
7
ant to the security memorandum of under-
8
standing, include any computer network to
9
which a computer or device described in sub-
10
paragraph (A) connects;
11
(5) the term ‘‘provide security’’ means to pro-
12
vide training, advice, support, technical assistance,
13
and other services to prevent, detect, and recover
14
from cyber attacks and hostile information collection
15
activities;
16
(6) the term ‘‘security memorandum of under-
17
standing’’ means a written memorandum of under-
18
standing that—
19
(A) is signed by—
20
(i) the Sergeant at Arms;
21
(ii) the Senate authorizer or covered
22
employee for whom the security will be
23
provided pursuant to the memorandum;
24
and
25
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
5
•S 890 IS
(iii) if the security is being provided
1
for a covered employee, the applicable Sen-
2
ate authorizer for the covered employee;
3
(B) specifies the personal accounts or per-
4
sonal technology devices, or categories of per-
5
sonal accounts or personal technology devices,
6
for which the Sergeant at Arms will provide se-
7
curity;
8
(C) describes the rights and responsibilities
9
of each signing party relating to the provision
10
of security and with respect to privacy; and
11
(D) shall be effective for a period of not
12
more than 1 year;
13
(7) the term ‘‘Senate authorizer’’—
14
(A) means a Senator or the head of a Sen-
15
ate office described in paragraph (1)(C);
16
(B) when used with respect to a covered
17
employee not described in subparagraph (C),
18
means the Senator or the head of a Senate of-
19
fice who has final authority to appoint, hire,
20
discharge, and set the terms, conditions, or
21
privileges of the employment of the covered em-
22
ployee; and
23
(C) when used with respect to a covered
24
employee of a joint committee or joint commis-
25
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
6
•S 890 IS
sion, the Senator from the majority party of the
1
Senate who—
2
(i) is a member of, or has authority
3
over, the committee or commission; and
4
(ii) serves in the highest leadership
5
role for a Senator in the committee or
6
commission or, if there is no such leader-
7
ship role, is the most senior Senator from
8
the majority party of the committee or
9
commission; and
10
(8) the term ‘‘Sergeant at Arms’’ means the
11
Sergeant at Arms and Doorkeeper of the Senate.
12
SEC. 3. CYBERSECURITY ASSISTANCE FOR PERSONAL
13
TECHNOLOGY DEVICES AND ACCOUNTS.
14
(a) AUTHORIZATION.—
15
(1) IN GENERAL.—Upon request by a Senate
16
authorizer and upon the signing of a security memo-
17
randum of understanding by the parties described in
18
section 2(6)(A), the Sergeant at Arms may use
19
funds provided for official purposes in order to pro-
20
vide security for personal accounts and personal
21
technology devices of the Senate authorizer or a cov-
22
ered employee of the Senate authorizer.
23
(2) ANNUAL RENEWAL.—A Senate authorizer
24
or covered employee for whom the Sergeant at Arms
25
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
7
•S 890 IS
is providing security for personal accounts and per-
1
sonal technology devices under a security memo-
2
randum of understanding may continue to receive
3
such security services under this Act if the applica-
4
ble signing parties described in section 2(6)(A) enter
5
into a security memorandum of understanding each
6
year.
7
(b) AGGREGATE REPORTING.—By the date that is 2
8
years after the date of enactment of this Act, and annually
9
thereafter, the Sergeant at Arms shall prepare and submit
10
to the Committee on Rules and Administration and the
11
Select Committee on Intelligence of the Senate a report
12
that includes aggregate statistics for the preceding fiscal
13
year of the number of Senate authorizers and covered em-
14
ployees who entered into a security memorandum of un-
15
derstanding with the Sergeant at Arms and received secu-
16
rity assistance for their personal accounts and personal
17
technology devices.
18
(c) RULE OF CONSTRUCTION.—Nothing in this Act
19
shall be construed to encourage any Senator or covered
20
employee to conduct official Government business using
21
a personal technology device.
22
SEC. 4. ANNUAL GAO REPORTS ON CYBERSECURITY AND
23
SURVEILLANCE THREATS.
24
(a) ANNUAL REPORTS.—
25
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
8
•S 890 IS
(1) IN GENERAL.—Beginning 180 days after
1
the date of enactment of this Act, and annually
2
thereafter, the Comptroller General of the United
3
States shall prepare and submit, to the Committee
4
on Rules and Administration and the Select Com-
5
mittee on Intelligence of the Senate, a report regard-
6
ing cybersecurity and surveillance threats to the leg-
7
islative branch.
8
(2) STATISTICS.—Each report required under
9
paragraph (1) shall include statistics on cyber at-
10
tacks, and other incidents of espionage or surveil-
11
lance targeted against Senators or the immediate
12
families or staff of the Senators, in which the non-
13
public communications and other private information
14
of such targeted individuals were lost, stolen, or oth-
15
erwise subject to unauthorized access by criminals or
16
a foreign government.
17
(b) CONSULTATION.—In preparing the report re-
18
quired under subsection (a), the Comptroller General shall
19
consult with the Director of National Intelligence and the
20
Sergeant at Arms.
21
Æ
VerDate Sep 11 2014
03:10 Apr 04, 2019
Jkt 089200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6301
E:\BILLS\S890.IS
S890
kjohnson on DSK79L0C42 with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.