Federal
Cybersecurity State Coordinator Act of 2020
Source: Congress.gov ·
2,138 words in original text
Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
Calendar No. 458
116TH CONGRESS
2D SESSION
S. 3207
[Report No. 116–227]
To require the Director of the Cybersecurity and Infrastructure Security
Agency to establish a Cybersecurity State Coordinator in each State,
and for other purposes.
IN THE SENATE OF THE UNITED STATES
JANUARY 16, 2020
Ms. HASSAN (for herself, Mr. CORNYN, Mr. PORTMAN, Mr. PETERS, Ms.
ROSEN, Mr. VAN HOLLEN, and Ms. SINEMA) introduced the following
bill; which was read twice and referred to the Committee on Homeland
Security and Governmental Affairs
JUNE 1, 2020
Reported by Mr. JOHNSON, with an amendment
[Strike out all after the enacting clause and insert the part printed in italic]
A BILL
To require the Director of the Cybersecurity and Infrastruc-
ture Security Agency to establish a Cybersecurity State
Coordinator in each State, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
2
•S 3207 RS
SECTION 1. SHORT TITLE.
1
This Act may be cited as the ‘‘Cybersecurity State
2
Coordinator Act of 2020’’.
3
SEC. 2. FINDINGS.
4
Congress finds that—
5
(1) cyber threats, such as ransomware, against
6
State, local, Tribal, and territorial entities have
7
grown at an alarming rate;
8
(2) State, local, Tribal, and territorial entities
9
face a growing threat from advanced persistent
10
threat actors, hostile nation states, criminal groups,
11
and other malicious cyber actors;
12
(3) there is an urgent need for greater engage-
13
ment and expertise from the Federal Government to
14
help these entities build their resilience and defenses;
15
and
16
(4) coordination within Federal entities and be-
17
tween Federal and non-Federal entities, including
18
State, local, Tribal, and territorial governments, In-
19
formation Sharing and Analysis Centers, election of-
20
ficials, State adjutants general, and other non-Fed-
21
eral entities, is critical to anticipating, preventing,
22
managing, and recovering from cyberattacks.
23
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6401
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
3
•S 3207 RS
SEC. 3. CYBERSECURITY STATE COORDINATOR.
1
(a) IN GENERAL.—Subtitle A of title XXII of the
2
Homeland Security Act of 2002 (6 U.S.C. 651 et seq.)
3
is amended—
4
(1) in section 2202(c) (6 U.S.C. 652(c))—
5
(A) in paragraph (10), by striking ‘‘and’’
6
at the end;
7
(B) by redesignating paragraph (11) as
8
paragraph (12); and
9
(C) by inserting after paragraph (10) the
10
following:
11
‘‘(11) appoint a Cybersecurity State Coordi-
12
nator in each State, as described in section 2215;
13
and’’; and
14
(2) by adding at the end the following:
15
‘‘SEC. 2215. CYBERSECURITY STATE COORDINATOR.
16
‘‘(a) APPOINTMENT.—The Director shall appoint an
17
employee of the Agency in each State who shall serve as
18
the Cybersecurity State Coordinator.
19
‘‘(b) DUTIES.—The duties of a Cybersecurity State
20
Coordinator appointed under subsection (b) shall in-
21
clude—
22
‘‘(1) building strategic relationships across Fed-
23
eral and non-Federal entities by advising on estab-
24
lishing governance structures to facilitate developing
25
and maintaining secure and resilient infrastructure;
26
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6401
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
4
•S 3207 RS
‘‘(2) serving as a principal Federal cybersecu-
1
rity risk advisor and coordinating between Federal
2
and non-Federal entities to support preparation, re-
3
sponse, and remediation efforts relating to cyberse-
4
curity risks and incidents;
5
‘‘(3) facilitating the sharing of cyber threat in-
6
formation between Federal and non-Federal entities
7
to improve understanding of cybersecurity risks and
8
situational awareness of cybersecurity incidents;
9
‘‘(4) raising awareness of the financial, tech-
10
nical, and operational resources available from the
11
Federal Government to non-Federal entities to in-
12
crease resilience against cyber threats;
13
‘‘(5) supporting training, exercises, and plan-
14
ning for continuity of operations to expedite recovery
15
from cybersecurity incidents, including ransomware;
16
‘‘(6) serving as a principal point of contact for
17
non-Federal entities to engage with the Federal Gov-
18
ernment on preparing, managing, and responding to
19
cybersecurity incidents;
20
‘‘(7) assisting non-Federal entities in developing
21
and coordinating vulnerability disclosure programs
22
consistent with Federal and information security in-
23
dustry standards; and
24
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6401
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
5
•S 3207 RS
‘‘(8) performing such other duties as necessary
1
to achieve the goal of managing cybersecurity risks
2
in the United States and reducing the impact of
3
cyber threats to non-Federal entities.
4
‘‘(c) FEEDBACK.—The Director shall take into ac-
5
count relevant feedback provided by State and local offi-
6
cials regarding the appointment, and State and local offi-
7
cials and other non-Federal entities regarding the per-
8
formance, of the Cybersecurity State Coordinator of a
9
State.’’.
10
(b) OVERSIGHT.—Not later than 1 year after the
11
date of enactment of this Act, the Director of the Cyberse-
12
curity and Infrastructure Security Agency shall provide to
13
the Committee on Homeland Security and Governmental
14
Affairs of the Senate and the Committee on Homeland
15
Security of the House of Representatives a briefing on the
16
placement and efficacy of the Cybersecurity State Coordi-
17
nators appointed under section 2215 of the Homeland Se-
18
curity Act of 2002, as added by subsection (a).
19
(c) RULE OF CONSTRUCTION.—Nothing in this sec-
20
tion or the amendments made by this section shall be con-
21
strued to affect or otherwise modify the authority of Fed-
22
eral law enforcement agencies with respect to investiga-
23
tions relating to cybersecurity incidents.
24
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6401
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
6
•S 3207 RS
(d) TECHNICAL AND CONFORMING AMENDMENT.—
1
The table of contents in section 1(b) of the Homeland Se-
2
curity Act of 2002 (Public Law 107–296; 116 Stat. 2135)
3
is amended by inserting after the item relating to section
4
2214 the following:
5
‘‘Sec. 2215. Cybersecurity State Coordinator.’’.
SECTION 1. SHORT TITLE.
6
This Act may be cited as the ‘‘Cybersecurity State Co-
7
ordinator Act of 2020’’.
8
SEC. 2. FINDINGS.
9
Congress finds that—
10
(1) cyber threats, such as ransomware, against
11
State, local, Tribal, and territorial entities have
12
grown at an alarming rate;
13
(2) State, local, Tribal, and territorial entities
14
face a growing threat from advanced persistent threat
15
actors, hostile nation states, criminal groups, and
16
other malicious cyber actors;
17
(3) there is an urgent need for greater engage-
18
ment and expertise from the Federal Government to
19
help these entities build their resilience and defenses;
20
and
21
(4) coordination within Federal entities and be-
22
tween Federal and non-Federal entities, including
23
State, local, Tribal, and territorial governments, In-
24
formation Sharing and Analysis Centers, election offi-
25
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6203
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
7
•S 3207 RS
cials, State adjutants general, and other non-Federal
1
entities, is critical to anticipating, preventing, man-
2
aging, and recovering from cyberattacks.
3
SEC. 3. CYBERSECURITY STATE COORDINATOR.
4
(a) IN GENERAL.—Subtitle A of title XXII of the
5
Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is
6
amended—
7
(1) in section 2202(c) (6 U.S.C. 652(c))—
8
(A) in paragraph (10), by striking ‘‘and’’
9
at the end;
10
(B) by redesignating paragraph (11) as
11
paragraph (12); and
12
(C) by inserting after paragraph (10) the
13
following:
14
‘‘(11) appoint a Cybersecurity State Coordinator
15
in each State, as described in section 2215; and’’; and
16
(2) by adding at the end the following:
17
‘‘SEC. 2215. CYBERSECURITY STATE COORDINATOR.
18
‘‘(a) APPOINTMENT.—The Director shall appoint an
19
employee of the Agency in each State, with the appropriate
20
cybersecurity qualifications and expertise, who shall serve
21
as the Cybersecurity State Coordinator.
22
‘‘(b) DUTIES.—The duties of a Cybersecurity State Co-
23
ordinator appointed under subsection (a) shall include—
24
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6203
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
8
•S 3207 RS
‘‘(1) building strategic relationships across Fed-
1
eral and, on a voluntary basis, non-Federal entities
2
by advising on establishing governance structures to
3
facilitate the development and maintenance of secure
4
and resilient infrastructure;
5
‘‘(2) serving as a Federal cybersecurity risk ad-
6
visor and coordinating between Federal and, on a vol-
7
untary basis, non-Federal entities to support prepa-
8
ration, response, and remediation efforts relating to
9
cybersecurity risks and incidents;
10
‘‘(3) facilitating the sharing of cyber threat in-
11
formation between Federal and, on a voluntary basis,
12
non-Federal entities to improve understanding of cy-
13
bersecurity risks and situational awareness of cyberse-
14
curity incidents;
15
‘‘(4) raising awareness of the financial, tech-
16
nical, and operational resources available from the
17
Federal Government to non-Federal entities to in-
18
crease resilience against cyber threats;
19
‘‘(5) supporting training, exercises, and plan-
20
ning for continuity of operations to expedite recovery
21
from cybersecurity incidents, including ransomware;
22
‘‘(6) serving as a principal point of contact for
23
non-Federal entities to engage, on a voluntary basis,
24
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6203
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
9
•S 3207 RS
with the Federal Government on preparing, man-
1
aging, and responding to cybersecurity incidents;
2
‘‘(7) assisting non-Federal entities in developing
3
and coordinating vulnerability disclosure programs
4
consistent with Federal and information security in-
5
dustry standards; and
6
‘‘(8) performing such other duties as determined
7
necessary by the Director to achieve the goal of man-
8
aging cybersecurity risks in the United States and re-
9
ducing the impact of cyber threats to non-Federal en-
10
tities.
11
‘‘(c) FEEDBACK.—The Director shall consult with rel-
12
evant State and local officials regarding the appointment,
13
and State and local officials and other non-Federal entities
14
regarding the performance, of the Cybersecurity State Coor-
15
dinator of a State.’’.
16
(b) OVERSIGHT.—The Director of the Cybersecurity
17
and Infrastructure Security Agency shall provide to the
18
Committee on Homeland Security and Governmental Af-
19
fairs of the Senate and the Committee on Homeland Secu-
20
rity of the House of Representatives a briefing on the place-
21
ment and efficacy of the Cybersecurity State Coordinators
22
appointed under section 2215 of the Homeland Security Act
23
of 2002, as added by subsection (a)—
24
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6203
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
10
•S 3207 RS
(1) not later than 1 year after the date of enact-
1
ment of this Act; and
2
(2) not later than 2 years after providing the
3
first briefing under this subsection.
4
(c) RULE OF CONSTRUCTION.—Nothing in this section
5
or the amendments made by this section shall be construed
6
to affect or otherwise modify the authority of Federal law
7
enforcement agencies with respect to investigations relating
8
to cybersecurity incidents.
9
(d) TECHNICAL AND CONFORMING AMENDMENT.—The
10
table of contents in section 1(b) of the Homeland Security
11
Act of 2002 (Public Law 107–296; 116 Stat. 2135) is
12
amended by inserting after the item relating to section 2214
13
the following:
14
‘‘Sec. 2215. Cybersecurity State Coordinator.’’.
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6213
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6213
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
Calendar No. 458
116TH CONGRESS
2D SESSION
S. 3207
[Report No. 116–227]
A BILL
To require the Director of the Cybersecurity and
Infrastructure Security Agency to establish a Cy-
bersecurity State Coordinator in each State, and
for other purposes.
JUNE 1, 2020
Reported with an amendment
VerDate Sep 11 2014
01:39 Jun 02, 2020
Jkt 099200
PO 00000
Frm 00012
Fmt 6651
Sfmt 6651
E:\BILLS\S3207.RS
S3207
pamtmann on DSKBC07HB2PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.