Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
I
118TH CONGRESS
1ST SESSION H. R. 2845
To direct the Director of the Cybersecurity and Infrastructure Security Agen-
cy to establish a School Cybersecurity Improvement Program, and for
other purposes.
IN THE HOUSE OF REPRESENTATIVES
APRIL 25, 2023
Ms. MATSUI (for herself and Mr. NUNN of Iowa) introduced the following bill;
which was referred to the Committee on Homeland Security, and in addi-
tion to the Committee on Education and the Workforce, for a period to
be subsequently determined by the Speaker, in each case for consider-
ation of such provisions as fall within the jurisdiction of the committee
concerned
A BILL
To direct the Director of the Cybersecurity and Infrastruc-
ture Security Agency to establish a School Cybersecurity
Improvement Program, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may cited as the ‘‘Enhancing K–12 Cyberse-
4
curity Act’’.
5
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
2
•HR 2845 IH
SEC.
2.
SCHOOL
CYBERSECURITY
INFORMATION
EX-
1
CHANGE.
2
(a) ESTABLISHMENT.—The Director of the Cyberse-
3
curity and Infrastructure Security Agency shall enhance
4
existing
information
exchange
efforts
implemented
5
through partnerships with one or more information shar-
6
ing and analysis organizations to focus specific attention
7
on the needs of K–12 organizations with regard to cyber-
8
security, including a new publicly accessible website (to be
9
known as the ‘‘School Cybersecurity Information Ex-
10
change’’) to disseminate information, cybersecurity best
11
practices, training, and lessons learned tailored to the spe-
12
cific needs, technical expertise, and resources available to
13
K–12 organizations in accordance with subsection (b).
14
(b) DUTIES.—In establishing the School Cybersecu-
15
rity Information Exchange under subsection (a), the Di-
16
rector shall—
17
(1) engage appropriate Federal, State, local,
18
and nongovernmental organizations to identify, pro-
19
mote, and disseminate information and best prac-
20
tices for local educational agencies, State educational
21
agencies, and educational service agencies (as such
22
terms are defined in section 8101 of the Elementary
23
and Secondary Education Act of 1965 (20 U.S.C.
24
7801)) with respect to cybersecurity, data protec-
25
VerDate Sep 11 2014
01:30 May 02, 2023
Jkt 039200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
3
•HR 2845 IH
tion, remote learning security, and student online
1
privacy;
2
(2) maintain a database for an elementary
3
school, secondary school, local educational agency,
4
State educational agency, and educational service
5
agency to identify cybersecurity security tools and
6
services funded by the Federal Government, as well
7
as tools and services recommended for purchase with
8
State and local government funding; and
9
(3) provide a searchable database for an ele-
10
mentary school, secondary school, local educational
11
agency, State educational agency, and educational
12
service agency to find and apply for funding oppor-
13
tunities to improve cybersecurity.
14
(c) CONSULTATION.—In carrying out the duties
15
under subsection (b), the Director shall consult with the
16
following:
17
(1) The Secretary of Education.
18
(2) The Director of the National Institute of
19
Standards and Technology.
20
(3) The Federal Communication Commission.
21
(4) The Director of the National Science Foun-
22
dation.
23
(5) The Federal Bureau of Investigation.
24
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
4
•HR 2845 IH
(6) State and local leaders, including, when ap-
1
propriate, Governors, employees of State government
2
departments and agencies, members of State legisla-
3
tures and State boards of education, local edu-
4
cational agencies, State educational agencies, rep-
5
resentatives of Indian tribes, teachers, principals,
6
other school leaders, charter school leaders, special-
7
ized instructional support personnel, paraprofes-
8
sionals, administrators, other staff, and parents.
9
(7) When determined appropriate by the Direc-
10
tor, subject-matter experts and expert organizations,
11
including nongovernmental organizations, vendors of
12
school information technology products and services,
13
cybersecurity insurance companies, and cybersecu-
14
rity threat companies.
15
SEC. 3. CYBERSECURITY INCIDENT REGISTRY.
16
(a) IN GENERAL.—The Director of the Cybersecurity
17
and Infrastructure Security Agency shall establish,
18
through partnerships with one or more information shar-
19
ing and analysis organizations, a voluntary registry of in-
20
formation relating to cyber incidents affecting information
21
technology systems owned or managed by a covered entity,
22
and determine the scope of cyber incidents to be included
23
in the registry and processes by which incidents can be
24
reported for collection in the registry.
25
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
5
•HR 2845 IH
(b) USE.—Information in the registry established
1
pursuant to subsection (a) may be used to—
2
(1) improve data collection and coordination ac-
3
tivities related to the nationwide monitoring of the
4
incidence and impact of cyber incidents affecting a
5
covered entity;
6
(2) conduct analyses regarding trends in cyber
7
incidents against such entity;
8
(3) develop systematic approaches to assist such
9
entity in preventing and responding to cyber inci-
10
dents;
11
(4) increase the awareness and preparedness of
12
a covered entity regarding the cybersecurity of such
13
covered entity; and
14
(5) identify, prevent, or investigate cyber inci-
15
dents targeting a covered entity.
16
(c) INFORMATION COLLECTION.—The Director of the
17
Cybersecurity and Infrastructure Security Agency may
18
collect information relating to cyber incidents to store in
19
the registry established pursuant to subsection (a). Such
20
information may be submitted by a covered entity and may
21
include the following:
22
(1) The dates of each cyber incident, including
23
the dates on which each such incident was initially
24
detected and the dates on which each such incident
25
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
6
•HR 2845 IH
was first publicly reported or disclosed to another
1
entity.
2
(2) A description of each cyber incident, which
3
shall include whether each such incident was as a re-
4
sult of a breach, malware, distributed denial of serv-
5
ice attack, or other method designed to cause a vul-
6
nerability.
7
(3) The effects of each cyber incident, including
8
descriptions of the type and size of each such inci-
9
dent.
10
(4) Other information determined relevant by
11
the Director.
12
(d) REPORT.—The Director of the Cybersecurity and
13
Infrastructure Security Agency shall make available on
14
the School Cybersecurity Information Exchange estab-
15
lished under section 2 an annual report relating to cyber
16
incidents affecting elementary schools and secondary
17
schools which includes data, and the analysis of such data,
18
in a manner that—
19
(1) is—
20
(A) de-identified; and
21
(B) presented in the aggregate; and
22
(2) at a minimum, protects personal privacy to
23
the extent required by applicable Federal and State
24
privacy laws.
25
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
7
•HR 2845 IH
(e) COVERED ENTITY DEFINED.—In this section, the
1
term ‘‘covered entity’’ means the following:
2
(1) An elementary school.
3
(2) A secondary school.
4
(3) A local educational agency.
5
(4) A State educational agency.
6
(5) An educational service agency.
7
SEC. 4. K–12 CYBERSECURITY TECHNOLOGY IMPROVEMENT
8
PROGRAM.
9
(a) ESTABLISHMENT.—The Director of the Cyberse-
10
curity and Infrastructure Security Agency, shall establish,
11
through partnerships with one or more information shar-
12
ing and analysis organizations, a program (to be known
13
as the ‘‘K–12 Cybersecurity Technology Improvement pro-
14
gram’’) to deploy cybersecurity capabilities to address cy-
15
bersecurity risks and threats to information systems of el-
16
ementary schools and secondary schools through—
17
(1) developing cybersecurity strategies and in-
18
stallation of effective cybersecurity tools tailored for
19
K–12 schools;
20
(2) making available cybersecurity services that
21
enhance the ability of K–12 schools to protect them-
22
selves from ransomware and other cybersecurity
23
threats; and
24
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
8
•HR 2845 IH
(3) continuing training opportunities on cyber-
1
security threats, best practices, and relevant tech-
2
nologies for K–12 schools.
3
(b) REPORT.—The Director of the Cybersecurity and
4
Infrastructure Security Agency shall make available on
5
the School Cybersecurity Information Exchange estab-
6
lished under section 2 an annual report relating to the
7
impact of the K–12 Cybersecurity Technology Improve-
8
ment Program, including information on the cybersecurity
9
capabilities made available to information technology sys-
10
tems owned or managed by elementary schools, secondary
11
schools, local educational agencies, State educational
12
agencies, and educational service agencies, the number of
13
students served, and cybersecurity incidents identified or
14
prevented.
15
SEC. 5. AUTHORIZATION OF APPROPRIATIONS.
16
There are authorized to be appropriated to carry out
17
this Act $10,000,000 for each of fiscal years 2024 and
18
2025.
19
SEC. 6. DEFINITIONS.
20
In this Act:
21
(1)
EDUCATIONAL
SERVICE
AGENCY.—The
22
term ‘‘educational service agency’’ has the meaning
23
given that term in section 8101 of the Elementary
24
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6201
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
9
•HR 2845 IH
and Secondary Education Act of 1965 (20 U.S.C.
1
7801).
2
(2) ELEMENTARY SCHOOL.—The term ‘‘elemen-
3
tary school’’ has the meaning given that term in sec-
4
tion 8101 of the Elementary and Secondary Edu-
5
cation Act of 1965 (20 U.S.C. 7801).
6
(3) INFORMATION SHARING AND ANALYSIS OR-
7
GANIZATION.—The term ‘‘information sharing and
8
analysis organization’’ has the meaning given that
9
term in section 2200 of the Homeland Security Act
10
of 2002 (6 U.S.C. 650).
11
(4) LOCAL EDUCATIONAL AGENCY.—The term
12
‘‘local educational agency’’ has the meaning given
13
that term in section 8101 of the Elementary and
14
Secondary Education Act of 1965 (20 U.S.C. 7801).
15
(5) STATE EDUCATIONAL AGENCY.—The term
16
‘‘State educational agency’’ has the meaning given
17
that term in section 8101 of the Elementary and
18
Secondary Education Act of 1965 (20 U.S.C. 7801).
19
(6) SECONDARY
SCHOOL.—The term ‘‘sec-
20
ondary school’’ has the meaning given that term in
21
section 8101 of the Elementary and Secondary Edu-
22
cation Act of 1965 (20 U.S.C. 7801).
23
Æ
VerDate Sep 11 2014
22:59 May 01, 2023
Jkt 039200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6301
E:\BILLS\H2845.IH
H2845
kjohnson on DSK79L0C42PROD with BILLS
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.