Plain English summary not yet available
The full original text is available below. Check back soon as we process this bill.
II
Calendar No. 195
118TH CONGRESS
1ST SESSION
S. 1425
[Report No. 118–92]
To require a report on Federal support to the cybersecurity of commercial
satellite systems, and for other purposes.
IN THE SENATE OF THE UNITED STATES
MAY 3, 2023
Mr. PETERS (for himself and Mr. CORNYN) introduced the following bill;
which was read twice and referred to the Committee on Homeland Secu-
rity and Governmental Affairs
SEPTEMBER 5, 2023
Reported by Mr. PETERS, with an amendment
[Strike out all after the enacting clause and insert the part printed in italic]
A BILL
To require a report on Federal support to the cybersecurity
of commercial satellite systems, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Satellite Cybersecurity
4
Act’’.
5
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
2
•S 1425 RS
SEC. 2. DEFINITIONS.
1
In this Act:
2
(1)
CLEARINGHOUSE.—The
term
‘‘clearing-
3
house’’ means the commercial satellite system cyber-
4
security clearinghouse required to be developed and
5
maintained under section 4(b)(1).
6
(2)
COMMERCIAL
SATELLITE
SYSTEM.—The
7
term ‘‘commercial satellite system’’—
8
(A) means a system that—
9
(i) is owned or operated by a non-
10
Federal entity based in the United States;
11
and
12
(ii) is composed of not less than 1
13
earth satellite; and
14
(B) includes—
15
(i) any ground support infrastructure
16
for each satellite in the system; and
17
(ii) any transmission link among and
18
between any satellite in the system and
19
any ground support infrastructure in the
20
system.
21
(3)
CRITICAL
INFRASTRUCTURE.—The
term
22
‘‘critical infrastructure’’ has the meaning given the
23
term in subsection (e) of the Critical Infrastructure
24
Protection Act of 2001 (42 U.S.C. 5195c(e)).
25
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
3
•S 1425 RS
(4) CYBERSECURITY RISK.—The term ‘‘cyberse-
1
curity risk’’ has the meaning given the term in sec-
2
tion 2209 of the Homeland Security Act of 2002 (6
3
U.S.C. 659).
4
(5) CYBERSECURITY THREAT.—The term ‘‘cy-
5
bersecurity threat’’ has the meaning given the term
6
in section 102 of the Cybersecurity Information
7
Sharing Act of 2015 (6 U.S.C. 1501).
8
(6) DIRECTOR.—The term ‘‘Director’’ means
9
the Director of the Cybersecurity and Infrastructure
10
Security Agency.
11
(7) SECTOR RISK MANAGEMENT AGENCY.—The
12
term ‘‘sector risk management agency’’ has the
13
meaning given the term ‘‘Sector-Specific Agency’’ in
14
section 2201 of the Homeland Security Act of 2002
15
(6 U.S.C. 651).
16
SEC. 3. REPORT ON COMMERCIAL SATELLITE CYBERSECU-
17
RITY.
18
(a) STUDY.—The Comptroller General of the United
19
States shall conduct a study on the actions the Federal
20
Government has taken to support the cybersecurity of
21
commercial satellite systems, including as part of any ac-
22
tion to address the cybersecurity of critical infrastructure
23
sectors.
24
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
4
•S 1425 RS
(b) REPORT.—Not later than 2 years after the date
1
of enactment of this Act, the Comptroller General of the
2
United States shall report to the Committee on Homeland
3
Security and Governmental Affairs and the Committee on
4
Commerce, Science, and Transportation of the Senate and
5
the Committee on Homeland Security and the Committee
6
on Science, Space, and Technology of the House of Rep-
7
resentatives on the study conducted under subsection (a),
8
which shall include information—
9
(1) on efforts of the Federal Government, and
10
the effectiveness of those efforts, to—
11
(A) address or improve the cybersecurity of
12
commercial satellite systems; and
13
(B) support related efforts with inter-
14
national entities or the private sector;
15
(2) on the resources made available to the pub-
16
lic by Federal agencies to address cybersecurity risks
17
and threats to commercial satellite systems, includ-
18
ing resources made available through the clearing-
19
house;
20
(3) on the extent to which commercial satellite
21
systems are reliant on, or relied on by, critical infra-
22
structure;
23
(4) that includes an analysis of how commercial
24
satellite systems and the threats to those systems
25
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
5
•S 1425 RS
are integrated into Federal and non-Federal critical
1
infrastructure risk analyses and protection plans;
2
(5) on the extent to which Federal agencies are
3
reliant on commercial satellite systems and how Fed-
4
eral agencies mitigate cybersecurity risks associated
5
with those systems;
6
(6) on the extent to which Federal agencies are
7
reliant on commercial satellite systems that are
8
owned wholly or in part or controlled by foreign enti-
9
ties, or that have infrastructure in foreign countries,
10
and how Federal agencies mitigate associated cyber-
11
security risks;
12
(7) on the extent to which Federal agencies co-
13
ordinate or duplicate authorities and take other ac-
14
tions focused on the cybersecurity of commercial sat-
15
ellite systems; and
16
(8) as determined appropriate by the Comp-
17
troller General of the United States, that includes
18
recommendations for further Federal action to sup-
19
port the cybersecurity of commercial satellite sys-
20
tems, including recommendations on information
21
that should be shared through the clearinghouse.
22
(c) CONSULTATION.—In carrying out subsections (a)
23
and (b), the Comptroller General of the United States
24
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
6
•S 1425 RS
shall coordinate with appropriate Federal agencies and or-
1
ganizations, including—
2
(1) the Office of the National Cyber Director;
3
(2) the Department of Homeland Security;
4
(3) the Department of Commerce;
5
(4) the Department of Defense;
6
(5) the Department of Transportation;
7
(6) the Federal Communications Commission;
8
(7) the National Aeronautics and Space Admin-
9
istration;
10
(8)
the
National
Executive
Committee
for
11
Space-Based Positioning, Navigation, and Timing;
12
and
13
(9) the National Space Council.
14
(d) BRIEFING.—Not later than 2 years after the date
15
of enactment of this Act, the Comptroller General of the
16
United States shall provide a briefing to the appropriate
17
congressional committees on the study conducted under
18
subsection (a).
19
(e) CLASSIFICATION.—The report made under sub-
20
section (b) shall be unclassified but may include a classi-
21
fied annex.
22
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
7
•S 1425 RS
SEC. 4. RESPONSIBILITIES OF THE CYBERSECURITY AND
1
INFRASTRUCTURE SECURITY AGENCY.
2
(a) SMALL BUSINESS CONCERN DEFINED.—In this
3
section, the term ‘‘small business concern’’ has the mean-
4
ing given the term in section 3 of the Small Business Act
5
(15 U.S.C. 632).
6
(b) ESTABLISHMENT
OF COMMERCIAL SATELLITE
7
SYSTEM CYBERSECURITY CLEARINGHOUSE.—
8
(1) IN
GENERAL.—Not later than 180 days
9
after the date of enactment of this Act, the Director
10
shall develop and maintain a commercial satellite
11
system cybersecurity clearinghouse.
12
(2) REQUIREMENTS.—The clearinghouse—
13
(A) shall be publicly available online;
14
(B) shall contain publicly available com-
15
mercial satellite system cybersecurity resources,
16
including the voluntary recommendations con-
17
solidated under subsection (c)(1);
18
(C) shall contain appropriate materials for
19
reference by entities that develop, operate, or
20
maintain commercial satellite systems;
21
(D)
shall
contain
materials
specifically
22
aimed at assisting small business concerns with
23
the secure development, operation, and mainte-
24
nance of commercial satellite systems; and
25
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
8
•S 1425 RS
(E) may contain controlled unclassified in-
1
formation distributed to commercial entities
2
through a process determined appropriate by
3
the Director.
4
(3)
CONTENT
MAINTENANCE.—The
Director
5
shall maintain current and relevant cybersecurity in-
6
formation on the clearinghouse.
7
(4) EXISTING PLATFORM OR WEBSITE.—To the
8
extent practicable, the Director shall establish and
9
maintain the clearinghouse using an online platform,
10
a website, or a capability in existence as of the date
11
of enactment of this Act.
12
(c) CONSOLIDATION
OF COMMERCIAL SATELLITE
13
SYSTEM CYBERSECURITY RECOMMENDATIONS.—
14
(1) IN GENERAL.—The Director shall consoli-
15
date voluntary cybersecurity recommendations de-
16
signed to assist in the development, maintenance,
17
and operation of commercial satellite systems.
18
(2)
REQUIREMENTS.—The
recommendations
19
consolidated under paragraph (1) shall include mate-
20
rials appropriate for a public resource addressing, to
21
the greatest extent practicable, the following:
22
(A) Risk-based, cybersecurity-informed en-
23
gineering, including continuous monitoring and
24
resiliency.
25
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
9
•S 1425 RS
(B) Planning for retention or recovery of
1
positive control of commercial satellite systems
2
in the event of a cybersecurity incident.
3
(C) Protection against unauthorized access
4
to vital commercial satellite system functions.
5
(D) Physical protection measures designed
6
to reduce the vulnerabilities of a commercial
7
satellite system’s command, control, and telem-
8
etry receiver systems.
9
(E) Protection against jamming, eaves-
10
dropping, hijacking, computer network exploi-
11
tation, spoofing, threats to optical satellite com-
12
munications, and electromagnetic pulse.
13
(F) Security against threats throughout a
14
commercial satellite system’s mission lifetime.
15
(G) Management of supply chain risks that
16
affect the cybersecurity of commercial satellite
17
systems.
18
(H)
Protection
against
vulnerabilities
19
posed by ownership of commercial satellite sys-
20
tems or commercial satellite system companies
21
by foreign entities.
22
(I) Protection against vulnerabilities posed
23
by locating physical infrastructure, such as sat-
24
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00009
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
10
•S 1425 RS
ellite ground control systems, in foreign coun-
1
tries.
2
(J) As appropriate, and as applicable pur-
3
suant to the maintenance requirement under
4
subsection (b)(3), relevant findings and rec-
5
ommendations from the study conducted by the
6
Comptroller General of the United States under
7
section 3(a).
8
(K) Any other recommendations to ensure
9
the confidentiality, availability, and integrity of
10
data residing on or in transit through commer-
11
cial satellite systems.
12
(d) IMPLEMENTATION.—In implementing this sec-
13
tion, the Director shall—
14
(1) to the extent practicable, carry out the im-
15
plementation in partnership with the private sector;
16
(2) coordinate with—
17
(A) the Office of the National Cyber Direc-
18
tor, the National Space Council, and the head
19
of any other agency determined appropriate by
20
the Office of the National Cyber Director or the
21
National Space Council; and
22
(B) the heads of appropriate Federal agen-
23
cies with expertise and experience in satellite
24
operations, including the entities described in
25
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00010
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
11
•S 1425 RS
section 3(c) to enable the alignment of Federal
1
efforts on commercial satellite system cyberse-
2
curity and, to the extent practicable, consist-
3
ency in Federal recommendations relating to
4
commercial satellite system cybersecurity; and
5
(3) consult with non-Federal entities developing
6
commercial satellite systems or otherwise supporting
7
the cybersecurity of commercial satellite systems, in-
8
cluding private, consensus organizations that develop
9
relevant standards.
10
(e) REPORT.—Not later than 1 year after the date
11
of enactment of this Act, and every 2 years thereafter until
12
the date that is 9 years after the date of enactment of
13
this Act, the Director shall submit to the Committee on
14
Homeland Security and Governmental Affairs and the
15
Committee on Commerce, Science, and Transportation of
16
the Senate and the Committee on Homeland Security and
17
the Committee on Science, Space, and Technology of the
18
House of Representatives a report summarizing—
19
(1) any partnership with the private sector de-
20
scribed in subsection (d)(1);
21
(2) any consultation with a non-Federal entity
22
described in subsection (d)(3);
23
(3) the coordination carried out pursuant to
24
subsection (d)(2);
25
VerDate Sep 11 2014
01:04 Sep 06, 2023
Jkt 039200
PO 00000
Frm 00011
Fmt 6652
Sfmt 6401
E:\BILLS\S1425.RS
S1425
pbinns on DSKJLVW7X2PROD with $$_JOB
12
•S 1425 RS
(4) the establishment and maintenance of the
1
clearinghouse pursuant to subsection (b);
2
(5) the recommendations consolidated pursuant
3
to subsection (c)(1); and
4
(6) any feedback received by the Director on
5
the clearinghouse from non-Federal entities.
6
SEC. 5. STRATEGY.
7
Not later than 120 days after the date of the enact-
8
ment of this Act, the National Space Council, jointly with
9
the Office of the National Cyber Director, in coordination
10
with the Director of the Office of Space Commerce and
11
the heads of other relevant agencies, shall submit to the
12
Committee on Homeland Security and Governmental Af-
13
fairs and the Committee on Commerce, Science, and
14
Transportation of the Senate and the Committee on
15
Homeland Security and the Committee on Science, Space,
16
and Technology of the House of Representatives a strat-
17
egy for the activities of Federal agencies to address and
18
improve the cybersecurity of commercial satellite systems,
19
which shall include an identification of—
20
(1) proposed roles and responsibilities for rel-
21
evant agencies; and
22
(2) as applicable, the extent to whic
[Text truncated for display. Full text available on Congress.gov.]
Important: This plain English summary was generated by AI and is provided for informational purposes only.
It is not legal advice. Always consult the official bill text on Congress.gov
or a qualified attorney for legal matters.